Provider vs Deployer under the EU AI Act
Last reviewed: · By Victor Humenhuk (AIGP certified)
Under the EU AI Act, the provider is the actor that develops an AI system or general-purpose AI model, or has one developed, and places it on the Union market or puts it into service under its own name or trade mark. The deployer is the organisation using that system under its own authority in a professional capacity. Providers carry the heavy compliance load for high-risk systems: risk management, data governance, technical documentation, conformity assessment, CE marking and registration. Deployers carry a shorter list centred on using the system as instructed, assigning human oversight, monitoring it and keeping logs, and a deployer that rebrands a high-risk system, substantially modifies it, or repurposes a system so that it becomes high-risk is treated as a provider under Article 25.
What is the difference between a provider and a deployer?
The EU AI Act (Regulation (EU) 2024/1689) allocates obligations by role, not by company size or sector. A provider develops an AI system or general-purpose AI model, or has one developed, and places it on the Union market or puts it into service under its own name or trade mark, whether for payment or free of charge (Article 3(3)). A deployer is a natural or legal person, public authority, agency or other body using an AI system under its authority, except where the use is a personal, non-professional activity (Article 3(4)).
The same organisation can be both. If you build an internal CV-screening tool and run it on your own applicants, you are the provider and the deployer of that system, and you owe both sets of duties.
| Provider | Deployer | |
|---|---|---|
| Core idea | Builds it, or badges it, and puts it on the market | Uses it under its own authority, professionally |
| Definition | Article 3(3) | Article 3(4) |
| Typical example | Vendor selling a CV-screening tool | Employer running that tool on applicants |
| Reach outside the EU | Caught where the system is placed on the Union market or put into service in the Union, wherever the provider is established, and where the output is used in the Union | Caught where established or located in the Union, or where the output produced by the system is used in the Union |
| Weight of high-risk duties | Heavy: the whole of Chapter III, Section 2 and Section 3 | Focused: Article 26, plus Article 27 for some deployers |
| Fine exposure | Up to 15 million euro or 3% of total worldwide annual turnover (Article 99(4)) | Up to 15 million euro or 3% of total worldwide annual turnover (Article 99(4)) |
Which obligations attach to each role for high-risk AI?
The provider must, before the system goes on the market, put in place a risk management system running across the lifecycle (Article 9); govern the training, validation and testing data (Article 10); draw up technical documentation (Article 11 and Annex IV); build in automatic logging (Article 12); supply instructions for use that let the deployer interpret and use the output (Article 13); design in human oversight measures (Article 14); and achieve an appropriate level of accuracy, robustness and cybersecurity (Article 15). On top of that sit a quality management system (Article 17), the conformity assessment (Article 43), the EU declaration of conformity (Article 47), CE marking (Article 48), registration in the EU database (Article 49), post-market monitoring (Article 72) and serious incident reporting (Article 73).
The deployer must, under Article 26: use the system in accordance with the instructions for use; assign human oversight to natural persons with the necessary competence, training, authority and support; ensure input data is relevant and sufficiently representative for the intended purpose, so far as it controls that data; monitor operation, and suspend use and inform the provider and the market surveillance authority where use may present a risk within the meaning of Article 79(1); retain automatically generated logs for at least six months where they are under its control; inform workers' representatives and affected workers before putting a high-risk system into use at the workplace; register, if it is a public authority or a Union institution; and inform individuals when they are subject to the use of a high-risk system in decisions about them. The Article 4 AI literacy duty falls on both roles.
When does a deployer become a provider? (Article 25)
Article 25 flips the role. A deployer, distributor, importer or other third party is treated as the provider of a high-risk system, with all provider obligations, where it:
- puts its name or trade mark on a high-risk AI system already placed on the market or put into service, subject to any contractual allocation of duties;
- makes a substantial modification to a high-risk system already on the market in such a way that it remains high-risk; or
- modifies the intended purpose of an AI system that was not classified as high-risk, including a general-purpose AI system, so that it becomes high-risk.
Where that happens, the original provider is no longer considered the provider of that specific system, but must cooperate, hand over information and give the technical access reasonably needed to comply. This is the trap that catches most organisations in the role analysis: buying a general-purpose tool and pointing it at recruitment or credit decisions can make you the provider, not merely the customer.
Where do importers, distributors and authorised representatives fit?
| Role | Definition | Main duty |
|---|---|---|
| Importer | Located or established in the Union and places on the market an AI system bearing the name or trade mark of a person established in a third country (Article 3(6)) | Verify before placing on the market that the conformity assessment was carried out, the technical documentation exists, the CE marking and declaration of conformity are present and an authorised representative was appointed (Article 23) |
| Distributor | Anyone in the supply chain other than the provider or importer making an AI system available on the Union market (Article 3(7)) | Verify the CE marking, declaration and instructions are in place and that the provider and importer met their duties, and act where it considers or has reason to consider the system non-conforming (Article 24) |
| Authorised representative | Person located or established in the Union with a written mandate from a provider (Article 3(5)) | Must be appointed by a third-country provider before a high-risk system is made available in the Union; keeps documentation and acts as a contact point for authorities (Article 22) |
Importers and distributors are equally caught by the Article 25 role switch if they rebrand or substantially modify.
How do you work out your role in practice?
- Fix the unit of analysis: the role is decided per AI system, not per company. One organisation can be a provider of system A and a deployer of system B.
- Ask who places it on the market or puts it into service under their own name or trade mark. That is the provider.
- Ask who uses it under their own authority in a professional context. That is the deployer.
- Test the Article 25 triggers: rebranding, substantial modification, or a change of intended purpose that lifts the system into high-risk.
- If you are building on a general-purpose AI model, separate the two questions: are you a provider of an AI system built on that model, or a provider of a modified model in your own right?
- Write the conclusion down. The role determines the entire compliance plan, and market surveillance authorities will ask how you reached it. See the four regulated roles for the full breakdown.
Related study notes
- The four regulated roles
- The four roles: developers, providers, deployers, users
- High-risk provider obligations
- Deployers, importers and distributors
- High risk - where most regulation lives
Frequently asked questions
Is a deployer the same thing as a user?
Not in the final text. Earlier drafts of the AI Act called this role the user, which caused constant confusion with the individuals on the receiving end. The adopted Regulation uses deployer for the organisation running the system and affected person for the individual subject to its output. If a study source says user obligations, read it as deployer obligations.
Can one company be both a provider and a deployer?
Yes, and it is common. An organisation that builds a high-risk system in-house and uses it on its own staff or customers holds both roles for that system and must satisfy both the provider requirements in Chapter III and the deployer duties in Article 26.
Does the EU AI Act apply to a provider based outside the EU?
Yes. Article 2 catches providers placing systems on the Union market or putting them into service in the Union irrespective of where they are established, and also catches providers and deployers located in a third country where the output produced by the system is used in the Union.
Who is responsible if a vendor's tool discriminates against job applicants?
Both roles can be exposed, on different grounds. The provider answers for the data governance, testing, documentation and conformity of the system; the deployer answers for using it as instructed, exercising human oversight, ensuring input data is appropriate, and for its own obligations under equality and data protection law. Contractual allocation between the parties does not displace the statutory duties.
Test yourself
Try the free AIGP practice questions, or read the full AIGP study guide - free.