Boardroom Answers · Security & Compliance · Compliance, Regulatory & Legal
Under the EU AI Act, are you the provider and am I the deployer? Because if your workforce-analysis modules are Annex III high-risk, one of us owes Brussels a conformity assessment — and I want to know which of us it is.?
The question a General Counsel / Chief Legal Officer (CLO) asks.
The short answer
We're provider, you're deployer — and the honest answer on Annex III is that classification of our workforce modules awaits counsel, with a geo-gate already coded that can switch off EU exposure for exactly those modules the day it's needed. Engineering first, certainty when counsel provides it.
The full executive answer
You've asked the exact question our counsel engagement is scoped around, so let me give you the precise current state rather than a confident guess. The allocation: under the Act, we would be the provider of the AI system (we place it on the market) and you the deployer (you use it under your authority) — provider obligations (conformity assessment, technical documentation, risk management system, CE marking for high-risk systems) would fall on us; deployer obligations (human oversight, input data governance, usage monitoring, and for workforce cases informing affected workers) on you. The pivotal open question is classification: our workforce-related modules — talent evaluation, skills assessment, organisational design, adoption monitoring — plausibly touch Annex III §4, which covers AI in employment and worker management. Whether our decision-support diagnostics, aimed at executives assessing organisational readiness rather than evaluating named individuals, actually fall within that class is a genuine legal question, and we have deliberately NOT self-certified the convenient answer.
What we've done instead is engineer for both outcomes before counsel decides. There's a geo-gate in the codebase — its own comments say it plainly — that can restrict exactly those four workforce modules for EU-located organisations with a single switch, so if counsel concludes high-risk-and-not-yet-conformant, EU exposure stops the day the flag flips, without touching any other module or market. The default is conservative pending the opinion. Meanwhile the Act's cross-cutting duties are already engineering reality: human oversight (Article 14) is the product's architecture; transparency and logging (Articles 13, 12) are the provenance system and the audit trail; the risk-management-system expectations map onto the controls framework we maintain for SOC 2/ISO readiness.
For you as deployer, the practical commitments: we'll supply the technical documentation and instructions-for-use the Act requires providers to give deployers, our classification opinion when counsel delivers it, and contractual warranty that we won't market Annex III-classified capability into the EU without the conformity work done. Timeline honesty: the Act's high-risk obligations phase in through 2026–2027; our counsel review is scheduled ahead of EU go-to-market, not after it — and the geo-gate means the compliance path never depends on shipping first and asking later.
Grounded in: EU AI Act Art. 3(3)/(4) (provider/deployer), Annex III §4 (employment), Art. 6 (classification), Arts. 12–14 (logging, transparency, human oversight), Art. 26 (deployer obligations).
The natural next questions
Related governed answers
- Before I put my team on your paper: what's your standard liability and indemnification structure, and where's your actual flexibility?
- Export controls and trade sanctions — does any of this apply to you? We have subsidiaries in jurisdictions that make my trade-compliance team nervous.?
- If a regulator or opposing counsel demands the complete history of a decision made on your platform two years from now, what can you actually produce — and can anyone have edited it?
Want this answered live, on your data?