AI decisions Governance and the EU AI Act
EU AI Act provider vs deployer: which role are you, and what does each one owe?
You are the provider if you develop an AI system, or have it developed, and place it on the market or put it into service under your own name or trademark, including for your own internal use; you are the deployer if you use a system under your authority in a professional context. The role attaches to each system, not to the company, and it can shift: under Article 25, a deployer that puts its brand on a high-risk system, substantially modifies it, or repurposes a system into a high-risk use takes on the provider’s obligations. This guide is practical orientation, not legal advice.
The options
Provider
Develops an AI system, or has it developed, and places it on the EU market or puts it into service under its own name or trademark (Art. 3(3)).
Deployer
Uses an AI system under its own authority, except for purely personal, non-professional activity (Art. 3(4)).
Side by side
| Criterion | Provider | Deployer |
|---|---|---|
| Typical situation | A software vendor, or a company whose own team builds a system and puts it into service for internal use. | A company that buys or licenses a system and uses it in its own processes. |
| Core duties for high-risk systems | Meet the requirements of Arts. 8–15 (risk management, data governance, technical documentation, logging, instructions for use, human oversight, accuracy and robustness) plus Art. 16: quality management system, conformity assessment, EU declaration of conformity, CE marking. | Art. 26: use the system according to its instructions, assign human oversight to competent people with authority, ensure input data under its control is relevant, monitor operation, keep the logs under its control for at least six months. |
| Fundamental rights impact assessment (FRIA) | Not an Art. 27 duty for the provider, but its instructions must give deployers what they need to carry it out. | Mandatory before use for public-law bodies, private entities providing public services, and deployers of Annex III systems for credit scoring or for life and health insurance risk assessment and pricing (Art. 27). |
| Transparency (Art. 50) | Design systems that interact with people so they know they are dealing with AI; mark synthetic audio, image, video and text in a machine-readable way. | Inform people exposed to emotion recognition or biometric categorisation; disclose deepfakes and AI-generated text published to inform the public on matters of public interest, unless it has had human editorial review. |
| Monitoring and incidents | Post-market monitoring system (Art. 72) and serious incident reporting to authorities (Art. 73). | Inform the provider and the authorities of risks or serious incidents and suspend use where warranted (Art. 26(5)). |
| People affected | Provides the information that makes oversight and explanation possible. | Informs workers and their representatives before using a high-risk system at the workplace, and informs people subject to Annex III decisions (Art. 26(7) and (11)). |
| EU database registration | Registers Annex III high-risk systems before placing them on the market, including those it argues are not high-risk under Art. 6(3) (Art. 49). | Public authorities and EU bodies register their use of Annex III high-risk systems (Art. 26(8)). |
| AI literacy (Art. 4) | Applies since 2 February 2025. | Applies since 2 February 2025. |
Choose Provider when…
- You build an AI system in-house and put it into service for your own use: your organisation is then both provider and deployer of that system, with both sets of duties.
- You sell, license or give away a system under your name or brand, including one built on a third-party foundation model.
- You put your name or trademark on a high-risk system already on the market (Art. 25(1)(a)).
- You make a substantial modification to a high-risk system and it remains high-risk (Art. 25(1)(b)).
- You change the intended purpose of a system that was not high-risk, including a general-purpose assistant, so that it becomes high-risk, for example using it to screen job candidates (Art. 25(1)(c)).
Choose Deployer when…
- You license a system and use it within the provider’s intended purpose and instructions for use.
- You configure it (thresholds, users, integrations) without changing its intended purpose or making a substantial modification, and you can document why.
- You use a general-purpose assistant for tasks that are not Annex III uses.
- You integrate a vendor’s high-risk system, such as credit scoring or recruitment, and keep the human oversight, logs and monitoring Art. 26 requires.
When to combine them
Large organisations often hold both roles, system by system. The same company can be provider of a claims-triage agent its own team built, deployer of a licensed recruitment tool and deployer of a general-purpose assistant. The workable answer is an AI inventory in which every system has a recorded role, intended purpose, risk classification and owner, reviewed whenever the purpose, the vendor or the model changes. Contracts should mirror those roles: who supplies documentation and instructions for use, who keeps which logs, who reports incidents, and what happens if the deployer’s use triggers Article 25.
Common mistakes
- Assuming “we only buy, so we are deployers”: if your team builds an application on a model API and puts it into service, you are the provider of that system.
- Treating the vendor’s conformity as your compliance: it does not cover your Art. 26 duties, your FRIA where required or your Art. 50 disclosures.
- Repurposing a general assistant into an Annex III use (hiring, credit, insurance pricing) without noticing that Art. 25(1)(c) makes you the provider.
- White-labelling a high-risk system without securing the documentation and technical access you now need as provider.
- Classifying once and forgetting: role and risk level move when the purpose, the model or the scope changes.
