SamfunnsGUIDE

Provider vs Deployer Under the EU AI Act

The EU AI Act defines a provider by development and market or service placement under its name, while a deployer uses an AI system under its authority in a professional context.

  • 3 minutters lesing
  • Sist oppdatert
På denne siden3 minutters lesing
  1. Oversikt
  2. Dypdykk
  3. Strategisk innvirkning
  4. The Future of Provider vs Deployer Under the EU AI Act
  5. Real-World Implementering
  6. Risikoer og rekkverk
  7. Veikart for implementering
  8. Fortsett å utforske
  9. Ofte stilte spørsmål

Oversikt

The role is determined by the actual activity and can change when an organization relabels or substantially modifies a high-risk system.

Dypdykk

The EU AI Act distinguishes a provider from a deployer. Under Article 3, a provider develops an AI system or has one developed and places it on the market, or puts it into service, under its own name or trademark. A deployer uses an AI system under its authority in a professional context; personal non-professional use is excluded. These roles do not simply mean vendor and customer. A business that commissions development and markets the system under its own name may be the provider; an organization using a purchased tool for work may be a deployer. One organization can hold different roles across systems. Importers, distributors, product manufacturers, and authorized representatives have separate roles. Article 25 can reassign provider duties to a distributor, importer, deployer, or another third party in specified cases: branding a high-risk system, substantially modifying it while it remains high-risk, or changing its intended purpose so it becomes high-risk. A user-interface change alone is not automatically a substantial modification. Under the 2026 AI Omnibus, when a role change occurs the initial provider generally ceases to be provider of that system but must cooperate with the new provider and supply necessary information, reasonable technical access, and assistance, including known limitations and failure modes. This duty does not apply if the initial provider clearly specified the system must not be changed into a high-risk system. The parties must agree in writing on needed support. Provider and deployer duties depend on the system and role. For high-risk systems, providers handle conformity and required documentation; deployers use the system according to instructions and assign competent human oversight. The Act has applied generally since August 2, 2026, with phased rules: Annex III high-risk system rules apply from December 2, 2027, and Annex I product-embedded rules apply from August 2, 2028. Check the current Regulation for the specific system and use.

Strategisk innvirkning

Risiko og sikkerhet

Katastrofale og hverdagslige AI-skader avhenger begge av hvem som forstår risikoen og hvem som kan handle.

Tydeligere avgjørelser

Offentlig og faglig kompetanse former om sterk sikkerhetspolitikk er politisk mulig.

Skjærer gjennom hypen

Tydelige forklaringer reduserer fangst av hype, laboratorie-PR og vagt etikkteater.

The Future of Provider vs Deployer Under the EU AI Act

The AI Act’s provider and deployer roles may overlap across a product supply chain, and the 2026 AI Omnibus changed both Article 25 cooperation duties and the timing of high-risk system rules. Annex III rules apply from 2 December 2027 and Annex I product-embedded rules from 2 August 2028. Keep role assessments tied to each system version and intended purpose, and review them when branding, modifications, or uses change. Check the current consolidated Regulation and Commission guidance at each launch.

Real-World Implementering

A software company that develops a system and places it on the EU market under its own name assesses provider duties.

A hospital that uses a vendor’s AI system under its authority assesses deployer duties alongside healthcare and data-protection rules.

A reseller that changes a system’s purpose or makes a substantial modification checks whether Article 25 shifts provider obligations to it.

A group that commissions a system under its own brand checks the provider definition even when an outside firm performed development.

Risikoer og rekkverk

  • Behandling av eksistensiell risiko som sci-fi mens evnesammensetninger.

  • Forvirrende overflateproduktsikkerhet med justering under høy autonomi.

  • Etterlater ikke-engelske og ikke-eksperter med kun kilder av lav kvalitet.

Veikart for implementering

  1. Separate risikoer for produktskade, misbruk og tap av kontroll/feiljustering.

  2. Spør hvilke bevis som vil endre ditt syn på tidslinjer og alvorlighetsgrad.

  3. Foretrekk primære kilder og konkrete vurderinger fremfor markedsføringspåstander.

  4. Identifiser én handlingsvei: karriere, politikk, finansiering eller ferdigheter – ikke bare bevissthet.

Fortsett å utforske

Free newsletter

Get the daily AI briefing

Three verified AI stories every weekday morning, written in plain English. Free forever, no ads.

One email each weekday. Unsubscribe in one click. We never sell or share your address.

Test yourself

Take the Provider vs Deployer Under the EU AI Act quiz

Instant feedback on every answer, and a shareable certificate with a verifiable ID once you pass a course.

Start quiz

Support free AI education. AI Understanding is a 501(c)(3) nonprofit — no ads, no paywall, ever. Make a donation

Ofte stilte spørsmål

What is Provider vs Deployer Under the EU AI Act?

The EU AI Act defines a provider by development and market or service placement under its name, while a deployer uses an AI system under its authority in a professional context. The role is determined by the actual activity and can change when an organization relabels or substantially modifies a high-risk system.

Under Article 3, which activity most directly describes a provider?

The provider definition concerns development and placement or putting into service under the provider’s own name or trademark.

Which activity most directly describes a deployer?

Article 3 defines a deployer as an organization or person using an AI system under its authority, excluding personal non-professional use.

A company commissions a system and markets it under its own brand. Which role should it assess?

The provider definition includes a party that has a system developed and places it under its own name or trademark.

When may Article 25 treat a deployer or distributor as the provider of a high-risk system?

Article 25 lists specific provider-requalification circumstances, including branding and certain substantial modifications.

What determines whether an organization is a provider or deployer?

The statutory definitions depend on what the organization actually does in the system lifecycle.