Published by Roast & Rise
EU AI Act Deployer Readiness Map
Find your deployer duties and missing evidence before EU AI Act deadlines hit.
This plan gives you a concrete workflow and practical tools to map which of your AI uses trigger EU AI Act deployer duties, spot missing owners and evidence, and decide what needs legal or compliance review before the next deadline hits.

Course thesis
Operators and leaders who deploy AI in the EU face new, specific obligations—distinct from those of AI model providers. The most urgent risks come from failing to trace which deployments fall under which duties, missing evidence, or waiting too long to escalate legal review. A simple, evidence-backed workflow can surface blindspots and shrink the compliance gap before deadlines.
What you leave with
By the end, you’ll know exactly which AI deployments in your operation trigger new EU AI Act obligations for deployers, what evidence and owners are missing, what needs legal review, and how to document it all for your next audit or board update.
For
Operators, founders, AI owners, compliance partners, legal-adjacent managers, product leads, and department heads in organisations that deploy AI systems into the EU, but who are not the AI model provider.
Workflow
Regularly inventory deployed AI uses, tag high- and transparency-risk uses, map responsibilities and evidence owners, record missing evidence, and escalate edge cases for expert review—well before the next EU AI Act deadline.
Change
Moves from unseen compliance gaps and ownerless AI uses to a mapped deployer duty landscape with named owners, missing evidence flagged, and specific items lined up for legal or compliance review—on record before the next regulatory deadline.
What you can do
Use these as checks while you move through the plan.
Surface all current AI-enabled systems and uses in your remit.
Classify their risk and your organisation’s deployer role under the EU AI Act.
Map deployer obligations, surface missing owners/evidence, and record what needs legal escalation or oversight.
Produce board-/audit-ready files that cut last-minute compliance scramble.
Chapters
01
Inventory and Name Your Deployed AI Uses
Build your AI Use Inventory: surface every active, pipeline, and shadow AI-enabled system, naming ownership and provider status for each.

The EU AI Act does not wait for clean lists or tidy project charts. Deployers face hard deadlines and harsh consequences if a system is missed—live, in stealth, or in the pipeline. Every AI-enabled use—automated loan approvals, chat assistants, demand forecasting, image scanning—counts. No exceptions for pilots, internal tools, or edge use cases.
Accountability begins when you write down what exists. Assume the risk: if you have not named ownership, purpose, and provider for every AI use, you will not spot high-risk cases or missing obligations later. Shadow deployments and projects-in-waiting become regulatory liabilities if skipped.
You are not mapping technical details. You are mapping accountability. Who owns the deployment? What is the AI used for? Who built or integrated it? This is your single source of truth. If you have to chase someone later, you failed to map it now.
This list is not legal advice. It is the starting point for compliance, risk, and audit. Use it to drive the next steps—the right review, the right escalation—before the real deadlines hit. [Official source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai]
Quality checklist
Every system accounted for, including pilots
Each entry has an owner and use case
Provider status is clear
Shadow or edge cases are flagged
## Common mistakes
Missing unregistered or pilot AI uses
Leaving owner or provider fields blank
Assuming IT or compliance already has a full list
Confusing technical inventory with accountability
## Checkpoint
Can you show someone your AI Use Inventory, with no missing live or pipeline systems?
## Social takeaway
Your AI Use Inventory is your first line of defence—list it before you answer to regulators.
Common mistakes
Missing unregistered or pilot AI uses
Leaving owner or provider fields blank
Assuming IT or compliance already has a full list
Confusing technical inventory with accountability
## Checkpoint
Can you show someone your AI Use Inventory, with no missing live or pipeline systems?
## Social takeaway
Your AI Use Inventory is your first line of defence—list it before you answer to regulators.
Checkpoint
Can you show someone your AI Use Inventory, with no missing live or pipeline systems? ## Social takeaway Your AI Use Inventory is your first line of defence—list it before you answer to regulators.
Exercise
Draft Your AI Use Inventory
- List every live and in-pipeline AI-enabled system in your remit—no exceptions.
- For each, note system name, use case, named owner, and AI provider/developer.
