COMPLIPATHDOC complipath.io/guides/provider-vs-deployer-eu-ai-actRENDERED 2026-08-23ENGINE 2026-08-09.1CORPUS 2024/1689 + 2026/1744 + Commission guidelines
Guides/Roles ·By Yobel Tzegai ·Updated 13 August 2026

Am I a provider or a deployer under the EU AI Act?

Updated 9 August 2026 for Regulation (EU) 2026/1744.

You are a provider if you develop an AI system — or have one developed — and place it on the market or put it into service under your own name (Article 3, point (3)). You are a deployer if you use an AI system under your authority (Article 3, point (4)). Build in-house and use it yourself: you are both.

Quick answer

What makes you a provider?

Under Article 3, point (3), a provider is anyone — company, public authority, agency or individual — who "develops an AI system or a general-purpose AI model", or has one developed, "and places it on the market or puts the AI system into service under its own name or trademark, whether for payment or free of charge."

Two parts catch people out:

What makes you a deployer?

Article 3, point (4): a deployer is any natural or legal person, public authority, agency or other body "using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity."

"Under its authority" is the operative phrase — the system runs inside your operation, on your decisions. Buy an AI CV screener and run it on your applicants: you're a deployer. The carve-out is narrow: it covers only natural persons in "a purely personal non-professional activity" (Article 2(10)) — never a company.

What is the practical test?

Two questions:

1. Who developed it — or had it developed — and whose name is on it? That's the provider. 2. Who runs it, under whose authority? That's the deployer.

For most SaaS relationships the split is clean: the vendor is the provider, the buying company is the deployer.

What does each role owe for a high-risk system?

Not from 2 August 2026 any more. Articles 16 and 26 sit in Chapter III, Section 3, and Regulation (EU) 2026/1744 moved Sections 1, 2 and 3 of that chapter to 2 December 2027 for systems high-risk under Article 6(2) and Annex III, and 2 August 2028 for systems high-risk under Article 6(1) and Annex I (Article 113, third paragraph, point (c), as amended). Both lists below move with that date: the roles were not changed, the deadline was. See the high-risk deadline guide and the full timeline.

Provider — Article 16, in substance:

Deployer — Article 26, in substance:

Can you be both at once?

Yes — in-house AI makes it the default: develop a tool and use it yourself, and you have put it into service "for own use" (Article 3, point (11)) — provider — while using it under your authority — deployer. You owe both lists: Article 16 as provider, Article 26 as deployer.

Whether it's high-risk at all: start with how to classify an AI system.

Can your role change?

Yes. Article 25(1) makes a distributor, importer, deployer or other third party the provider of a high-risk AI system — with the full Article 16 obligations — in three cases, all concerning systems already placed on the market or put into service: putting its name or trademark on a high-risk AI system, "without prejudice to contractual arrangements stipulating that the obligations are otherwise allocated"; making a substantial modification to a high-risk AI system such that it remains high-risk pursuant to Article 6; or modifying the intended purpose of a system not classified as high-risk so that it becomes high-risk in accordance with Article 6. The mechanics — including where fine-tuning and white-labelling sit — are in when a deployer becomes a provider. Importers and distributors have their own duties under Articles 23 and 24 — see importer and distributor obligations. Providers of general-purpose AI models face a separate regime under Chapter V — see GPAI obligations.

What this means for you

If you're a provider: Article 16 is a build program, not a policy binder — technical documentation must be drawn up and the conformity assessment passed before the system is placed on the market or put into service (Article 11(1); Article 16, point (f)). Inventory every system that ships under your name, including ones a contractor built, then classify each one: the list only bites if the system is high-risk.

If you're a deployer: Your Article 26 duties are yours alone — a vendor's compliance package does not discharge them. For every AI tool in use, record in your AI inventory who the provider is, whether your use is in an Annex III area, and who exercises human oversight. That last answer needs a name, not a department — Complipath's register keeps a named business and technical owner on every system.

Which role do you hold, system by system?

Classify your system now — 7 questions on the main line, plus follow-ups where they apply, no account, and the classification runs in your browser: answers stay there unless you choose to keep the result.

FAQ

Is a company that just uses an AI SaaS tool really regulated? Yes, as a deployer. Article 3, point (4) covers anyone using an AI system under their authority in a professional context. The exclusion in Article 2(10) applies only to natural persons in purely personal non-professional activity — it never covers a company's use of a tool.

We built an internal AI tool we never sell. Are we a provider? Yes. "Putting into service" under Article 3, point (11) includes supply "for own use" in the Union for the system's intended purpose. You are the provider and the deployer at once, and for a high-risk system you carry both the Article 16 and Article 26 obligations.

Can our vendor contract decide who counts as the provider? As a rule, no — the roles follow from the Article 3 definitions, and your Article 26 deployer duties stay yours whatever the contract says. The carve-out: the Article 25(1), point (a) re-badging switch applies "without prejudice to contractual arrangements stipulating that the obligations are otherwise allocated" — there, contracts can reallocate the obligations.

Do the provider and deployer rules apply to companies outside the EU? Often, yes. Article 2(1), point (a) covers providers placing systems on the Union market wherever they are established, and Article 2(1), point (c) covers third-country providers and deployers "where the output produced by the AI system is used in the Union."


Sources: Regulation (EU) 2024/1689 (EUR-Lex), Articles 2, 3, 16, 25, 26 and 113, the last as amended by Regulation (EU) 2026/1744 (EUR-Lex), Article 1, point (40). The Article 3 definitions of provider and deployer, Article 16 and Article 26 were not amended; Article 25(1) was not amended, though the same regulation replaced Article 25(2) and part of Article 25(4), which this guide does not cover — see the Article 25 guide. The boundary of "substantial modification" under Article 25(1) (including fine-tuning): no guidance settling it is in our source corpus as of 12 August 2026 — verify before relying. Case law sits outside our corpus altogether, and this guide does not report whether a court has ruled; treat any reading as provisional.

← All guides
Complipath

Complipath is EU AI Act compliance software for AI-heavy software companies without a compliance team — an AI system register, deterministic risk classification, the obligations that follow, and the evidence behind every decision.

Complipath is built by Yobel Tzegai in Gothenburg, Sweden.

Complipath provides legal information, not legal advice. Every guide cites its source on EUR-Lex — Regulation (EU) 2024/1689, and Regulation (EU) 2026/1744 where that has amended it; where the law is still settling, the guide says so.

We measure page views with Vercel Web Analytics. It uses no third-party cookies. Visitors are identified by a hash derived from the incoming request, which is discarded after 24 hours, and no identifier is stored that could follow a visitor to another site. What is collected: the time of the visit, the URL, the referring page, filtered query parameters, city-level location, operating system, browser and device type.