EU AI Act Implementation Guide · Chapter 2 of 15

Provider vs Deployer — Your Role Changes Everything

Published 25 March 2026 · 1 min read

The EU AI Act assigns completely different obligations depending on whether you are a provider or a deployer. Getting this wrong means either over-investing in compliance you do not need, or missing obligations you are legally required to fulfil.

Providers vs deployers

Providers develop AI systems and place them on the market under their own name. They face twelve obligations under Article 16 — risk management, technical documentation, CE marking, post-market monitoring, and more. Deployers use AI systems developed by others in a professional context. They face 7 obligations under Article 26 — following the provider's instructions, assigning human oversight, monitoring the system, retaining logs, and informing workers and affected individuals. For most businesses, this is a workload of 30 to 90 hours.

The gray zone

If you rebrand a third-party AI system under your own name, change its intended purpose, or substantially modify it (such as fine-tuning the model), Article 25 reclassifies you as a provider — with the full provider obligations. Using the system exactly as the provider intended keeps you in deployer territory.

You can be both

A company that develops its own AI product and also uses third-party AI tools is both a provider and a deployer — with separate obligations for each system.

Watch for shadow AI

If employees use AI tools without formal approval, your organisation may still be considered a deployer of those systems.

What's in the full chapter

Our full chapter includes a 4-question practical test and a self-check worksheet to confirm your role for every AI system in your organisation.

Read the Full Chapter

Get the complete Chapter 2 with the practical role-determination test, gray zone scenarios, and self-check worksheet.

Read the Full ChapterCheck Your AI Risk Level — Free