Enterprise AI Deployer
stable enterprise-ai-deployer · v1.1An organisation that procures AI systems built by others and operates them under its own authority, alongside the security programme it already runs. It keeps its own identity, data, incident, continuity and personnel controls, so the security domains apply to it as they would to any organisation. Its AI duties are the ones the EU AI Act, ISO/IEC 42001 and the NIST AI RMF place on the operator: use within the provider's instructions, input data relevance, assignment of human oversight, monitoring in use, retention of the logs the system generates, AI literacy and telling the people its decisions affect. Build-side controls such as training data, verification testing and technical documentation are marked satisfied by provider: the deployer's evidence is the documentation, test summary and instructions for use it obtains from the provider under AIG-032 and AIG-034, so a questionnaire shows the evidence to collect rather than a gap. A deployer that puts its own name on a high-risk system, substantially modifies it or changes its intended purpose becomes its provider under Art.25 and moves to a provider profile. A public body, and a deployer of a system that scores creditworthiness or prices life or health insurance risk, carries the fundamental rights impact assessment and the public register entry as conditional rows here rather than in a profile of its own. Rows a cloud provider discharges for its customers are marked satisfied by provider; where the deployer runs the system on infrastructure it controls, those rows are conditional on the deployment model and the duty is its own.
- Roles
- Deployer
- Deployment models
- Cloud, multi-tenant SaaSCloud, single tenantOn premisesHybridEdgeOn deviceEmbeddedAir gapped
- Risk classes
- noneminimaltransparencyhigh-risk-annex-iii
- Jurisdictions
- EUUS-federalINT
- Frameworks
- EU-AI-ActISO-42001NIST-AI-RMFNIST-AI-600-1OWASP-LLMOWASP-AGENTICGDPRSOC2ISO-27001NIST-800-53CSA-CCMCSA-AICM
GOV · Governance & Risk
IAM · Identity & Access Management
The deployer's own repositories and pipelines, including the prompt and configuration repositories for the AI systems it integrates.
Administrative access to the deployer's own production estate is its own duty, whoever built the AI system running on it. The administration of the provider's service reaches the deployer as a tenant administration console, which is a designated system like any other.
DAT · Data Protection
The deployer uses the information the provider supplies to complete its assessment (Art.26.8), obtained through AIG-034.
The deployer taking a decision on the system's output is the controller for Art.22.
APP · Application Security
Applies to the deployer's own development, including the integrations, prompts and agents it builds on procured models. The provider's lifecycle for the product is evidenced through AIG-032.
The deployer's own estate and integrations. The provider's test reports for the product are reviewed under VND-006.
The deployer's own builds. The product's bill of materials is the provider's, obtained under VND-002 where contracted.
The deployer's own pipeline. Integrity of the product's releases is the provider's.
The processing specification covers the input pipelines the deployer controls, which is where Art.26.3 input data relevance is tested.
Applies where the deployer executes model-generated or third-party code. Where the sandbox is a provider feature the deployer holds the provider's description of its limits.
INF · Infrastructure & Cloud Security
The deployer's own systems. For the hosted tier the provider's baseline is inherited and evidenced under VND-004.
The tenant separation clause is the provider's. Segmentation of the deployer's own estate is its own.
The deployer's own infrastructure. The provider's availability architecture is evidenced under VND-006 and BCM-010.
MON · Monitoring & Logging
Includes the Art.26.5 minimum of six months for the automatically generated logs of a high-risk system under the deployer's control (AIG-020).
VND · Vendor & Third-Party Risk
The deployer is the controller: it obtains the provider's sub-processor register and objection route under VND-002. Where the deployer is itself a processor for its own customers, the register is its own.
The control through which the deployer evidences every hosted-tier control inherited from a cloud provider.
INC · Incident Response
Includes informing the provider of a risk or incident found in use (Art.26.4).
The deployer is the customer notified. The provider's commitment is contracted under VND-002 and the deployer's own duties to data subjects and authorities run through INC-005. Where the deployer processes personal data for its own customers, the row is its own.
BCM · Business Continuity
The continuity control for every AI system the deployer does not host.
AIG · AI Governance
The inventory, the risk class recorded for each system and the Art.25 check on the deployer's own modifications are the deployer's. The provider's classification and registration references are taken from the documentation it releases (AIG-034). Registration of use by a public authority (EU-AI-Art.49.2 in the extract, Art.49(3) in the Regulation) belongs to public-body-deployer-eu.
The impact assessment before use is the deployer's under ISO 42001 A.5. The Art.27 fundamental rights impact assessment is an addition that binds a public body, or a private body providing a public service, deploying a high-risk system. public-body-deployer-eu owns it.
