Title card: What the EU AI Act asks of deployers after the Digital Omnibus. Article 4, Article 26, Article 50, Dec 2027, Aug 2028.

What the EU AI Act asks of deployers after the Digital Omnibus.

Short answer. A deployer is anyone using an AI system under its own authority for work. If that system is high-risk, Article 26 asks for use per instructions, competent human oversight, sound input data, ongoing monitoring, logs kept at least six months and workers told before deployment. The Digital Omnibus (a 2026 update to the EU AI Act), in force since 27 July 2026, pushed the high-risk compliance dates back but left Article 26 itself unchanged.

The EU AI Act has been in force since 1 August 2024, but the obligations that touch most organisations using AI sit in a handful of articles. The Digital Omnibus amended some of those this summer and left others exactly as written. Knowing which is which matters more than a general sense that “the AI Act changed.”

Who counts as a deployer under the AI Act?

Article 3, point 4 of Regulation (EU) 2024/1689 defines a deployer as “a natural or legal person, public authority, agency or other body using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity.” See Article 3 on the Commission’s AI Act Service Desk and the full regulation text on EUR-Lex.

A firm that licenses a system a vendor built and runs it inside its own operations is the deployer, whatever the vendor calls itself. A bank running a vendor’s credit-scoring model against its own loan applicants is a deployer; so is a hospital running a vendor’s triage tool against its own patients. The provider built the system; the deployer puts it to work, and one organisation can hold both roles for the same system.

What must a deployer of a high-risk system do under Article 26?

Article 26 sets out the operating obligations once a system is classified as high-risk under Article 6 and Annex III or Annex I. The Commission’s own summary gives these duties.

  • Use per instructions. Deployers “take appropriate technical and organisational measures to ensure they use such systems in accordance with the instructions for use” the provider supplied.
  • Human oversight. Deployers assign oversight “to natural persons who have the necessary competence, training and authority, as well as the necessary support.”
  • Input data. To the extent the deployer controls the input data, it must be “relevant and sufficiently representative in view of the intended purpose” of the system.
  • Monitoring. Deployers “monitor the operation of the high-risk AI system” and tell the provider or market surveillance authority if it may present a risk; for a serious incident, they inform the provider first, then the authorities.
  • Log retention. Deployers “keep the logs automatically generated by that high-risk AI system, to the extent such logs are under their control, for a period appropriate to the intended purpose of the high-risk AI system, of at least six months.”
  • Informing workers. Before putting a high-risk system to work in the workplace, employers “inform workers’ representatives and the affected workers that they will be subject to the use of the high-risk AI system.”

See Article 26 on the Commission’s AI Act Service Desk for the full set, including the public-authority registration duty under Article 49. The Digital Omnibus does not amend Article 26. The six-month log floor and the rest of this list stand as originally enacted.

What does Article 4 ask about AI literacy, and what did the Omnibus change?

Article 4 has applied since 2 February 2025 and asks providers and deployers to support AI literacy among staff and anyone else operating an AI system on their behalf. The Digital Omnibus rewrote it. The original wording asked providers and deployers to ensure “to their best extent, a sufficient level” of AI literacy. Regulation (EU) 2026/1744 replaces that with a duty to “take measures to support the development of AI literacy.” The old duty was about the outcome: a sufficient level had to be reached. The new duty is about effort: measures have to be taken. The amended text adds that no specific literacy level has to be guaranteed for any individual. See Regulation (EU) 2026/1744 on EUR-Lex and Article 4 on the Commission’s Service Desk.

The duty has applied since February 2025 and has not moved. What changed is the standard: a documented programme of measures, not proof every individual reached a defined competence bar.

What does Article 50 ask on transparency?

Article 50 splits obligations between providers and deployers. Providers ensure that “AI systems intended to interact directly with natural persons are informed that they are interacting with an AI system,” and mark AI-generated audio, image, video or text output as “artificially generated or manipulated” in machine-readable form. Deployers carry three duties. They must tell people exposed to an emotion-recognition or biometric-categorisation system that it is running. They must disclose a deepfake as artificially generated when publishing one. They must also disclose AI-generated text on a matter of public interest, unless it has had human review with an individual holding editorial responsibility. Each disclosure must be given “in a clear and distinguishable manner” no later than the first interaction or exposure, subject to law-enforcement and narrow artistic exceptions. See Article 50 on the Commission’s AI Act Service Desk. The Digital Omnibus amended only paragraph 7, on codes of practice; the disclosure duties above are unchanged.

When do the high-risk rules actually apply now?

