Roast & Rise

Published by Roast & Rise

EU AI Act Deployer Readiness Map

Find your deployer duties and missing evidence before EU AI Act deadlines hit.

This plan gives you a concrete workflow and practical tools to map which of your AI uses trigger EU AI Act deployer duties, spot missing owners and evidence, and decide what needs legal or compliance review before the next deadline hits.

Editorial still life of a clean, organized desktop with open folders, a blank ledger, and soft light creating shadows. No people or text, just tools ready for mapping and compliance. Warm orange and neutral palette.
An empty, well-lit workspace awaits the arrival of key records, hinting at the calm before a mapping and review process begins.

Course thesis

Operators and leaders who deploy AI in the EU face new, specific obligations—distinct from those of AI model providers. The most urgent risks come from failing to trace which deployments fall under which duties, missing evidence, or waiting too long to escalate legal review. A simple, evidence-backed workflow can surface blindspots and shrink the compliance gap before deadlines.

What you leave with

By the end, you’ll know exactly which AI deployments in your operation trigger new EU AI Act obligations for deployers, what evidence and owners are missing, what needs legal review, and how to document it all for your next audit or board update.

For

Operators, founders, AI owners, compliance partners, legal-adjacent managers, product leads, and department heads in organisations that deploy AI systems into the EU, but who are not the AI model provider.

Workflow

Regularly inventory deployed AI uses, tag high- and transparency-risk uses, map responsibilities and evidence owners, record missing evidence, and escalate edge cases for expert review—well before the next EU AI Act deadline.

Change

Moves from unseen compliance gaps and ownerless AI uses to a mapped deployer duty landscape with named owners, missing evidence flagged, and specific items lined up for legal or compliance review—on record before the next regulatory deadline.

What you can do

Use these as checks while you move through the plan.

Surface all current AI-enabled systems and uses in your remit.

Classify their risk and your organisation’s deployer role under the EU AI Act.

Map deployer obligations, surface missing owners/evidence, and record what needs legal escalation or oversight.

Produce board-/audit-ready files that cut last-minute compliance scramble.

Chapters

01

Inventory and Name Your Deployed AI Uses

Build your AI Use Inventory: surface every active, pipeline, and shadow AI-enabled system, naming ownership and provider status for each.

Top-down editorial view of orange and deep orange cards and file folders neatly arranged on a light table, some partly pulled forward as if to reveal their presence. The arrangement suggests no AI use is left unaccounted for. No text, people, or technology in view.
A set of color-coded cards and folders, each slightly open, sits arranged on a table. Their staggered spacing suggests hidden entries emerging into reach.

The EU AI Act does not wait for clean lists or tidy project charts. Deployers face hard deadlines and harsh consequences if a system is missed—live, in stealth, or in the pipeline. Every AI-enabled use—automated loan approvals, chat assistants, demand forecasting, image scanning—counts. No exceptions for pilots, internal tools, or edge use cases.

Accountability begins when you write down what exists. Assume the risk: if you have not named ownership, purpose, and provider for every AI use, you will not spot high-risk cases or missing obligations later. Shadow deployments and projects-in-waiting become regulatory liabilities if skipped.

You are not mapping technical details. You are mapping accountability. Who owns the deployment? What is the AI used for? Who built or integrated it? This is your single source of truth. If you have to chase someone later, you failed to map it now.

This list is not legal advice. It is the starting point for compliance, risk, and audit. Use it to drive the next steps—the right review, the right escalation—before the real deadlines hit. [Official source: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai]

Quality checklist

Every system accounted for, including pilots

Each entry has an owner and use case

Provider status is clear

Shadow or edge cases are flagged

## Common mistakes

Missing unregistered or pilot AI uses

Leaving owner or provider fields blank

Assuming IT or compliance already has a full list

Confusing technical inventory with accountability

## Checkpoint

Can you show someone your AI Use Inventory, with no missing live or pipeline systems?

## Social takeaway

Your AI Use Inventory is your first line of defence—list it before you answer to regulators.

Common mistakes

Missing unregistered or pilot AI uses

Leaving owner or provider fields blank

Assuming IT or compliance already has a full list

Confusing technical inventory with accountability

## Checkpoint

Can you show someone your AI Use Inventory, with no missing live or pipeline systems?

## Social takeaway

Your AI Use Inventory is your first line of defence—list it before you answer to regulators.