Obtain the intended purpose, deployment context and design documentation from the provider (AIG-015 documentation, AIG-034 instructions for use). The deployer's own statement of purpose and context for each use is the AIG-039 use register.
Obtain the provider's verification and validation summary (AIG-034). The deployer's acceptance checks in its own context are the pre-deployment checks in AIG-009 and, where the system scores people, the in-production evaluation in AIG-025.
The deployment plan and the substantial-modification definition are the deployer's. The same definition is the Art.25 test: a substantial modification makes the deployer the provider.
Obtain the provider's training data summary (AIG-015, released under AIG-034). Where the deployer fine-tunes or evaluates a model on its own data, the practices apply to that data and the row is its own.
Obtain the provider's provenance statement for the training data (AIG-015). Provenance of data the deployer fine-tunes or evaluates on is its own.
Screening of the provider's training and evaluation sets is the provider's. Evaluation sets the deployer builds from its own data carry the DAT-024 screening result.
The documentation is the provider's. The deployer's evidence is the released version, held against the inventory entry and matching the deployed version.
Notifying affected persons (Art.26.7) and the Art.86 explanation route are the deployer's at high risk. Deep fake and public-interest text disclosure (Art.50.4) is the deployer's where it publishes the content. Interaction disclosure and machine-readable marking are built by the provider; the deployer confirms they are active in its configuration. Worker notification before workplace use (EU-AI-Art.26.6) is dispositioned to this profile and has no canonical control yet.
Obtain the explainability documentation from the provider (AIG-015). The deployer uses it in the AIG-022 oversight design and the AIG-016 explanation route.
Monitoring in operation and informing the provider of risks are the deployer's (Art.26.4). The post-market monitoring plan and the analysis of data reported by deployers (Art.72) are the provider's.
Performance on the deployer's own population and input distribution is measured by the deployer. Retraining is the provider's escalation, reached through the AIG-032 change notification terms.
The log design is the provider's. The deployer retains the automatically generated logs under its control for the Art.26.5 period of at least six months and controls read access to them.
The deployer detects incidents in its use, informs the provider and, where the provider cannot be reached, the market surveillance authority (Art.26.4). The serious incident report under Art.73 is the provider's.
Assignment of oversight to competent, trained persons and the record of oversight activity are the deployer's (Art.26.2). The oversight measures available are designed by the provider (Art.14) and described in the instructions for use.
The mechanism is built by the provider. Naming who may invoke it, exercising it at intervals and recording whether the supplier was needed are the deployer's.
Art.5 binds use as well as placing on the market. The acquisition-record check is the deployer's main artefact.
Pre-deployment bias evaluation is the provider's, obtained through AIG-034. Evaluation in production on the deployer's own population is the deployer's.
Obtain the provider's AI security evaluation summary (AIG-034). Testing of what the deployer builds on top is APP-005 and AIG-029.
Threshold calibration and validation logic are the provider's. The deployer sets the fallback in its own workflow, in the AIG-022 oversight design, using the thresholds the instructions for use give.
The use cases, the acceptable rate and the measured rate on the deployer's own data are the deployer's. The grounding mechanism may be a provider feature or the deployer's own retrieval layer.
The row is the deployer's for every integration that places its own or external content into a prompt. Where the provider's interface is used as shipped, the testing is the provider's (AIG-034 test summary).
Runtime detection and response on systems the deployer exposes to users are its own. The assessment of prohibited generation outcomes for each model placed on the market is the provider's.
The procurement control for every AI system the deployer adopts and the agreement the satisfied-by-provider rows rest on.
The deployer is the customer this control addresses. Its evidence is the instructions for use, limitations, oversight guidance and update notices the provider issues, held against the inventory entry. The agreement allocating regulatory responsibility is the AIG-032 agreement. This is the route the other satisfied-by-provider rows name.
The channel for the people the deployer's use affects is the deployer's. The provider's channel serves its own users.
Use in accordance with the instructions (Art.26.1) and input data relevance (Art.26.3) are the deployer's central duties. The row binds every deployer through ISO 42001 A.9 and becomes a legal duty at high risk.
The deployer is the customer. It obtains the provider's statement on whether its inputs are used for training, exercises the opt-out and records the answer in the AIG-032 assessment.
Permission sets, approval of consequential actions and invocation logs for agents the deployer runs against its own systems are its own. Where the agent runtime is the provider's, enforcement is a provider feature and the deployer configures and records the grants.
The pipeline the deployer fine-tunes or evaluates on is its own. The providers training pipeline is evidenced through the providers documentation (AIG-034).
