EU AI ActRoles

Provider or deployer? The one question that decides most of your AI Act obligations

Before you read a single article of the AI Act, answer one question: are you a provider or a deployer? Almost everything else — how long your obligation list is, which deadlines bite, how much documentation you owe — follows from that answer. Get it wrong and you'll either over-build or, worse, miss duties that are genuinely yours.

The two roles, plainly

A provider develops an AI system (or has one developed) and puts it on the market or into service under its own name — you built it, or you badge it as yours. A deployer uses an AI system under its own authority in the course of business — you bought or licensed it and you run it on real people. The Act (Art. 3 defines the roles; Art. 25 covers when responsibilities shift) puts the heavier load on providers, because they shape the system; deployers carry a lighter but real set focused on using it properly.

Why the role changes your whole list

For a high-risk system the asymmetry is stark. A provider owes the full engineering-grade set: a risk-management system, data governance, technical documentation (Annex IV), logging, a quality management system, conformity assessment and EU-database registration. A deployer of that same system owes a much shorter list: use it according to the provider's instructions, assign competent human oversight, monitor it, keep logs, and — for certain uses — run a fundamental-rights impact assessment (Art. 27). Same system, very different homework, depending on where you sit.

You can be both — and that's the trap

Here's what catches mid-market companies. If you take a third-party model and substantially modify it, put your own name on a high-risk system, or change its intended purpose, you can step into the provider role for that system — inheriting the heavier obligations you assumed were someone else's. Fine-tuning a foundation model for a high-risk use is the classic example. The lesson: don't assume "we just use it" settles the question. Map each system separately; a company is frequently a deployer of some systems and a provider of others.

How to establish it — quickly

Do it per system, not per company. For each AI system, ask three questions: Did we build it or brand it as ours? (leaning provider) Did we substantially modify it or repurpose it? (possibly provider) Or do we simply run someone else's system as-is? (deployer). Write the answer down with a one-line justification. That short record is the foundation of your whole AI Act position — and, not coincidentally, exactly what a well-run ISO 42001 role map (your RACI) already captures.

The one-line rule. Providers shape the system; deployers use it. When you shape what you use, you become a provider for that system. Decide it deliberately, per system, and the rest of the Act stops being a fog and becomes a checklist.
BJ

Former IBM and Deloitte strategy consultant, now advising mid-market companies on AI governance. Founder of Govern42.

Questions about your ISO 42001 or EU AI Act programme? Email me directly: bigjay11@gmail.com

Educational orientation, not legal advice. EU AI Act references current as of September 2026. For binding interpretation of your role, consult qualified counsel.