Glossary · AI Act
Provider vs Deployer
The AI Act's two central roles: the provider develops or places an AI system on the market; the deployer uses it under its own authority.
Explained in depth: AI Act overview
The provider is the actor who develops an AI system or general-purpose model, or has one developed, and places it on the EU market or puts it into service under its own name or trademark. The deployer is anyone using an AI system under its authority in a professional context. Providers carry the bulk of the obligations, especially for high-risk systems; deployers have lighter but real duties, including using systems according to instructions, ensuring human oversight and staff competence, monitoring operation, and, for certain high-risk deployments, performing a fundamental rights impact assessment. The roles can shift: a deployer that puts its name on a high-risk system, substantially modifies one, or changes its intended purpose into a high-risk use becomes a provider and inherits provider obligations. Importers and distributors have their own, narrower duties.
Why it matters
"Provider or deployer?" is the second question of every AI Act assessment, right after risk classification, because it determines which obligation set applies. Companies that fine-tune, white-label, or repurpose third-party AI are the ones most often surprised to find themselves providers.
