Deployers · HR · Credit · Healthcare · Workforce

You deploy an AI system, not just a piece of software.

Hiring, credit scoring, medical diagnosis, HR management- if your AI system affects people, the AI Act imposes deployer obligations on you, distinct from the provider's.

Identify my obligationsSee all features
Your situation

What makes you concerned

The AI Act distinguishes the "provider" (who designs the system) from the "deployer" (who uses it in their activity). If you're in HR and use a CV screening tool, in banking or insurance and use a scoring system, or a healthcare provider using diagnostic assistance, you're a deployer under Art. 3- even if you didn't build the system yourself.

Most HR, credit and healthcare use cases fall under Annex III (high-risk systems): recruitment and candidate selection, creditworthiness assessment, medical devices with an AI component. The exact level of obligation depends on your precise role- your DILAIG audit determines it precisely from your answers, not a generic estimate.

Your obligations

What the AI Act expects from a deployer

01Qualified human oversightAssign competent, trained personnel with the necessary authority to oversee the system in real-world conditions.Art. 26§2
02Use in line with the instructionsUse the system according to the instructions for use provided by the provider- any use outside that scope engages your own liability.Art. 26§1
03Log retentionRetain the logs automatically generated by the system for at least 6 months, unless a longer period is otherwise required.Art. 26§6
04FRIA before deploymentCarry out a Fundamental Rights Impact Assessment before putting the system into service, notably for banks, insurers and public bodies.Art. 27
05Worker notificationInform workers' representatives and affected workers before putting an AI system into service in the workplace.Art. 26§7
06Incident reportingInform the provider and market surveillance authorities of any risk identified during use.Art. 26§5
07Informing affected individualsInform natural persons that a decision concerning them is being taken with the assistance of a high-risk AI system.Art. 26§11
08GDPR coordinationAlign your AI Act impact assessment with your existing GDPR impact assessment whenever personal data is processed.Art. 26§9
With DILAIG

An audit that speaks your business language

01Automatic classificationThe questionnaire identifies whether your use case falls under Annex III and computes your exact risk level- not an estimate, a deterministic score.
02FRIA pre-filledIf an impact assessment is required, DILAIG drafts it from your system's context- ready for your legal counsel to review.
03Prioritised action planMissing obligations are ranked by severity- you know where to start, not just what's missing.
04Re-audit on every changeNew provider, new use case? Re-run the audit for free- your score recomputes identically if nothing has changed.
Frequently asked

What deployers ask most

You're a deployer if you use an AI system in your professional activity without having placed it on the market yourself. If you have a system custom-built for your own internal use only, you may hold both roles- the audit determines this precisely.

Yes, recruitment and candidate selection are explicitly listed in Annex III as high-risk use cases- whether it's automatic pre-selection, scoring, or CV analysis.

No. It's mandatory for public bodies, banks and insurance companies deploying a high-risk system. For others it remains recommended best practice- the audit tells you your exact situation.

AI Act penalties for non-compliance with deployer obligations go up to €15 million or 3% of global annual turnover, whichever is higher.

20 minutes to know exactly where you stand.

Compliance score, deployer obligations identified, FRIA if required. Free, unlimited, no credit card.

Start the free audit
AI Act for Deployers- HR, Credit, Healthcare, Workforce | DILAIG