Deployer
What is 'Deployer'
The term 'Deployer' refers to any natural or legal person, public authority, agency, or other body that uses an Artificial Intelligence (AI) system under its authority in a professional or organisational context. The deployer is distinguished from the 'provider' (developer) of the AI system: while a provider creates and trains the AI model, the deployer is the entity that implements it in real-world settings, determines the context and purpose of its use, and bears responsibility for its operation and effects on end-users.
Artificial Intelligence is becoming integral to modern life, fuelling innovation while presenting complex legal challenges. Unlike traditional software, AI operates with a degree of autonomy, producing outcomes that its developers or deployers cannot fully anticipate. Advances in underlying technology have further enhanced this autonomy, giving rise to AI agents — systems capable of interacting with their environment independently, often with minimal or no human oversight. As AI decision-making is inherently imperfect, its increasing deployment inevitably results in instances of harm, prompting the critical question of whether developers and deployers should be held liable under tort law.
Scholars have frequently answered this question in the negative. Many, adopting a framework of technological exceptionalism, assume AI to be uniquely disruptive. Citing the lack of transparency and unpredictability of AI models, they contend that AI challenges conventional notions of causality, rendering existing liability regimes inadequate.
At the regulatory level, the concept of 'deployer' has gained increasing importance across jurisdictions — particularly under the European Union's Artificial Intelligence Act (EU AI Act), which provides the most comprehensive and widely cited legislative framework for the term. The deployer sits at the critical juncture between technology and society, carrying obligations related to monitoring, transparency, human oversight, and compliance.
Official Definition of 'Deployer'
This section presents authoritative definitions of 'Deployer' as articulated in legislation, international instruments, official documents, and policy frameworks.
'Deployer' as Defined in Legislation(s)
EU Artificial Intelligence Act, Article 3(4): The EU AI Act provides the primary binding legislative definition of 'deployer'. Under Article 3(4), a deployer is defined as:
'a natural or legal person, public authority, agency or other body using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity.'
This definition is significant because it is broad and functional — it captures any entity that uses an AI system within a professional or organisational scope, irrespective of whether that entity developed the system. The exclusion of personal, non-professional use ensures that private individuals using everyday AI tools are not swept within the regulatory ambit.[1]
Kentucky Revised Statutes (2025 Session, Act 0066): The Commonwealth of Kentucky enacted one of the early US state-level AI governance frameworks. Under this legislation, a deployer is defined as:
'any state department, state agency, or state administrative body in the Commonwealth that puts into use a high-risk artificial intelligence system.'
This definition is narrower than the EU AI Act — it is limited to public governmental entities and concerns only high-risk AI systems. It reflects a jurisdictionally bounded, government-focused approach to AI deployment governance.[2]
Legal Provisions Relating to 'Deployer'
Article 26 of the EU AI Act sets out the core obligations of deployers of high-risk AI systems. These provisions are conceptually essential for understanding the full regulatory meaning and expectations attached to the role:[1]
• Article 26(1): Deployers must take appropriate technical and organisational measures to ensure high-risk AI systems are used in accordance with instructions provided by the provider. This establishes a mandatory duty of diligence.
• Article 26(2): Human oversight must be assigned to natural persons with the necessary competence, training, and authority. This provision ensures that automated AI decision-making is subject to human checks.
• Article 26(4): Where the deployer exercises control over input data, they must ensure such data is relevant and sufficiently representative for the intended purpose of the AI system.
• Article 26(5): Deployers must monitor operations, inform providers of identified risks, suspend use where necessary, and immediately notify market surveillance authorities of serious incidents.
• Article 26(6): Logs automatically generated by high-risk AI systems must be retained for at least six months, unless applicable Union or national law requires otherwise.
• Article 26(7): Deployers who are employers must inform workers' representatives and affected workers prior to deploying high-risk AI systems in the workplace.
• Article 26(8): Deployers who are public authorities or Union institutions must comply with registration obligations under Article 49 and must not use unregistered high-risk AI systems.
