Module 7 of the AI Act Deployer certification: assembling the deployer file — classification record, the Art. 27 FRIA determination, the Art. 4 literacy register, vendor due diligence, and what to do first.
Six modules of obligations produce one thing: a file. This module assembles it, in the order a supervisory conversation actually goes, and ends with what to do first if you are starting from nothing.
The order the questions come in
A supervisor does not begin with your policy. They begin with a system, and they work outward.
"Which AI systems do you use?" The inventory from Module 1. The failure here is not having one; the more common failure is having one that omits the systems adopted outside procurement, which are the ones most likely to carry obligations.
"How did you classify this one, and against what?" The determination record: the tier, the Annex III point checked, the carve-out relied on, who decided, when, and against which version of the law. That last field is what lets a determination be reviewed rather than redone — the Digital Omnibus moved the Chapter III dates and rewrote Art. 4 in July 2026, and a record that does not name its legal baseline cannot be audited.
"Show me the instructions for use." Art. 13 obliges the provider to give you these. Not having them is a finding against you even though the duty to supply is the vendor's, because Art. 26(1) requires you to use the system in accordance with them and you cannot do what you have not read.
"Who oversees it, and what may they do?" Named individuals, training tied to this system, a written delegation of authority, and the override rate. Module 3.
"What do you monitor, and what happened when a threshold was crossed?" The monitoring plan and at least one worked example. A plan with no incidents in eighteen months invites the question of whether anyone is reading it.
"Show me six months of logs." Or longer, per Art. 26(6) and whatever sectoral law imposes. If the vendor holds them, show the contractual right and demonstrate an export.
"Who did you tell?" Workers' representatives before go-live under Art. 26(7); affected persons under Art. 26(11); Art. 50 notices where they apply.
"What is your AI literacy programme?" Art. 4, and the register behind it.
The FRIA determination — including when you do not owe one
Art. 27 requires a fundamental rights impact assessment from a narrow set of deployers:
- bodies governed by public law;
- private entities providing public services;
- deployers of the systems in Annex III point 5(b) — creditworthiness evaluation and credit scoring of natural persons;
- deployers of the systems in Annex III point 5(c) — risk assessment and pricing in relation to life and health insurance.
Everyone else does not owe one. A private employer deploying recruitment screening under Annex III point 4 does not owe a FRIA. A retailer deploying biometric categorisation does not owe a FRIA.
This is worth stating plainly because the market has broadly got it wrong, and the cost of getting it wrong in the over-inclusive direction is real: teams spend quarters producing an assessment nobody asked for while the Art. 26 artefacts that are owed remain unbuilt.
Write down the determination either way. "We assessed Art. 27 and concluded it does not apply, because we are not a public body, do not provide public services, and the system is Annex III point 4 rather than 5(b) or 5(c)" is a two-line record that answers the question permanently.
Where you do owe one, Art. 27 sets out its content: a description of the deployer's processes in which the system will be used, the period and frequency of intended use, the categories of natural persons likely to be affected, the specific risks of harm to those persons, the human oversight measures, and the measures to take if those risks materialise. And where a DPIA is also required, the FRIA complements it rather than duplicating it.
The Art. 4 literacy register
Art. 4 was rewritten by Regulation (EU) 2026/1744 in July 2026. Providers and deployers must now take measures to support the development of AI literacy among staff and others operating systems on their behalf, taking into account their technical knowledge, experience, education and training, the context of use, and the persons on whom the systems are used. The text states expressly that it does not require guaranteeing any specific level of AI literacy of any individual.
Three consequences.
Evidence measures, not levels. Before the amendment, a defensible position needed something approaching an assessment of attainment. Now the artefact is the measure itself: what you provided, to whom, when, and why it fit their role.
Art. 4 carries no fine band of its own. It appears in none of the paragraphs of Art. 99. The exposure is indirect: a literacy failure feeds an Art. 26(2) finding, which does carry the Art. 99(4) band, and it colours the assessment of any other breach.
The register is the artefact. One row per person: name, role, what they were trained on, date, duration, which systems it relates to, and the evidence — an attendance record, a completion record, or a certificate with a verifiable id. Reviewed when roles change or when a new system is deployed.
That register is also the natural output of a training programme, which is why running one is cheaper than documenting one after the fact.
