High-Risk AI: Deployer Obligations
Seven requirement areas, all of them satisfied before launch.
What Is High-Risk AI: Deployer Obligations?
A high-risk AI system has to meet seven requirement areas before launch, and most of them are the provider's to prove. You'll run a deployer's review of a system used on employee performance reviews, check the vendor's evidence area by area, and find the gaps that block launch. You'll leave knowing which duties are yours as the deployer, such as informing workers and assigning human oversight.
What You'll Learn in High-Risk AI: Deployer Obligations
- Identify the seven requirement areas for high-risk AI systems under the EU AI Act
- Conduct a compliance assessment for a high-risk AI deployment
- Recognize that human oversight cannot be replaced by accuracy metrics
- Understand that an employer must inform workers before using high-risk AI at work
- Respond correctly when compliance gaps are discovered before deployment
High-Risk AI: Deployer Obligations — Training Steps
-
High-Risk AI Requirements
High-risk AI systems have the strictest obligations under the EU AI Act. The system itself must meet requirements across seven areas (Articles 9-15), and it is the provider's job to meet them (Article 16). As the deployer, you must see evidence of each before use, then meet your own duties under Article 26: Risk management - Identify and mitigate risks throughout the system lifecycle Data governance - Ensure training data is relevant, representative, and free from bias Technical documentation - Maintain detailed documentation of the system's design and function Record-keeping - Enable audit trails and automatic logging Transparency - Provide clear information to deployers and affected persons Human oversight - Ensure humans can effectively supervise the system Accuracy, robustness, and cybersecurity - Meet performance and security standards This exercise walks through a deployer's review of a real deployment: checking the provider's evidence and closing the gaps that are yours.
-
Email from the CISO
An email arrives from James Morton, Pinnacle Group's CISO. The AI vendor has delivered the employee performance review system, and Alice must complete the compliance review before it goes live. The email links directly to the AI Systems Registry on the governance portal.
-
AI Systems Registry
The AI Systems Registry loads with three entries: PerformanceAI (the new high-risk system flagged for review), plus two already-compliant systems (EmailGuard and ChatAssist). The registry tracks risk tier, compliance status, and audit history for every AI system at Pinnacle Group.
-
Compliance Assessment
The PerformanceAI system has clear gaps in its compliance status: a FRIA is not required for a private employer, but the affected workers have not yet been informed, no human reviewer has been assigned, and data governance is still pending review. Alice clicks Run Compliance Assessment inside the PerformanceAI entry to open the detailed checklist for this system.
-
Flag the Gaps
Alice works through each requirement section and flags only the items that are NOT satisfied. Data Governance has an unaddressed gap: training data representativeness across employee demographics has never been assessed. Human Oversight has another: no qualified human reviewer has been assigned with override authority. The remaining sections are in good shape and need nothing flagged. During the review, Alice encounters a note from the vendor: 'Human oversight is not needed because the algorithm has 99.2% accuracy in performance scoring.' This claim needs to be evaluated against what the EU AI Act actually requires.
-
Human Oversight Requirement
-
Critical Gaps Identified
The compliance review has surfaced three critical gaps that must be resolved before PerformanceAI can go live: Workers not informed - Article 27's FRIA does not apply to a private employer, but Article 26(7) does: before a high-risk system is used at work, the employer must inform workers' representatives and the affected workers. That has not happened. No designated human reviewer - No person has been assigned with the authority and training to override the AI's performance scores. Article 26(2) requires the deployer to assign oversight to people with the competence, training and authority to exercise it (Article 14). Data representativeness not assessed - Training data has not been evaluated for representativeness across employee demographics, creating potential bias risk. Article 10 is the provider's duty, so Pinnacle must request PerformanceAI Inc.'s data governance documentation before launch. Each of these gaps represents a legal compliance failure. The system cannot be deployed until all three are resolved.
-
Remediation Email
Alice drafts an email back to the CISO detailing the compliance gaps and recommending that the launch be postponed until all issues are resolved.
-
Compliance Before Deployment
High-risk AI deployment is not just 'install and configure.' It is a structured compliance process with ongoing obligations. The seven requirement areas are not checkboxes to rush through - they protect people affected by AI decisions. Key takeaways: All seven requirement areas must be independently satisfied before deployment, and the deployer should see the provider's evidence for each: risk management, data governance, technical documentation, record-keeping, transparency, human oversight, and accuracy/robustness/cybersecurity. Inform workers first. Before using high-risk AI at work, the employer must inform workers' representatives and the affected workers (Article 26(7)). A FRIA is mandatory only for public bodies, public-service providers and credit or insurance scoring deployers (Article 27). Human oversight cannot be replaced by accuracy . Even a 99.9% accurate system requires a designated human with override authority. If your compliance review finds gaps, the correct response is to delay deployment until they are resolved - not to deploy and fix later.
Security Framework Coverage
NIST CSF
- PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
EU AI Act
- Art. 8 Compliance with the requirements
- Art. 9 Risk management system