The definitions, as written
Article 3(3): a provider is a natural or legal person, public authority, agency or other body that develops an AI system or a general-purpose AI model, or has one developed, and places it on the market or puts it into service under its own name or trademark — whether for payment or free of charge. A deployer uses an AI system under its own authority. The distinction turns on whose name is on it and who put it into service, not on who wrote the code.
Three ways a deployer becomes a provider
Article 25 lists them. You put your name or trademark on a high-risk AI system already on the market. You make a substantial modification to a high-risk system that keeps it high-risk. Or you modify the intended purpose of a system — including a general-purpose AI system — that was not classified as high-risk, in a way that makes it high-risk. Each of these makes you subject to the provider obligations of Article 16.
Why the distinction is expensive to get wrong
Provider duties for high-risk systems include the risk management system, data governance, technical documentation, record keeping, human oversight design and conformity assessment. Deployer duties are real but far narrower. An organisation that white-labels a vendor's system and assumes it stayed a deployer can be carrying the full provider set without having built any of it.
This is not only a high-risk question
The name-and-trademark and substantial-modification routes in Article 25 are written for high-risk systems, but the transparency duties in Article 50 also allocate by role: 50(1) and 50(2) are provider duties, 50(4) is a deployer duty. Establishing your role once, per system, answers several questions at the same time.
Why the Commission's guidance is organised the same way
The Commission's guidelines on the Article 50 transparency obligations, published 20 July 2026 and applying from 2 August, are themselves structured by role: which duties fall on providers and which on deployers. That is a useful cross-check on your own classification — if you cannot place yourself in their structure, the role question is not settled yet.
What to do
Go through your AI inventory and record, per system, whether you develop it, put your name on it, or merely use it — and whether you have changed what it is for. Keep the reasoning, not just the label: the moment a procurement team rebrands a vendor tool or a product team repurposes a general-purpose model, the answer can change and the earlier assessment is what shows you noticed.
Sources
Last verified against the primary sources: 2026-08-04
Check your own systems
The free
Article 50 check maps one system to the transparency duties in about two minutes, quoting the official text per answer. No sign-up, and the full result before any contact details.
← EU AI Act overview