• Article 26(11): Deployers of high-risk AI systems making or assisting in decisions affecting natural persons must inform those persons that they are subject to an AI system.
• Article 26(12): Deployers must cooperate with competent authorities in all actions taken to implement the AI Act.
'Deployer' as Defined in International Instruments
ASEAN Guide on AI Governance and Ethics: The ASEAN Guide provides a non-binding but influential regional governance framework. It defines a deployer as:
'an entity that uses or implements an AI system, which could either be developed by their in-house team or via a third-party developer.'
This definition is wider than the EU AI Act in one respect: it expressly covers entities that use AI systems built in-house, removing any ambiguity about whether self-developed systems fall within the concept. The ASEAN Guide emphasises that deployers have a responsibility to clearly disclose AI implementation to stakeholders, prevent discriminatory outcomes, conduct regular bias testing, perform risk assessments before deployment, and ensure the proper functioning of AI systems in accordance with applicable laws, internal governance policies, and ethical principles.[3]
'Deployer' as Defined in Official Documents
BSA | The Software Alliance — Comments on India's Subcommittee Report on AI Governance Guidelines (Page 3):
This official submission to India's AI governance development process provides a functional distinction between developers and deployers: AI Developers design or produce AI systems, while deployers use those systems. Because of these different roles, their access to data and ability to identify or mitigate risks will vary. Developers have access to information about how the AI system was initially trained, including various aspects of training data such as labelling techniques and types of data. Deployers, by contrast, have greater insight into the context in which that particular AI system is being used, and are better positioned to monitor issues arising during deployment.[4]
Fundamentals of Secure AI Systems with Personal Data: This official framework reiterates the standard definition — a deployer is any natural or legal person, public authority, agency or other body using an AI system under its authority, except where the AI system is used in the course of a personal non-professional activity. The key characteristic is that the deployer operates the AI system as part of an organisational function, not for personal purposes.[10]
'Deployer' as Defined in Official Government Reports
European Parliament Committee on Legal Affairs (JURI) Proposed Amendment
The European Parliament's Committee on Legal Affairs proposed an amendment offering a functionally richer definition of deployer:
'Deployer means the person who decides on the use of the AI-system, exercises control over the associated risk and benefits from its operation.'
This proposed definition focuses on three elements: decision-making authority (the person decides to use the system), risk control (the person is responsible for managing associated risks), and benefit (the person receives the value generated). This formulation is more functional and less identity-based than the final Article 3(4) definition, and reflects an attempt to address accountability gaps.[5]
Variations
The Deployer–Provider Overlap
The terms 'provider' and 'deployer' are not mutually exclusive under the EU AI Act. A deployer can also become a provider, and a provider can also become a deployer. Article 25(1) of the EU AI Act states that if any deployer or third party makes a substantial modification to an AI system, or uses the AI system for a purpose outside its original intended scope, that deployer is considered a provider. In such a case, the original provider is reclassified as a third-party supplier and must cooperate with the new provider. The Act leaves open the question of what constitutes a 'substantial modification', creating a grey area in practice.[6]
Similarly, the concept of AI-as-a-Service (AIaaS) has generated definitional ambiguity: a deployer who rents or subscribes to an AI system may, by customising or fine-tuning it substantially, transition into the provider role. This boundary is actively debated in legal scholarship.
Jurisdictional Variations in the Meaning of Deployer
The meaning and scope of the term 'deployer' varies meaningfully across jurisdictions, reflecting different regulatory philosophies and the maturity of each framework.
