NEWVenvera speaks your language: the full platform, in English, German, Spanish, Bulgarian and Arabic.See what’s new
EU AI Act: Provider vs Deployer
Learn

EU AI Act: Provider vs Deployer

·Alexander Sverdlov

A provider develops an AI system and places it on the market or puts it into service under its own name or trademark. A deployer uses an AI system under its own authority, outside a personal non-professional activity. That is the whole of the definitional difference, and it sits in Article 3, points (3) and (4), of the EU AI Act.

The part that catches people is that the role is not a permanent attribute of your company. It is decided per system, and Article 25 converts a deployer into a provider in three specific circumstances. Most organisations that use AI at any scale are providers of some systems and deployers of others at the same time, with a different obligation set attached to each.

QuestionProviderDeployer
Where is it defined?Art. 3(3): develops and places on the market or puts into service under its own name or trademark.Art. 3(4): uses the system under its own authority, except in a personal non-professional activity.
Which article carries the duties?Art. 16, twelve lettered points, plus the quality management system in Art. 17.Art. 26, twelve paragraphs, plus the impact assessment in Art. 27 where it applies.
Who registers the system?Art. 16(i) and Art. 49(1). Also Art. 49(2) where the Art. 6(3) derogation is used.Only if you are a public authority or Union body, under Art. 26(8) and Art. 49(3).
What is the maximum fine?EUR 15 000 000 or 3% of worldwide annual turnover, higher wins. Art. 99(4)(a).The same ceiling, under Art. 99(4)(e).
Can the role change?Yes. Art. 25(2): the initial provider stops being the provider of that system.Yes. Art. 25(1): three circumstances make a deployer the provider.
The order of the EU AI Act role test: whether you developed the system, whether it carries your name, whether you only use it, and whether you modified it

What is the difference between a provider and a deployer?

Article 3(3) defines a provider as a body that develops an AI system or a general-purpose AI model, or that has one developed, and places it on the market or puts the AI system into service under its own name or trademark, whether for payment or free of charge. Two phrases there do real work. Having a system built for you by a contractor still makes you the provider. And free of charge is inside the definition, so an internal tool handed to another part of the group is not outside it by virtue of being unpaid.

Article 3(4) defines a deployer as a body using an AI system under its authority, except where the system is used in the course of a personal non-professional activity. Under its authority is the operative phrase: an employee operating a tool their employer procured is not the deployer, the employer is.

Article 2 then decides who is reachable at all. Providers are in scope wherever they are established, if they place a system on the Union market or put it into service in the Union. Deployers are in scope where they are established or located in the Union. And under Article 2(1)(c), a provider or deployer established in a third country is in scope where the output produced by the AI system is used in the Union, which is why the role question matters to firms with no EU entity at all.

What does a provider of a high-risk AI system owe?

Article 16 lists twelve obligations, points (a) to (l), and they group into four jobs. Build it to the Chapter III Section 2 requirements, which is point (a), plus the accessibility requirements of Directives (EU) 2016/2102 and (EU) 2019/882 in point (l). Run a quality management system under Article 17, keep the Article 18 documentation and the Article 19 logs, which are points (c), (d) and (e). Prove conformity and mark it: the Article 43 conformity assessment in point (f), the Article 47 EU declaration of conformity in point (g), the Article 48 CE marking in point (h), and your name and contact address on the system in point (b). Then register, correct and answer: the Article 49(1) registration in point (i), the Article 20 corrective action duty in point (j), and the duty to demonstrate conformity on a reasoned request in point (k).

Two duties sit outside Article 16 but attach only to providers. Under Article 22, a provider established in a third country must appoint an authorised representative in the Union by written mandate before making a high-risk system available on the Union market. And under Article 25(3), where a high-risk system is a safety component of a product covered by the Section A Annex I legislation, the product manufacturer, not the AI supplier, is the provider if the system carries the manufacturer's name or trademark.

Which EU AI Act article carries which duty: Article 16 for providers, Article 26 for deployers, Article 25 for the role flip, and Articles 4, 27 and 50

What does a deployer of a high-risk AI system owe?

Article 26 has twelve paragraphs. They are lighter than Article 16, but they are not administrative.

Paragraph 1 requires appropriate technical and organisational measures to ensure the system is used in accordance with the instructions for use. Paragraph 2 requires human oversight to be assigned to natural persons who have the necessary competence, training and authority, as well as the necessary support. Paragraph 4 requires input data to be relevant and sufficiently representative in view of the intended purpose, to the extent the deployer controls it.

Paragraph 5 is the monitoring and escalation duty, and it is the one with a clock on it. Where a deployer has reason to consider that use in accordance with the instructions may present a risk within the meaning of Article 79(1), it must inform the provider or distributor and the market surveillance authority without undue delay, and suspend use of the system. Where it identifies a serious incident, it informs the provider first, then the importer or distributor and the market surveillance authorities. Financial institutions already subject to internal governance requirements under Union financial services law are deemed to satisfy the monitoring limb by complying with those rules.

