← Practitioner
Module 5 of 10 · 15 min
Stage 2 · Apply the rules to real scenarios

High-risk provider and deployer obligations

Distinguish what the system provider must build from what the deployer must do in operation.

Learn

High-risk providers face requirements around risk management, data/data governance, technical documentation, logging, information to deployers, human oversight, accuracy, robustness and cybersecurity.

Deployers have their own operational obligations; buying a compliant product does not remove responsibility for appropriate use, oversight, monitoring and other duties that apply to the deployer.

Map obligation ownership across the supply chain rather than assigning everything to the vendor.

Remember
  • •Provider builds compliance into the system.
  • •Deployer must operate it compliantly.
  • •Contract and evidence flow link the two.
Client practice

Create a two-column obligation map for a third-party high-risk recruitment system: vendor/provider versus client/deployer.

Evidence you should be able to produce
Obligation matrixVendor evidence requestInternal operating controls
Source basis

Based on the uploaded EU AI Specialist lesson notes and checked against the consolidated EU AI Act in force on 27 July 2026. Where the source pack and current law differ, the current law wins.

← Previous moduleNext module →