You Resold the Model. The AI Act Gave You a Role You Never Read.
Almost every discussion of the EU AI Act splits the world into providers and deployers. The Act has two more operator roles sitting between them — importer and distributor — and they are occupied by the resellers, managed service providers, marketplaces and EU subsidiaries who assumed the obligation belonged to whoever built the model.
The Role Is Assigned by Conduct, Not by Contract
The most expensive misreading in the channel is that operator roles are allocated by agreement. They are not. The Act describes what each operator does, and an entity that does it holds the role whatever the reseller agreement says about who bears regulatory responsibility. A contract can allocate indemnity between two parties; it cannot move a public-law obligation off the party whose conduct triggered it.
That has a specific consequence for groups with a European entity. A US company selling directly into Europe has an authorised-representative question. A US company selling through its own Irish or Dutch subsidiary has a different one, because the subsidiary is established in the Union and is placing on the market a system that bears the parent's trademark. Internally that is one company shipping its own product. Under the Act it is an importer relationship, and the importer duties are real.
What the Importer Has to Verify
Before a high-risk system is placed on the Union market, the importer verifies that the provider ran the applicable conformity assessment, that the technical documentation exists, that the system carries its conformity marking and is accompanied by its declaration of conformity and instructions for use, and that an authorised representative has been appointed where one is required. The importer also may not place the system on the market if it has reason to consider it non-conforming, or the documentation falsified.
- Conformity assessment carried out — with the certificate where a notified body was involved.
- Technical documentation drawn up and available on request.
- Conformity marking present on the system.
- Declaration of conformity and instructions for use accompanying it.
- Authorised representative appointed where the provider is outside the Union.
- Importer's own name and contact details on the system, packaging or documentation.
Read that list as a procurement gate rather than as legal theory. It is answerable in a single email to the vendor before a deal closes, and unanswerable afterwards at any price. The reason so few channel businesses have asked is that nothing in a normal software purchase order has ever required it, and AI products were sold through the same purchase orders as everything else.
The Distributor's Narrower, Continuing Duty
A distributor makes a system available on the market without being the provider or the importer. The verification duty is lighter — confirm the conformity marking, the declaration and instructions, and that the provider and importer have complied with their own obligations — but it does not stop at the point of sale. A distributor that considers a system it has made available not to be in conformity has to take the corrective action needed to bring it into conformity, withdraw or recall it, or ensure the provider or importer does, and inform the relevant authorities.
Storage and transport conditions sit in the same clause and read as an afterthought until you translate them into software: a distributor is responsible for not degrading conformity while the system is under its control. For a managed service provider that hosts, configures and updates a customer's deployment, "under its control" is a much broader window than the word distribution suggests.
The Clause That Rewrites Your Role
The provision channel businesses most need to read is the one that reassigns the provider role. A distributor, importer, deployer or other third party becomes the provider of a high-risk system, with all of the provider's obligations, if it puts its name or trademark on a system already placed on the market, makes a substantial modification to it while it remains high-risk, or modifies the intended purpose of a system so that it becomes high-risk.
Each of those is a routine commercial act. White-labelling a vendor's model under your own brand is the default in the MSP market. Fine-tuning on customer data, adding a retrieval layer, or changing thresholds so a recommendation becomes a decision are routine implementation work. Marketing a general-purpose assistant specifically for recruitment screening or credit triage is a purpose change made in a product page rather than in code.
When the role flips, the original provider is no longer the provider of that system, and you inherit the technical documentation, the quality management system, the registration obligation and post-market monitoring for a model whose training data and evaluation history you have never seen. The provider does have to cooperate and supply what you need — but the obligation to hold the file is yours, and cooperation is a weaker thing to depend on than possession.
A Channel Compliance Checklist
- List every AI product you resell, host or bundle, and name the entity that first made it available in the Union.
- Classify each: provider, importer, distributor, deployer — by conduct, then check whether the contract agrees.
- For anything plausibly high-risk, request the documentation set before renewal, not after an inquiry.
- Flag every white-label and every deployment where you fine-tune, re-thresholds or re-purpose.
- Put the certificate, declaration and instructions in a ten-year archive indexed by system and version.
- Add your importer contact details to the artefacts you ship, not only to your website.
- Build an internal escalation route for a suspected non-conformity, and name the person who owns it.
Questions Channel Teams Are Asking
Our vendor says it handles all EU AI Act compliance. Is that enough?
It is enough for the vendor's own obligations and irrelevant to yours. The verification duties exist precisely because the Union authority cannot reach a provider established abroad as easily as it can reach the entity established in Europe that sold the product. That is the design: the importer is the accountable point of contact inside the Union. A vendor assurance is useful evidence that the artefacts exist, and it is also the cheapest thing a vendor can produce. Ask for the artefacts. A provider that has genuinely completed a conformity assessment can send the declaration and instructions the same day, and one that cannot is telling you something about the state of its file.
We only sell low-risk AI tools. Do any of these duties apply?
The heavy verification and retention duties attach to high-risk systems, so a genuinely limited-risk catalogue carries much less. Two cautions. First, classification is not a marketing judgement — a tool sold as productivity software can fall in scope by virtue of where the customer uses it, and the substantial-modification and purpose-change provisions mean your own configuration can move it. Second, transparency obligations for systems that interact with people, generate synthetic content or perform emotion recognition apply regardless of risk tier, and those land on the customer-facing surface you control. Document the classification decision for each product with a date and a reason, because the value of that record is that it shows the question was asked.
Does hosting a customer's deployment make us a distributor or a deployer?
Potentially both, for different systems, and the two roles carry different obligations. If you make a third party's system available to your customer in the course of commercial activity, that looks like distribution. If you use an AI system under your own authority in your own operations — including to run the managed service — you are a deployer of that one, with human-oversight, input-data and monitoring duties of your own. MSPs commonly hold three roles across a single customer account, and the useful exercise is to map them per system rather than per customer. A single answer at the account level is almost always wrong for at least one product in the stack.
How does this interact with an authorised representative?
The authorised representative is the provider's appointee, acting on a written mandate to hold the documentation and be the contact point for the authorities. The importer is a distinct operator in its own commercial chain with its own duties, and appointing a representative does not discharge them. What the representative does change is your verification list: for a non-Union provider, the existence of the appointment is one of the things you are checking. If the vendor cannot name its representative, you have found a gap in the provider's compliance before you have taken on any of the consequences of it.
What is the realistic enforcement exposure for a mid-sized reseller?
Market-surveillance authorities work from complaints, from incidents and from sweeps, and the operator they reach first is the one established in their own jurisdiction — which in a cross-border chain is frequently the importer or distributor rather than the provider. The financial ceilings under the Act are tied to turnover and scale with the nature of the breach, with the highest tier reserved for prohibited practices. But the more probable first contact is not a fine; it is a reasoned request for documentation with a deadline attached. An organisation that can answer it in days has a compliance function. One that discovers at that moment that nobody ever received the declaration of conformity has a commercial problem with its supplier and a regulatory one at the same time.
Start With the White-Label List
Before any documentation exercise, pull every product you sell under your own brand that contains someone else's model. That list is where the role flip happens, and it is usually shorter than people expect and shorter than it should be, because nobody has counted the bundles.
Then work outward: verification artefacts for what you import, retention for what you hold, and an escalation path for what you sell. In that order, because the first one determines whether the other two are even yours to do.