EU AI Act (Article 3(4)): The EU AI Act adopts the broadest and most widely referenced definition. It covers any natural or legal person, public authority, agency, or body using an AI system under its authority in a professional or organisational capacity, expressly excluding personal non-professional activity. This formulation captures the widest possible range of entities — from large corporations to public institutions — and applies across sectors.[1]
Kentucky, USA (2025 Act): By contrast, the Commonwealth of Kentucky's framework is deliberately narrow. It limits the deployer concept to state departments, state agencies, and state administrative bodies, and further restricts its application to high-risk AI systems only. This reflects the federalist structure of US governance and an incremental, government-first approach to AI regulation. Private sector entities deploying AI are not covered by this definition.[2]
ASEAN Guide on AI Governance and Ethics: The ASEAN Guide occupies a middle position. It defines a deployer broadly as any entity that uses or implements an AI system, whether developed in-house or by a third party. Unlike the EU AI Act, this framework explicitly addresses in-house developed systems, removing any ambiguity that might arise when a single organisation both develops and deploys an AI tool.[3]
JURI Proposed Amendment (European Parliament): The proposed JURI definition moves away from identity-based framing toward a functional one. Rather than focusing on who the deployer is, it focuses on what the deployer does: the deployer is the person who decides on the use of the AI system, exercises control over associated risks, and benefits from its operation. This formulation, while not adopted in the final AI Act text, reflects a substantive accountability approach that several legal scholars have endorsed.[5]
Baker McKenzie / Broad Contractual Framework: A further, expansive reading — found in commercial and compliance guidance — extends the deployer concept to any natural or legal person under whose authority or direction a system is operated, or who receives the benefit of the system's output, regardless of whether that person directly operates, supervises, or hosts the system. This definition is the widest in scope and is particularly significant for corporate group structures where a parent entity benefits from AI deployed by a subsidiary.[10]
Functional Variations: High-Risk vs. General AI Systems
The regulatory burden on a deployer varies significantly depending on whether the AI system in question is classified as 'high-risk' under applicable law. Deployers of high-risk AI systems face a substantially more demanding set of obligations than deployers of general-purpose or low-risk systems, including mandatory human oversight, logging requirements, fundamental rights impact assessments, and market surveillance authority notifications. Deployers of non-high-risk systems may only need to comply with general transparency and monitoring standards.
Variation in Nomenclature
In earlier drafts of the EU AI Act, the entity now called a 'deployer' was referred to as a 'User'. This change in terminology was deliberate, reflecting the intent to capture the professional, organisational nature of the role — as opposed to an individual end-user of a product. The term 'operator' is also used in some non-EU frameworks and scholarly literature to describe entities performing the deployer function.[11]
International Experience
European Union — EU Artificial Intelligence Act
The EU AI Act is the most comprehensive binding legislative framework for AI governance globally and provides the most elaborated definition and regulatory treatment of deployers. The Act adopts a risk-based approach, classifying AI systems into prohibited, high-risk, limited-risk, and minimal-risk categories. Deployers of high-risk systems bear the most extensive obligations, including implementing provider instructions, assigning human oversight, maintaining logs, conducting fundamental rights impact assessments before certain deployments, suspending use where risks emerge, and informing relevant authorities of serious incidents. Deployers must also ensure transparency toward individuals affected by AI-assisted decisions.[1]
A significant aspect of the EU framework is that it explicitly acknowledges the shifting boundary between deployer and provider: where a deployer makes a substantial modification to an AI system or repurposes it, they assume the legal obligations of a provider. This dynamic definition is designed to prevent liability gaps.[6]
ASEAN — Guide on AI Governance and Ethics
The ASEAN Guide on AI Governance and Ethics offers a non-binding but instructive framework. It places particular emphasis on the deployer's disclosure obligations, anti-discrimination duties, and governance responsibilities. Key deployer obligations under the ASEAN framework include: clearly disclosing AI use to all stakeholders; conducting risk assessments and testing before deployment; ensuring safeguards against discriminatory or biased algorithmic decisions; implementing appropriate human intervention mechanisms; and ensuring the AI system complies with applicable law, internal governance policies, and ethical principles. The ASEAN framework reflects a values-led approach that complements the EU's rules-based model.[3]
United States — State-Level Frameworks (Kentucky 2025)
In the absence of a comprehensive federal AI governance law in the United States, individual states have begun enacting legislation. Kentucky's 2025 Act represents one such framework. The state-level approach limits the deployer concept to governmental bodies and focuses exclusively on high-risk AI systems. This reflects the federalist structure of US governance and a cautious, incremental approach to AI regulation, contrasting with the EU's horizontal and sector-spanning framework.[2]
Deviations from Indian Practice
India does not yet have a comprehensive enacted AI law that defines the term 'deployer'. However, the ongoing development of the Digital India Act and AI governance guidelines — to which BSA submitted comments analysed in this entry — suggests that India is moving toward a framework that would distinguish between AI developers and deployers along functional lines similar to the EU model. The BSA submission explicitly recommends that India adopt a deployer-developer distinction and assign differentiated obligations based on each party's access to information and ability to mitigate risk. India's approach, once enacted, is likely to reflect the EU model while adapting it to the domestic regulatory and judicial context.[4]
Best Practices and Learnings
• Deployer obligations should be proportionate to the level of risk posed by the AI system — higher risk systems should attract more demanding requirements.
