IN SHORT
- You are almost always a deployer, not a provider. The duties differ sharply and most of the heavy ones sit with providers.
- Regulation (EU) 2026/1744, the Digital Omnibus for AI, moved the high-risk obligations of Annex III to 2 December 2027. It did not move the transparency duties of Article 50.
- The practical duty for a normal business system: if a person is talking to AI or reading text a machine produced, say so.
- Penalties reach €35m or 7% of worldwide turnover at the top, and €15m or 3% for most other breaches. They are aimed at conduct nobody reading this is engaged in.
Provider or deployer, and why it decides everything
A provider develops an AI system and puts it on the market. A deployer uses one under its own authority. If you build an internal system with AI features inside it, you are a deployer, and the provider duties belong to us.
The split is worth reading twice, because the compliance material aimed at small businesses often flattens it and leaves owners believing they have obligations that belong to their supplier.
The line moves in one case worth knowing about: if you take what you build, put your own name on it and sell it as an AI product to others, you have become a provider of that product. Building an internal system, or a system for your own customers to use, does not do that.
| Who | What that covers here |
|---|---|
| Provider | The studio and Vera, the assistant on this site - ours |
| Deployer | The system you build and run in your business - yours |
The dates that actually apply, after the Omnibus moved them
Regulation (EU) 2026/1744 - the Digital Omnibus for AI, adopted 8 July 2026, published 24 July and in force 27 July 2026 - postponed the Annex III high-risk obligations to 2 December 2027. Article 50 transparency was not moved.
For most readers only the first line matters, and it is already in force. The high-risk regime that generated most of the anxiety concerns things like recruitment scoring, creditworthiness and access to essential services. A job-card system for a garage is not in Annex III and moving its date changes nothing for you.
| What | When | Moved by the Omnibus? |
|---|---|---|
| Article 50 transparency duties | 2 August 2026 | No |
| End of the labelling grace period | 2 December 2026 | Introduced by it |
| Prohibition on NCII and CSAM generation | 2 December 2026 | Introduced by it |
| Annex III high-risk obligations | 2 December 2027 | Yes, postponed |
What transparency requires, in practice
Two things. If a person is interacting with an AI system, they must be able to tell. If content is generated by AI, it has to be marked as such in a machine-readable way.
For a business system this is usually a single sentence and one label. A chat assistant on your site says it is an assistant. A description drafted by AI on a job card is visibly a draft until somebody approves it. Neither is expensive and both are better product design anyway.
Vera, the assistant on this site, is our example of the first: she says what she is, records no audio, keeps text for 90 days, hashes IP addresses, and is capped at five minutes and three conversations per visitor per day. Those are provider duties and provider design choices, and they are on the AI Act page rather than left implicit.
Human oversight, which is also just good design
Article 14 asks that a person can oversee and override the system. For an ordinary business system this is the same rule as "AI proposes, a person confirms", which you would want regardless of the regulation.
The design that satisfies it is the one described elsewhere in this series: an extraction appears on a screen next to the original document, and somebody presses confirm. Nothing goes out, nothing gets paid and nothing gets filed on a model's say-so.
This is the happiest part of the regulation, in that the compliant design and the design that stops you sending a customer the wrong number are the same design. If you build it the safe way you do not have to think about Article 14 again.
The parts that almost certainly do not concern you
The prohibited practices, the high-risk regime, and the general-purpose model obligations. Three chapters that take up most of the text and apply to almost nobody reading this.
- Prohibited practices: social scoring, manipulation of vulnerable groups, untargeted scraping of faces. If you are wondering whether this applies to you, it does not
- High-risk under Annex III: recruitment, creditworthiness, essential services, education. Real obligations, real deadline of 2 December 2027, and irrelevant to a job-card or invoicing system
- General-purpose model duties: these belong to the people who train the models, not to anyone who uses one
- Penalties: up to €35m or 7% of worldwide turnover for prohibited practices, €15m or 3% for most other breaches - aimed at conduct, not at paperwork slips
What we cannot do for you
We can tell you which duties are ours and describe how the platform helps with yours. We cannot tell you whether your particular system is high-risk, and we are not your lawyer.
For most internal business systems the answer is obvious enough that a lawyer is not needed. If your system touches hiring decisions, credit, insurance pricing, education outcomes or access to public services, that is the point at which the question stops being obvious and an hour of legal advice is cheap relative to being wrong.
The AI Act page is kept current with the dates and the split of duties. It is not legal advice either, and it says so.
QUESTIONS
Do I need to register my system anywhere?
Not for a normal internal business system. Registration duties attach to high-risk systems under Annex III, which is a defined and fairly narrow list.
Do I have to tell customers that AI is involved?
If they are interacting with it, or reading content it generated, yes. That is Article 50 and it has applied since 2 August 2026. A sentence and a label are usually the whole of it.
Did the Digital Omnibus delay everything?
No. It postponed the Annex III high-risk obligations to 2 December 2027 and left the Article 50 transparency duties where they were. It also introduced two new dates at 2 December 2026.
Who is the provider of the system I build?
We are the provider of the studio and of Vera. You are the deployer of what you build. That changes only if you put your own name on it and place it on the market as an AI product.
RELATED
The AI Act - the maintained page, with the full split of duties
AI inside your own system - the design that satisfies Article 14 by accident
Seven security questions - the neighbouring set of questions, about data rather than AI
When to stop and ask a person - where the confirm step belongs