The Week in One Line
Buying an AI system does not transfer your compliance obligations to the vendor. Under the EU AI Act, deployers carry their own responsibilities regardless of who built the technology.
What the Act Actually Says
The Act distinguishes clearly between two roles: providers and deployers.
A provider develops or places an AI system on the market.
A deployer uses that system in a professional context.
Most organisations using enterprise AI tools today are deployers.
Under Article 26, deployers have their own obligations independent of the vendor’s obligations. Those include:
• Using the system according to provider instructions
• Assigning meaningful human oversight
• Ensuring input data is relevant and fit for purpose
• Retaining automated logs
• Actively monitoring system operation
• Reporting serious incidents
One of the most common misconceptions in enterprise AI governance right now is assuming the hard part sits entirely with the vendor.
It does not.
A provider’s certification, audit evidence, or conformity assessment does not substitute for your organisation’s operational responsibilities as the deployer.
Source: artificialintelligenceact.eu – Article 3, Article 26
What This Means for Your Business
Many procurement and compliance teams are currently overestimating vendor-side responsibility.
There is a growing assumption that buying from a major enterprise platform vendor transfers operational liability upstream. In practice, the Act does not work that way.
Your vendor contract probably does not protect you.
Even if the vendor contract includes broad compliance language, your organisation still needs its own:
• Oversight process
• Escalation process
• Classification rationale
• Monitoring capability
• Incident management process
• Evidence trail
Compliance cannot be outsourced operationally.
Internal deployments are not exempt either.
If a company uses high-risk AI internally for:
• Employee monitoring
• Resource allocation
• Workforce decisions
• Internal scoring
• Operational recommendations
...the deployer obligations still apply.
Most companies are currently focusing heavily on procurement review while underinvesting in operational governance after deployment. That imbalance will become a major problem once enforcement activity increases.
Five Evidence Gaps Worth Checking Immediately
- Do we have a named human overseer for every high-risk system?
- Can we access and retain automated logs?
- Is there a documented escalation process?
- Have we documented classification rationale?
- Do we have a serious-incident reporting process?
The Fundamental Rights Impact Assessment requirement is another area many organisations still have not fully assessed.
Certain deployers, particularly in financial, insurance, and public-service contexts, may need a formal FRIA before deployment.
This Week's Action Point
Review the contracts for your top AI vendors.
Specifically check:
• Compliance responsibility clauses
• Liability allocation
• Logging access
• Audit rights
• Incident reporting responsibilities
• AI Act language
If the contract is silent, your organisation still carries the deployer obligation regardless.
Then compare the contract language against your actual internal governance process.
In many companies, those two realities currently do not match.
Further Reading
Article 26 – Obligations of Deployers:
artificialintelligenceact.eu/article/26
EU AI Act Compliance Checker:
artificialintelligenceact.eu/assessment/eu-ai-act-compliance-checker
EU AI Act Timeline:
artificialintelligenceact.eu/implementation-timeline
Next Tuesday
What enforcement actually looks like once national authorities begin investigating non-compliant AI deployments.