01
The roles set out in the regulation
Regulation (EU) 2024/1689 identifies specific roles to involve in AI governance: the provider, who develops or has the system developed and places it on the market; the deployer, who uses it under its own professional authority; and, where relevant, the authorised representative in the Union. Alongside these, an accountability framework assigns specific tasks to leadership and other staff regarding data, risks, incidents, and record-keeping. Providers and deployers must also ensure a sufficient level of AI literacy for those who operate the systems on their behalf.
02
Where these definitions come from
Article 3 of the regulation distinguishes provider, deployer, and authorised representative based on the degree of control exercised over the AI system. Article 4 adds the requirement of AI literacy for staff, calibrated to technical knowledge, experience, education, and context of use. The accountability framework required of providers of high-risk systems assigns tasks to leadership regarding data management, risks, post-market monitoring, incidents, records, and communication with authorities.
03
How to assign roles step by step
Steps
- Classify the company as provider, deployer, or authorised representative for each AI system used.
- If the company is a provider of high-risk AI systems, assign leadership the accountability framework for data, risks, incidents, and records required for its quality management system.
- Plan AI literacy pathways for operational staff.
- Define communication channels with the relevant national competent authorities.
- Keep documentation of decisions and relevant records.
04
Hypothetical example
Hypothetical example: a European company using an AI system to screen job applications acts as a deployer, while the software provider remains responsible for development. Leadership assigns an internal manager to monitor risks and incidents according to the accountability framework required of providers of high-risk systems, and organizes an AI literacy session for the team operating the tool, consistent with Article 4 of the regulation.
05
Check before proceeding
- Provider, deployer, and authorised representative roles identified for each system.
- Leadership accountability framework documented for data, risks, and incidents, if the company is a provider of high-risk systems.
- AI literacy planned for operational staff.
- Communication channel with the national competent authority identified.
06
How management software can support governance
A company can ask its software partner for a role registry (provider, deployer, authorised representative) for each AI system, with traceable fields to assign responsibilities to leadership. Periodic review workflows, staff training reminders, and a history of communications with competent authorities are suggested operational choices, not an obligation arising from the regulation.
07
Frequently asked questions about roles
The following questions clarify definitions already mentioned in the article, without introducing new obligations.
08
The first practical step
Map the AI systems in use, assign roles and responsibilities according to Article 3, and plan the first AI literacy session for those who use them, as required by Article 4.
FAQ
Frequently asked questions
Who is the deployer under the regulation?
It is the natural or legal person, public authority, or body that uses an AI system under its own professional authority, excluding non-professional personal use.
What does the leadership accountability framework require?
For providers of high-risk AI systems, the accountability framework defines the responsibilities of leadership and staff regarding data management, the risk management system, post-market monitoring, serious incidents, and record-keeping.
What does AI literacy require?
Providers and deployers must ensure, as far as possible, a sufficient level of literacy for those operating the systems, considering knowledge, experience, education, and context.
✓