- Mark which are visible to compliance or IT, and flag any shadow (unregistered) or edge cases.
- Save this as your AI Use Inventory for further mapping.
Use this at work tomorrow
Schedule a meeting to capture every AI deployment and shadow use in your area.
02
Classify Risk and Map Your Role
Sort every AI system into the right risk class and clarify if you’re a deployer or provider, using the EU AI Act as your guide.

You can’t meet your duties if you don’t know which law applies. The EU AI Act splits responsibilities: some belong to AI model providers, others to deployers. Deployer duties trigger for specific risks—high-risk, general-purpose (GPAI), or transparency-relevant systems. If you classify wrong, you may miss full obligations: risk assessment, documentation, human oversight, new transparency rules.
Start from your inventory. For each AI use, answer: Does this system fall in a high-risk sector? (Source: EU AI Act, see risk list.) Does it generate content that could mislead? (Article 50, transparency rules apply.) Is it built on or exposes a general-purpose AI? (GPAI rules now live.)
Next, map your role. Did your organisation build the core AI model, or are you deploying/optimising someone else’s? If you only deploy, you’re a deployer—most duties are yours unless the system is clearly off-the-shelf and unmodified. Tag each use in your map with both risk status and your role.
These tags decide your next legal and compliance steps. Don’t trust gut feeling or defaults—use the Commission’s sources. If there’s doubt, flag for legal review. This is a living map: new rules, products, or system changes may shift risk and obligations.
Quality checklist
Risk status references the official risk list
Role tagged for every use
Sources cited for each decision
Unclear or edge cases flagged
## Common mistakes
Assuming provider duties when only deploying
Missing GPAI or transparency triggers
Leaving risk or role blank
Skipping source documentation
## Checkpoint
Are all your AI uses classified and risk-tagged with sources?
## Social takeaway
Every AI deployment in your org needs a source-backed risk tag and clear deployer or provider role.
Common mistakes
Assuming provider duties when only deploying
Missing GPAI or transparency triggers
Leaving risk or role blank
Skipping source documentation
## Checkpoint
Are all your AI uses classified and risk-tagged with sources?
## Social takeaway
Every AI deployment in your org needs a source-backed risk tag and clear deployer or provider role.
Checkpoint
Are all your AI uses classified and risk-tagged with sources? ## Social takeaway Every AI deployment in your org needs a source-backed risk tag and clear deployer or provider role.
Exercise
Tag Risk and Role for Each AI Use
- Take your completed AI Use Inventory.
- For each entry, check if high-risk, GPAI, or transparency duties apply (use EU Act sources).
- Decide and record if you are the deployer or provider.
- Flag any unclear cases for legal review.
- Fill in one row per use in your map.
Use this at work tomorrow
Tag each deployed AI use with risk and your deployer/provider status in your systems map.
03
Map Deployer Obligations and Surface Gaps
Log EU AI Act deployer duties for each use, mark missing evidence, and flag what needs legal/compliance review before deadlines.

Knowing which duties fall to your organisation—as deployer, not provider—is where compliance shifts from risk to control. The EU AI Act splits duties differently than older frameworks. Most missed requirements come from not mapping evidence or from unclear handoff between compliance, legal, and technical teams. The work: For every AI deployment, use your risk and role classification to check which deployer duties apply. Reference current deadlines from official sources for high-risk and transparency-classified AI, bearing in mind that rules for General Purpose AI and Article 50 transparency enter force August 2025 and 2026 (see Commission sources). Log every required element: risk assessment, data quality proof, use-case documents, transparency labelling, oversight process. Name the specific owner or team for each. Mark any missing evidence, unclear owner, or process that is in draft or absent. For high- or transparency-risk uses, escalate gaps for legal or compliance review; do not wait for next cycle. The product is a live ledger. Each use is status-marked: complete, missing, or flagged for expert review. This is not legal advice. It is a field map for internal readiness, always cross-checked with your legal team as enforcement dates approach.
