01
What it means to document an AI system
Documenting an AI system means recording, in a file that can be consulted, the system's purpose, the role of whoever uses it, and the types of data processed. Regulation (EU) 2024/1689 precisely defines these figures: the provider develops or has the system developed and places it on the market or puts it into service under its own name, while the deployer uses it under its own authority. The same rule distinguishes training, validation, testing, and input data, including biometric categories, which must be tracked for every system active in the company to know who answers for what.
02
Why the distinction between roles matters
The distinction between provider and deployer is not theoretical: it determines who must mark synthetic outputs in a machine-readable format, who must inform people exposed to emotion recognition or biometric categorisation, and who must flag deep fake content. This information must reach the people concerned clearly and distinguishably, at the latest at the time of first interaction, and in an accessible format. Documenting therefore means linking each system to its responsible party, the data it processes, and the specific transparency obligation that follows, without leaving grey areas between who produces and who deploys the system.
03
A five-step method
Steps
- Identify for each system who is the provider and who is the deployer according to the definitions in Article 3.
- Classify the data processed: training, validation, testing, input, and, where present, biometric categories.
- Check whether the system generates synthetic content and plan for machine-readable marking of the output.
- Define when and how to inform people exposed to emotion recognition, biometric categorisation, or deep fakes.
- Schedule AI literacy measures for staff who operate or use the system.
04
A hypothetical case
Hypothetical example: a company using a biometric categorisation system for premises access acts as deployer and must inform the people exposed about how the system works, processing the personal data collected in accordance with the data protection rules referenced by the regulation. If the same system also generates synthetic audio or video content, it is the provider who must ensure the output is marked as artificially generated or manipulated, in a detectable format.
05
Minimum checks before activating a system
- Register of active AI systems, with the provider or deployer role indicated for each.
- Internal label for the types of data used: training, validation, testing, input, biometric.
- Note on the marking of synthetic outputs and on labelling deep fake content.
- Evidence of when and how the people concerned are informed.
- AI literacy plan for staff operating the systems in use.
06
What a company can set up with its software partner
- A digital register that assigns each AI system a role, provider or deployer, and an internal owner.
- Structured fields to classify each system's training, validation, testing, and input data.
- A verification status for the marking of synthetic outputs and for labelling deep fakes.
- A timestamp recording when exposed people were informed, in an accessible format.
- A log of AI literacy activities carried out by staff, with dates and participants.
07
Frequent clarifications
- The provider develops or has the system developed and places it on the market; the deployer uses it under its own authority.
- Information for exposed people must be provided at the latest at first contact, clearly and accessibly.
- AI literacy concerns staff and anyone who operates the system on the company's behalf.
08
The next step
The most useful practical step is to build, together with your team or software partner, a single register of AI systems indicating role, data processed, and the status of transparency obligations for each system. From there it becomes easier to plan output marking, information for exposed people, and AI literacy sessions for the staff involved.
FAQ
Frequently asked questions
Who decides whether a company is a provider or a deployer of an AI system?
This is set by the definition in Article 3: a provider is one who develops or has the system developed and places it on the market under its own name; a deployer is one who uses it under its own authority.
When must people exposed to an emotion recognition system be informed?
The deployer must inform them about how the system works and process personal data according to the data protection rules referenced by the regulation, before or at the moment of exposure.
What is meant by AI literacy?
The measures that providers and deployers adopt to ensure, as far as possible, a sufficient level of understanding of AI among staff and those operating the systems on their behalf.
✓