Am I a provider or a deployer under the EU AI Act?
Updated 9 August 2026 for Regulation (EU) 2026/1744.
You are a provider if you develop an AI system — or have one developed — and place it on the market or put it into service under your own name (Article 3, point (3)). You are a deployer if you use an AI system under your authority (Article 3, point (4)). Build in-house and use it yourself: you are both.
Quick answer
- Provider = develops an AI system or GPAI model, or has one developed, and places it on the market or puts it into service under its own name or trademark (Article 3, point (3)).
- Deployer = uses an AI system under its authority, except purely personal non-professional use (Article 3, point (4)).
- Providers carry the heavy load for high-risk systems: the full Article 16 list. Deployer duties are operational: Article 26.
- The same company is often both — and the roles can switch under Article 25.
What makes you a provider?
Under Article 3, point (3), a provider is anyone — company, public authority, agency or individual — who "develops an AI system or a general-purpose AI model", or has one developed, "and places it on the market or puts the AI system into service under its own name or trademark, whether for payment or free of charge."
Two parts catch people out:
- "Has developed" counts. Commissioning a contractor to build a system that ships under your brand makes you the provider, not the developer you paid.
- "Putting into service" includes own use. Article 3, point (11) defines it as supply "for first use directly to the deployer or for own use in the Union for its intended purpose." "Placing on the market" (Article 3, point (9)) is the first making available on the Union market.
What makes you a deployer?
Article 3, point (4): a deployer is any natural or legal person, public authority, agency or other body "using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity."
"Under its authority" is the operative phrase — the system runs inside your operation, on your decisions. Buy an AI CV screener and run it on your applicants: you're a deployer. The carve-out is narrow: it covers only natural persons in "a purely personal non-professional activity" (Article 2(10)) — never a company.
What is the practical test?
Two questions:
1. Who developed it — or had it developed — and whose name is on it? That's the provider. 2. Who runs it, under whose authority? That's the deployer.
For most SaaS relationships the split is clean: the vendor is the provider, the buying company is the deployer.
What does each role owe for a high-risk system?
Not from 2 August 2026 any more. Articles 16 and 26 sit in Chapter III, Section 3, and Regulation (EU) 2026/1744 moved Sections 1, 2 and 3 of that chapter to 2 December 2027 for systems high-risk under Article 6(2) and Annex III, and 2 August 2028 for systems high-risk under Article 6(1) and Annex I (Article 113, third paragraph, point (c), as amended). Both lists below move with that date: the roles were not changed, the deadline was. See the high-risk deadline guide and the full timeline.
Provider — Article 16, in substance:
- ensure the system complies with the Section 2 requirements (risk management, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy, robustness and cybersecurity) — point (a);
- indicate your name, registered trade name or registered trade mark, and the address at which you can be contacted, on the system — or, where that is not possible, on its packaging or accompanying documentation, as applicable — point (b);
- run an Article 17 quality management system — point (c);
- keep the Article 18 documentation — point (d);
- keep the logs your system generates automatically, when they are under your control, as required by Article 19 — point (e);
- complete the Article 43 conformity assessment before placing on the market or putting into service — point (f);
- draw up the EU declaration of conformity under Article 47 — point (g);
- affix the CE marking to the system to indicate conformity with this Regulation — or, where that is not possible, to its packaging or accompanying documentation — in accordance with Article 48 — point (h);
- comply with the Article 49(1) registration obligations — point (i). This point moves with the Section 3 date, but Article 49 itself sits in Chapter III, Section 5, which point (c) does not defer: the registration provision has applied since 2 August 2026;
- take corrective action and provide information as required by Article 20 — point (j);
- demonstrate conformity on a reasoned request from a national competent authority — point (k);
- meet the accessibility requirements of Directives (EU) 2016/2102 and (EU) 2019/882 — point (l).