• The deployer–provider boundary should be clearly delineated in legislation, with mechanisms to address situations where a deployer substantially modifies a system and thereby assumes provider responsibilities.
• Deployers should be required to maintain records (logs) sufficient to enable post-hoc accountability and regulatory review.
• Transparency toward affected individuals — particularly in AI-assisted decision-making affecting legal rights or significant interests — should be a non-negotiable baseline obligation.
• Human oversight must be meaningfully implemented, not reduced to a formality.
Research That Engages With 'Deployer'
AI Liability and the Law-and-Economics Framework (arXiv, October 2024)
This research paper offers the first comprehensive normative analysis of AI agent liability through a law-and-economics lens. Contrary to prevailing assumptions about AI's disruptiveness, the paper finds that AI largely aligns with traditional production structures and that existing tort frameworks can be adapted rather than replaced. The paper engages directly with the deployer concept, noting that the terms 'provider' and 'deployer' are not mutually exclusive. It analyses Article 25(1) of the EU AI Act — the provision that reclassifies a deployer as a provider upon substantial modification — and observes that the Act leaves open the definition of 'substantial', creating interpretive uncertainty. The paper argues that optimal AI liability rules should incentivise both developers and deployers to internalise the social costs of AI-induced harm.[6]
Roles of Provider and Deployer Under the AI Act — Stephenson Harwood
This credible legal blog examines the operational distinction between providers and deployers under the EU AI Act. It clarifies that a deployer is any natural or legal person or body using an AI system under its authority, excluding personal non-professional activity, as per Article 3(4). The analysis notes that deployers operate systems provided by others but carry their own distinct obligations regarding use, monitoring, and transparency to affected individuals. Key deployer obligations identified include: implementing the provider's instructions for use; conducting fundamental rights impact assessments before deploying high-risk systems in certain contexts; ensuring human oversight; suspending use if a risk is identified; informing market surveillance authorities of serious incidents; and providing transparency to individuals affected by the system's decisions.[7]
EU AI Act's 'Deployers' Definition — Life Sciences Implications (Osborne Clarke)
This sector-specific analysis examines the implications of the EU AI Act's deployer definition for the life sciences industry. It notes that the deployer definition is expansive — capturing a wide array of businesses using AI whether as part of core operations or for ancillary activities such as organisational management or recruitment. The analysis highlights that deployers must ensure their teams possess adequate AI literacy, taking into account their technical expertise and the deployment context. It identifies a significant regulatory tension with existing EU pharmaceutical and medical device legislation, which does not typically impose usage obligations on end users. The paper observes that the new deployer obligations may complicate off-label use of health technologies — a context where physicians and hospitals have traditionally exercised autonomous clinical judgment.[8]
Software Deployment: Past, Present and Future — A. Dearle (FOSE 2007)
This foundational computer science paper traces the evolution of software deployment as a technical and organisational practice. While not a legal text, it is relevant to understanding the conceptual origin of the term 'deployer' in the technology domain. The paper examines how deployment — the process of making software operational in a target environment — has evolved from simple distribution to complex, multi-stage operations involving configuration, integration, monitoring, and update management. This technical genealogy informs the legal concept of deployer, which mirrors the real-world responsibility of entities that take a technology product and make it function within a specific operational context.[9]
Responsible Data Sharing for AI: A Test Bench for EU Data Law (European Journal of Privacy Law & Technologies)
This peer-reviewed article in the European Journal of Privacy Law & Technologies examines the deployer concept in the context of AI-as-a-Service (AIaaS). It observes that the deployer rents or uses AI as a service. The article identifies a persistent grey area: a deployer can become a provider by making a substantial modification to the AI system, but the AI Act does not clearly define what 'substantial' means in this context. This ambiguity has important practical and liability implications — entities that customise, fine-tune, or adapt AI models acquired from third parties may unwittingly assume the full compliance obligations of a provider without having designed or trained the underlying system.
