AIPolicyTracker

By role · Deployer / user organisation

AI regulation for deployers and user organisations

A deployer uses an AI system under its own authority in the course of its business. Deployer duties are lighter than provider duties but they are the ones most organisations actually have: follow the instructions, keep humans in a position to oversee, retain logs, tell people when AI is used in decisions about them, and in some jurisdictions assess the impact before use.

Recorded duties
70
53 legally binding
Jurisdictions
12
Controls
25
that meet these duties
Evidence items
75

What deployers get wrong

Treating a purchased system as the vendor's problem. The vendor's documentation is an input to the deployer's own oversight, notice and logging duties, not a substitute for them, and a deployer who materially changes a system can become its provider.

The short list

An inventory of the systems in use, a named owner for each, the vendor documentation on file, a human oversight arrangement that can actually intervene, notices to affected people, and logs kept for the period the instrument names. The controls below cover that list and say which duty each one serves.

Which controls meet these duties?

Sorted by how many of the duties on this page each control satisfies, so the ones worth building first are at the top. A control page lists every other duty it serves, in every jurisdiction.

Controls for this audience
ControlSatisfiesSupportsOwner · frequency
AI interaction and use disclosure notices
Process
143Product owner · at launch and on material change
Privacy and data-protection controls for AI
Process
84Data protection officer · once per ai system
Decision explanation, human review and appeal route
Process
73Customer operations lead · once per ai system
AI governance policy and accountability structure
Policy
72Executive sponsor for AI · annual
AI risk assessment and lifecycle risk register
Process
55AI system owner · once per ai system
AI incident management and regulatory reporting
Process
51Incident coordinator · continuous
AI impact and fundamental-rights impact assessment
Process
46AI system owner · once per ai system
Prohibited and unacceptable-use screening gate
Process
41AI governance lead · once per ai system
Synthetic content labelling and provenance marking
Technical measure
40Engineering lead · continuous
Human oversight design and override procedure
Process
37AI system owner · once per ai system
Accuracy, robustness, fairness and security testing
Technical measure
35Quality or testing lead · at launch and on material change
Data governance and dataset documentation
Process
24Data governance lead · once per ai system
Post-deployment monitoring and drift detection
Technical measure
23AI system owner · continuous
Technical documentation, model cards and instructions for use
Process
13Product or model owner · at launch and on material change
Automatic event logging and record retention
Technical measure
13Engineering lead · continuous
AI literacy and role-based training programme
Training programme
13Learning and development lead · annual
Contractual allocation of AI duties across the supply chain
Contractual term
11Legal counsel · once per ai system
Public-sector AI use-case register and algorithmic transparency
Process
11Agency AI officer · annual
Conformity assessment, declaration and registration
Process
10Regulatory compliance lead · once per ai system
Model release and change-management gate
Process
10Release manager · at launch and on material change
AI system inventory and classification
Process
09AI governance lead · continuous
Vendor and third-party AI due diligence
Process
04Procurement or vendor risk lead · once per ai system
Adversarial and red-team testing for generative AI
Technical measure
02AI security or safety lead · at launch and on material change
Training-data provenance and copyright register
Process
01Model development lead · at launch and on material change
Quality management system for AI development and supply
Policy
01Quality lead · annual

Which duties are recorded?

Every published duty whose record names this audience. It is the recorded set, not every rule in the world; a jurisdiction missing here may simply not be mapped yet (open gaps).

Australia 3 duties

Colorado (United States) 7 duties

European Union 20 duties

India 4 duties

Nepal 1 duty

New York (United States) 5 duties

Singapore 6 duties

South Korea 7 duties

Texas (United States) 5 duties

United Arab Emirates 2 duties

United Kingdom 7 duties

United States 3 duties

What evidence would a reviewer expect?