How Thinkia approaches it
We start with the inventory, not with the regulation. For each AI system we record who built it, under whose name it runs, what it is for and whether that purpose falls under Annex III. The goal is to find the systems the company believes it is only using but in fact built, and therefore provides, before a regulator or an auditor does.
Our public AI governance guide sets out risk tiers, roles and a 20-item checklist, with links to EUR-Lex and the Commission’s AI Act Service Desk. Within the Thinkia AI Compass Framework, role and risk classification belong to the Trust Fabric dimension, next to DPIA and FRIA, and the AI Nexus committee signs off whenever a change of purpose or a white-label deal could move a system from deployer to provider.
On the technical side we design for the evidence each role needs: attributable logs with defined retention, human oversight with real authority to override, written instructions for use. A governed platform such as Synapse centralises access, logging and model routing, which makes deployer duties easier to demonstrate; it does not replace the legal analysis. For any conclusion with legal effect we work with your legal counsel. This guide is orientation, not legal advice.
Thinkia products involved
- EU AI Act governance guideRisk tiers, timeline, roles and a 20-point checklist. Not legal advice.
- SynapseGoverned agentic platform: agents, models, costs and data in one place.
Related AI solutions
- AI governance, risk & controlAI your board, legal team and regulators can sign off on.
- AI Act governance for underwritingHigh-risk under Annex III. Documented, logged, defensible.
- AI compliance monitoringStay compliant without making compliance a full-time job.
- AI readiness & maturity auditHonest gaps, risks, and the next 90 days
Frequently asked questions
If we build an internal tool on top of a commercial LLM API, are we the provider?
For the AI system you built, generally yes: the AI Act treats putting a system into service for your own use, under your name, as acting as a provider. The model vendor remains the provider of the general-purpose AI model, with its own obligations. How heavy your duties are then depends on the risk classification of your system.
Does fine-tuning a model make us a provider?
It can, and there are two separate questions. Modifying a general-purpose AI model can make you the provider of the modified model; the Commission’s guidelines on general-purpose AI models set criteria for when that happens. And if you build and use a system on top of it, you are already the provider of that system. Check both against the official guidance before assuming either way.
Who has to carry out a fundamental rights impact assessment?
Under Article 27, before deploying a high-risk system: bodies governed by public law, private entities providing public services, and deployers of Annex III systems used for creditworthiness assessment or credit scoring of natural persons, or for risk assessment and pricing in life and health insurance. Critical-infrastructure uses are excluded. The results are notified to the market surveillance authority.
When do these obligations apply?
The Regulation entered into force on 1 August 2024; AI literacy and the prohibitions apply since 2 February 2025, general-purpose AI model obligations since 2 August 2025 and Article 50 transparency since 2 August 2026. The Digital Omnibus on AI, in force since 27 July 2026, delayed Annex III high-risk obligations by sixteen months, to December 2027, and does not change Articles 4 or 50. Annex I obligations apply later. Check the consolidated text on EUR-Lex or the AI Act Service Desk before you plan.
Can a contract move the provider role back to the vendor?
A contract can allocate cooperation, information and liability, but it does not change who the Regulation treats as the provider when Article 25 is triggered. What it should secure is the documentation, technical access and support you need; Article 25 obliges the original provider to cooperate, unless it clearly specified that its system was not to be turned into a high-risk system.
What are the penalties for deployers?
Breaching deployer or transparency obligations can lead to fines of up to 15 million euros or 3% of worldwide annual turnover, whichever is higher; for SMEs, whichever is lower. Prohibited practices carry up to 35 million euros or 7%. National authorities enforce them; in Spain, the supervisory agency is AESIA.
Keep exploring
Related decisions
- Centralised vs federated AI governance: who should decide what in your organisation?
- Build vs buy AI agents: which agents should you own, and which should you rent?
- RAG vs fine-tuning: which one does your enterprise use case need?
- Open-source vs proprietary LLMs: how should an enterprise choose?
- Microsoft Copilot vs custom AI agents: when is the suite assistant enough, and when do you need your own agents?
Sectors where this decision comes up
Key terms
Thinkia articles
- Human-in-the-Loop AI: A Practical Blueprint for Regulated Industries
- Beyond Spreadsheets: Why New AI Governance Tools Are Essential for Compliance
- AI Governance: The Strategic Engine for Competitive Advantage
Whitepapers
- The AI Act already applies.The Digital Omnibus postponed Annex III to December 2027. It did not touch Article 4 or Article 50. Five questions for your next committee meeting.
- AI Ethics & Governance. Beyond compliance.How the EU AI Act turns ethics and governance into business value—the operational lens, Thinkia AI Compass, and a roadmap to scale AI with trust.
Sources
- Regulation (EU) 2024/1689 (AI Act), EUR-Lex
- AI Act Service Desk: AI Act Explorer (European Commission)
- EU AI Act Compliance Checker (European Commission)
Orientation, not legal advice. Confirm obligations and deadlines with qualified counsel and the official EU sources. EU AI Act guide and checklist.