Guide · Last reviewed 26 August 2026
Provider vs deployer: the role that decides your EU AI Act duties
Under the EU AI Act, a provider develops an AI system (or has it developed) and places it on the market or puts it into service under its own name or trademark (Article 3(3)); a deployer uses an AI system under its own authority in a professional context (Article 3(4)). The role is assessed per AI system, and it determines almost every obligation you have — including which half of the Article 50 transparency duties applies to you.
Last reviewed: 26 August 2026 · Primary source: Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744.
The definitions, precisely
A provider is a natural or legal person that develops an AI system or a general-purpose AI model — or has one developed — and places it on the market or puts it into service under its own name or trademark, whether for payment or free of charge (Article 3(3)). A deployer is a natural or legal person using an AI system under its authority, except where the system is used in the course of a personal, non-professional activity (Article 3(4)).
Two immediate consequences. First, 'free of charge' does not help: giving a system away still makes you a provider. Second, the deployer definition captures every ordinary business use of AI — a company whose staff use a third-party generative tool, a recruiter using a screening feature in an HR suite, a shop running a vendor's chatbot. Being 'just a customer' of an AI vendor is a role under the Act, with its own duties.
Why the role decides everything
The AI Act is written as a chain of role-specific obligations, and the weight is very unevenly distributed. In broad strokes:
- Providers of high-risk systems carry the full compliance programme from 2 December 2027 (Annex III) or 2 August 2028 (Annex I): risk management (Article 9), data governance (Article 10), technical documentation per Annex IV (Article 11), logging, transparency and instructions for use, human-oversight design (Article 14), accuracy and robustness (Article 15), quality management, conformity assessment, CE marking, registration and post-market monitoring.
- Deployers of high-risk systems have a much shorter list (Article 26): use the system per the instructions, assign competent human oversight, monitor operation, keep logs, inform affected workers — plus, for public bodies and certain private deployers, a fundamental rights impact assessment (Article 27).
- Both roles share Article 4 (AI literacy measures) and the Article 5 prohibitions, which bind everyone.
- Article 50 transparency is split cleanly between the roles — see below.
That is the duty-table logic in one sentence: providers owe the market a compliant product; deployers owe the people affected a responsible use of it. Misclassify your role and you will either build a compliance programme you do not need, or miss one you do.
The white-label trap: when a deployer becomes a provider
The most expensive mistake in role assessment is drifting into providership without noticing. Under Article 25(1), you are treated as the provider of a high-risk AI system if you put your name or trademark on a system already on the market, make a substantial modification to it, or modify its intended purpose in a way that brings it into high-risk territory. Classic scenarios:
- White-labelling a vendor's chatbot or scoring engine as 'YourCompany AI';
- Fine-tuning or re-purposing a general-purpose model into a product you offer under your own brand;
- Taking a general-utility tool and marketing it for an Annex III purpose (say, candidate ranking).
What does not make you a provider: calling a vendor's API, configuring settings within the intended purpose, or building an internal integration that stays under the vendor's brand and intended use. The line is name/trademark, substantial modification, or purpose change — document which side of it you are on.
Assess the role per system, not per company
There is no such thing as 'we are a deployer company'. Roles attach to each AI system and each use. A software firm can simultaneously be: provider of the AI feature in its own product, deployer of a third-party coding assistant, and deployer of an HR screening tool. Each row in your AI system inventory therefore needs its own role entry, its own Article 5 screen and its own Article 50 mapping. When roles are unclear — resellers, integrators, group companies using a parent's system — resolve them by the facts (who developed it, whose name is on it, who decides the use) and record the reasoning. Our Risk Classification and Vendor Due Diligence templates both include a role-assessment section for exactly this.
The Article 50 split in practice
Article 50 is where the role distinction bites first, because it has applied since 2 August 2026:
- Provider duties: Article 50(1) — design systems that interact with natural persons so that people know they are dealing with AI (per the Commission's July 2026 guidelines, this covers genuine two-way conversational exchanges, not one-way automated messages); Article 50(2) — mark synthetic audio, image, video and text in a machine-readable, detectable way (grace until 2 December 2026 for generative systems on the market before 2 August 2026; no SME exemption, though cost and state of the art may be taken into account).
- Deployer duties: Article 50(3) — inform people exposed to emotion recognition or biometric categorisation; Article 50(4) — disclose deepfakes, and disclose AI-generated or manipulated text published to inform the public on matters of public interest (exception where the content underwent human editorial review and someone holds editorial responsibility).
The practical upshot for tool users: a company using a third-party generative tool is a deployer and does not inherit the provider's marking duty under Article 50(2) — that stays with the tool's provider. Your job is the visible-disclosure layer where Article 50(4) applies. Full guide: Article 50 transparency.
Other roles in the value chain
For completeness: the Act also defines importers (Article 23) and distributors (Article 24), who must verify that high-risk systems they bring into or make available on the EU market carry the required conformity marks and documentation, and authorised representatives (Article 22) for non-EU providers of high-risk systems. Most SMEs will only ever wear the provider or deployer hat — but if you resell AI products into the EU, check whether the importer or distributor duties reach you once the high-risk regime applies from 2 December 2027.
Related reading
- AI System Inventory template
- Risk Classification Assessment template
- Vendor Due-Diligence Questionnaire template
- Chatbot Disclosure template
- AI Content-Marking SOP template
- Internal AI-Use Policy template
- The EU AI Act, explained
- Compliance checklist
- High-risk AI systems
- Article 50 transparency
- EU AI Act for SMEs
Frequently asked
We use ChatGPT, Claude and Copilot at work — what is our role?+
You are a deployer of each of those systems (Article 3(4)). Your duties are Article 4 literacy measures and, where relevant, deployer transparency under Article 50(3)-(4). The Article 50(2) marking duty for synthetic output remains with the providers of those tools.
Does fine-tuning a model make us a provider?+
It can. Placing a fine-tuned or substantially modified system on the market under your own name or trademark makes you its provider (Articles 3(3) and 25(1)). Internal fine-tuning within the original intended purpose, without marketing the result, generally does not — but document the assessment.
Can one company be both provider and deployer?+
Yes, and most tech companies are: provider of the AI in their own products, deployer of the third-party AI tools their staff use. The role is assessed per AI system and per use, so your inventory should record a role for every entry.
We white-label a vendor's AI tool under our brand — who is the provider?+
For high-risk systems, putting your name or trademark on a system already on the market makes you the provider under Article 25(1), with the full provider obligations. Even outside high-risk, offering a system under your own name fits the Article 3(3) provider definition. Contract terms with the original vendor do not change your role toward regulators.