The rest is shorter than it looks. Logs kept for at least six months where they are under your control, paragraph 6. Workers' representatives and affected workers informed before a high-risk system goes into service at the workplace, paragraph 7. Registration for public authority and Union body deployers, plus a bar on using a system they find is unregistered, paragraph 8. The Article 13 information fed into your own data protection impact assessment, paragraph 9. And under paragraph 11, deployers of Annex III systems that make or assist decisions about natural persons must tell those people they are subject to the system.

Article 27 adds the fundamental rights impact assessment, and it does not apply to every deployer. It applies to deployers that are bodies governed by public law or private entities providing public services, and to deployers of the creditworthiness and life and health insurance systems in points 5(b) and (c) of Annex III. It does not apply to the critical infrastructure systems in point 2 of Annex III. The obligation attaches to first use, and the result has to be notified to the market surveillance authority.

When does a deployer become a provider?

Article 25(1) is exact. Any distributor, importer, deployer or other third party is considered to be a provider of a high-risk AI system, and is subject to the Article 16 obligations, in any of three circumstances: it puts its name or trademark on a high-risk system already placed on the market or put into service, without prejudice to contractual arrangements allocating the obligations otherwise; it makes a substantial modification to a high-risk system already on the market such that it remains high risk under Article 6; or it modifies the intended purpose of a system, including a general-purpose AI system, that was not classified as high risk, in such a way that it becomes high risk under Article 6.

The third circumstance is the one that surprises deployers. Taking a general-purpose model that nobody classified as high risk and pointing it at, say, sifting job applications is a change of intended purpose into an Annex III use case. The organisation that made that decision is now the provider, with Article 16 in full, including the conformity assessment and the CE marking.

Article 25(2) then removes the initial provider from the picture for that specific system, and this is the paragraph the 2026 Digital Omnibus rewrote. The initial provider must closely cooperate with the new provider and make available the necessary information and reasonably expected technical access. The amended text now spells out what that includes where relevant: technical documentation sufficient to assess compliance with Article 16, information about known limitations and failure modes, and targeted technical access including for testing and validation. The relief is unchanged: none of it applies where the initial provider clearly specified that its system is not to be changed into a high-risk system.

Article 25(4), also amended in 2026, requires a written agreement between the provider of a high-risk system and any third party supplying an AI system, AI model, tools, services, components or processes integrated into it. It does not apply to third parties making tools, services, processes or components other than general-purpose AI models publicly available under a free and open-source licence.

The three circumstances in EU AI Act Article 25(1) that make a deployer the provider of a high risk AI system, and the Article 25(2) hand over that follows

Which duties fall on both roles?

Two, and both apply outside the high-risk tier.

Article 4, the AI literacy duty, applies to providers and deployers of AI systems whatever the risk class, and the Omnibus replaced it. It now requires taking measures to support the development of AI literacy of staff and other persons dealing with the operation and use of AI systems on their behalf, and adds explicitly that the obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual. It has been in application since 2 February 2025, so it is the one obligation on this page that is already live for almost everyone. Our guide to the AI literacy requirements covers what a defensible programme looks like.

Article 50 splits the transparency obligations between the roles rather than sharing them. Paragraph 1, systems interacting directly with natural persons, and paragraph 2, machine-readable marking of synthetic audio, image, video and text, fall on providers. Paragraph 3, emotion recognition and biometric categorisation, and paragraph 4, deep fakes and AI-generated text published to inform the public on matters of public interest, fall on deployers. Both carry the same ceiling under Article 99(4)(g).

What does getting the role wrong cost?

Article 99(4) sets one ceiling for both roles: up to EUR 15 000 000 or, for an undertaking, up to 3% of total worldwide annual turnover for the preceding financial year, whichever is higher. Provider obligations under Article 16 sit at point (a), deployer obligations under Article 26 at point (e), and the Article 50 transparency obligations for either role at point (g).

The 2026 amendment added point (da): obligations of providers and operators pursuant to Article 25(2) and (4). Failing to hand over documentation to a new provider, or failing to put the Article 25(4) written agreement in place, now carries the same ceiling as failing the substantive duties themselves.

Above it, Article 99(3) prices the Article 5 prohibited practices at EUR 35 000 000 or 7%. Below it, Article 99(5) prices incorrect, incomplete or misleading information to notified bodies or national competent authorities at EUR 7 500 000 or 1%. The SME rule in Article 99(6) inverts the formula: for SMEs, including start-ups, each fine is up to the percentage or the amount, whichever is lower, and the Omnibus inserted Article 99(6a) extending that lower-of rule to small mid-cap enterprises. The tiers are set out in full in our guide to EU AI Act penalties and fines.

EU AI Act Article 99 penalty ceilings by role: 7 percent for prohibited practices, 3 percent for provider and deployer duties, and 1 percent for misleading information

What the other results get wrong

Three errors recur, and each of them changes what a compliance team should do next.

The first is calling a deployer a user. The 2021 draft used user; the adopted Regulation does not. Article 3(4) says deployer, and the distinction is not cosmetic, because an employee operating a system is a natural person using it while the employer is the deployer. Guidance written against the draft text allocates duties to the wrong party.

