M.A.I. Consulting
BriefingEntry8 September 20263 min read

"Deployer" is the word that puts you in scope

Organisations that do not build AI systems are still deployers under the EU AI Act if staff use AI tools in their work, which puts them within scope of Article 4.

The most common reason an organisation decides the AI Act is not its problem is a sentence that sounds obviously true: we do not build AI systems.

That is almost certainly correct. It is also not the test.

Two roles, not one

The Act distinguishes between the organisation that provides an AI system, builds it, puts it on the market, puts its name on it, and the organisation that deploys one: uses it under its own authority in the course of its work.

Providers carry the heavier burden. That is the right design; they control the system.

But deployers carry obligations of their own, and Article 4 is one of them. If your programme officers use a general-purpose assistant to draft donor reports, your organisation is a deployer. You did not build anything. You are still in scope.

Why this catches mission-driven organisations specifically

Three reasons, in the order I usually encounter them.

You have no AI in your systems register. Nobody procured an AI system. Staff opened a browser tab. There is no contract, no line in the budget, no entry on the risk register, so when someone asks "do we use AI?", the honest institutional answer is "not that we know of", and it is wrong.

Your sector vocabulary works against you. "Deployment" in an NGO usually means field deployment. The regulatory sense, putting a system into use under your authority, does not register as the same word.

The tools do not look like systems. A chat interface does not feel like a deployed system in the way a case-management platform does. The Act does not share that intuition.

The exemption that is narrower than people hope

There is a personal, non-professional carve-out. It is doing less work than people want it to do.

A staff member using an assistant on their own time for their own purposes is one thing. The same person using their personal account to draft a funder report on Tuesday afternoon is doing it in the course of your work, on your behalf. The account it was billed to is not the test. Whose work it was, is.

This is the single most consequential misreading I see: organisations treating "not procured by us" as equivalent to "not used by us".

What deployer status actually obliges

Less than people fear, and more than they are doing.

For a general-purpose assistant used for drafting and summarising, the practical obligations are proportionate: know what is in use, take measures to support staff literacy in it, and be able to show what you did. That is closer to a training record and a tool inventory than to a compliance programme.

The heavier obligations attach to high-risk uses, which most mission-driven organisations do not have, with the important exception of anything touching eligibility decisions, access to services, or employment screening. If you are doing any of those with AI in the loop, that is a different conversation and you should have it with counsel.

The practical takeaway

Ask one question at your next management meeting: "Under whose authority is AI being used in this organisation, and on which tasks?"

If nobody can answer, you are a deployer who cannot describe their own deployment. Every other obligation is downstream of fixing that, and the fix is an inventory, not a policy.

Sources

Series · The EU AI Act, as it now stands · part 2 of 3
02 ยท AI Use Policy

What are our people allowed to do, and how?

If this is the question on your desk, a thirty-minute call tells you whether the service fits, or that you do not need us yet.