  • AI customer or deployer clause set Contract clause or supplier term
  • AI data-flow and legal-basis record Register entry
  • AI decision challenge and human review procedure Procedure or standard operating process
  • AI governance forum minutes Governance meeting record
  • AI impact assessment Impact assessment
  • AI incident record Incident record
  • AI incident response playbook Procedure or standard operating process
  • AI intake and classification procedure Procedure or standard operating process
  • AI interaction or use notice Disclosure or notice
  • AI policy Policy document
  • AI quality management system manual Policy document
  • AI responsibility map Register entry
  • AI supplier and component register Register entry
  • AI supplier clause set Contract clause or supplier term
  • AI supplier due-diligence assessment Supplier assessment
  • AI system event logs Access or activity log
  • AI system register Register entry
  • AI system risk assessment Risk assessment
  • AI training completion records Training record
  • AI training curriculum and materials Policy document
  • Adversarial findings tracker Risk register
  • Adverse-decision explanation template Disclosure or notice
  • Algorithmic transparency statement for one use case Disclosure or notice
  • Board or executive approval of the AI policy Approval or sign-off record
  • Challenge and reversal log Monitoring record
  • Conformity evidence pack Technical documentation file
  • Content labelling and provenance standard Procedure or standard operating process
  • Contract clause index against the AI register Register entry
  • Copyright and rights-reservation policy Policy document
  • Data protection impact assessment for an AI system Data protection impact assessment
  • Data quality and bias check report Evaluation or test report
  • Dataset approval for use Approval or sign-off record
  • Dataset documentation sheet Dataset documentation
  • Declaration of conformity or certificate Conformity declaration or certificate
  • Human oversight and override procedure Procedure or standard operating process
  • Human-involvement design rationale Approval or sign-off record
  • Impact assessment approval Approval or sign-off record
  • Impact assessment procedure and template Procedure or standard operating process
  • Incident report to an authority Regulatory filing or notification
  • Independent data audit or DPO review Audit or assurance report
  • Instructions for use Disclosure or notice
  • Internal audit of the AI management system Audit or assurance report
  • Inventory review and publication sign-off Approval or sign-off record
  • Log integrity and retention check Audit or assurance report
  • Log schema and retention standard Procedure or standard operating process
  • Management review minutes Governance meeting record
  • Model card or deployer information pack Model documentation
  • Monitoring dashboard or periodic monitoring report Monitoring record
  • Monitoring review decision Approval or sign-off record
  • Notice catalogue Register entry
  • Notice wording approval Approval or sign-off record
  • Overseer training completion Training record
  • Per-system AI risk register Risk register
  • Post-market monitoring plan Procedure or standard operating process
  • Pre-release test report Evaluation or test report
  • Privacy notice section on AI use Disclosure or notice
  • Prohibited-use screening record Approval or sign-off record
  • Public AI use-case inventory Register entry
  • Public summary of training content Disclosure or notice
  • Red-team exercise report Evaluation or test report
  • Red-team rules of engagement and scenario library Procedure or standard operating process
  • Registration record in the relevant database Regulatory filing or notification
  • Release and change-classification procedure Procedure or standard operating process
  • Release or change approval record Approval or sign-off record
  • Release test sign-off Approval or sign-off record
  • Residual-risk acceptance Approval or sign-off record
  • Risk-tier classification sign-off Approval or sign-off record
  • Role-to-curriculum training matrix Procedure or standard operating process
  • Screening list and escalation procedure Procedure or standard operating process
  • Supplier onboarding decision Approval or sign-off record
  • Technical documentation file Technical documentation file
  • Test plan and acceptance criteria Procedure or standard operating process
  • Training source register Register entry
  • Visible AI-generated content label Disclosure or notice
  • Watermark and provenance robustness test Evaluation or test report

Latest changes to these instruments

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.

Frequently asked questions

Do deployer duties apply to internal tools?
Usually yes when the tool makes or supports decisions about people, such as hiring, credit or access to services. Purely personal, non-professional use is typically excluded. The duty pages cite the scope article.
What evidence should a deployer keep?
The system register entry, the vendor's instructions and documentation, the oversight arrangement, the notices shown to people, the logs, and any impact assessment the instrument requires. The controls below list each item.