Vendor due diligence, before signature
Everything a deployer owes depends on information only the provider has. Ask for it while you still have commercial leverage:
- the instructions for use (Art. 13), in full, not a datasheet;
- the provider's classification of the system and its reasoning;
- where the Art. 6(3) derogation is claimed, the Art. 6(4) documentation and the Art. 49(2) registration reference;
- a sample export of the Art. 12 logs, so you know what you will be retaining and can confirm you can retain it;
- the declared intended purpose, quoted, for your inventory;
- the human oversight measures the provider considers appropriate, per Art. 14;
- an Art. 25 cooperation clause: information and technical access if you ever become the provider, with a service level;
- a log access and export clause, if the vendor hosts;
- notification commitments, so your Art. 26(5) and their Art. 73 obligations connect.
A vendor unable to supply the first three is selling a product that cannot be deployed compliantly for a high-risk purpose. That is a finding about the product, not about your paperwork.
If you are starting from nothing
In order, and none of these requires the Chapter III deadline to have arrived:
- Build the inventory. You cannot do anything else first.
- Run the Art. 5 check across it. Prohibitions are in force, carry the highest band, and catch ordinary deployments — emotion inference at work above all.
- Run the Art. 50 check. In force since August 2026, tier-independent, and two of the four duties are yours.
- Classify, and write the determinations down.
- Start the literacy register. It is cheap, it is owed now, and it feeds Art. 26(2) later.
- Fix procurement. Every future system arrives with its instructions, its classification and its cooperation clause, or it does not arrive.
- Then build the Art. 26 artefacts for the systems that turned out to be high-risk, against the December 2027 date.
Steps 1 to 3 are where the enforceable exposure is today. Steps 6 and 7 are where the work is.
Check yourself
- We are a private hospital deploying an Annex III point 5 triage system. FRIA? — Consider Art. 27 carefully: a private entity providing public services is in scope, and the answer turns on that characterisation rather than on the Annex III point alone.
- Our AI literacy programme has no exam. Is that a problem under Art. 4? — No. As rewritten, Art. 4 asks for measures supporting literacy and expressly does not require guaranteeing a level for any individual.
- The vendor will not share the instructions for use. — Art. 13 obliges them to provide it. Without it you cannot satisfy Art. 26(1); treat it as a blocker at procurement, not a compliance gap afterwards.
- We have no incidents recorded in eighteen months of monitoring. — Expect that to be probed. Either the thresholds are set where nothing can cross them, or nobody is reading the output.
Previous: Module 6 — Transparency you owe directly
You have completed the seven modules. Together they cover the obligations that attach to the organisation using an AI system rather than the one building it — sit the Deployer examination →
AI Act meets DORA and NIS2
Is your organisation subject to both the AI Act and DORA? The two regulations intersect on the operational resilience of financial AI systems. Our sister site regulation-dora.eu covers DORA in depth — including what the AI Act adds on top of an existing DORA programme.
The AI Act for financial institutions ↗ Explore regulation-dora.eu ↗Frequently Asked Questions
Usually not. Art. 27 applies to deployers that are bodies governed by public law, private entities providing public services, and deployers of the systems in Annex III points 5(b) and 5(c) — creditworthiness evaluation and credit scoring, and risk assessment and pricing in life and health insurance. A private employer deploying an Annex III point 4 recruitment system owes no FRIA. Writing down why you concluded that is more useful than performing one you do not owe.
Art. 4 as rewritten in July 2026 asks providers and deployers to take measures supporting the development of AI literacy, and states expressly that it does not require guaranteeing any specific level for any individual. So the evidence is the measures: a dated register of who was trained, on what, when, and how it was tailored to their role and to the systems they touch. A certificate with a verifiable id is one such record.
The instructions for use required by Art. 13; the provider's classification and, where the Art. 6(3) derogation is claimed, the Art. 6(4) documentation and Art. 49(2) registration; a sample export of the Art. 12 logs; the declared intended purpose in writing; the human oversight measures the provider considers appropriate; and a cooperation clause covering information and technical access if Art. 25 ever fires. Every one of these is far cheaper to obtain before signature.
Take compliance further with the AI Act Academy
A free course, a server-graded exam, a verifiable certificate — and the working templates.