Provider vs. Deployer: Understanding Your Role Under the AI Act — Pitch Knowledge Base
This accessible secondary resource synthesises the practical differences between providers and deployers under the EU AI Act. It notes that deployers operate systems provided by others but carry their own obligations regarding use, monitoring, and transparency. It provides a concise summary of deployer obligations: following provider instructions; conducting fundamental rights impact assessments before deploying in sensitive contexts; ensuring human oversight; suspending use where risks are identified; informing authorities of serious incidents; and being transparent with individuals affected by AI-assisted decisions. This resource is particularly useful for practitioners seeking a plain-language overview of their responsibilities.[7]
Challenges
• Definitional ambiguity at the provider–deployer boundary: The EU AI Act's concept of 'substantial modification' — the threshold at which a deployer becomes a provider — remains undefined, creating significant legal uncertainty for entities that customise or fine-tune acquired AI systems.
• Liability gaps in multi-party AI supply chains: Modern AI deployment often involves multiple intermediaries between the original developer and the end deployer. Assigning clear accountability across these chains is complex, particularly when harm results from the interaction of components created by different parties.
• Transparency and explainability limitations: Deployers are obligated to monitor AI systems and inform users of AI-assisted decisions, but the opacity of many AI systems makes it technically difficult to explain or audit decisions in a meaningful way.
• Compliance burden on smaller deployers: The obligations imposed on deployers of high-risk AI systems — particularly around human oversight, logging, and impact assessments — may be disproportionately burdensome for smaller organisations lacking technical and legal expertise.
• Lack of harmonised frameworks: Outside the EU, there is no globally harmonised definition or set of obligations for AI deployers. Multinational organisations must navigate a patchwork of national and regional requirements, increasing compliance complexity.
• Human oversight in practice: The requirement to assign human oversight to natural persons with the necessary competence, training and authority is difficult to operationalise consistently — particularly as AI systems become more autonomous.
• Data input quality: Deployers who control input data bear responsibility for ensuring its relevance and representativeness. This is challenging when AI systems process large, dynamic datasets from varied sources that may contain biases or gaps.
Way Ahead
• Clarification of the 'substantial modification' threshold: Regulators and legislators should provide guidance or safe harbours to clarify when customisation of an AI system by a deployer rises to the level of a substantial modification triggering provider obligations.
• Development of a global baseline standard: International bodies such as the OECD, ISO, and UN agencies should work toward a harmonised minimum standard for deployer obligations, reducing compliance fragmentation for multinational actors.
• AI literacy mandates: The obligation on deployers to ensure adequate AI literacy among their teams — articulated in the EU AI Act and the ASEAN Guide — should be supported by practical training frameworks, certification standards, and government guidance.
• Proportionate compliance frameworks for SMEs: Regulators should consider tiered compliance pathways for small and medium enterprises acting as deployers, acknowledging that the same obligations cannot be applied uniformly without regard to organisational capacity.
• Algorithmic auditing standards: Development of standardised third-party auditing protocols for high-risk AI deployments would improve accountability and help deployers demonstrate compliance objectively.
• India-specific framework development: As India develops its Digital India Act and AI governance guidelines, it should draw on the EU AI Act's deployer-provider distinction while adapting obligations to the Indian administrative, judicial, and sectoral context.
