Distinguish what the system provider must build from what the deployer must do in operation.
High-risk providers face requirements around risk management, data/data governance, technical documentation, logging, information to deployers, human oversight, accuracy, robustness and cybersecurity.
Deployers have their own operational obligations; buying a compliant product does not remove responsibility for appropriate use, oversight, monitoring and other duties that apply to the deployer.
Map obligation ownership across the supply chain rather than assigning everything to the vendor.
Create a two-column obligation map for a third-party high-risk recruitment system: vendor/provider versus client/deployer.
Based on the uploaded EU AI Specialist lesson notes and checked against the consolidated EU AI Act in force on 27 July 2026. Where the source pack and current law differ, the current law wins.