Deployer — Article 26, in substance:
- use the system in accordance with its instructions for use (Article 26(1));
- assign human oversight to people with the necessary competence, training and authority (Article 26(2));
- ensure input data you control is relevant and sufficiently representative (Article 26(4));
- monitor operation, and suspend use and inform the provider (or distributor) and the market surveillance authority if the system presents a risk (Article 26(5));
- keep the automatically generated logs under your control for at least six months (Article 26(6));
- inform workers and their representatives before workplace use (Article 26(7)), and inform natural persons subject to decisions the system makes or assists (Article 26(11)).
Can you be both at once?
Yes — in-house AI makes it the default: develop a tool and use it yourself, and you have put it into service "for own use" (Article 3, point (11)) — provider — while using it under your authority — deployer. You owe both lists: Article 16 as provider, Article 26 as deployer.
Whether it's high-risk at all: start with how to classify an AI system.
Can your role change?
Yes. Article 25(1) makes a distributor, importer, deployer or other third party the provider of a high-risk AI system — with the full Article 16 obligations — in three cases, all concerning systems already placed on the market or put into service: putting its name or trademark on a high-risk AI system, "without prejudice to contractual arrangements stipulating that the obligations are otherwise allocated"; making a substantial modification to a high-risk AI system such that it remains high-risk pursuant to Article 6; or modifying the intended purpose of a system not classified as high-risk so that it becomes high-risk in accordance with Article 6. The mechanics — including where fine-tuning and white-labelling sit — are in when a deployer becomes a provider. Importers and distributors have their own duties under Articles 23 and 24 — see importer and distributor obligations. Providers of general-purpose AI models face a separate regime under Chapter V — see GPAI obligations.
What this means for you
If you're a provider: Article 16 is a build program, not a policy binder — technical documentation must be drawn up and the conformity assessment passed before the system is placed on the market or put into service (Article 11(1); Article 16, point (f)). Inventory every system that ships under your name, including ones a contractor built, then classify each one: the list only bites if the system is high-risk.
If you're a deployer: Your Article 26 duties are yours alone — a vendor's compliance package does not discharge them. For every AI tool in use, record in your AI inventory who the provider is, whether your use is in an Annex III area, and who exercises human oversight. That last answer needs a name, not a department — Complipath's register keeps a named business and technical owner on every system.
Which role do you hold, system by system?
Classify your system now — 7 questions on the main line, plus follow-ups where they apply, no account, and the classification runs in your browser: answers stay there unless you choose to keep the result.
FAQ
Is a company that just uses an AI SaaS tool really regulated? Yes, as a deployer. Article 3, point (4) covers anyone using an AI system under their authority in a professional context. The exclusion in Article 2(10) applies only to natural persons in purely personal non-professional activity — it never covers a company's use of a tool.
We built an internal AI tool we never sell. Are we a provider? Yes. "Putting into service" under Article 3, point (11) includes supply "for own use" in the Union for the system's intended purpose. You are the provider and the deployer at once, and for a high-risk system you carry both the Article 16 and Article 26 obligations.
Can our vendor contract decide who counts as the provider? As a rule, no — the roles follow from the Article 3 definitions, and your Article 26 deployer duties stay yours whatever the contract says. The carve-out: the Article 25(1), point (a) re-badging switch applies "without prejudice to contractual arrangements stipulating that the obligations are otherwise allocated" — there, contracts can reallocate the obligations.
Do the provider and deployer rules apply to companies outside the EU? Often, yes. Article 2(1), point (a) covers providers placing systems on the Union market wherever they are established, and Article 2(1), point (c) covers third-country providers and deployers "where the output produced by the AI system is used in the Union."
Sources: Regulation (EU) 2024/1689 (EUR-Lex), Articles 2, 3, 16, 25, 26 and 113, the last as amended by Regulation (EU) 2026/1744 (EUR-Lex), Article 1, point (40). The Article 3 definitions of provider and deployer, Article 16 and Article 26 were not amended; Article 25(1) was not amended, though the same regulation replaced Article 25(2) and part of Article 25(4), which this guide does not cover — see the Article 25 guide. The boundary of "substantial modification" under Article 25(1) (including fine-tuning): no guidance settling it is in our source corpus as of 12 August 2026 — verify before relying. Case law sits outside our corpus altogether, and this guide does not report whether a court has ruled; treat any reading as provisional.