Hlinix.com

EU AI Act Implementation Guide — Chapter 2 of 15

Chapter 2: Provider vs Deployer — Your Role Changes Everything

Published 25 March 2026 · 14 min read

What you will know after reading this chapter:

By the end of this chapter, you will be able to determine whether your organisation is a provider, a deployer, or both — and understand why this distinction is the single most important factor in determining your compliance workload.

Why this is the first question you must answer

Before you can determine your risk classification, before you can identify your obligations, before you can estimate your compliance workload — you need to know your role. The EU AI Act assigns fundamentally different sets of obligations to providers and deployers. A provider of a high-risk AI system faces twelve obligations under Article 16, points (a) to (l), requiring significantly more time and resources than deployer obligations. The exact workload varies depending on the system's complexity, but it is an order of magnitude greater. A deployer of the same system faces 7 obligations under Article 26, requiring 30 to 90 hours. Getting your role wrong does not just mean doing the wrong tasks. It means either massively over-investing in compliance you do not need, or — far worse — missing obligations you are legally required to fulfil.

What is a provider?

Article 3(3) of the AI Act defines a provider as:

"a natural or legal person, public authority, agency or other body that develops an AI system or a general-purpose AI model or that has an AI system or a general-purpose AI model developed and places it on the market or puts the AI system into service under its own name or trademark, whether for payment or free of charge."

In plain language, you are a provider if you do two things: (1) you develop an AI system, or you pay someone else to develop it for you, and (2) you release it to the market or put it into use under your own brand.

The key phrase is "under its own name or trademark." If your company's name is on the AI product — in the marketing, in the documentation, in the contract — you are likely a provider.

Examples of providers include a company that trains a machine learning model and sells access to it via an API, a software company that builds an AI-powered recruitment screening tool and licences it to other businesses, a startup that develops an AI diagnostic system and sells it to hospitals, and an organisation that commissions a third-party developer to build a custom AI system and then deploys it under its own brand name. In each case, the organisation is responsible for creating the AI system and making it available for others to use. The law treats them as the source of the system, and therefore assigns them the heaviest obligations.

What is a deployer?

Article 3(4) defines a deployer as:

"a natural or legal person, public authority, agency or other body using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity."

In plain language, you are a deployer if you use someone else's AI system in a professional or business context. You did not build it. You did not train the model. You are the customer, the user, the operator.

Examples of deployers include an HR department using an AI-powered tool to screen job applications, a bank using a third-party AI system to assist with credit scoring decisions, a hospital using an AI diagnostic tool purchased from a medical device company, a marketing team using an AI content generation tool via API, and a law firm using an AI-powered contract review system. In every case, the organisation is using an AI system that someone else developed. The deployer's obligations focus on how the system is used, not how it was built.

The critical difference in obligations

The difference in workload between providers and deployers is not incremental — it is an order of magnitude.

Provider obligations (Article 16 — high-risk systems): Providers must establish and maintain a risk management system throughout the AI system's lifecycle. They must ensure training data meets quality criteria, including relevance, representativeness, and freedom from errors. They must produce and maintain technical documentation before the system is placed on the market. They must design the system to automatically record events (logging). They must provide clear and comprehensive instructions for use to deployers. They must design the system to allow effective human oversight. They must ensure appropriate levels of accuracy, robustness, and cybersecurity. They must establish a quality management system. They must obtain a CE marking and EU declaration of conformity. They must register the system in the EU database. They must implement post-market monitoring. They must report serious incidents to authorities. They must take corrective action when the system does not conform with the regulation.

Deployer obligations (Article 26 — high-risk systems): Deployers must use the system in accordance with the provider's instructions for use. They must assign human oversight to competent persons with the authority, training, and resources to override the system. They must ensure that input data is relevant and sufficiently representative for the system's intended purpose. They must monitor the system's operation and report risks or incidents to the provider. They must retain logs automatically generated by the system for at least six months. They must inform workers and their representatives when AI is used in the workplace. They must inform affected individuals when AI assists in decisions about them. For certain high-risk categories listed in Annex III (such as law enforcement, immigration, and democratic processes), deployers must also ensure individuals can obtain a clear and meaningful explanation of those decisions. Chapter 6 covers which categories this applies to.

The provider builds the foundation. The deployer operates on it responsibly. If you are a deployer, you are not expected to audit the model's training data or redesign its architecture. You are expected to use it properly, watch it carefully, and be transparent about it.

The gray zone: when a deployer becomes a provider

This is where many organisations get into trouble. Article 25 specifies several scenarios in which a deployer is reclassified as a provider, taking on the full set of provider obligations:

Scenario 1: You put your name on it. If you take an existing AI system and place it on the market or put it into service under your own name or trademark, you become the provider for regulatory purposes. This applies even if you did not modify the system at all. The moment your brand is on it, you own the compliance.

Scenario 2: You change its intended purpose. Every AI system comes with an intended purpose defined by the original provider. If you use the system for a purpose the provider did not intend — for example, using a general customer service chatbot to make employment decisions — you are reclassified as a provider for that new use.

