Chapter 7: High-Risk Provider — What Providers Must Do
If you develop, train, or place a high-risk AI system on the EU market, you are a provider — and the EU AI Act holds you to the highest standard in the entire regulation. Provider obligations are not about responsible use. They are about responsible creation. The decisions you make in design, data selection, and testing shape everything that follows for every deployer downstream.
The Four Lifecycle Phases
Provider obligations span the full lifecycle, organised into four phases. In the design phase, you must establish a continuous risk-management system, implement data governance for training, validation, and testing data sets — including bias detection — and ensure measurable levels of accuracy, robustness, and cybersecurity. Before placing the system on the market, you must prepare comprehensive technical documentation to Annex IV standards, conduct a conformity assessment (internal for most Annex III systems, third-party for biometric identification and certain safety-component products), affix the CE marking, issue an EU declaration of conformity, and register the system in the public EU database.
At deployment, you must provide deployers with honest, complete Instructions for Use — covering capabilities, limitations, known failure modes, and demographic performance differences — and design the system to be transparent enough for deployers to interpret outputs and explain decisions. After market placement, you must operate a post-market monitoring system, report serious incidents to authorities within 15 days, take immediate corrective action when non-compliance is discovered, and maintain an auditable quality-management system tying all obligations together.
Provider and Deployer: Complementary, Not Substitutable
The relationship between provider and deployer is complementary, not substitutable. The provider builds the foundation — risk management, documentation, conformity, monitoring infrastructure. The deployer operates on it — following instructions, assigning oversight, retaining logs, informing individuals. Neither can do the other’s job, and neither’s compliance excuses the other’s gaps.
What the Full Chapter Covers
The full chapter details every obligation by lifecycle phase, explains how each connects to the corresponding deployer duty in Chapter 6, includes a provider-versus-deployer comparison table, and provides a 13-item self-check covering all major requirements.
Read the Full Chapter
Get the complete Chapter 7 with detailed implementation guidance, evidence checklists, and a provider self-assessment table.
Read the Full Chapter Check Your AI Risk Level — Free