Provider or deployer? The one question that decides most of your AI Act obligations
Before you read a single article of the AI Act, answer one question: are you a provider or a deployer? Almost everything else — how long your obligation list is, which deadlines bite, how much documentation you owe — follows from that answer. Get it wrong and you'll either over-build or, worse, miss duties that are genuinely yours.
The two roles, plainly
A provider develops an AI system (or has one developed) and puts it on the market or into service under its own name — you built it, or you badge it as yours. A deployer uses an AI system under its own authority in the course of business — you bought or licensed it and you run it on real people. The Act (Art. 3 defines the roles; Art. 25 covers when responsibilities shift) puts the heavier load on providers, because they shape the system; deployers carry a lighter but real set focused on using it properly.
Why the role changes your whole list
For a high-risk system the asymmetry is stark. A provider owes the full engineering-grade set: a risk-management system, data governance, technical documentation (Annex IV), logging, a quality management system, conformity assessment and EU-database registration. A deployer of that same system owes a much shorter list: use it according to the provider's instructions, assign competent human oversight, monitor it, keep logs, and — for certain uses — run a fundamental-rights impact assessment (Art. 27). Same system, very different homework, depending on where you sit.
You can be both — and that's the trap
Here's what catches mid-market companies. If you take a third-party model and substantially modify it, put your own name on a high-risk system, or change its intended purpose, you can step into the provider role for that system — inheriting the heavier obligations you assumed were someone else's. Fine-tuning a foundation model for a high-risk use is the classic example. The lesson: don't assume "we just use it" settles the question. Map each system separately; a company is frequently a deployer of some systems and a provider of others.
How to establish it — quickly
Do it per system, not per company. For each AI system, ask three questions: Did we build it or brand it as ours? (leaning provider) Did we substantially modify it or repurpose it? (possibly provider) Or do we simply run someone else's system as-is? (deployer). Write the answer down with a one-line justification. That short record is the foundation of your whole AI Act position — and, not coincidentally, exactly what a well-run ISO 42001 role map (your RACI) already captures.
Educational orientation, not legal advice. EU AI Act references current as of September 2026. For binding interpretation of your role, consult qualified counsel.