Scenario 3: You make a substantial modification. If you modify the AI system in a way that affects its compliance with the regulation, or changes its intended purpose, you become a provider. Article 3(23) defines a substantial modification as a change made after the system is placed on the market or put into service that was not foreseen or planned in the provider’s initial conformity assessment, and that either affects the system’s compliance with the Chapter III, Section 2 requirements or modifies the intended purpose for which it was assessed. Applying that test, the following actions are likely to qualify: fine-tuning a model with your own data in a way that changes its behaviour, retraining the model on a different dataset, modifying the system's output logic or decision boundaries, and integrating the system into a new product in a way that changes its risk profile.

The practical implication is clear. If you are using a third-party AI system exactly as the provider intended — through their API, within their documented use cases, without rebranding or modifying — you are a deployer. The moment you start customising, rebranding, or repurposing, you risk crossing the line.

Can you be both?

Yes. This is more common than most organisations realise.

Consider a company that develops its own AI-powered analytics platform (provider) and also uses a third-party AI tool for internal HR screening (deployer). For the analytics platform, the company bears full provider obligations. For the HR tool, it bears deployer obligations. The two sets of obligations apply independently and simultaneously.

Another common scenario: a company develops an AI system for internal use only, without placing it on the market. Under the AI Act's definitions, this company is both the provider (it developed the system) and the deployer (it uses the system under its own authority). It must satisfy both sets of obligations for that single system.

This is why the checker at hlinix.com/checker now asks about your role as the very first question. Your answer determines which compliance pathway applies.

Other roles in the AI value chain

The AI Act also defines three additional roles: importers, distributors, and authorised representatives.

Importers (Article 23) are entities that bring an AI system from outside the EU onto the EU market. Before doing so, they must verify that the provider has completed the conformity assessment, that CE marking and EU declaration of conformity are in place, and that instructions for use are available. Importers are essentially a compliance checkpoint at the EU border.

Distributors (Article 24) are entities that make an AI system available on the EU market without modifying it. Their obligations are lighter — primarily verifying that the required documentation and markings are in place before distribution, and cooperating with authorities when requested.

Authorised Representatives (Article 22) are entities established in the EU that act on behalf of providers based outside the EU. They serve as the point of contact for EU authorities and must maintain records related to the AI system.

These three roles are relevant primarily to larger supply chains and cross-border trade. If you are a small or medium-sized business using AI tools in your operations, you are almost certainly a provider, a deployer, or both — not an importer or distributor. However, if your business involves reselling or distributing AI products from non-EU companies, verify whether importer or distributor obligations apply to you.

How to determine your role: a practical test

Important note before you begin: If employees in your organisation use AI tools without formal approval — sometimes called "shadow AI" — your organisation may still be considered a deployer of those systems. When answering Question 1, consider not only officially adopted AI systems but also tools that staff may be using independently. Chapter 11 addresses AI literacy and governance measures to manage this risk.

Answer the following questions for each AI system your organisation uses or develops:

Question 1: Did your organisation develop this AI system, or have it developed on your behalf?

If no — you are a deployer. Proceed to Question 4.

If yes — continue to Question 2.

Question 2: Do you offer this AI system to others (customers, clients, other organisations) under your own name or brand?

If yes — you are a provider. Continue to Question 3.

If no — you developed it for internal use only. You are both a provider and deployer. Continue to Question 3.

Question 3: Do you also use AI systems developed by other organisations in your business operations?

If yes — you are also a deployer for those systems. You have dual roles across different systems.

If no — your role is provider (or provider + deployer for internal systems) only.

Question 4 (for deployers): Have you modified the AI system in any of the following ways?

Rebranded it under your own name. Changed its intended purpose or use case. Fine-tuned or retrained the model. Modified its decision logic or output behaviour.

If yes to any — you may have been reclassified as a provider under Article 25. Seek further assessment.

If no to all — you remain a deployer.

Self-Check: Confirm Your Role

Before filling in this list, inventory all AI systems your organisation uses — including SaaS products with AI features, API-based services, internal tools, and any AI capabilities embedded in existing software. Many organisations underestimate the number of AI systems they rely on.

Based on the practical test above, write down your answer for each AI system in your organisation:

AI System 1: ____________________
My role: Provider / Deployer / Both

AI System 2: ____________________
My role: Provider / Deployer / Both

AI System 3: ____________________
My role: Provider / Deployer / Both

If you have multiple AI systems, you may have different roles for different systems. This is normal. Your obligations are determined per system, not per organisation.

Keep this list. You will need it in Chapter 3, where you determine the risk classification for each system — and your obligations will be the intersection of your role and your risk classification.

Summary

The EU AI Act assigns different obligations based on your role in the AI value chain. Providers — who develop AI systems and place them on the market — carry the heaviest compliance burden, with twelve obligations under Article 16, points (a) to (l), for high-risk systems. Deployers — who use AI systems developed by others — face 7 obligations under Article 26. It is possible to be both a provider and a deployer simultaneously, either for the same system (if you developed it for internal use) or across different systems. A deployer can be reclassified as a provider by rebranding, repurposing, or substantially modifying an AI system. Importers, distributors, and authorised representatives have additional but narrower obligations. Your next step is to determine the risk classification of each AI system you have identified — which is the subject of Chapter 3.

Check your AI system now

Use our free compliance checker to find out your risk classification in 2 minutes.

Check Your AI Risk Level — Free
← Back to Blog Summary