Checkpoint

Can you show someone your AI Use Inventory, with no missing live or pipeline systems? ## Social takeaway Your AI Use Inventory is your first line of defence—list it before you answer to regulators.

Exercise

Draft Your AI Use Inventory

  1. List every live and in-pipeline AI-enabled system in your remit—no exceptions.
  2. For each, note system name, use case, named owner, and AI provider/developer.
  3. Mark which are visible to compliance or IT, and flag any shadow (unregistered) or edge cases.
  4. Save this as your AI Use Inventory for further mapping.

Use this at work tomorrow

Schedule a meeting to capture every AI deployment and shadow use in your area.

02

Classify Risk and Map Your Role

Sort every AI system into the right risk class and clarify if you’re a deployer or provider, using the EU AI Act as your guide.

Editorial scene of orange and neutral cards laid out along two clear, branching tracks on a plain surface, converging and then splitting at labeled gates—representing classification by role and risk. Warm, intent light. No text or people.
A branching set of document cards and tokens arranged along two diverging tracks, meeting decision gates that control their onward path.

You can’t meet your duties if you don’t know which law applies. The EU AI Act splits responsibilities: some belong to AI model providers, others to deployers. Deployer duties trigger for specific risks—high-risk, general-purpose (GPAI), or transparency-relevant systems. If you classify wrong, you may miss full obligations: risk assessment, documentation, human oversight, new transparency rules.

Start from your inventory. For each AI use, answer: Does this system fall in a high-risk sector? (Source: EU AI Act, see risk list.) Does it generate content that could mislead? (Article 50, transparency rules apply.) Is it built on or exposes a general-purpose AI? (GPAI rules now live.)

Next, map your role. Did your organisation build the core AI model, or are you deploying/optimising someone else’s? If you only deploy, you’re a deployer—most duties are yours unless the system is clearly off-the-shelf and unmodified. Tag each use in your map with both risk status and your role.

These tags decide your next legal and compliance steps. Don’t trust gut feeling or defaults—use the Commission’s sources. If there’s doubt, flag for legal review. This is a living map: new rules, products, or system changes may shift risk and obligations.

Quality checklist

Risk status references the official risk list

Role tagged for every use

Sources cited for each decision

Unclear or edge cases flagged

## Common mistakes

Assuming provider duties when only deploying

Missing GPAI or transparency triggers

Leaving risk or role blank

Skipping source documentation

## Checkpoint

Are all your AI uses classified and risk-tagged with sources?

## Social takeaway

Every AI deployment in your org needs a source-backed risk tag and clear deployer or provider role.

Common mistakes

Assuming provider duties when only deploying

Missing GPAI or transparency triggers

Leaving risk or role blank

Skipping source documentation

## Checkpoint

Are all your AI uses classified and risk-tagged with sources?

## Social takeaway

Every AI deployment in your org needs a source-backed risk tag and clear deployer or provider role.

Checkpoint

Are all your AI uses classified and risk-tagged with sources? ## Social takeaway Every AI deployment in your org needs a source-backed risk tag and clear deployer or provider role.

Exercise

Tag Risk and Role for Each AI Use

  1. Take your completed AI Use Inventory.
  2. For each entry, check if high-risk, GPAI, or transparency duties apply (use EU Act sources).
  3. Decide and record if you are the deployer or provider.
  4. Flag any unclear cases for legal review.
  5. Fill in one row per use in your map.

Use this at work tomorrow

Tag each deployed AI use with risk and your deployer/provider status in your systems map.

03

Map Deployer Obligations and Surface Gaps

Log EU AI Act deployer duties for each use, mark missing evidence, and flag what needs legal/compliance review before deadlines.

Editorial close-up of an open ledger on a workspace. Some lines are marked with orange and red tokens, while one clear row is signaled by an empty slot or vertical marker, suggesting a missing item or need for escalation. No text or people; only objects and light.
A ledger open on a table, with colored markers showing some duties checked and others flagged, while an empty slot signals a gap needing escalation.

