EU AI Act Provider vs Deployer: Responsibilities Explained
Buying an AI tool usually makes a company a deployer, but substantial modification or rebranding can move it into provider duties.

Bottom line
A practical guide to provider, downstream provider, deployer, importer, and distributor roles under the EU AI Act and the records each should keep.
Editorial accountability
Who checked this guide
- Evaluation type
- Research-based verification
- Last materially checked
- Evidence
- 4 listed sources
Hands-on testing is identified explicitly. Research-based coverage uses cited product documentation and other named sources; it does not imply every paid plan was used. Read the full methodology.
Editorial basis
What this guidance is based on
- Editorial basis
- Source-led analysis
- Primary references
- 4
- Products covered
- 0
- Last checked
- 2026-09-21
Important limits
- • This guide is general information, not legal advice.
- • Roles and duties depend on the exact system, purpose, changes, market activity, and implementation timeline.
In this guide
*This operational overview is not legal advice. It was checked against Regulation (EU) 2024/1689 and European Commission guidance on September 21, 2026.*
Short answer
An AI provider develops an AI system or general-purpose model, or has one developed, and places it on the market or puts it into service under its own name. A deployer uses an AI system under its authority in a professional context. A company can hold more than one role, and a deployer can become a provider by rebranding a system, making a substantial modification, or changing its intended purpose into a high-risk use.
The role map
| Role | Practical description |
|---|---|
| Provider | Builds or commissions the system/model and releases it under its name |
| Downstream provider | Integrates a general-purpose model into another AI system |
| Deployer | Uses an AI system professionally under its authority |
| Importer | Places a non-EU provider's system on the EU market |
| Distributor | Makes a system available in the supply chain without changing it |
The label follows the activity, not company size or the wording in a sales contract. A SaaS buyer using an off-the-shelf assistant internally is commonly a deployer. A consultancy that turns a general-purpose model into a branded product for clients may be a downstream provider and a provider of the resulting system.
When a deployer can become a provider
Do not assume the vendor keeps every provider obligation after customization. Article 25 addresses parties that put their name or trademark on an existing high-risk system, make a substantial modification, or change the intended purpose so the system becomes high-risk. The original provider must supply necessary information and technical access in covered cases, but the new provider inherits provider responsibilities for the modified system.
Configuration is not automatically a substantial modification. Document what changed, whether performance or compliance is affected, who defines the intended purpose, and why the role conclusion remains valid.
What providers should be ready to evidence
Depending on the system, providers may need risk management, data governance, technical documentation, logs, instructions, human-oversight design, accuracy and cybersecurity controls, conformity assessment, registration, post-market monitoring, and incident reporting. General-purpose model providers have a separate obligation set, including model documentation, downstream information, copyright policy, and a public training-content summary; systemic-risk models face added duties.
What deployers should be ready to evidence
Deployers should follow instructions, assign competent human oversight, monitor use, preserve relevant logs under their control, assess workplace and fundamental-rights impacts where applicable, manage input data they control, and report serious issues through the required path. Transparency duties can also fall directly on deployers—for example, certain deepfakes or public-interest text without human editorial control.
Start with the [small-business AI Act checklist](/articles/eu-ai-act-compliance-checklist-small-businesses), then classify whether the use is covered by the [high-risk rules](/articles/which-ai-tools-eu-ai-act-high-risk-rules).
A practical role-assignment record
For each system, record the legal entity, product name, intended purpose, affected people, model provider, system provider, importer/distributor, deployer, branding, modifications, high-risk analysis, contract owner, evidence owner, and reassessment trigger. Revisit the record after model swaps, connector changes, new users, new decisions, or vendor updates.
Bottom line
“We only use someone else's AI” is not a compliance strategy. Name the role for the exact activity, document why, and reclassify when branding, purpose, or modification changes the answer.
Sources and verification
Product details and claims were checked against the following primary sources.
Frequently asked questions
Is a business using ChatGPT an AI provider or deployer?
For ordinary professional use, it is generally a deployer. It may take on provider duties if it releases a branded system, substantially modifies a covered system, or changes its intended purpose into a high-risk use.
Can one company be both provider and deployer?
Yes. A company may provide one AI system, deploy another, and act as a downstream provider when integrating a general-purpose model.
What is a downstream provider?
It is an actor that integrates a general-purpose AI model into an AI system. The model provider must make specified information available so downstream providers can understand capabilities and limitations.
Does a white-label AI product change the role?
It can. Putting a company name or trademark on an existing high-risk system is one circumstance in which provider responsibilities may shift. Obtain legal review for the exact arrangement.
Found this useful?
Get the next one in your inbox.
One five-minute briefing a week: a meaningful change, a practical workflow, and a clearer tool decision—already filtered for lean teams.
Free · one email a week · unsubscribe any time
Read next
