GUIA DA SOCIEDADE

Provider vs Deployer Under the EU AI Act

The EU AI Act defines a provider by development and market or service placement under its name, while a deployer uses an AI system under its authority in a professional context.

  • 3 minutos de leitura
  • Última atualização
Nesta página3 minutos de leitura
  1. Visão geral
  2. Mergulho profundo
  3. Impacto Estratégico
  4. The Future of Provider vs Deployer Under the EU AI Act
  5. Implementação no mundo real
  6. Riscos e guarda-corpos
  7. Roteiro de implementação
  8. Continue explorando
  9. Perguntas frequentes

Visão geral

The role is determined by the actual activity and can change when an organization relabels or substantially modifies a high-risk system.

Mergulho profundo

The EU AI Act distinguishes a provider from a deployer. Under Article 3, a provider develops an AI system or has one developed and places it on the market, or puts it into service, under its own name or trademark. A deployer uses an AI system under its authority in a professional context; personal non-professional use is excluded. These roles do not simply mean vendor and customer. A business that commissions development and markets the system under its own name may be the provider; an organization using a purchased tool for work may be a deployer. One organization can hold different roles across systems. Importers, distributors, product manufacturers, and authorized representatives have separate roles. Article 25 can reassign provider duties to a distributor, importer, deployer, or another third party in specified cases: branding a high-risk system, substantially modifying it while it remains high-risk, or changing its intended purpose so it becomes high-risk. A user-interface change alone is not automatically a substantial modification. Under the 2026 AI Omnibus, when a role change occurs the initial provider generally ceases to be provider of that system but must cooperate with the new provider and supply necessary information, reasonable technical access, and assistance, including known limitations and failure modes. This duty does not apply if the initial provider clearly specified the system must not be changed into a high-risk system. The parties must agree in writing on needed support. Provider and deployer duties depend on the system and role. For high-risk systems, providers handle conformity and required documentation; deployers use the system according to instructions and assign competent human oversight. The Act has applied generally since August 2, 2026, with phased rules: Annex III high-risk system rules apply from December 2, 2027, and Annex I product-embedded rules apply from August 2, 2028. Check the current Regulation for the specific system and use.

Impacto Estratégico

Risco e segurança

Os danos catastróficos e diários da IA ​​dependem de quem entende os riscos e de quem pode agir.

Decisões mais claras

A literacia pública e profissional determina se uma política de segurança forte é politicamente possível.

Cortando o hype

Explicações claras reduzem a captura por exageros, relações públicas de laboratório e teatro de ética vaga.

The Future of Provider vs Deployer Under the EU AI Act

The AI Act’s provider and deployer roles may overlap across a product supply chain, and the 2026 AI Omnibus changed both Article 25 cooperation duties and the timing of high-risk system rules. Annex III rules apply from 2 December 2027 and Annex I product-embedded rules from 2 August 2028. Keep role assessments tied to each system version and intended purpose, and review them when branding, modifications, or uses change. Check the current consolidated Regulation and Commission guidance at each launch.

Implementação no mundo real

A software company that develops a system and places it on the EU market under its own name assesses provider duties.

A hospital that uses a vendor’s AI system under its authority assesses deployer duties alongside healthcare and data-protection rules.

A reseller that changes a system’s purpose or makes a substantial modification checks whether Article 25 shifts provider obligations to it.

A group that commissions a system under its own brand checks the provider definition even when an outside firm performed development.

Riscos e guarda-corpos

  • Tratar o risco existencial como ficção científica enquanto aumenta a capacidade.

  • Confundir segurança do produto de superfície com alinhamento sob alta autonomia.

  • Deixando o público não-inglês e não especializado com apenas fontes de baixa qualidade.

Roteiro de implementação

  1. Separe os riscos de danos ao produto, uso indevido e perda de controle/desalinhamento.

  2. Pergunte quais evidências mudariam sua visão sobre prazos e gravidade.

  3. Prefira fontes primárias e avaliações concretas em vez de afirmações de marketing.

  4. Identifique um caminho de ação: carreira, política, financiamento ou habilidades – não apenas conscientização.

Continue explorando

Free newsletter

Get the daily AI briefing

Three verified AI stories every weekday morning, written in plain English. Free forever, no ads.

One email each weekday. Unsubscribe in one click. We never sell or share your address.

Test yourself

Take the Provider vs Deployer Under the EU AI Act quiz

Instant feedback on every answer, and a shareable certificate with a verifiable ID once you pass a course.

Iniciar teste

Support free AI education. AI Understanding is a 501(c)(3) nonprofit — no ads, no paywall, ever. Make a donation

Perguntas frequentes

What is Provider vs Deployer Under the EU AI Act?

The EU AI Act defines a provider by development and market or service placement under its name, while a deployer uses an AI system under its authority in a professional context. The role is determined by the actual activity and can change when an organization relabels or substantially modifies a high-risk system.

Under Article 3, which activity most directly describes a provider?

The provider definition concerns development and placement or putting into service under the provider’s own name or trademark.

Which activity most directly describes a deployer?

Article 3 defines a deployer as an organization or person using an AI system under its authority, excluding personal non-professional use.

A company commissions a system and markets it under its own brand. Which role should it assess?

The provider definition includes a party that has a system developed and places it under its own name or trademark.

When may Article 25 treat a deployer or distributor as the provider of a high-risk system?

Article 25 lists specific provider-requalification circumstances, including branding and certain substantial modifications.

What determines whether an organization is a provider or deployer?

The statutory definitions depend on what the organization actually does in the system lifecycle.