Vigilis
EU AI Act

Provider vs. deployer: what’s the difference and why it matters

Sourced from Regulation (EU) 2024/1689, Articles 3, 16, 25, and 26

In short

A provider builds an AI system and places it on the market under its own name (Article 3(3)), carrying the full Article 16 / Articles 9–15 obligation set. A deployer uses an AI system under its own authority (Article 3(4)), with the lighter Article 26 duties. Most businesses are deployers, but Article 25 turns a deployer into a provider if it rebrands, substantially modifies, or repurposes a high-risk system.

The EU AI Act does not impose one uniform set of obligations on every company that touches an AI system. Instead, it assigns different duties to different roles in the AI value chain. The two roles that matter to almost every business are provider and deployer, and getting the classification wrong is one of the most consequential compliance mistakes a company can make, because the two roles carry very different obligation sets.

Provider, Article 3(3)

A provider is a natural or legal person that develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark, whether for payment or free of charge. Providers carry the heaviest compliance load under the Act, set out in Article 16: establishing a risk management system (Art. 9), ensuring data governance (Art. 10), preparing technical documentation (Art. 11), building in logging capability (Art. 12), designing for transparency and supplying instructions for use (Art. 13), enabling human oversight (Art. 14), meeting accuracy/robustness/cybersecurity requirements (Art. 15), undergoing conformity assessment, affixing the CE marking, and registering the system in the EU database.

Deployer, Article 3(4)

A deployer is any natural or legal person using an AI system under its own authority, other than in a purely personal, non-professional activity. This is the role that captures the vast majority of businesses, any company using a third-party AI tool (an applicant-tracking system, a credit-scoring API, a chatbot) is a deployer of that system. Deployer obligations under Article 26 are lighter than provider obligations but still substantive: using the system in accordance with the provider’s instructions, assigning competent human oversight, monitoring operation for risks, retaining automatically generated logs, informing affected workers and their representatives before deployment, and (for certain deployers) completing a fundamental rights impact assessment (Art. 27).

Importers and distributors

Two further roles apply to companies further down the supply chain. An importer (Art. 3(6)) places on the EU market an AI system that bears the name or trademark of a person established outside the EU, and must verify the provider has completed conformity assessment before doing so. A distributor (Art. 3(7)) makes an AI system available on the EU market without being the provider or importer, and must verify the system carries the required CE marking and documentation before making it available.

When a deployer becomes a provider

Article 25(1) contains a trap many companies miss: a distributor, importer, deployer, or other third party is treated as a provider (and inherits full provider obligations ) if it puts its own name or trademark on a high-risk AI system already on the market, makes a substantial modification to a high-risk AI system that remains high-risk after the change, or modifies the intended purpose of an AI system in a way that makes a previously non-high-risk system high-risk. A company that fine-tunes a purchased AI model and rebrands it as its own product does not stay a deployer.

Why the distinction matters commercially

Provider obligations are designed around product development and market placement; deployer obligations are designed around safe use in operations. A company that misclassifies itself as a deployer when it has, in practice, taken on provider responsibilities (through rebranding, substantial modification, or repurposing) risks operating a high-risk system with none of the required risk management, technical documentation, or conformity assessment in place, a gap that only surfaces during a regulatory audit or an incident investigation.

Frequently asked questions

What is the difference between a provider and a deployer under the EU AI Act?
A provider (Article 3(3)) develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark, carrying the full Article 16 obligation set. A deployer (Article 3(4)) uses an AI system under its own authority in a professional capacity, with the lighter but still substantive Article 26 duties.
Can a company that only uses AI become a provider?
Yes. Under Article 25(1) a deployer, importer, or distributor is treated as a provider (inheriting full provider obligations) if it puts its own name or trademark on a high-risk AI system, makes a substantial modification to one, or repurposes a system so that a previously non-high-risk system becomes high-risk.
Which role do most businesses fall into?
Most businesses are deployers. Any company using a third-party AI tool (an applicant-tracking system, a credit-scoring API, a chatbot) is a deployer of that system under Article 3(4).

Related guides

Not sure which role applies to your company?

Our assessment determines your role per AI system and maps the exact obligations that follow.

Start the free check