The memory policy, the review of its own entries and the response to a suspected poisoning are the deployer's for agents it runs against its own systems and data. Where the agent runtime and its memory store are the provider's, the scope enforcement, the validation before commit and the version history are provider features and the deployer configures them and records that it has (AIG-034 instructions for use).
Required, as the library states every control whose trigger is a feature set rather than a facet (DAT-018, AIG-014, AIG-042, AIG-056): the documented assessment the control opens with is the first artefact. It bites where a system relies on user-supplied or external audio, image or video as evidence of a person's identity, of the provenance of an artefact or of a real-world event, which is a live case for identity verification, onboarding, claims and content-moderation features. An organisation whose assessment finds no such intake point records that finding and the detection limb has nothing to attach to. Restated from recommended on the S13 benchmark (ADR-049 amendment, 2026-09-16). A deployer that runs an identity, claims or evidence intake on a provider's product relies on the provider's detection step and records its rates from the provider's evaluation.
HRS · Human Resources Security
Art.4 binds deployers directly. The oversight-role content is the deployer's for the persons it assigns under AIG-022.
DAT · Data Protection
Condition: deployment_model in on-prem, hybrid, edge, on-device, embedded, air-gapped
Where the deployer runs the AI system on infrastructure it controls, key ownership and the behaviour on withdrawal are its own. Under cloud-saas or cloud-single-tenant the row is satisfied by the provider and the deployer obtains the key ownership statement and the withdrawal test result under VND-004.
Condition: deployment_model in on-prem, hybrid, edge, on-device, embedded, air-gapped
Where the deployer runs the AI system on infrastructure it controls, the location record for that system is its own and is enforced by its own configuration. Under cloud-saas or cloud-single-tenant the row is satisfied by the provider: the deployer obtains the provider's location record under VND-004 and reflects it in DAT-006 and DAT-015.
Condition: deployment_model in on-prem, hybrid, edge, on-device, embedded, air-gapped
Where the deployer runs the AI system on infrastructure it controls, the export interface and the retrieval window belong to the service it operates. Under cloud-saas or cloud-single-tenant the row is satisfied by the provider: the export interface and the post-termination retrieval terms are obtained under VND-004 and BCM-010 so the exit plan can be exercised.
INF · Infrastructure & Cloud Security
Condition: deployment_model in on-prem, hybrid, edge, on-device, embedded, air-gapped
Where the deployer runs the AI system on infrastructure it controls, isolation between its own tenants, environments and workloads is its own and INF-004 covers the boundary. Under cloud-saas or cloud-single-tenant the row is satisfied by the provider: the isolation statement and the cross-tenant test summary are obtained under VND-004.
MON · Monitoring & Logging
Condition: deployment_model in on-prem, hybrid, edge, on-device, embedded, air-gapped
Where the deployer runs the AI system on infrastructure it controls, the availability objective and the status channel for that service are its own. Under cloud-saas or cloud-single-tenant the row is satisfied by the provider: the deployer holds the provider's service level objective and status channel and reviews them under VND-006.
VND · Vendor & Third-Party Risk
Condition: deployment_model in on-prem, hybrid, edge, on-device, embedded, air-gapped
Where the deployer runs the AI system on infrastructure it controls, it owns the responsibility split it publishes to whoever consumes that service. Under cloud-saas or cloud-single-tenant the row is satisfied by the provider: the deployer receives the matrix under VND-004 and reads it against this profile so each inherited control has a named owner.
Condition: deployment_model in on-prem, hybrid, edge, on-device, embedded, air-gapped
Where the deployer runs the AI system on infrastructure it controls, the data a request could compel is in its own custody and its procedure covers receipt, legal review, narrowing, approval and the record end to end. Under cloud-saas or cloud-single-tenant the deployer is the customer the provider notifies, it obtains the provider's request-handling terms under VND-004, and its own procedure still covers the personal data it controls directly.
AIG · AI Governance
Condition: ai_risk_class in high-risk-annex-iii
Conformity assessment is the provider's. For a high-risk system the deployer obtains the EU declaration of conformity and confirms the CE marking before putting the system into service, recording both in the AIG-032 assessment.
Condition: ai_risk_class in high-risk-annex-iii
Corrective action and the authority request register are the provider's (Art.20, 21). The deployer reports non-conformity to the provider (Art.26.4), acts on a withdrawal, disablement or recall notice and produces the logs it holds to a competent authority on request.
