# AI Act obligations for businesses that deploy AI

> Most businesses do not build AI systems: they use them. The AI Act gives them a status, that of deployer, with lighter obligations than a provider's, but real ones. This guide goes through them, with the timetable as amended in 2026.

Source: https://smartagt.ai/en/ressources/ai-act-entreprise/
Published: 2026-09-22
Publisher: SmartAGT (NERVIAL LABS)

---
## Provider or deployer: the first sort {#role}

[Regulation (EU) 2024/1689](https://eur-lex.europa.eu/eli/reg/2024/1689/oj), the AI Act, allocates obligations according to each party's role. Two roles matter for a business that makes generative AI available to its teams.

- **Provider** Whoever develops an AI system, or has it developed, and places it on the market or puts it into service under its own name. It carries most of the technical obligations.
- **Deployer** Whoever uses an AI system under its authority, other than in a personal non-professional activity. That is the business equipping its staff with an assistant or agents.

*Definitions from Article 3: the role depends on what you do with the system, not on its technology.*

The role can switch. Under Article 25, a deployer becomes the provider of a high-risk system if it puts its name or trademark on it, makes a substantial modification to it, or changes its intended purpose so that it becomes high-risk. A business that takes a general-purpose assistant and reconfigures it to screen job applications falls into that last case.

## The timetable, after the 2026 omnibus {#timetable}

The AI Act entered into force on 1 August 2024 and applies in stages. The timetable for high-risk systems was postponed by [Regulation (EU) 2026/1744](https://eur-lex.europa.eu/eli/reg/2026/1744/oj), the AI omnibus, which entered into force on 27 July 2026.

| Date | What applies |
| --- | --- |
| 2 February 2025 | Prohibited practices and the AI literacy obligation |
| 2 August 2025 | Governance rules and obligations for general-purpose AI models |
| 2 August 2026 | General application of the regulation, including transparency obligations |
| 2 December 2027 | High-risk systems in the Annex III areas (employment, credit, education, biometrics...) |
| 2 August 2028 | High-risk systems embedded in regulated products (Annex I) |

These are the dates published by the [European Commission](https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai) after the omnibus entered into force. Before it was published, the obligations for Annex III systems were due to apply on 2 August 2026: a compliance plan drawn up in 2025 probably needs realigning.

## What already applies to every deployer {#already}

Even without any high-risk use, three sets of rules concern every business that uses AI.

### Prohibited practices

Article 5 bans certain uses, whoever the provider is. For a business, the most concrete one is the ban on using an AI system to infer the emotions of a person in the workplace or in an educational institution, except for medical or safety reasons. A tool that analyses employees' “sentiment” in meetings or on the phone needs to be examined in that light.

### AI literacy

Article 4 asks providers and deployers to take measures so that their staff have a sufficient level of AI literacy. The 2026 omnibus relaxed this requirement: according to the Commission, it is simplified, with the Commission and the Member States taking a stronger role in promoting it. Training users on how the tools work, their limits and the permitted uses remains the most direct way to meet it.

### Transparency

Article 50 splits the obligations. The provider must design a conversational system so that people know they are interacting with an AI. The deployer, for its part, must:

- inform the people exposed to an emotion recognition or biometric categorisation system;
- disclose that content is a deep fake (image, audio or video generated or manipulated);
- disclose that text published to inform the public on matters of public interest was generated or manipulated by AI, unless it underwent human review or editorial control and a person holds editorial responsibility for it.

## If a use is high-risk {#high-risk}

Annex III lists the high-risk areas. Three directly concern private businesses: recruitment and staff management (screening applications, evaluation, task allocation, promotion or termination decisions), assessing the creditworthiness of natural persons, and pricing in life and health insurance.

For these uses, [Article 26](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-26) requires the deployer, from 2 December 2027, to:

- **Use it as instructed** Follow the provider's instructions and take the matching technical and organisational measures.
- **Assign human oversight** To people who have the necessary competence, training and authority.
- **Control input data** Where it controls it, ensure it is relevant and sufficiently representative.
- **Monitor and report** Monitor operation, inform the provider and authorities of a risk or serious incident, suspend use if necessary.
- **Keep the logs** Retain those under its control for at least six months, unless another rule applies.
- **Inform** Workers' representatives and affected employees before use in the workplace, and the people subject to decisions the system makes or helps make.

*The obligations of the deployer of a high-risk system, Article 26.*

A fundamental rights impact assessment (Article 27) is added for bodies governed by public law, private entities providing public services, and deployers of creditworthiness assessment or life and health insurance pricing systems. Article 26 also provides that the provider's information is used to carry out the impact assessment required by the GDPR: the two exercises are best run together, as explained in the guide [GDPR and generative AI](~/ressources/rgpd-ia-generative/).

Penalties are set by Article 99: up to 35 million euros or 7% of total worldwide annual turnover for a prohibited practice, and up to 15 million euros or 3% for breaches of operators' obligations, including deployers', whichever is higher. For SMEs, it is whichever is lower.

## A four-step approach {#approach}

- **Inventory actual uses**, not just the tools purchased: assistants, agents, AI features built into business software.
- **Qualify your role for each**: deployer by default, provider if you rebranded it, substantially modified it or turned it to a high-risk use.
- **Classify each use**: prohibited, high-risk, subject to transparency, or with no specific obligation.
- **Attach the evidence**: training delivered, instructions, logs, human oversight decisions. These are what an inspection will ask for.

Human oversight and logging are also the governance levers described in the guide [Human approval of agent actions](~/ressources/validation-humaine-agent/). The overall framework is in the guide [Data sovereignty and generative AI](~/ressources/souverainete-donnees-ia/).

## Frequently asked questions {#faq}

### Does using ChatGPT or a similar assistant make us a deployer?

Yes, as soon as the tool is used under the company's authority in a professional context. For general-purpose use, this mainly brings the AI literacy obligation and, depending on the content produced, transparency obligations.

### Is an internal writing assistant a high-risk system?

Generally not. High risk depends on the use, not the technology. The same assistant becomes high-risk if it is used to screen applications or evaluate employees, because those uses are listed in Annex III.

### Does the omnibus postponement cover all obligations?

No. It postpones the obligations for high-risk systems. Prohibited practices, AI literacy and the obligations for general-purpose models already applied, and transparency obligations have applied since August 2026.

### Where SmartAGT fits
SmartAGT is technically aligned with the AI Act requirements that depend on the tool: logging in a SHA-256 hash-chained audit trail, transparency, and human oversight. Any write or execute action by an agent is paused until confirmed, and the decision is recorded with the person who made it.
The platform is not yet certified by a third party. Details are on the [Security](~/security/) page.
