CASF™ — AI Safety Certified

EU AI Act

EU AI Act: You're Probably a Deployer, Not a Provider

By Get AI Safety Certified Team, Get AI Safety Certified · September 2026

Key Takeaways

  • Safety = protect people from the model (accidental harm: bias, hallucinations, leaking PII, over-reliance) — guardrails. Security = protect the model from attackers (adversarial: prompt injection, breaches, exfiltration). Intent is the key distinction.
  • A deployer uses AI under its authority. A provider places a system on the market.
  • Article 4 literacy is already in force for providers and deployers. High-risk product duties expand in August 2026.

What Article 4 actually requires (tailored literacy)

Article 4 requires providers and deployers to take measures so staff have a sufficient level of AI literacy, tailored to their role, the context, and the risk of the systems they use. A deployer that only assigns a generic awareness video will struggle to show the training matched the job. Safety = protect people from the model (accidental harm: bias, hallucinations, leaking PII, over-reliance) — guardrails. Security = protect the model from attackers (adversarial: prompt injection, breaches, exfiltration). Intent is the key distinction. Literacy for a deployer is safety practice — oversight, disclosure, logs — not a CISO red-team syllabus.

Deployer vs Provider in 30 seconds

A provider develops an AI system or places it on the market. A deployer uses that system under its authority. A law firm running a vendor contract-review tool is a deployer. The vendor is a provider. If you bought Copilot, shipped a chatbot on a third-party model, or let HR screen resumes with a model, you are a deployer. About nine in ten companies that “do AI” are that deployer, not a foundation-model lab.

12-point deployer checklist (disclosure, logs, human review)

  1. Name the deployer owner who can stop or override the system.
  2. Tell staff which tools this deployer has authorized — and which are banned.
  3. Disclose to users when they are interacting with AI the deployer operates.
  4. Log prompts and outputs the deployer may need for an incident review.
  5. Keep a human review path before the deployer lets AI move money, legal rights, or employment decisions.
  6. List data a deployer never pastes into a prompt (secrets, source, customer files, health data).
  7. Map each use to risk so the deployer trains people for that context, not a generic video.
  8. Record who the deployer trained and when, as Article 4 literacy evidence.
  9. Separate deployer duties (use) from provider duties (placing a system on the market).
  10. Plan for August 2026 high-risk rules if this deployer later offers a high-risk product.
  11. Give the deployer a one-page AI Safety Policy HR and Legal can sign.
  12. Revisit the deployer checklist when you add a new model or vendor.

Timeline: February 2025 AI literacy + August 2026 high-risk

Article 4 literacy obligations for providers and deployers apply from February 2025. A deployer can start now: name an owner, ban secret prompts, disclose AI to users, and keep a human in the loop. Additional high-risk product obligations expand in August 2026. Do not wait for that date to train the deployer team. Literacy is the part you can finish in a weekend.

How Get AI Safety Certified maps to Article 4 literacy

Foundations is a 12-hour, $199 path that teaches a deployer to tell Safety from Security, write a policy, and pass an identity-verified exam. Module 0 is free. Write and quiz stay in the classroom. This is not an official EU, government, or accredited certificate. It is the plain-English literacy a deployer can actually use. Compare the security track on TAISE vs CASF.

Do I need EU AI Act training as a deployer?

If you are a deployer, you need role-tailored literacy, not a poster. Enter the free classroom that covers Article 4 themes in Module 0, then unlock M1–M5 for $199 if you want the full path.

Does this satisfy EU AI Act Article 4 AI literacy?
Article 4 requires providers and deployers to take measures to ensure a sufficient level of AI literacy among staff, tailored to their role, the context, and the risk of the AI systems they operate. Get AI Safety Certified Foundations is plain-English literacy and deployer-practice training covering oversight, transparency, and record-keeping. It is not an official EU, government, or accredited certificate, and it does not by itself meet every high-risk obligation (those expand in August 2026). Use it as role-tailored literacy, then map remaining duties with counsel.
What is an EU AI Act deployer?
A deployer is the organization that uses an AI system under its authority. If you buy Copilot, embed a vendor model, or run an internal chatbot, you are typically a deployer — not a provider who places a system on the market.
Do I need EU AI Act training as a deployer?
If you are a deployer of AI at work, Article 4 expects role-tailored AI literacy for the people who operate and use those systems. Get AI Safety Certified Foundations is literacy training for that deployer role. It is not an official EU certificate.
Is this an official EU AI Act certificate?
No. Get AI Safety Certified is a professional certificate. Curriculum aligns to Article 4 literacy themes for a deployer. It does not claim government recognition, ANAB, or NICCS listing.

CASF™ is a trademark of Gabby Software Engineering LLC DBA getaisafetycertified.com. U.S. Trademark Application Serial No. 50097545 filed September 9, 2026 (Class 041 - Intent to Use). © 2026 Gabby Software Engineering LLC. All rights reserved.