Witness
Get Started
Free ToolsPricing
Sign In
  1. Home
  2. /Free Tools
  3. /Provider vs Deployer

Free tool

Are you a provider or a deployer under the EU AI Act?

Your role decides which obligations apply. This page explains the provider, deployer, and dual-role definitions and the Article 25 rules that can turn a deployer into a provider.

Legal basis: EU AI Act Article 3 definitions and Article 25 role allocation.

Determine my role

The three roles

Most EU AI Act obligations attach to a role. Under Article 3, a provider develops or has an AI system developed and places it on the market under its own name; a deployer uses an AI system under its authority. Many companies are both.

Art. 3(3)

Provider

You develop an AI system, or have one developed for you, and place it on the market or put it into service under your own name or trademark. Providers carry the primary compliance burden: technical documentation, conformity assessment, and post-market monitoring.

Art. 3(4)

Deployer

You use an AI system under your authority for professional purposes. Deployers follow the provider's instructions, ensure human oversight, monitor operation, and meet transparency and notification duties.

Art. 25

Both

You develop your own systems and use third-party systems. You then carry provider obligations for what you build and deployer obligations for what you use.

When a deployer becomes a provider (Article 25)

Article 25 shifts provider responsibilities onto a deployer in specific situations. If any of these apply to a high-risk system, you are treated as a provider and inherit the full provider obligations.

  • →You place a high-risk AI system on the market under your own name or trademark (Art. 25(1)(a)).
  • →You make a substantial modification to a high-risk AI system already on the market (Art. 25(1)(b)).
  • →You change the intended purpose of an AI system so that it becomes high-risk (Art. 25(1)(c)).

Role-shifting applies only to high-risk systems. Under Article 25(2), the original provider must cooperate and hand over the documentation you need.

Determine your exact role

The guided intake asks a short set of questions, applies the Article 3 and Article 25 rules, and returns your role together with the obligations that follow from it.

Start the guided intake

Free. No account required to see your result.

Frequently asked questions

Can I be both a provider and a deployer?+

Yes. If you develop or rebrand AI systems and also use third-party AI systems, you hold both roles and must satisfy both sets of obligations.

Does using ChatGPT or a third-party model make me a provider?+

Not by itself. Simply using a third-party AI system under your authority makes you a deployer. You only become a provider if you rebrand a high-risk system, substantially modify it, or change its intended purpose so it becomes high-risk (Article 25).

Why does my role matter?+

The EU AI Act allocates almost every obligation by role. Providers of high-risk systems must run conformity assessments and maintain technical documentation; deployers must ensure human oversight and, in some cases, complete a fundamental rights impact assessment.

What counts as a substantial modification?+

A change not foreseen in the initial conformity assessment that affects compliance with the requirements, or that alters the intended purpose of a high-risk AI system.

Related reading

  • The EU AI Act explained: risk tiers, roles, and deadlines
  • Browse all free EU AI Act tools