Provider vs Deployer — Your Role Changes Everything
The EU AI Act assigns completely different obligations depending on whether you are a provider or a deployer. Getting this wrong means either over-investing in compliance you do not need, or missing obligations you are legally required to fulfil.
Providers vs deployers
Providers develop AI systems and place them on the market under their own name. They face twelve obligations under Article 16 — risk management, technical documentation, CE marking, post-market monitoring, and more. Deployers use AI systems developed by others in a professional context. They face 7 obligations under Article 26 — following the provider's instructions, assigning human oversight, monitoring the system, retaining logs, and informing workers and affected individuals. For most businesses, this is a workload of 30 to 90 hours.
The gray zone
If you rebrand a third-party AI system under your own name, change its intended purpose, or substantially modify it (such as fine-tuning the model), Article 25 reclassifies you as a provider — with the full provider obligations. Using the system exactly as the provider intended keeps you in deployer territory.
You can be both
A company that develops its own AI product and also uses third-party AI tools is both a provider and a deployer — with separate obligations for each system.
Watch for shadow AI
If employees use AI tools without formal approval, your organisation may still be considered a deployer of those systems.
What's in the full chapter
Our full chapter includes a 4-question practical test and a self-check worksheet to confirm your role for every AI system in your organisation.
Read the Full Chapter
Get the complete Chapter 2 with the practical role-determination test, gray zone scenarios, and self-check worksheet.
Read the Full ChapterCheck Your AI Risk Level — Free