EU AI Act deployer obligations for companies running LLMs internally: what applies, and from when
Eurokommerz, Vienna, since 2006: Private AI/ML · IT Managed Services · Enterprise Training · AI Hardware & Software
- A company that uses an AI system under its authority is a deployer (Article 3(4)); one that develops an assistant and puts it into service under its own name, which includes supply for own use, can also be its provider (Article 3(3) and (11))
- Regulation (EU) 2026/1744, the Digital Omnibus on AI, in force since 27 July 2026, moved the high-risk rules for Annex III uses from 2 August 2026, the date the 2024 text says, to 2 December 2027, and those for Annex I products from 2 August 2027 to 2 August 2028
- Article 4 has applied since 2 February 2025; as amended, providers and deployers take measures to support the development of AI literacy of their staff, and the Commission’s Q&A says no certificate is needed and an internal record of trainings can be kept
- Article 50 has applied since 2 August 2026: providers make sure people are informed that they are interacting with an AI system unless that is obvious, and mark generated output in a machine-readable format; deployers disclose deep fakes and AI-generated text published on matters of public interest, unless it had human review under someone’s editorial responsibility
- Drafting, search and summaries are not Annex III purposes; filtering job applications, evaluating staff or scoring the creditworthiness of natural persons are, and for those uses the amended law applies Article 26, with human oversight, monitoring and logs kept for at least six months, from 2 December 2027
Eurokommerz × Vixen.UNO: Private AI/ML Talk to an expert →
What the EU AI Act requires of a company running an internal LLM
A company that runs an LLM assistant or a RAG tool for its staff is a deployer under the EU AI Act, and if it built the assistant itself it can be its provider as well. For an assistant used for drafting, search and summaries, two obligations apply today: measures for the AI literacy of the staff who use it (Article 4, applicable since 2 February 2025) and, where the use fits them, the transparency duties of Article 50 (applicable since 2 August 2026). The high-risk rules, with the deployer obligations of Article 26, attach only to uses listed in Annex III, such as filtering job applications. Under the AI Act as amended by Regulation (EU) 2026/1744, the Digital Omnibus on AI, in force since 27 July 2026, they apply to those uses from 2 December 2027; the 2024 text says 2 August 2026. The prohibitions of Article 5 have bound every company since 2 February 2025, and two new ones apply from 2 December 2026.
The AI Act timeline after the Digital Omnibus on AI
The Commission proposed the amendment on 19 November 2025. The European Parliament and the Council reached a political agreement on 7 May 2026, and the Council gave its final approval on 29 June 2026. Regulation (EU) 2026/1744 of 8 July 2026 was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. The consolidated text as at 27 July 2026 is on eur-lex.europa.eu, and the Commission’s AI Act Service Desk marks each changed provision.
| WHAT APPLIES | 2024 TEXT SAYS | AMENDED LAW | FOR AN INTERNAL LLM |
|---|---|---|---|
| Prohibitions, AI literacy | 2 February 2025 | 2 February 2025 | applies now |
| GPAI models, penalties | 2 August 2025 | 2 August 2025 | duties of the model’s provider; penalty rules in force |
| Article 50, most other rules | 2 August 2026 | 2 August 2026 | applies now where the use fits |
| Intimate deep fakes, CSAM | no such ban | 2 December 2026 | prohibited; Article 5(1a) sets the scope for providers and deployers |
| Article 50(2), older systems | 2 August 2026 | 2 December 2026 | marking for generative systems on the market before 2 August 2026 |
| High-risk, Annex III uses | 2 August 2026 | 2 December 2027 | only for an Annex III purpose |
| High-risk, Annex I products | 2 August 2027 | 2 August 2028 | AI in products such as lifts and toys |
Regulation (EU) 2024/1689, Articles 113 and 111(4), 2024 text and consolidated version as at 27 July 2026 (eur-lex.europa.eu); AI Act Service Desk timeline; Council press release of 29 June 2026.
Provider or deployer: which role your company has
A deployer is a person or organisation “using an AI system under its authority”, other than in a personal non-professional activity (Article 3(4)). A provider develops an AI system, or has one developed, and places it on the market or puts it into service “under its own name or trademark, whether for payment or free of charge” (Article 3(3)). Putting into service includes supply “for own use in the Union” (Article 3(11)), so a company that assembles its own assistant from an open-weight model, a chat front end and a document index can be both its provider and its deployer. Article 50(1) and (2) bind providers; Article 50(4) and Article 26 bind deployers.