Worked example
A team lists their main customer-facing chatbot as high-risk. They check the EU AI Act for deployer duties: oversight process, transparency disclosure, and documentation. Oversight is documented and owned by IT. Transparency labels are missing—no owner. Documentation is in draft with the product team. They flag the transparency item for legal review and note the documentation status as 'in progress'. Their ledger shows each duty matched to an owner or escalation step, ready for review.
Output template
- AI deployment/use:
- Risk classification:
- Deployer duties (list):
- Duties status (complete/missing/legal review needed):
- Named owner/team per duty:
- Deadline for compliance:
- Escalation notes:
Quality checklist
- Duties sourced from official EU AI Act pages
- Each item status-marked and owner assigned
- Missing or unclear items flagged for review
- Ledger covers all classified deployments
Quality checklist
Duties sourced from official EU AI Act pages
Each item status-marked and owner assigned
Missing or unclear items flagged for review
Ledger covers all classified deployments
## Common mistakes
Copying duties from old frameworks
Assuming duties are provider-only
Skipping owner assignment
Filing gaps without escalation
## Checkpoint
Can you show the status (complete, missing, escalated) for every deployer obligation on your ledger?
## Social takeaway
Map every deployer duty—spot gaps, flag reviews, and avoid EU AI Act scramble.
Common mistakes
Copying duties from old frameworks
Assuming duties are provider-only
Skipping owner assignment
Filing gaps without escalation
## Checkpoint
Can you show the status (complete, missing, escalated) for every deployer obligation on your ledger?
## Social takeaway
Map every deployer duty—spot gaps, flag reviews, and avoid EU AI Act scramble.
Checkpoint
Can you show the status (complete, missing, escalated) for every deployer obligation on your ledger? ## Social takeaway Map every deployer duty—spot gaps, flag reviews, and avoid EU AI Act scramble.
Exercise
Build and Review Your Deployer Obligations Ledger
- Copy your Provider-Deployer Role Map from the last chapter.
- List the EU AI Act deployer duties per use (e.g., documentation, oversight, transparency labels).
- For each item, mark status: complete, missing, or needs legal review.
- Log the owner/team responsible for each duty.
- Save this as your Transparency and Oversight Ledger.
Use this at work tomorrow
Review your main AI use and complete its duties and owner status in the ledger.
30-day path
Week 1: Inventory all AI-enabled systems—include live, in-pipeline, and shadow uses.
Week 2: Run risk and role mapping; tag high-risk, GPAI, transparency-relevant, and provider/deployer status for each.
Week 3: Cross-check deployer obligations, document evidence and process owners, log gaps and escalate legal review needs.
Week 4: Finalise files, review status with leadership, and schedule follow-up for new deployments or law changes.
Success signals
All AI-enabled uses are mapped and classified by the deadline.
No high- or transparency-risk deployment is missing a named owner or evidence file.
Every edge case needing escalation has a tracked legal/compliance ticket before the next regulatory enforcement date.
Leadership receives a complete compliance map as a single, current packet.
Reflection prompts
Which deployed AI use is still invisible to compliance or leadership?
Where are we assuming the provider owns duties that may belong to us?
What evidence would make this deployment review-ready?
Manager checklist
Assign one owner for the AI Use Inventory and one escalation owner for legal review.
Do not leave high-risk or transparency-relevant uses without evidence files.
Review role classification when a provider, workflow, or model changes.
Send leadership a current readiness packet before the next deadline.
In this library
Related RisePlans
Agentic Work Redesign Sprint
Learn how to redesign work for teams using AI agents to handle delegated, long-running, and cross-functional tasks. Build a new operating model that makes room for parallel delegation, reusable instructions, modern review cycles, and the next level of team collaboration.
From Chatbots to Superagents
Stop settling for one-off chatbot interactions. This plan shows you how to delegate real, repeatable work to AI agents with control, confidence, and results your team can trust.
AI Search Visibility: A Practical Sprint
Audit how your company appears in AI search, publish verifiable source pages, set crawler policy, and measure changes in Search Console.
Want this shaped around your company?
Risey can research your company foundation first, then build a version of this path around your real workflows, customers, and culture.
Start with your company