GUIDA della Società

Provider vs Deployer Under the EU AI Act

The EU AI Act defines a provider by development and market or service placement under its name, while a deployer uses an AI system under its authority in a professional context.

  • 3 minuti di lettura
  • Ultimo aggiornamento
In questa pagina3 minuti di lettura
  1. Panoramica
  2. Immersione profonda
  3. Impatto strategico
  4. The Future of Provider vs Deployer Under the EU AI Act
  5. Implementazione nel mondo reale
  6. Rischi e guardrail
  7. Tabella di marcia per l'implementazione
  8. Continua a esplorare
  9. Domande frequenti

Panoramica

The role is determined by the actual activity and can change when an organization relabels or substantially modifies a high-risk system.

Immersione profonda

The EU AI Act distinguishes a provider from a deployer. Under Article 3, a provider develops an AI system or has one developed and places it on the market, or puts it into service, under its own name or trademark. A deployer uses an AI system under its authority in a professional context; personal non-professional use is excluded. These roles do not simply mean vendor and customer. A business that commissions development and markets the system under its own name may be the provider; an organization using a purchased tool for work may be a deployer. One organization can hold different roles across systems. Importers, distributors, product manufacturers, and authorized representatives have separate roles. Article 25 can reassign provider duties to a distributor, importer, deployer, or another third party in specified cases: branding a high-risk system, substantially modifying it while it remains high-risk, or changing its intended purpose so it becomes high-risk. A user-interface change alone is not automatically a substantial modification. Under the 2026 AI Omnibus, when a role change occurs the initial provider generally ceases to be provider of that system but must cooperate with the new provider and supply necessary information, reasonable technical access, and assistance, including known limitations and failure modes. This duty does not apply if the initial provider clearly specified the system must not be changed into a high-risk system. The parties must agree in writing on needed support. Provider and deployer duties depend on the system and role. For high-risk systems, providers handle conformity and required documentation; deployers use the system according to instructions and assign competent human oversight. The Act has applied generally since August 2, 2026, with phased rules: Annex III high-risk system rules apply from December 2, 2027, and Annex I product-embedded rules apply from August 2, 2028. Check the current Regulation for the specific system and use.

Impatto strategico

Rischio e sicurezza

I danni catastrofici e quotidiani dell’IA dipendono entrambi da chi comprende i rischi e da chi può agire.

Decisioni più chiare

L’alfabetizzazione pubblica e professionale determina la possibilità politica di una forte politica di sicurezza.

Tagliare il clamore

Spiegazioni chiare riducono la cattura da parte di montature pubblicitarie, PR di laboratorio e vaghi teatrini etici.

The Future of Provider vs Deployer Under the EU AI Act

The AI Act’s provider and deployer roles may overlap across a product supply chain, and the 2026 AI Omnibus changed both Article 25 cooperation duties and the timing of high-risk system rules. Annex III rules apply from 2 December 2027 and Annex I product-embedded rules from 2 August 2028. Keep role assessments tied to each system version and intended purpose, and review them when branding, modifications, or uses change. Check the current consolidated Regulation and Commission guidance at each launch.

Implementazione nel mondo reale

A software company that develops a system and places it on the EU market under its own name assesses provider duties.

A hospital that uses a vendor’s AI system under its authority assesses deployer duties alongside healthcare and data-protection rules.

A reseller that changes a system’s purpose or makes a substantial modification checks whether Article 25 shifts provider obligations to it.

A group that commissions a system under its own brand checks the provider definition even when an outside firm performed development.

Rischi e guardrail

  • Trattare il rischio esistenziale come fantascienza mentre le capacità si aggravano.

  • Confondere la sicurezza del prodotto superficiale con l'allineamento in condizioni di elevata autonomia.

  • Lasciando il pubblico non inglese e non esperto solo con fonti di bassa qualità.

Tabella di marcia per l'implementazione

  1. Separare i rischi di danni al prodotto, uso improprio e perdita di controllo/disallineamento.

  2. Chiedi quali prove cambierebbero la tua opinione sulle tempistiche e sulla gravità.

  3. Preferire fonti primarie e valutazioni concrete alle affermazioni di marketing.

  4. Identifica un percorso d’azione: carriera, politica, finanziamenti o competenze, non solo consapevolezza.

Continua a esplorare

Free newsletter

Get the daily AI briefing

Three verified AI stories every weekday morning, written in plain English. Free forever, no ads.

One email each weekday. Unsubscribe in one click. We never sell or share your address.

Test yourself

Take the Provider vs Deployer Under the EU AI Act quiz

Instant feedback on every answer, and a shareable certificate with a verifiable ID once you pass a course.

Inizia il quiz

Support free AI education. AI Understanding is a 501(c)(3) nonprofit — no ads, no paywall, ever. Make a donation

Domande frequenti

What is Provider vs Deployer Under the EU AI Act?

The EU AI Act defines a provider by development and market or service placement under its name, while a deployer uses an AI system under its authority in a professional context. The role is determined by the actual activity and can change when an organization relabels or substantially modifies a high-risk system.

Under Article 3, which activity most directly describes a provider?

The provider definition concerns development and placement or putting into service under the provider’s own name or trademark.

Which activity most directly describes a deployer?

Article 3 defines a deployer as an organization or person using an AI system under its authority, excluding personal non-professional use.

A company commissions a system and markets it under its own brand. Which role should it assess?

The provider definition includes a party that has a system developed and places it under its own name or trademark.

When may Article 25 treat a deployer or distributor as the provider of a high-risk system?

Article 25 lists specific provider-requalification circumstances, including branding and certain substantial modifications.

What determines whether an organization is a provider or deployer?

The statutory definitions depend on what the organization actually does in the system lifecycle.