Related Terms
• Provider / Developer — the entity that designs, trains, and places on the market an AI system; distinguished from the deployer by the stage of the AI lifecycle at which it acts.
• Operator — an alternative term used in some non-EU frameworks and scholarly literature for the entity performing the deployer function.
• User — the earlier terminology used in draft versions of the EU AI Act for what is now called a 'deployer'; also used to refer to end-users (individuals affected by AI systems), a distinct concept.
• High-Risk AI System — an AI system classified under applicable law as presenting significant risk to health, safety, or fundamental rights; triggers the most demanding deployer obligations.
• AI-as-a-Service (AIaaS) — a commercial model where AI capabilities are delivered via cloud or subscription services; raises particular questions about deployer vs. provider roles when the service is substantially customised.
• Substantial Modification — the undefined threshold in the EU AI Act at which a deployer who modifies an AI system assumes the obligations of a provider.
• Human Oversight — a core deployer obligation requiring that AI-assisted decisions or actions be subject to review and intervention by natural persons with appropriate authority and competence.
References
Footnotes in this document contain hyperlinks to the cited sources. The full list of sources referenced is set out below.
1. EU Artificial Intelligence Act (Regulation (EU) 2024/1689), art. 3(4), art. 25(1), art. 26. Available at: https://www.europarl.europa.eu/doceo/document/JURI-AM-652548_EN.pdf (Accessed on 28/03/2026).
2. Commonwealth of Kentucky, Acts of the 2025 Regular Session, Act 0066. Available at: https://apps.legislature.ky.gov/law/acts/25RS/documents/0066.pdf (Accessed on 28/03/2026).
3. ASEAN Guide on AI Governance and Ethics (2nd Edition). Available at: https://asean.org/book/asean-guide-on-ai-governance-and-ethics/ (Accessed on 28/03/2026).
4. BSA | The Software Alliance, Comments on Subcommittee Report on AI Governance Guidelines Development, p. 3. Available at: https://itforchange.net/sites/default/files/add/Formatted_ITfC%20comment%20on%20IT%20Amendment%20Rules%202025.pdf (Accessed on 28/03/2026).
5. European Parliament, Committee on Legal Affairs (JURI), Amendment to the AI Act (Proposed Definition of Deployer). Available at: https://www.europarl.europa.eu/doceo/document/JURI-AM-652548_EN.pdf (Accessed on 28/03/2026).
6. Anonymous, 'AI Liability and Optimal Regulatory Frameworks,' arXiv, October 2024. Available at: https://arxiv.org/pdf/2410.14501 (Accessed on 28/03/2026).
7. Stephenson Harwood, 'The Roles of the Provider and Deployer in AI Systems and Models.' Available at: https://www.stephensonharwood.com/insights/the-roles-of-the-provider-and-deployer-in-ai-systems-and-models (Accessed on 28/03/2026).
8. Osborne Clarke, 'EU AI Act's Deployers Definition Has Wide-Ranging Significance for Life Sciences.' Available at: https://www.osborneclarke.com/insights/eu-ai-acts-deployers-definition-wide-ranging-significance-life-sciences (Accessed on 28/03/2026).
9. A. Dearle, 'Software Deployment, Past, Present and Future,' FOSE '07, Minneapolis, 2007, pp. 269–284. Available at: https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=4221626&isnumber=4221601 (Accessed on 28/03/2026).
10. Baker McKenzie, 'Fundamentals of Secure AI Systems with Personal Data,' Insight Plus. Available at: https://insightplus.bakermckenzie.com/bm/attachment_dw.action?attkey=Z7ihh84NQcZGwOJduvi%2FhL8Thu1hv0q%2FzlcQF0enB75zND1%2BgKcaDWbyCeHBgkv3cjKQPsiCr6qGWxhAcrDLCQ173j12Zxo%3D (Accessed on 28/03/2026).
11. EU Artificial Intelligence Act, Article 3 — Definitions. Available at: https://artificialintelligenceact.eu/article/3/ (Accessed on 28/03/2026).