Provider or deployer under the EU AI Act: which one are you?
Updated: Sep 21

Nearly every duty in the EU AI Act hangs off one question you have to answer first: are you the provider or the deployer? It's worth getting right. The two roles carry very different amounts of work.
If you build an AI system, or pay someone to build it, and release it under your own name, you're the provider. If you take a system someone else made and use it in your business, you're the deployer. Bought a tool off the shelf and switched it on? Almost certainly a deployer. Put your own logo on something and shipped it? Provider. The reason the label matters is that it decides which set of obligations you're carrying.
Based on Regulation (EU) 2024/1689 (the AI Act), as amended by the Digital Omnibus on AI, Regulation (EU) 2026/1744, in force 27 July 2026. Last updated 9 September 2026.
What the Act means by "provider" and "deployer"
The Act doesn't go by your size or your industry, and it certainly doesn't go by whatever your contract calls you. It goes by what you actually do with the system. Both definitions sit in Article 3.
Provider (Article 3(3))
A provider develops an AI system or a general-purpose model, or has one developed for them, and then places it on the market or puts it into service under their own name or trademark. That last part is what trips people up. You don't need to have written a line of the code yourself. Commission a system, put your brand on it, and that's enough to make you the provider.
Deployer (Article 3(4))
A deployer uses an AI system under its own authority, as part of its work. Using something privately at home doesn't count. For most businesses running AI tools they bought from a vendor, this is you.
If you've been through GDPR, the logic will feel familiar. It's the same idea as controller versus processor: your role comes from what you do in practice, not the badge you'd rather wear. And where you're based doesn't decide it.
Provider | Deployer | |
The question | Did you build it, or pay to have it built, and put your name on it? | Are you using someone else's system, under your own authority, for work? |
A typical case | A software firm that sells an AI hiring tool under its own brand. | The employer that buys that tool to screen candidates. |
Where it lives in the Act | Article 16, plus the high-risk requirements in Articles 8 to 15. | Article 26, plus Article 27 for some deployers. |
Scope of duties | The larger set, spanning the system's whole life. | A focused set, on running and overseeing the system. |
What each role has to do:
Providers carry most of the obligations. For high-risk systems that means risk management, data governance, technical documentation, record-keeping, instructions for use, human oversight built into the design, testing for accuracy and security, a quality management system, conformity assessment, CE marking, registration on the EU database, and post-market monitoring. Articles 8 to 15 set the requirements the system has to meet; Article 16 sets what the provider has to do.
Deployers have fewer obligations, but they're substantive. Article 26 asks you to run the system the way the provider intended, put competent people in charge of oversight and give them real authority to step in, feed it data that's fit for the job, keep an eye on how it behaves and report serious incidents, hold on to the logs for at least six months, tell your staff and their reps before a high-risk system goes live in their workplace, and tell affected people where the law requires it. A smaller group of deployers has one more job: public bodies, anyone delivering a public service, and users of certain high-risk systems such as credit scoring or life and health insurance pricing also have to run a fundamental rights impact assessment under Article 27.
These duties are yours, and no contract moves them. You can make the supplier "responsible for AI Act compliance" on paper, and that might win you some money back if it all goes wrong, but the regulator still comes to you, not the vendor.
How a deployer becomes a provider without meaning to:
This is where people get caught. You can take on the full set of provider obligations without buying or building anything new. Article 25 sets out three ways it happens. You count as the provider of a high-risk system the moment you:
put your own name or brand on a high-risk system that's already on the market;
make a substantial change to a high-risk system and it stays high-risk; or
take something that wasn't high-risk, a general-purpose tool for instance, and use it in a way that makes it high-risk under Article 6.
The third is the one that's easiest to miss. Fine-tune a vendor's model on your own data, or point a general tool at something like filtering job applications or credit decisions, and you can cross the line without realising you've moved. There's no notification step and no grace period. The full provider obligations are yours from that moment.
When the rules start to apply:
The Act applies in phases, and the Digital Omnibus moved the main high-risk dates back. As things stand:
Already in force: the Article 5 prohibitions (since 2 February 2025) and the general-purpose AI model rules (since 2 August 2025).
From 2 August 2026: the Article 50 transparency duties, like telling people when they're dealing with AI or looking at AI-generated content. For generative systems already on the market before then, the machine-readable marking of AI content under Article 50(2) applies from 2 December 2026.
From 2 December 2027: the obligations for standalone high-risk systems in Annex III. This is where most provider and deployer duties apply. It was 2 August 2026 until the Omnibus moved it.
From 2 August 2028: high-risk AI built into regulated products under Annex I.
What non-compliance costs:
Breaching your provider or deployer obligations can bring fines of up to 15 million euro or 3% of worldwide annual turnover, whichever is higher (different for start-ups and SMEs). Using a system that's prohibited under Article 5 is treated more seriously still: up to 35 million euro or 7%.
How to work out your own role:
Built it, or paid to have it built, and put your name on it? Provider.
Using someone else's system, under your own authority, for work? Deployer.
Doing both across different systems? Completely normal. Judge each system on its own.
Rebranded, substantially modified, or repurposed something into a high-risk use? Reread Article 25, because you may have become a provider.
Not sure where you sit?
Most people pencil themselves in as a deployer and move on, and that's often where the real exposure sits. Pinning down your role, system by system, is the first step toward being ready, and the most straightforward one to get right. It's also what we do. veritas_fox goes through your systems, confirms where you stand, and builds governance that holds up to scrutiny.
Frequently asked questions
Am I a provider or a deployer under the EU AI Act?
If you build an AI system, or pay to have it built, and release it under your own name, you're the provider. If you use someone else's system in your business, you're the deployer. Off-the-shelf tool switched on for work: deployer. Your brand on something you shipped: provider.
Can I be both a provider and a deployer?
Yes, and plenty of companies are. Your role is judged per system, so you can be the provider of one thing you built and the deployer of another you bought. Look at each system on its own.
Does the EU AI Act apply to UK companies?
t can. Under Article 2 the Act reaches companies outside the EU whenever they put an AI system on the EU market, or their system's output gets used inside the EU. A UK company serving EU users can be caught even though it isn't based there.
Can I make my vendor responsible for my deployer obligations?
No. Article 26 duties stay with the deployer and can't be signed away. A contract clause putting compliance on the supplier might get you compensation if things go wrong, but your legal duties to the regulator don't move.
When do the high-risk obligations start?
fter the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force 27 July 2026), standalone high-risk systems in Annex III are covered from 2 December 2027, and high-risk AI built into regulated products under Annex I from 2 August 2028.
This article is general information about Regulation (EU) 2024/1689 and its amendment by Regulation (EU) 2026/1744. It isn't legal advice and doesn't create a client relationship. Roles and duties turn on the facts of each system. For a view on your own situation, speak to a qualified adviser.



Comments