·AI Act

Provider and deployer: how the AI Act allocates obligations

Who carries compliance obligations under the AI Act depends on how a system is placed on the market and used. The provider-deployer distinction has structural implications that are not always visible in a straightforward reading of the text.

The distinction

A provider is the entity that develops an AI system and places it on the market. A deployer is the entity that uses it under its own authority. Providers carry the primary obligations for high-risk systems: conformity assessment, technical documentation, and registration. Deployers carry a narrower set: using systems according to providers’ instructions, maintaining human oversight, and conducting data protection assessments where required.

When a deployer substantially modifies a high-risk system, the AI Act treats them as a provider for that version, and the full set of provider obligations applies.

“Substantial modification” is a threshold with meaningful compliance consequences. Current guidance leaves ambiguity, particularly for entities that fine-tune or adapt foundation models for specific applications.

Multi-party configurations

Many AI deployments involve chains of entities: foundation model developers, API providers, system integrators, and end deployers. The AI Act distributes obligations across these chains, but how responsibility is allocated in complex configurations will be clarified primarily through early guidance and enforcement decisions.

Regulatory Reality · 2026 · Observational analysis. Not legal advice.