← All guides

Foundations

Provider or deployer? Why your role decides your duties

The same AI system carries very different obligations depending on your role in the value chain — and you can become a provider without meaning to.

Updated 3 July 2026 · Reference material, not legal advice


Before you ask how risky is my system?, ask a more decisive question: what is my role? The AI Act assigns obligations by position in the value chain, and the same high-risk system means very different things for the party that built it and the party that merely uses it.

The four roles

  • Provider — develops an AI system (or has it developed) and places it on the market, or puts it into service, under its own name or trademark. Providers of high-risk systems carry the heavy obligations: risk management, data governance, technical documentation, logging, human-oversight design, accuracy and robustness, a quality-management system, conformity assessment, CE marking and registration.
  • Deployer — uses an AI system under its own authority, in a professional capacity. Duties are lighter but real (Article 26): use the system per its instructions, assign competent human oversight, ensure input-data relevance where you control it, keep logs for at least six months, inform affected workers, and — for public bodies and certain others — complete a fundamental-rights impact assessment (Article 27).
  • Importer — places on the EU market a system from a provider established outside the Union; verifies conformity upstream.
  • Distributor — makes a system available on the market without being provider or importer.

Becoming a provider by accident (Article 25)

This is the trap that catches teams off guard. A distributor, importer, deployer or other third party becomes a provider — and inherits the full Article 16 obligations — if it:

  • puts its own name or trademark on a high-risk system already on the market;
  • makes a substantial modification that keeps the system high-risk; or
  • repurposes a system (including a general-purpose one) so that it becomes high-risk.

For teams that fine-tune, wrap, rebrand or significantly adapt third-party AI, this is easy to trigger without noticing. When the original provider steps back, the obligations land on you.

Why it changes everything

Knowing only your risk tier tells you a duty exists, not who owns it. Role scoping is what turns “this system is high-risk” into “here are the specific things you must produce.” It is also the difference between missing a duty you owe and wasting effort on one that is not yours.

What this means in practice

Euridium’s assessment asks the role question first — including the Article 25 change-of-status branch — so the obligations you see are the ones that genuinely bind you, each mapped to its source article.

See where your own AI systems stand.

Run a guided assessment and get the obligations that apply to your role.

Open the platform

This guide is a plain-language summary for orientation. The authoritative text is Regulation (EU) 2024/1689 as published in the Official Journal of the European Union (12 July 2024). It does not constitute legal advice.