RatedWithAI

RatedWithAI

Accessibility scanner

EU AI ActJuly 29, 2026

EU AI Act: Provider vs Deployer Obligations 2026 — Which Role Are You?

The EU AI Act doesn't apply to everyone the same way. It splits obligations between "providers" and "deployers" — and the gap between the two is enormous. Guess wrong, and you either over-spend on compliance you don't owe, or you skip requirements that carry fines up to €35M. Worse: a handful of routine actions silently flip you from a light-touch deployer into a full-burden provider.

€35M
Max fine (or 7% of global turnover) for prohibited-practice breaches
Art. 25
The clause that turns a deployer into a provider — the most-missed trap
Aug 2026
High-risk system obligations phasing in through 2026–2027

Start With the Definitions

The Act defines several "operators" in the AI value chain. Two do most of the work for a typical business:

  • Provider — develops an AI system or general-purpose AI model (or has one developed) and places it on the EU market or puts it into service under its own name or trademark, whether for payment or free.
  • Deployer — uses an AI system under its authority in the course of a professional activity. (Using an AI system for a purely personal, non-professional activity doesn't make you a deployer.)

The other roles — importer, distributor, authorized representative — matter mostly for moving a provider's system across borders. If you build the AI, you're a provider. If you buy and use it, you're a deployer. That's the 90% case. The remaining 10% is where the money is lost.

Obligations at a Glance

The tables below focus on high-risk AI systems (the tier that carries the real compliance weight — e.g. AI used in hiring, credit, education, essential services, or biometric identification). Limited-risk systems mostly trigger transparency duties; minimal-risk systems are largely unregulated.

Provider obligations (high-risk)

PROVIDER
Establish and maintain a risk management system across the lifecycle
PROVIDER
Data governance: training/validation/testing data quality and bias examination
PROVIDER
Draw up technical documentation and keep it current
PROVIDER
Design for automatic logging (record-keeping) and traceability
PROVIDER
Provide clear instructions for use to deployers
PROVIDER
Design for human oversight and appropriate accuracy, robustness, cybersecurity
PROVIDER
Put a quality management system in place
PROVIDER
Undergo conformity assessment and affix CE marking before market entry
PROVIDER
Register the system in the EU database; report serious incidents; take corrective action

Deployer obligations (high-risk)

DEPLOYER
Use the system in accordance with the provider's instructions for use
DEPLOYER
Assign human oversight to competent, trained, resourced people
DEPLOYER
Ensure input data is relevant and sufficiently representative (where you control input)
DEPLOYER
Monitor operation; suspend use and inform the provider/authority on serious incident or risk
DEPLOYER
Keep the automatically generated logs the system produces (where under your control)
DEPLOYER
Inform workers and their representatives before putting a high-risk system into use at work
DEPLOYER
Where the system makes/assists decisions about people, inform the affected individuals
DEPLOYER
Conduct a fundamental rights impact assessment (public bodies and certain private deployers)

The Article 25 Trap: When a Deployer Becomes a Provider

This is the single most expensive misunderstanding in the whole Act. Under Article 25, a deployer (or distributor or importer) is treated as the provider of a high-risk AI system — inheriting the entire provider obligation set above — in any of these situations:

  • You put your name or trademark on it. Rebrand a third-party high-risk system as your own product and you become its provider, even though you didn't build the model.
  • You substantially modify it. A change to a high-risk system already on the market that affects its compliance or changes its risk profile makes you the provider of the modified system.
  • You change its intended purpose. Repurpose an AI system (including a general-purpose one) so that it now qualifies as high-risk, and you're the provider of that high-risk system.

Concrete example: You license a general-purpose language model, fine-tune it on your recruiting data, wrap it in your own "SmartHire" UI, and sell it to employers to screen candidates. You are now a provider of a high-risk AI system — hiring is a high-risk use case — and you owe conformity assessment, technical documentation, CE marking, and EU database registration. The original model vendor's compliance does not cover your product.

When Article 25 flips you to provider, the original provider must cooperate and hand over information, but the market-facing obligations become yours. Budget and staff accordingly before you rebrand or fine-tune anything.

A 6-Question Self-Assessment

  1. Did we build the AI system, or have it built to our spec, and release it under our name? → Provider.
  2. Are we putting our brand/trademark on a system someone else built? → Provider (Art. 25).
  3. Have we fine-tuned or substantially modified a high-risk system, or changed its purpose so it's now high-risk? → Provider (Art. 25).
  4. Are we simply using a third-party AI tool, as sold, inside our business? → Deployer.
  5. Is the use case high-risk (hiring, credit, education, essential services, biometric ID, etc.)? → determines whether the heavy obligations attach at all.
  6. Is the output used, or the system placed, in the EU? → determines whether the Act reaches you extraterritorially.

Frequently Asked Questions

We only use ChatGPT / an off-the-shelf AI tool internally. Are we a provider?

No — using an AI system as sold, under your own authority in your business, makes you a deployer, not a provider. You take on deployer duties (use per instructions, human oversight, staff awareness, and for high-risk uses, transparency to affected people). You only become a provider if you rebrand it, substantially modify it, or repurpose it into a high-risk system.

Does the general-purpose AI (GPAI) model provider handle our compliance?

No. GPAI model providers have their own obligations (documentation, copyright policy, training-data summaries, and for systemic-risk models, extra safety duties). But those obligations sit at the model layer. If you build a downstream AI system on top of a GPAI model and place it on the market, you are the provider of that system with your own separate obligations.

Are limited-risk systems obligation-free for deployers?

Not entirely. Even outside high-risk, transparency duties apply: users must be told when they're interacting with an AI system (e.g. a chatbot), and AI-generated or manipulated content such as deepfakes generally must be labeled. These transparency obligations fall on providers and, in some cases, deployers.

What happens if we misclassify ourselves as a deployer when we're really a provider?

You'd be missing the core provider obligations — conformity assessment, technical documentation, CE marking, registration — which is exactly the kind of non-compliance that draws the largest fines (up to €15M or 3% of global turnover for most provider breaches, and up to €35M or 7% for prohibited practices). Misclassification is not a defense; the role follows what you actually do, not what you call yourself.

Nail Down Your Role Before You Ship

The provider/deployer question isn't a formality — it decides the entire shape of your EU AI Act program. Map every AI system you build, buy, rebrand, or fine-tune. For each one, record who built it, whose name is on it, whether you modified it, and whether the use case is high-risk. That inventory tells you which role you hold for each system and which obligation set attaches.

Do it before launch. Discovering you're an Article 25 provider after you've shipped means retrofitting conformity assessment and documentation under enforcement pressure — the most expensive way to comply.

Is your own site ADA compliant?

Run a free WCAG 2.1 AA scan on any public URL. Real axe-core checks in a real browser — instant report, no signup.

Need it watched instead of checked once? Starter is $29/mo for continuous monitoring, audit trails and PDF/CSV exports.