European Union · Regulation (EU) 2024/1689

The AI Act obligations that land on you as a deployer

Most AI Act coverage is written for providers. AccessPoint runs the deployer side — the Article 27 fundamental rights impact assessment that public bodies owe, the Article 26 use duties, registration and transparency, all against a register of the AI systems you actually run.

European Union — AI Act (deployers) at a glance

Who this is for
Deployers — organizations using AI systems, not building them
FRIA
Art. 27 — required of public bodies and public-service providers before using a high-risk system
Core duties
Art. 26 — instructions for use, human oversight, input data, monitoring, logs, incident reporting
Registration
Art. 49 — public-authority deployers register their use of high-risk systems
Transparency
Art. 50 — informing affected persons where the Act requires it
Languages
English

Built for European Union — AI Act (deployers)

One platform for the whole access-and-privacy mandate, pre-configured for this regime and running in your own Microsoft 365 tenant.

The Article 27 FRIA

Run the fundamental rights impact assessment as a real case — the processes the system will be used in, the categories of people affected, the specific risks of harm, the human oversight measures, and the governance if risks materialize — with a dated sign-off before use.

A register of the systems you run

Deployer duties attach to specific systems. Keep an AI and automated-decision-making register recording each system, its role, its provider, its risk classification, and the assessments that cleared it.

Human oversight, assigned

Article 26 requires oversight by people with the competence, training, and authority to exercise it. Record who holds that role for each system, rather than describing oversight in the abstract.

Monitoring and incident reporting

Log AI incidents and malfunctions, assess them, and work the reporting duties to the provider and the authority on a live checklist against the clock.

A playbook of phased obligations

The Act's duties arrive in stages. The pack ships a playbook of what applies when, so the question of whether an obligation has bitten yet has a documented answer rather than a debate.

In your own tenant

Assessments, registers, and incident records stay inside your own Microsoft 365 and Azure tenant — no third-party cloud and no vendor access.

The assessment public bodies owe

Article 27 singles out the public sector. If you deliver public services, the FRIA is yours.

The AI Act's heaviest obligations fall on providers, and most organizations reading it conclude they are largely out of scope. Article 27 is the exception that catches the public sector directly: a deployer that is a body governed by public law, or a private entity providing public services, must carry out a fundamental rights impact assessment before putting a high-risk AI system into use. It asks specific questions — which processes the system will be used in, over what period and how often, which categories of people are affected, what specific risks of harm they face, what human oversight will apply, and what happens if the risks materialize. Those are not questions a procurement form answers. AccessPoint runs the FRIA as an assessment case alongside your PIAs and AIAs, on the same register and the same audit ledger.

Before it goes live A dated assessment that precedes deployment, as required.
Affected people named Categories of persons and specific risks, not generic harms.
Linked to the system Every assessment tied to the register entry it clears.

Configured out of the box

Installing the eu-ai-act jurisdiction pack seeds your tenant with everything this regime needs — a starting point you can adjust, not a lock-in.

Related guide: FOI Workflow Quick Check
  • Regulation (EU) 2024/1689 as the legal-authority spine, scoped to deployer obligations
  • The Article 27 fundamental rights impact assessment questionnaire
  • An AI and automated-decision-making system register with risk classification
  • Article 26 compliance rules — instructions for use, human oversight, input data, monitoring, and logs
  • Named human-oversight roles recorded per system, with competence and authority
  • AI incident and malfunction logging with provider and authority reporting workflows
  • Article 49 registration and Article 50 transparency tracking
  • A playbook of the phased obligations and their application dates

European Union — AI Act (deployers) Questions

Is this pack for AI providers or deployers?

Deployers — organizations that use AI systems rather than develop and place them on the market. That is where most public-sector bodies sit, and it is the side of the Act least well served by generic compliance tooling. Provider-side conformity assessment and technical documentation are outside this pack's scope.

Who has to do a fundamental rights impact assessment?

Article 27 requires it of deployers that are bodies governed by public law, and of private entities providing public services, before putting a high-risk AI system into use — with some further categories the Act specifies. AccessPoint ships the FRIA as an assessment type with the questions the Article actually asks, and records it as dated and signed off before deployment.

How does this relate to Canada's AIA or Ontario's Bill 194?

They are separate regimes with overlapping subject matter, and AccessPoint ships each as its own assessment type on a shared AI systems register. An organization operating across jurisdictions assesses a system once per applicable regime, with each assessment carrying its own questionnaire and citing its own authority, rather than maintaining parallel spreadsheets.

Does this pack replace our GDPR obligations?

No. It installs alongside the GDPR pack, or a national pack, rather than replacing it. A system can require both a DPIA under the GDPR and a FRIA under the AI Act, and the two ask different questions — AccessPoint runs both against the same register entry so the answers stay consistent.

Run EU AI Act Deployer Compliance in Your Own Tenant

Try AccessPoint free for 30 days, configured for Article 27 and the deployer duties. No credit card required.

Start Free Trial