Guide · Roles · Article 3, points (3) and (4)

Am I a provider or a deployer under the EU AI Act?

Updated 9 August 2026 for Regulation (EU) 2026/1744.

You are a "provider" if you develop an AI system — or have one developed — and place it on the market or put it into service under your own name (Article 3, point (3)). You are a deployer if you use an AI system under your authority (Article 3, point (4)). Build in-house and use it yourself: you are both.

The short answer

  • Provider = develops an AI system or GPAI model, or has one developed, and places it on the market or puts it into service under its own name or trademark (Article 3, point (3)).
  • Deployer = uses an AI system under its authority, except purely personal non-professional use (Article 3, point (4)).
  • Providers carry the heavy load for high-risk systems: the full Article 16 list. Deployer duties are operational: Article 26.
  • The same company is often both — and the roles can switch under Article 25.

What makes you a provider?

Under Article 3, point (3), a provider is anyone — company, public authority, agency or individual — who "develops an AI system or a general-purpose AI model", or has one developed, "and places it on the market or puts the AI system into service under its own name or trademark, whether for payment or free of charge."

Two parts catch people out:

What makes you a deployer?

Article 3, point (4): a deployer is any natural or legal person, public authority, agency or other body "using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity." That is why buying a tool rather than building one makes you its deployer: nothing in the definition asks who developed it.

"Under its authority" is the operative phrase — the system runs inside your operation, on your decisions. Buy an AI CV screener and run it on your applicants: you're a deployer. The carve-out is narrow: it covers only natural persons in "a purely personal non-professional activity" (Article 2(10)) — never a company.

What is the practical test?

Two questions:

  1. Who developed it — or had it developed — and whose name is on it? That's the provider.
  2. Who runs it, under whose authority? That's the deployer.

For most SaaS relationships the split is clean: the vendor is the provider, the buying company is the deployer.

What does each role owe for a high-risk system?

Not from 2 August 2026 any more. Articles 16 and 26 sit in Chapter III, Section 3, and Regulation (EU) 2026/1744 moved Sections 1, 2 and 3 of that chapter to 2 December 2027 for systems high-risk under Article 6(2) and Annex III, and 2 August 2028 for systems high-risk under Article 6(1) and Annex I (Article 113, third paragraph, point (c), as amended). Both lists below move with that date: the roles were not changed, the deadline was. See the high-risk deadline guide and the full timeline.

Provider — Article 16, in substance:

Deployer — Article 26, in substance:

Can you be both at once?

Yes — in-house AI makes it the default: develop a tool and use it yourself, and you have put it into service "for own use" (Article 3, point (11)) — provider — while using it under your authority — deployer. You owe both lists: Article 16 as provider, Article 26 as deployer.

Whether it's high-risk at all: start with how to classify an AI system.

Can your role change?

Yes. Article 25(1) makes a distributor, importer, deployer or other third party the provider of a high-risk AI system — with the full Article 16 obligations — in three cases, all concerning systems already placed on the market or put into service: putting its name or trademark on a high-risk AI system, "without prejudice to contractual arrangements stipulating that the obligations are otherwise allocated"; making a substantial modification to a high-risk AI system such that it remains high-risk pursuant to Article 6; or modifying the intended purpose of a system not classified as high-risk so that it becomes high-risk in accordance with Article 6. The mechanics — including where fine-tuning and white-labelling sit — are in when a deployer becomes a provider. Importers and distributors have their own duties under Articles 23 and 24 — see importer and distributor obligations. Providers of general-purpose AI models face a separate regime under Chapter V — see GPAI obligations.

What this means for you

If you're a provider: Article 16 is a build program, not a policy binder — technical documentation must be drawn up and the conformity assessment passed before the system is placed on the market or put into service (Article 11(1); Article 16, point (f)). Inventory every system that ships under your name, including ones a contractor built, then classify each one: the list only bites if the system is high-risk. How much of that build program in-house work covers, and where it stops, is set out beside what we could read of twelve tools.

If you're a deployer: Your Article 26 duties are yours alone — a vendor's compliance package does not discharge them. For every AI tool in use, record in your AI inventory who the provider is, whether your use is in an Annex III area, and who exercises human oversight. That last answer needs a name, not a department — Complipath's register keeps a named business owner on every system, and a technical owner when there is one.

FAQ

Is a company that just uses an AI SaaS tool really regulated? Yes, as a deployer. Article 3, point (4) covers anyone using an AI system under their authority in a professional context. The exclusion in Article 2(10) applies only to natural persons in purely personal non-professional activity — it never covers a company's use of a tool.

We built an internal AI tool we never sell. Are we a provider? Yes. "Putting into service" under Article 3, point (11) includes supply "for own use" in the Union for the system's intended purpose. You are the provider and the deployer at once, and for a high-risk system you carry both the Article 16 and Article 26 obligations.

Can our vendor contract decide who counts as the provider? As a rule, no — the roles follow from the Article 3 definitions, and your Article 26 deployer duties stay yours whatever the contract says. The carve-out: the Article 25(1), point (a) re-badging switch applies "without prejudice to contractual arrangements stipulating that the obligations are otherwise allocated" — there, contracts can reallocate the obligations.

Do the provider and deployer rules apply to companies outside the EU? Often, yes. Article 2(1), point (a) covers providers placing systems on the Union market wherever they are established, and Article 2(1), point (c) covers third-country providers and deployers "where the output produced by the AI system is used in the Union."


Sources: Regulation (EU) 2024/1689 (EUR-Lex), Articles 2, 3, 16, 25, 26 and 113, the last as amended by Regulation (EU) 2026/1744 (EUR-Lex), Article 1, point (40). The Article 3 definitions of provider and deployer, Article 16 and Article 26 were not amended; Article 25(1) was not amended, though the same regulation replaced Article 25(2) and part of Article 25(4), which this guide does not cover — see the Article 25 guide. The boundary of "substantial modification" under Article 25(1) (including fine-tuning): no guidance settling it is in our source corpus as of 12 August 2026 — verify before relying. Case law sits outside our corpus altogether, and this guide does not report whether a court has ruled; treat any reading as provisional.

Where this question meets the product: EU AI Act compliance for AI providers. Answering it in a customer's questionnaire: how to answer AI questions in a supplier questionnaire.

Read nextWhat are the importer and distributor obligations under the EU AI Act?Articles 23 and 24When does a deployer become a provider?Article 25Who needs an EU authorised representative?Article 22

See which of your AI systems the Act covers.

No account needed. Every answer cites the article it rests on.

Get your free readiness review

Check your AI systems, free