Condition: ai_risk_class in high-risk-annex-iii and the system is used at a workplace
Art.26(7) binds a deployer that is an employer, before the system is put into use at the workplace. The audience is the recognised representatives and the workers within the system's reach, through the information and consultation route the organisation's own agreements or the applicable employment rules set. Where the description of the system in the notice comes from the provider it is obtained under AIG-032 and AIG-034.
Condition: ai_risk_class in high-risk-annex-iii and the deployer is a public authority, an agency or another body governed by public law, or acts on behalf of one
Art.49(3) binds a public authority, an EU institution or a person acting on their behalf, before the system is put into service or used. The Annex III point 2 carve-out applies. The provider-side arm of Art.49 sits on AIG-003 and stays with the provider, so a deployer holds two references against one system.
Condition: ai_risk_class in high-risk-annex-iii and the deployer is a body governed by public law or a private entity providing a public service, or the system is used to assess creditworthiness or to price and assess risk in life or health insurance
Art.27 binds public-law bodies, private entities providing public services and deployers of the Annex III point 5(b) and (c) systems, excluding the point 2 area. The assessment is due before first use and its result is notified to the market surveillance authority. Where the deployer holds a data protection impact assessment covering an element, Art.27(4) lets it cross-reference that section, so DAT-013 supplies part of the artefact. The provider's instructions for use, its risk description and its oversight measures are obtained under AIG-032 and AIG-034.
GOV · Governance & Risk
A deployer is the customer in this relationship, so the supervisory access it needs is its provider's: contracted under VND-002, obtained with the service under VND-004 and reviewed under VND-006. Where the deployer supplies a service of its own to a regulated customer, the row is its own and reads as it does on saas-ai-provider.
APP · Application Security
The disclosure programme for the product is the provider's and is reviewed under VND-006. A deployer with internet-facing services of its own benefits from one; no framework in the profile requires it of a deployer.
AIG · AI Governance
The registry is the provider's. The deployer records the model versions in production against the AIG-003 inventory entry and the BCM-010 continuity entry and takes version and change notices under the AIG-032 agreement.
DAT · Data Protection
The deployer is the party switching, not the party executing the switch. BCM-010 and VND-008 hold its side: the exit plan over the services it buys and the offboarding of a departing supplier.
The deployer calls the retrieval interfaces rather than publishing them. Whether the provider's interfaces reach it on equal terms is a question it asks under VND-001 and VND-004.
VND · Vendor & Third-Party Risk
Exit and regulatory terms are what a provider owes the customers of a service it sells. An enterprise operating AI systems for its own business is the customer in that relationship, and the terms it reads are covered by VND-002 and VND-004. Where the deployer also supplies a service to external customers it holds the provider seat for that service and reads the row on saas-ai-provider.
The deployer exercises audit rights rather than granting them; VND-006 is where it reviews the suppliers it buys from. Where it supplies a service to external customers it holds the provider seat for that service.
The deployer reads the provider's subcontractor disclosure and objects through it under VND-002 and VND-003 rather than publishing one. Where it supplies a service to external customers, the disclosure and the hold on a change are its own and it reads the row on saas-ai-provider.
AIG · AI Governance
Art.17 binds providers of high-risk systems. A deployer that triggers Art.25 becomes the provider and moves to high-risk-provider-eu.
Art.22 and Art.54 bind providers established outside the Union. Where a non-EU provider has appointed a representative, the deployer records the contact details from the provider's documentation in its AIG-032 assessment.
A general-purpose model providers duty (gpai-model-provider, ADR-046). The deployer takes the model documentation and the published training summary the provider issues into its AIG-032 assessment.
A general-purpose model providers duty (gpai-model-provider, ADR-046). The deployer takes the model documentation and the published training summary the provider issues into its AIG-032 assessment.
A general-purpose model providers duty (gpai-model-provider, ADR-046). The deployer takes the model documentation and the published training summary the provider issues into its AIG-032 assessment.
A general-purpose model providers duty (gpai-model-provider, ADR-046). The deployer takes the model documentation and the published training summary the provider issues into its AIG-032 assessment.
A general-purpose model providers duty (gpai-model-provider, ADR-046). The deployer takes the model documentation and the published training summary the provider issues into its AIG-032 assessment.
A general-purpose model providers duty (gpai-model-provider, ADR-046). The deployer takes the model documentation and the published training summary the provider issues into its AIG-032 assessment.
A general-purpose model providers duty (gpai-model-provider, ADR-046). The deployer takes the model documentation and the published training summary the provider issues into its AIG-032 assessment.
A general-purpose model providers duty (gpai-model-provider, ADR-046). The deployer takes the model documentation and the published training summary the provider issues into its AIG-032 assessment.
Published 2026-09-14