EU AI Act Guide
Provider vs Deployer Under the EU AI Act: Which One Are You?
Last updated: 2026-07-09
Every obligation in the EU AI Act attaches to a role. Providers — those who develop and place AI systems on the market — carry the heavy stack. Deployers — those who use AI systems professionally — carry a lighter but real set. Getting the role wrong means doing the wrong compliance work entirely.
For SaaS the split is usually clean: the vendor is the provider, the customer is the deployer. But three traps can silently convert a deployer into a provider — including putting your logo on someone else’s model. Here is how the roles actually work.
Not sure which tier applies to you? Check your system in 2 minutes — free and rule-based.
Quick shortcut
Already know you need documents? Skip straight to the Doc Pack — your classification is done for you.
Get Doc Pack ($229–$499)The definitions, in plain terms
A provider develops an AI system (or has one developed) and places it on the market or puts it into service under its own name or trademark — whether paid or free. A deployer uses an AI system under its own authority in a professional context. Personal, non-professional use is out of scope entirely.
The roles are per system, not per company. A SaaS company is provider of the AI features it ships, and simultaneously deployer of the AI tools it uses internally — the hiring platform it sells and the resume screener it uses on its own candidates carry different hats.
What providers owe (high-risk systems)
The provider stack for high-risk systems: risk management system (Art. 9), data governance (Art. 10), Annex IV technical documentation (Art. 11), automatic logging capability (Art. 12), transparent instructions for use (Art. 13), human-oversight-by-design (Art. 14), accuracy, robustness and cybersecurity (Art. 15), quality management system (Art. 17), conformity assessment and CE marking (Art. 43, 47–49), EU database registration, post-market monitoring (Art. 72) and serious-incident reporting (Art. 73).
Non-EU providers with EU customers additionally need an authorised representative established in the Union (Art. 22) — a frequently missed line item for US and Asian SaaS.
What deployers owe
Deployers of high-risk systems must use them per the provider’s instructions, assign competent human oversight, ensure input data is relevant and representative, monitor operation, keep logs at least six months, inform workers’ representatives before workplace deployment, inform affected persons subject to the system’s decisions, and report serious incidents (Art. 26). Article 27 FRIA applies only to defined deployers and use cases: public-law bodies, private entities providing public services, and Annex III 5(b)/(c) creditworthiness or insurance systems.
Deployers of limited-risk systems mostly inherit the transparency reality: make sure the disclosure the provider built actually reaches the end user. And every professional user of AI carries Article 4 AI-literacy duties for staff.
The three traps that make a deployer a provider
Article 25 converts a deployer (or distributor, or any third party) into the provider of a high-risk system when they: (1) put their name or trademark on a high-risk system already on the market — the white-label trap; (2) make a substantial modification to it — the fine-tuning-and-repackaging trap; or (3) modify the intended purpose of a system so that it becomes high-risk — the repurposing trap, e.g. wiring a general chatbot into candidate screening.
In all three cases the full provider stack transfers. The original provider must hand over documentation and cooperate, but the obligations are now yours. If your product is a branded wrapper around a third-party model doing Annex III work, budget as a provider, not a deployer.
What this means for a SaaS contract
Expect the AI Act to show up in your enterprise contracts from both directions. Your EU customers, as deployers, will ask you for the artifacts that let them comply: instructions for use, oversight guidance, logging access, incident-notification terms. And if you consume upstream models, you need the mirror-image terms from your model providers.
The vendor who arrives with a provider pack ready — classification memo, Annex IV documentation, model card, instructions for use — turns this from a negotiation blocker into a checkbox.
Where does your system land?
Check your AI system against the actual Annex I/III rules in 2 minutes. Free, rule-based, no signup.
Start the free risk check →Frequently asked questions
We fine-tune an open-source model and sell the product. Provider or deployer?
Provider. You place an AI system on the market under your own name; that you built on open weights does not change the role. Depending on the modification, some documentation duties may be shared with the upstream model’s publisher, but the system-level obligations are yours.
Our customers configure the AI themselves. Are they the providers?
Ordinary configuration within your intended purpose keeps customers as deployers. They cross into provider territory only via Article 25 — rebranding, substantial modification, or repurposing the system into a high-risk use you did not intend. Define the intended purpose precisely in your instructions for use; it is your main control over this boundary.
Can one company be both provider and deployer of the same system?
Yes — a provider who puts its own system into service for its own use holds both roles simultaneously, and each role’s obligations apply. This is common: an HR-tech vendor using its own screening product on its own vacancies is provider and deployer at once.
Related guides
EU AI Act Deadlines: The Complete 2025-2028 Timeline
Every EU AI Act deadline from February 2025 to August 2028 - what applies when, to whom, and what to do before 2 December 2027.
AI Act Compliance Tools Compared (2026): Platforms, Packs & DIY
Honest comparison of EU AI Act compliance options — GRC platforms like Vanta and Drata, documentation packs, and doing it yourself. Sized by risk, systems and workflow needs.
Is AI Resume Screening High-Risk Under the EU AI Act? (Yes — Here's What That Means)
AI recruitment and CV screening tools fall under Annex III of the EU AI Act. What HR-tech vendors and employers must do before 2 December 2027.
Annex IV Technical Documentation: Structure, Template & Examples
What EU AI Act Annex IV technical documentation must contain, section by section — and how to produce a structured first draft without a custom law-firm drafting engagement.
About these guides
Written by the TrustPacket team. We track Regulation (EU) 2024/1689, Commission guidance, and enforcement developments to keep these guides current. Not legal advice — when in doubt, consult qualified counsel.
Last updated: 2026-07-09 · Content review: 11 July 2026 · Questions? Email us
This is informational editorial content based on Regulation (EU) 2024/1689 and cited official implementation material. It is not legal advice, not a conformity assessment, and does not create a lawyer-client relationship. Application depends on facts this guide cannot verify. Consult qualified counsel for a binding assessment.