Article 25(1)(c) matters more for an internal assistant than Chapter V, whose duties bind the providers of general-purpose AI models. A deployer that changes the intended purpose of an AI system, “including a general-purpose AI system”, so that it becomes high-risk “shall be considered to be a provider of a high-risk AI system”, with the provider obligations of Article 16. An assistant that HR starts to use for ranking applicants can be that kind of change.
Article 4 AI literacy: what the amended text asks
Article 4 applies to providers and deployers of all AI systems, not only high-risk ones, and has applied since 2 February 2025 under both texts. The 2024 text asked for measures to ensure, as far as possible, “a sufficient level of AI literacy” of staff and others operating or using AI systems on the company’s behalf. Regulation (EU) 2026/1744 replaced that with measures “to support the development of AI literacy” of the same persons, taking into account their technical knowledge, experience, education and training and the context of use. It added that the obligation “does not require providers or deployers to guarantee any specific level of AI literacy of any individual”, and that the Commission and the Member States “support and facilitate” the efforts of providers and deployers, in particular SMEs.
The Commission’s AI literacy Q&A, last updated on 27 July 2026, says staff who use generative AI for writing or translating text “should be informed about the specific risks, for example hallucination”. It adds that no certificate is needed and that organisations “can keep an internal record of trainings and/or other guiding initiatives”. The same Q&A places supervision and enforcement of Article 4 with national market surveillance authorities from August 2026.
A practical measure for an internal assistant is a short programme per role, with a record. Users learn which data may go in, where answers fail, how to check the cited source and how to report a wrong answer; administrators learn the permission model and what the logs contain. Grant access through a directory group that trained users join. Our guide to shadow AI policy and controls covers the usage policy.
Article 50 transparency for chat assistants and generated text
Article 50 has applied since 2 August 2026 under both texts, and the Commission published guidelines on its scope on 20 July 2026. Providers design systems that interact directly with people so that those people are informed they are interacting with an AI system, “unless this is obvious” (paragraph 1). Providers of systems that generate synthetic audio, image, video or text mark the output in a machine-readable format, except where the system performs “an assistive function for standard editing” or does not substantially alter the input (paragraph 2). Deployers disclose deep fakes and AI-generated text “published with the purpose of informing the public on matters of public interest”, unless the text has undergone human review or editorial control and someone holds editorial responsibility for it (paragraph 4).
For an internal assistant, name it as AI in its interface, clearly and at the latest at the first interaction (paragraph 5), and send text published on matters of public interest through a named editor. If your company built the assistant and is its provider, it also has to apply the machine-readable marking of paragraph 2, unless an exception applies. For generative systems placed on the market before 2 August 2026, the amended law sets 2 December 2026 for that marking (Article 111(4)), whereas the 2024 text applied 2 August 2026 to all systems. Infringements of Article 50 carry fines of up to EUR 15 million or, for an undertaking, 3 per cent of total worldwide annual turnover for the preceding financial year, whichever is higher (Article 99(4)).
When an internal assistant becomes high-risk: Annex III examples
Article 6(2) makes the systems listed in Annex III high-risk. Annex III lists purposes rather than technologies, so the same assistant can be outside it in one department and inside it in another. Article 6(3) exempts an Annex III system without a significant risk of harm, for example one intended to perform “a narrow procedural task”, but a system that profiles natural persons “shall always be considered to be high-risk”. The Commission’s draft guidelines on high-risk classification, with practical examples, were open for consultation from 19 May to 23 July 2026. Its AI Act Q&A, updated on 7 August 2026, says the guidelines “will be published ahead of the application date for these rules”.
| USE OF THE ASSISTANT | ANNEX III OR ART. 5 | WHAT APPLIES |
|---|---|---|
| Drafting, summaries, RAG Q&A | not listed | Article 4; Article 50 where it fits |
| Filtering job applications | Annex III, point 4(a) | high-risk from 2 December 2027 |
| Evaluating staff performance | Annex III, point 4(b) | high-risk from 2 December 2027 |
| Tasks by personal traits | Annex III, point 4(b) | high-risk from 2 December 2027 |
| Credit scoring of persons | Annex III, point 5(b), fraud detection excepted | high-risk from 2 December 2027 |
| Emotion recognition at work | Article 5(1)(f) | prohibited since 2 February 2025, medical or safety reasons excepted |
Regulation (EU) 2024/1689, Articles 3(39), 5(1)(f), 6(2) and 6(3) and Annex III, points 4 and 5, which Regulation (EU) 2026/1744 did not change; dates from Article 113 as amended. The examples are our reading of the listed purposes.
