Am I a deployer if we just use ChatGPT at work?
Written 27 August 2026 against Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744.
Yes, if you use it under your own authority in a professional activity: a deployer is "a natural or legal person, public authority, agency or other body using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity" (Article 3, point (4)). Whether you built the system or bought it is not part of the test.
Quick answer
- The test is authority and purpose, not ownership. Using a system under your authority makes you its deployer; nothing in the definition asks who developed it or who paid for it.
- The exception is personal and non-professional use. An employee using a chatbot at work is not in that exception — the company is using it in a professional activity.
- Being a deployer is not a tier. What you owe depends on the system's classification: most deployer duties in Article 26 attach to high-risk systems, and a general-purpose assistant used for drafting is usually not one.
- One duty reaches every deployer whatever the tier. Article 4 AI literacy carries no risk qualifier and has bound providers and deployers since 2 February 2025.
- You can stop being only a deployer. Article 25(1) turns a deployer into a provider if you put your name on a high-risk system, substantially modify it, or change its intended purpose.
What makes someone a deployer?
The definition has three moving parts and none of them is a purchase. There has to be an AI system — the Article 3, point (1) test, which not every piece of software passes. It has to be used under your authority, which is what separates a company from its individual staff: the organisation that decides the tool will be used — for what and by whom — is the one using it under its authority. And the use must not be in the course of a personal non-professional activity, which is the only carve-out the definition contains.
A team told to use an assistant for customer replies satisfies all three. So does a finance department running a bought forecasting tool, and a recruiter using a screening product. The vendor is the provider; you are the deployer; both roles exist at once for the same system, and they carry different duties.
Does being a deployer mean the high-risk duties apply?
No, and this is where most of the worry lands in the wrong place. Article 26 is titled "Obligations of deployers of high-risk AI systems", and its substance follows that title: appropriate technical and organisational measures to use the system in accordance with the instructions for use (Article 26(1)), assigning human oversight to natural persons with the necessary competence, training and authority (Article 26(2)), monitoring operation (Article 26(5)). Those duties attach to high-risk systems, and they apply from 2 December 2027 for Annex III systems.
A general-purpose assistant used to draft text is normally in the residual tier — not prohibited, not high-risk on either route, no Article 50 trigger of its own. What that tier still owes is short, and it is not nothing: the Article 4 duty binds you, and the reasoning behind your conclusion is worth recording per system rather than per company.
What changes the answer is the use, not the tool. The same assistant pointed at CV screening is being used for a purpose point 4 of Annex III covers, and the analysis restarts there — the decision tree is the order to work through.
When does a deployer become the provider?
Article 25(1) is the switch, and it lists the circumstances. A distributor, importer, deployer or other third party is considered a provider of a high-risk system, and takes on the Article 16 provider obligations, where they put their name or trademark on a high-risk system already placed on the market, where they make a substantial modification to one, or where they modify the intended purpose of a system in such a way that it becomes high-risk. What that switch actually costs is a guide of its own, because the obligations that arrive are the full provider stack.
Fine-tuning a bought model on your own data is the case people ask about most, and it is not answered by the fact of fine-tuning alone: what matters is whether the result is a substantial modification, or a change of intended purpose that makes the system high-risk.
What this means for you
If you're a deployer: list the systems, not the vendors. One vendor can supply two systems and one system can be used for two purposes, and how many AI systems you have is a question with a real answer per use. For each, record the tier and the reasoning; for each high-risk one, the Article 26 duties are yours and they are not delegable to the vendor by contract.
If you're a provider who also uses your own system: you are both. The provider obligations attach to placing it on the market or putting it into service, and the deployer obligations attach to using it under your authority — including where you put it into service for your own use.
What this check can and cannot decide states where our own classification stops: it reads the tier from your confirmed answers, and it does not decide your role for you.
Which bought tools are you the deployer of?
Classify your first system — 5 questions on every run, plus follow-ups where they apply, no account, and the classification runs in your browser: answers stay there unless you choose to keep the result.
FAQ
Is every employee using AI at work a deployer?
No — the deployer is the organisation, not the person at the keyboard. Article 3, point (4) turns on using a system under its authority, and it is the company that decides a tool will be used and for what. The personal non-professional carve-out does not cover work use.
Does buying a tool instead of building it change the answer?
No. Nothing in the deployer definition refers to who developed the system or who paid for it. Buying makes the vendor the provider; it does not stop your use of the system under your authority from making you the deployer of it.
Do we owe the Article 26 obligations for a chatbot?
Only if it is high-risk. Article 26 is expressly about deployers of high-risk AI systems, and a general-purpose assistant used for drafting is normally residual. Point it at a use case Annex III covers and the classification — and the obligations — change.
Can a contract make the vendor responsible instead of us?
Not for your deployer duties. The Regulation attaches them to the deployer by role. A contract can allocate cost and cooperation between you, but it does not move a duty the Act puts on the person using the system under their authority.
Sources: Regulation (EU) 2024/1689 (EUR-Lex), Article 3, points (1), (3), (4) and (11), Article 4, Article 25(1), Article 26 and point 4 of Annex III; as amended by Regulation (EU) 2026/1744 (EUR-Lex), which replaced Article 4 in its entirety and amended Article 25. The deployer definition in Article 3, point (4) was not amended.