Skip to content
Amended. Regulation (EU) 2026/1744 entered into force 27 July 2026. See what moved →
EU AI Act ChecklistIndependent reference
Chapter III · Articles 16, 22, 25, 26

Provider or deployer? The answer decides your entire obligation set

Nearly every practical EU AI Act question resolves to this: which role are you in for this system? Providers carry design-time obligations. Deployers carry use-time obligations. And Article 25 quietly moves companies from the second column to the first.

Arts. 3(3), 3(4), 16, 25, 26

Side by side

ObligationProviderDeployer
Risk management system (Art. 9)Yes
Data governance (Art. 10)YesInput data relevance, where you control it (Art. 26(4))
Technical documentation, Annex IV (Art. 11)Yes
Logging (Art. 12)Design the capabilityRetain logs, min. 6 months (Art. 26(6))
Instructions for use (Art. 13)Write themFollow them (Art. 26(1))
Human oversight (Art. 14)Build the measures inAssign competent, trained, authorised people (Art. 26(2))
Accuracy, robustness, cybersecurity (Art. 15)Yes
Quality management system (Art. 17)Yes
Conformity assessment & CE marking (Arts. 43, 48)Yes
EU database registration (Art. 49)YesPublic authority deployers register too
FRIA (Art. 27)Public bodies & certain essential-service deployers
Inform workers before workplace deployment (Art. 26(7))Yes
Post-market monitoring (Art. 72)YesCooperate; report incidents
Serious incident reporting (Art. 73)YesInform the provider without undue delay
Article 50 transparency50(1), 50(2)50(3), 50(4)
Article 4 AI literacyYesYes

Provider and deployer obligations for high-risk systems apply from 2 December 2027 for stand-alone Annex III systems. Article 4 and Article 50 apply now.

Where this usually goes next

Three situations account for most people reading this page. Each has a different answer.

A deal is blocked on an AI questionnaire

Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.

How this works for AI companies →

You need ISO/IEC 42001 documentation

23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.

Free gap assessment →
See the three tiers →

You are not sure what reaches you

Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.

Book a free 20-minute call →

This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →

The two roles nobody claims

Importer (Art. 23) — established in the Union, places on the market a high-risk system bearing the name of a non-EU provider. You must verify the conformity assessment was carried out, the technical documentation exists, the CE marking is affixed and an authorised representative is appointed. You cannot place a system you have reason to believe is non-conforming.

Distributor (Art. 24) — anyone in the supply chain other than provider or importer making a system available. You verify CE marking, the declaration and the instructions, and you act if you have reason to consider the system non-conforming.

Marketplaces, integrators and resellers routinely occupy one of these roles without having noticed.

Article 25, the role-shifter

Three ways a buyer becomes a builder

  1. You put your name or trade mark on a high-risk system already on the market.
  2. You make a substantial modification to a high-risk system that remains high-risk.
  3. You modify the intended purpose of a system — including a general-purpose AI system, so that it becomes high-risk.

Point 3 is the one that catches modern software companies. Building an Annex III use case on a foundation model makes you the provider of a high-risk AI system. The model vendor’s documentation is an input to yours; it is not a substitute for it.

Where this happens, the original provider must cooperate: they are required to provide the information reasonably needed for the new provider to comply, unless they have clearly specified the system is not to be changed into a high-risk one.

Arts. 23, 24, 25Reg. (EU) 2024/1689
Next step

Write your role down, per system

Role is per system, not per company. The same organisation is commonly a provider for one product, a deployer for a purchased tool, and a distributor for something it resells. An AI system inventory that records the role alongside the system is the artefact that makes every later question answerable.

Not sure where you sit?

The classifier maps your system against Articles 5, 6, 50 and Annex III. Twelve questions, no email.

Run the classifier →

Questions

What is the difference between a provider and a deployer under the EU AI Act?

A provider develops an AI system or has one developed and places it on the market or puts it into service under its own name or trade mark, whether for payment or free of charge. A deployer uses an AI system under its own authority, except where the use is a personal non-professional activity. Providers carry the design-time obligations in Articles 8 to 22; deployers carry the use-time obligations in Article 26, plus Article 27 fundamental rights impact assessments for certain deployers.

Can a deployer become a provider?

Yes. Article 25 makes a deployer, importer or distributor a provider of a high-risk AI system if it puts its name or trade mark on a system already on the market, makes a substantial modification to a high-risk system that remains high-risk, or modifies the intended purpose of a system, including a general-purpose AI system, so that it becomes high-risk.

What are the deployer obligations under Article 26?

Deployers of high-risk AI systems must use the system in accordance with the instructions for use, assign human oversight to people with the necessary competence, training and authority, ensure input data is relevant and sufficiently representative for the intended purpose to the extent they control it, monitor operation and inform the provider and authorities of risks or serious incidents, keep automatically generated logs for at least six months where they control them, and inform workers' representatives and affected workers before putting a high-risk system into service in the workplace.

Who is responsible if we buy an AI tool from a vendor?

Both parties, for different things. The vendor remains the provider and carries the conformity assessment, technical documentation and CE marking obligations. You are the deployer and carry the Article 26 use-time obligations. Neither set transfers by contract. A contractual indemnity may allocate financial risk between you but it does not move a regulatory obligation.