Skip to content
Call, 0511 – 47 55 58 11

Provider or deployer: the role decides the obligations

Whoever develops an AI system or offers it under their own name is a provider. Whoever uses someone else's system is a deployer. The line is permeable, and it is usually crossed unintentionally.

Almost every question about the AI Act leads back to this one first. The role determines which obligations apply to you, which records you have to keep and whom the authority approaches. It therefore belongs at the start of every project, not at the end.

The two roles

A provider is anyone who develops an AI system, or has one developed, and places it on the market or puts it into service under their own name or trademark. By far the largest part of the obligations falls on the provider: risk management, data and documentation requirements, technical documentation, logging, conformity assessment and the reporting of serious incidents. Whether the system is supplied for payment or free of charge makes no difference.

A deployer is anyone using an AI system under their own authority. Purely personal, non-professional use is excluded. Deployers face considerably fewer obligations, but by no means none: use in accordance with the instructions, human oversight by suitably capable people, retention of logs, information of affected staff and, depending on the use, transparency towards the people facing the system.

When a deployer becomes a provider

The roles are not fixed labels. The AI Act sets out cases in which a deployer, distributor or importer takes on the provider obligations for a high-risk system. They regularly arise unintentionally.

Why the classification comes first

Anyone who considers themselves a deployer but is in fact a provider has met none of the provider obligations. That does not surface during normal operation but when a supervisory authority, a client or a competitor asks the question. At that point technical documentation cannot be produced retrospectively, and a conformity assessment even less so.

The opposite happens just as often. Companies impose a provider programme on themselves although they are simply using someone else’s tool. That costs money too, only needlessly.

How we support you

We record the systems in use and planned, assign a role to each one and put the reasoning in writing so that it can be evidenced later. From that follows the set of obligations, and from those in turn what belongs in the contracts with providers and what has to be settled internally.

Unclear which role you are in?

We classify your systems and tell you which obligations follow.

Request a classification

Frequently asked questions

We use a bought-in system under our own name. Does that change anything?

Possibly yes. Whoever puts their own name or trademark on a high-risk system already placed on the market counts as its provider under the AI Act. The provider's set of obligations then applies, even though the system came from someone else. Before applying your own branding, a classification is worth the effort.

We fine-tune a model with our own data. Does that make us a provider?

That depends on the extent. Use within the intended scope does not change the role. A substantial modification of a high-risk system, or a change of intended purpose that turns a system into a high-risk system in the first place, can tip the role. Where the line runs in a particular case is a question of design and belongs before the start of the project.

Can we be provider and deployer at the same time?

Yes. The roles attach to the individual system, not to the company. Whoever develops their own system for clients and also uses third-party tools in house is provider for the one and deployer for the other. A review should therefore start from the systems and not from the organisation chart.

Related