The EU AI Act allocates obligations by role. Before you can work out what applies to you, you have to establish which role you hold — and companies frequently assume it is none of them because they are not building AI. That assumption is usually wrong.
The two roles that matter for most companies
A provider develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark.
A deployer uses an AI system under its own authority in a professional capacity.
If your company uses an AI assistant for its work, you are a deployer. This surprises people who assumed the regulation concerned technology companies. Deployer obligations are lighter than provider obligations, but they exist.
How the roles can shift
The distinction is not fixed by what kind of company you are. It depends on what you do in a specific case.
Buy a platform and use it as supplied: you are a deployer. Have a custom integration built for your internal use: still generally a deployer, though the arrangement should be documented. Take a system and offer it to your own customers under your own brand: you may have become a provider, with substantially heavier obligations.
That last transition catches people. Rebranding and reselling an AI capability can move you into provider territory without any technical work on your part.
Risk categories
Obligations scale with risk. Certain practices are prohibited outright. A defined set of uses is classified high-risk — including, notably for ordinary businesses, employment contexts such as recruitment screening and decisions affecting workers, as well as access to essential services.
Most general business use — drafting, summarising, internal knowledge search, document processing — falls outside the high-risk category. But if you are considering AI in hiring or personnel decisions, that is precisely where the regulation bites hardest, and it needs proper assessment rather than an assumption.
Transparency
Where people interact with an AI system, they should be able to know that. If you deploy a customer-facing assistant, say that it is one. Certain generated content carries marking expectations as well.
AI literacy
This obligation deserves specific attention because it applies broadly and is widely unnoticed. Both providers and deployers are expected to take measures to ensure a sufficient level of AI literacy among staff dealing with these systems on their behalf.
In practice this means your people should understand what the systems can and cannot do, that outputs can be wrong, and what they must check. For most companies this is a modest training obligation — but it is one that "we haven't formally adopted AI" does not avoid, if employees are using these tools in their work.
What to do
Write down which AI systems are in use and what for. Determine your role for each. Check whether any use falls into a high-risk category, paying particular attention to anything touching employment. Ensure people using these systems have been told, in writing, what they are responsible for checking. And agree roles explicitly in contracts with providers — the allocation should not be left to inference.
This article is general information, not legal advice. For your specific situation, consult a qualified lawyer.