Think Build Implement Repeat
London, UK +44 7367 067226
WhatsApp FOLLOW f in X
Software Strategy

EU AI Act High-Risk Rules: What Changes If You Use AI, Not Build It

Last updated:

Most of the Act's high-risk duties are not aimed at you, but some are

Talk about the EU AI Act has mostly focused on the companies building AI, who carry the heaviest load. If you are a 60-person recruitment firm or a regional lender, you probably build none of it.

But you might well use it. The Act has a separate role called the deployer, which is any organisation using an AI system under its own authority in a professional capacity. If the system you use is classed as high-risk, deployers have obligations of their own, and a vendor's compliance does not discharge them.

This post is about that role. It is not legal advice, and the timing in particular is moving, which we come back to below. If you want the wider picture first, our general guide to EU AI Act compliance covers the risk tiers and the provider side.

Which AI tools count as high-risk?

High-risk is defined by use, not by technology. The same classification model can be harmless when it sorts support tickets and high-risk when it decides who gets a loan. The Act lists areas of use in an annex, and for ordinary businesses the ones that come up most are these:

  • Employment and worker management. Screening or ranking CVs, filtering applications, evaluating candidates, allocating tasks based on personal traits, monitoring and evaluating performance, decisions on promotion or termination.
  • Access to essential private services. Creditworthiness assessment and credit scoring of individuals, and risk assessment and pricing for life and health insurance.
  • Education and training. Deciding admission, assessing learners, detecting cheating in tests.
  • Biometrics. Remote biometric identification and certain categorisation or emotion recognition uses, some of which are prohibited outright rather than merely high-risk.
  • Critical infrastructure. Safety components in the management of utilities, road traffic and digital infrastructure.

A second route to high-risk is AI used as a safety component in products already covered by EU product safety law, such as machinery or medical devices. That route has a later timetable.

Notice what is absent. A delivery-questions chatbot, a stock forecast or an invoice extraction tool is not high-risk under the annex, though some carry transparency duties.

What deployers of high-risk AI actually have to do

The deployer duties are shorter than the provider list, and most of them describe good operational practice that a careful business would want anyway.

ObligationWhat it means in practice
Use it according to instructionsRead the provider's instructions for use and keep within them. Using a tool for a purpose it was not designed for can shift you into the provider role.
Human oversightAssign named people with the competence, training and authority to supervise the system and override it.
Input dataWhere you control the input data, make sure it is relevant and sufficiently representative for the intended purpose.
MonitoringWatch how the system behaves, and inform the provider (and in serious cases the authorities) if you see risks or incidents.
Log retentionKeep the logs the system generates, where they are under your control, for an appropriate period of at least six months unless other law says otherwise.
Workplace noticeInform workers' representatives and affected workers before putting a high-risk system into use in the workplace.
Informing individualsTell people when a high-risk system is used to make or assist decisions about them.

Some deployers also need a fundamental rights impact assessment before first use. That applies to public bodies and private organisations providing public services, and to deployers using AI for credit scoring or life and health insurance pricing. If you are in lending or insurance, assume this applies and check.

Individuals affected by a decision based on a high-risk system also gain a right to an explanation of the role the AI played. An explanation you cannot produce is one you cannot give.

When you accidentally become the provider

This is the trap for businesses that customise. Under the Act, a deployer can be treated as a provider if it puts its own name or trademark on a high-risk system, makes a substantial modification to one, or changes the intended purpose of a system so that it becomes high-risk.

The last one catches people. Wrap a general-purpose model in an internal tool and point it at ranking job applicants, and you may have just built a high-risk system, with the full provider duties attached.

The question is not which model you used. It is what decision the output feeds and who it affects.

When do the high-risk obligations apply?

Here we are deliberately careful. The Act entered into force in August 2024, with obligations phasing in. The prohibitions and AI literacy duties came first, in early 2025. Obligations for general-purpose AI models followed from August 2025. Most high-risk obligations, including those for the employment and credit uses above, were scheduled to apply from August 2026, with the product-safety route later.

However, the European Commission's digital omnibus proposals include delaying some high-risk obligations, partly because the harmonised standards businesses need to demonstrate compliance were running late. Whether and how those proposals are adopted, and what the final dates are, is something to confirm with counsel at the time you read this. We would not plan a compliance programme around a date quoted in a blog post, including this one.

Our practical advice does not change with the date. The work below takes months and is far easier before a regulator or a rejected candidate asks for it.

A preparation plan that holds up whatever the timetable

  1. Inventory every AI-assisted system. Include features buried inside HR, finance and CRM software. Vendors have added AI to products you bought years ago.
  2. Classify by use. For each, write one sentence on what decision the output feeds and who it affects. That sentence tells you whether the annex is in play.
  3. Ask vendors for their position. Do they consider the system high-risk? Will they provide instructions for use, log access and documentation? Their answer is evidence either way.
  4. Name the overseers. For anything high-risk, decide who supervises it, what training they need and what authority they have to override.
  5. Check log access. Confirm you can actually retrieve and retain the system's logs. Many SaaS tools keep them on the vendor side with short retention.
  6. Draft the notices. Worker consultation and individual notification wording, reviewed by counsel.

When we help clients with this at SpiderHunts, the inventory is usually the revealing step. A typical 150-person business finds more AI in its software estate than anyone expected, and a small number of uses that genuinely need attention. Our enterprise AI work often starts here, because you cannot govern what you have not listed.

When this is not your problem

If you have no EU customers, staff or operations, and no output of your systems is used in the EU, the Act may not reach you at all. UK, US and Gulf businesses should check that carefully rather than assume it, because the Act can apply where an AI system's output is used in the Union.

And if your AI use is entirely in the minimal-risk category, the high-risk regime is irrelevant. You still want the inventory and a sensible light-touch governance habit, but not a compliance project.

Frequently asked questions

Is a CV-screening tool high-risk under the EU AI Act?

AI used to filter or rank job applications or evaluate candidates is in the employment area of the high-risk annex. If you use one for roles involving people in the EU, treat it as high-risk and confirm with counsel. The vendor's own classification is useful evidence but not the final word.

Does the vendor's compliance cover our obligations?

No. Providers and deployers have separate duties. A compliant vendor makes your job easier by supplying instructions, documentation and log access, but human oversight, monitoring, notices and log retention are on you.

When do high-risk obligations start?

Most were scheduled to apply from August 2026, with some product-related uses later. EU digital omnibus proposals may delay some of them, so check the current position with a lawyer before fixing plans around a date.

We only use a chatbot. Are we affected?

A customer service chatbot is not high-risk under the annex. You may have transparency duties, such as making clear people are interacting with AI. The high-risk regime only matters if the system feeds decisions in the listed areas.

Can we become a provider without building a model?

Yes. Putting your name on a high-risk system, substantially modifying one, or repurposing a general tool for a high-risk use can move you into the provider role, with its much heavier obligations.

Keep reading

Not sure whether a tool you use counts as high-risk?

Send us a list of the AI-assisted systems you run. We will help you sort them into the obvious, the borderline and the irrelevant, so your lawyer's time goes on the ones that matter.

Book a free 30-minute call Get a project estimate WhatsApp us

Related services

What we build for problems like this one

Custom Software DevelopmentDigital Transformation