Whether a particular use falls under Annex III or under the exemption of Article 6(3), and which role your company then holds, is a legal assessment for your legal department. IT can keep connectors to applicant tracking or performance reviews closed until that assessment is made.
Article 26 deployer obligations for high-risk uses
Article 26 is in Chapter III, Section 3, which the amended Article 113 applies to Annex III uses from 2 December 2027. Human oversight goes to people with “the necessary competence, training and authority”, and the logs the system generates automatically, as far as the deployer controls them, are kept for at least six months unless applicable Union or national law, in particular Union data protection law, provides otherwise. Employers inform workers’ representatives and the affected workers before workplace use.
| ARTICLE 26 DUTY | TECHNICAL MEASURE | EVIDENCE TO KEEP |
|---|---|---|
| (1) Use per instructions | model, version and settings pinned; changes through change control | the provider’s instructions, change records |
| (2) Human oversight | an approval step before any decision; reviewers in a named role | role assignments, training records |
| (4) Relevant input data | curated, versioned document sources for retrieval | source register with owners |
| (5) Monitoring | quality and error metrics, a way to report wrong answers, a switch to suspend the use | monitoring reports, incident notes |
| (6) Logs, six months or more | prompts, answers, sources and user identity, logged with access control | retention setting, log extracts |
| (7) and (11) Information | notices in the tool and in the HR process | copies of the notices |
Regulation (EU) 2024/1689, Article 26, unchanged by Regulation (EU) 2026/1744. The measures and evidence are our summary.
Infringements of Article 26 carry the same ceiling as those of Article 50 (Article 99(4)). For SMEs the lower of the two amounts applies (Article 99(6)), and the amending regulation extended that rule to small mid-cap enterprises (Article 99(6a)).
Logging of queries and answers, data and permissions management and protection against prompt injection are part of our Private AI/ML service. Describe the use a department has proposed and the data it would reach, in the form below.
An AI Act checklist for an internal assistant or RAG tool
The steps cover today’s obligations and build the record a high-risk use would need.
- List every AI system in use, built or bought, including public chat services staff use on their own, with owner, users, data sources and purpose.
- Note whether your company built, bought or adapted each one, and record each use’s classification once it is decided.
- Check each use against Article 5 and Annex III; connectors to applicant, HR or credit data stay closed until then.
- Run AI literacy measures per role and keep the record of who completed what, and when.
- Name the assistant as AI in its interface, mark its output if you are its provider, and route text published on matters of public interest through a named editor.
- Log prompts, answers, retrieved sources and user identity, with retention agreed with your data protection officer; our private ChatGPT alternative guide shows where these logs are configured.
- Protect retrieval and tool calls against injected instructions, as in our article on prompt injection and LLM security.
- Repeat steps 2 and 3 when a model, connector or department is added.
A new assistant enters the list with its pilot plan, which names the process, users and metrics; our article on what a private AI pilot should measure covers the metrics.
The first call about your assistants is free of charge, and you leave it with two or three possible solution scenarios. Tell us which assistants you run today, who uses them and what you log.
General information on EU law as of October 2026, not legal advice for an individual case.
What we do
Our Private AI/ML service builds the AI platform under your control, on your servers or on dedicated hardware in a Tier-3 data centre in Lithuania, and nothing goes to public services unless you explicitly enable it. Queries and answers are logged, with data and permissions management, so data governance and process documentation become technically possible. On the AI Act we deliver the technical part, and we train your team to run the platform. Eurokommerz holds the contract and supplies the hardware, with engineering by our partner Vixen.UNO, and the price of the technical assessment is fixed before work begins. How we handle data during a project is set out on our security and compliance page.
FAQ
What are the deployer obligations under the EU AI Act?
What is the AI Act timeline after the Digital Omnibus on AI?
What does Article 4 AI literacy require?
Is an internal chatbot high-risk under the AI Act?
Does Article 50 of the AI Act apply to an internal AI assistant?
What are the AI Act fines for deployers?
Send us a list of the AI assistants you run or plan, who uses them, which data sources they reach and what you log today. We reply within one business day to arrange a first call, from which you leave with two or three possible solution scenarios. The first call is free of charge.
Talk to an expertWe reply within one business day