Knowing which duties fall to your organisation—as deployer, not provider—is where compliance shifts from risk to control. The EU AI Act splits duties differently than older frameworks. Most missed requirements come from not mapping evidence or from unclear handoff between compliance, legal, and technical teams. The work: For every AI deployment, use your risk and role classification to check which deployer duties apply. Reference current deadlines from official sources for high-risk and transparency-classified AI, bearing in mind that rules for General Purpose AI and Article 50 transparency enter force August 2025 and 2026 (see Commission sources). Log every required element: risk assessment, data quality proof, use-case documents, transparency labelling, oversight process. Name the specific owner or team for each. Mark any missing evidence, unclear owner, or process that is in draft or absent. For high- or transparency-risk uses, escalate gaps for legal or compliance review; do not wait for next cycle. The product is a live ledger. Each use is status-marked: complete, missing, or flagged for expert review. This is not legal advice. It is a field map for internal readiness, always cross-checked with your legal team as enforcement dates approach.

Worked example

A team lists their main customer-facing chatbot as high-risk. They check the EU AI Act for deployer duties: oversight process, transparency disclosure, and documentation. Oversight is documented and owned by IT. Transparency labels are missing—no owner. Documentation is in draft with the product team. They flag the transparency item for legal review and note the documentation status as 'in progress'. Their ledger shows each duty matched to an owner or escalation step, ready for review.

Output template
  • AI deployment/use:
  • Risk classification:
  • Deployer duties (list):
  • Duties status (complete/missing/legal review needed):
  • Named owner/team per duty:
  • Deadline for compliance:
  • Escalation notes:
Quality checklist
  • Duties sourced from official EU AI Act pages
  • Each item status-marked and owner assigned
  • Missing or unclear items flagged for review
  • Ledger covers all classified deployments

Quality checklist

Duties sourced from official EU AI Act pages

Each item status-marked and owner assigned

Missing or unclear items flagged for review

Ledger covers all classified deployments

## Common mistakes

Copying duties from old frameworks

Assuming duties are provider-only

Skipping owner assignment

Filing gaps without escalation

## Checkpoint

Can you show the status (complete, missing, escalated) for every deployer obligation on your ledger?

## Social takeaway

Map every deployer duty—spot gaps, flag reviews, and avoid EU AI Act scramble.

Common mistakes

Copying duties from old frameworks

Assuming duties are provider-only

Skipping owner assignment

Filing gaps without escalation

## Checkpoint

Can you show the status (complete, missing, escalated) for every deployer obligation on your ledger?

## Social takeaway

Map every deployer duty—spot gaps, flag reviews, and avoid EU AI Act scramble.

Checkpoint

Can you show the status (complete, missing, escalated) for every deployer obligation on your ledger? ## Social takeaway Map every deployer duty—spot gaps, flag reviews, and avoid EU AI Act scramble.

Exercise

Build and Review Your Deployer Obligations Ledger

  1. Copy your Provider-Deployer Role Map from the last chapter.
  2. List the EU AI Act deployer duties per use (e.g., documentation, oversight, transparency labels).
  3. For each item, mark status: complete, missing, or needs legal review.
  4. Log the owner/team responsible for each duty.
  5. Save this as your Transparency and Oversight Ledger.

Use this at work tomorrow

Review your main AI use and complete its duties and owner status in the ledger.

30-day path

Week 1: Inventory all AI-enabled systems—include live, in-pipeline, and shadow uses.

Week 2: Run risk and role mapping; tag high-risk, GPAI, transparency-relevant, and provider/deployer status for each.

Week 3: Cross-check deployer obligations, document evidence and process owners, log gaps and escalate legal review needs.

Week 4: Finalise files, review status with leadership, and schedule follow-up for new deployments or law changes.

Success signals

All AI-enabled uses are mapped and classified by the deadline.

No high- or transparency-risk deployment is missing a named owner or evidence file.

Every edge case needing escalation has a tracked legal/compliance ticket before the next regulatory enforcement date.

Leadership receives a complete compliance map as a single, current packet.

Reflection prompts

Which deployed AI use is still invisible to compliance or leadership?

Where are we assuming the provider owns duties that may belong to us?

What evidence would make this deployment review-ready?

Manager checklist

Assign one owner for the AI Use Inventory and one escalation owner for legal review.

Do not leave high-risk or transparency-relevant uses without evidence files.

Review role classification when a provider, workflow, or model changes.

Send leadership a current readiness packet before the next deadline.

In this library

Related RisePlans

Want this shaped around your company?

Risey can research your company foundation first, then build a version of this path around your real workflows, customers, and culture.

Start with your company