The second is treating the role as a company-level label. Nothing in Article 3 or Article 25 supports that. A single organisation can be the provider of a system it built, the deployer of a system it bought, and, through Article 25(1)(c), the provider of a system it merely repurposed. Any inventory that records one role per company will misstate most of its rows.

The third is reproducing the pre-2026 text. Article 4 has been replaced, Article 25(2) and (4) have been amended, and Article 99 has a new point (da) and a new paragraph 6a. Articles 13, 14, 16, 22 and 26 were not amended by the Omnibus, so the two duty lists themselves are stable, but the hand-over duty around them and its price are not what they were.

Working out your own position

Fill this in per system rather than per company. The last column is the article that decides the row.

QuestionYour answerWhat it decides
Did you develop the system, or have it developed, and put it out under your name?Art. 3(3). If yes, you are the provider, whether or not money changed hands.
Do you only use it, under your own authority, in a professional context?Art. 3(4). If yes, and nothing below applies, you are the deployer.
Have you put your name or trademark on someone else's system?Art. 25(1)(a). You are the provider, and Art. 16 applies in full.
Have you substantially modified it, or changed its intended purpose?Art. 25(1)(b) and (c). The same result, and the most commonly missed route.
If a role flipped, do you have the documentation from the initial provider?Art. 25(2), as amended in 2026. Documentation, failure modes and technical access.
Is there a written agreement with every third party whose components you integrate?Art. 25(4). Not required for free and open-source components other than GPAI models.
Are you a public body or an entity providing public services?Art. 27. A fundamental rights impact assessment before first use, notified to the authority.

If more than a handful of systems are in play, the useful artefact is an inventory with a role and a classification recorded against each entry, both dated, because both move. The documentation each role has to hold sets out what those entries need to point at, and a free compliance check gives you a starting position across the whole set.

The bottom line on EU AI Act roles: the provider and deployer question is decided for each system rather than once for the company

Frequently asked questions

Can one company be both a provider and a deployer?

Yes, and most are. The role attaches to a system, not to an organisation. Building a model and buying a tool in the same quarter puts you on both sides of the Regulation at once.

Is a deployer the same as a user?

No. The adopted text uses deployer, and defines it in Article 3(4) as the body using the system under its authority. A member of staff operating the system is not the deployer; the organisation whose authority they act under is.

Does fine tuning a model make us the provider?

It depends on what the change does. Article 25(1)(b) covers a substantial modification to a system that remains high risk, and Article 25(1)(c) covers modifying the intended purpose of a system, including a general-purpose AI system, so that it becomes high risk under Article 6. A change that does neither leaves you as the deployer.

Do the transparency rules in Article 50 depend on the risk class?

No. Article 50 applies to certain AI systems whatever their classification, and paragraph 6 makes clear it does not affect the Chapter III requirements. A chatbot that is not high risk still engages paragraph 1, and its provider carries that duty.

We are outside the EU and have no EU entity. Does this apply?

Possibly. Article 2(1)(c) brings providers and deployers established in a third country into scope where the output produced by the AI system is used in the Union, and Article 2(1)(a) covers providers placing systems on the Union market wherever they are established. Our guide to whether the AI Act applies outside the EU works through the limbs.

When do the high-risk duties in Articles 16 and 26 start to apply?

After the 2026 amendment to Article 113, Chapter III Sections 1, 2 and 3 apply from 2 December 2027 for systems classified as high risk under Article 6(2) and Annex III, and from 2 August 2028 for systems classified under Article 6(1) and Annex I. Article 4 and Article 5 are already in application, and Article 50 applies from 2 August 2026. The complete set is in our guide to EU AI Act deadlines and dates.

Primary sources

Definitions, scope and duties above are quoted from Articles 2, 3, 4, 16, 22, 25, 26, 27, 49, 50 and 99 of Regulation (EU) 2024/1689. The 2026 changes to Articles 4, 25(2), 25(4), 99 and 113 come from Regulation (EU) 2026/1744, the Digital Omnibus on AI, adopted 8 July 2026, published in the Official Journal on 24 July 2026 and in force from 27 July 2026. Articles 13, 14, 16, 22 and 26 were not amended by that Regulation. Confirm the current consolidated text before relying on a specific paragraph, and see the EU AI Act framework page for how the obligations hang together.

Alexander Sverdlov

Alexander Sverdlov

CEO & Founder

Alexander is the founder of Venvera and a 20+ year veteran of European cybersecurity and compliance. He has led security and risk programmes for regulated financial institutions, fintechs and SaaS companies operating under DORA, NIS2, GDPR, ISO 27001 and the EU AI Act. Before Venvera, he founded Atlant Security, an offensive security consultancy that ran penetration tests, red-team exercises and ISO 27001 readiness programmes for clients across the EU and the Middle East. He writes on the cross-framework realities of running modern compliance: how to map one control to many obligations, where the spreadsheets fall apart, and what regulators are actually asking for once the auditor sits down.

More articles by Alexander

CONTINUE READING