This is the change most worth flagging to a deployer who planned around the original timetable. Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and amended Article 113 (dates reviewed against the regulation text on EUR-Lex, reviewed through 3 October 2026). High-risk obligations tied to Article 6(2) and Annex III, the stand-alone use cases such as employment screening and creditworthiness assessment, now apply from 2 December 2027, deferred from the original 2 August 2026 date. Obligations tied to Article 6(1) and Annex I, safety components embedded in regulated products, now apply from 2 August 2028, deferred from the original 2 August 2027 date. See Regulation (EU) 2026/1744 on EUR-Lex.

Article 4 and Article 50 run on their own timetable, regardless of any system’s risk classification. Article 4 has applied since 2 February 2025 and Article 50 since 2 August 2026. The Omnibus gives providers whose generative AI systems were already on the market before that date a four-month transition for the marking duty in Article 50(2). It leaves the deployer duties above unchanged.

Which record backs which obligation?

Obligation Article The record to keep
Deployer status established Article 3(4) A short note on which systems your organisation uses under its own authority, and who the provider is for each one
Used per the provider’s instructions Article 26(1) The instructions for use as supplied, and evidence of the configuration you actually run against them
Human oversight assigned Article 26(2) The named individual or role with oversight authority, their training record and their scope to intervene
Input data controlled Article 26(4) A description of the input data your organisation supplies and why it is representative for the intended purpose
Operation monitored Article 26(5) The monitoring record, and any notice sent to the provider or authority when operation indicated a risk
Logs retained Article 26(6) The automatically generated logs, held for at least six months, with an owner and a retrieval process that does not depend on the provider
Workers informed Article 26(7) The notice given to workers’ representatives and affected workers before deployment, with the date it was given
AI literacy supported Article 4 The measures your organisation has taken to support literacy among staff who operate or use the system, dated and scoped to their role
Interaction and content disclosed Article 50 The disclosure text or marking shown to the affected person, and when it was first shown

We set out the matching evidence discipline in how to prove AI controls to an auditor: a policy describes what should happen, and a regulator samples what did happen.

How should a deployer prepare, in order?

  1. List every AI system your organisation uses under its own authority, and mark which ones you believe fall under Annex III or Annex I, with your classification reasoning.
  2. For each high-risk candidate, get the provider’s instructions for use and check them against how the system is actually configured.
  3. Name the individual or role who holds human oversight for each system, with authority and training to intervene, not only to observe.
  4. Confirm where the system’s logs live, who owns that storage, and whether you can retrieve six months of history without the provider’s help.
  5. Draft the worker notice for any workplace deployment now, even for a system that will not reach the 2027 or 2028 deadline. Consultation takes longer than the notice itself.
  6. Record what your organisation is doing to support AI literacy among staff who operate each system, scoped to their role, and date it.
  7. Check every user-facing AI interaction and every AI-generated public post against Article 50’s disclosure duty, already in force regardless of risk classification.

Step one is the one organisations skip because it sounds administrative. It decides which of the rest applies to you.

Questions buyers ask.

Did the Digital Omnibus delay Article 26 obligations?

Not directly. It delayed the dates on which systems become subject to high-risk classification under Article 6, Annex III and Annex I. Article 26 itself, the deployer duties that apply once a system is high-risk, was not amended.

Does a small business count as a deployer?

Yes, if it uses an AI system under its own authority for anything beyond a personal, non-professional activity. Article 3(4) sets no size threshold. The Digital Omnibus simplified some documentation duties for SMEs elsewhere in the regulation, but the deployer definition is unchanged.

Do the December 2027 and August 2028 dates apply to every AI system we use?

No. They apply to systems classified as high-risk under Annex III (now due 2 December 2027) or Annex I (now due 2 August 2028). Article 4 and Article 50 already apply and are not affected by this deferral.

Does keeping logs for six months satisfy every retention duty we might have?

Six months is the Article 26(6) floor, appropriate to the system’s intended purpose. Sector rules, contracts or other law can require longer. Confirm the applicable period with your compliance reviewer instead of treating six months as a ceiling.

This is the evidence discipline behind the twelve tests in the Agentic AI Procurement Handbook. Handvantage builds Vantage Workspace, a self-hosted AI workspace built so that AI actions go through human approval and leave a record, so weigh my view accordingly. This is an evaluation method, not legal advice. Your own counsel should confirm how these obligations apply to your systems and your regulator’s current guidance.

For how to use the extra time before the high-risk dates, see the Omnibus deferral guide on the workspace site.

Josh Olayemi · Founder, Handvantage · September 2026 · About the author

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *