Request a scoping call Contact
← Research

Who is the provider? The question that decides your obligations

Determine the organisation’s AI Act role from the system, intended use and changes it makes. Branding, substantial modification or a new high-risk purpose can require reassessment, with the applicable conditions checked by legal advisers.

Governance / Conceptual study
Trace the evidence.
  1. Sources
  2. Evidence links
  3. Decision record

Keep sources linked to the record used for review. The diagram does not represent automatic approval.

A readiness assessment should show the evidence behind the organisation’s stated role. “We are a deployer” is a conclusion to check against the actual system and activity. Retain the supplier documentation, modification record and intended use that support it.

Provider and deployer obligations differ under the EU AI Act. Article 25 addresses specified changes along the value chain. Check its official conditions rather than treating any branding, fine-tuning or configuration change as an automatic transfer of role.

Reassess role when a material system or purpose change occurs. The legal outcome depends on the Act’s conditions, including high-risk classification and the nature of the modification. Product labels and a party’s self-description cannot settle it.

The three that move the line

What changes an organisation's role along the value chain Fig. 01

Have you done any of these to a system somebody else built?

  • Put your own name or trade mark on it You may hold provider obligations for it. Assess a high-risk system under the branding provision and relevant contractual conditions.
  • Substantially modified it You may hold provider obligations for the modified system. Assess substantial modification of a high-risk system that remains high risk.
  • Changed its intended purpose A general-purpose system pointed at a high-risk use is a different system. Assess whether the changed purpose makes the system high risk under Article 6.

Changing the purpose of an existing system so it becomes high risk can trigger provider obligations under Article 25. A drafting assistant redirected to an application-screening task therefore needs a fresh assessment. The task label alone does not establish classification, and the supplier’s obligations must be assessed alongside the modified use.

Bring the role review into the change process. Record the proposed purpose, affected population and difference from the supplier’s documented use before approving it. Refer the facts for legal determination where the classification or role is uncertain.

Distinguish assumptions from the role assessment

What is assumed, and what determines the answer Fig. 02
The assumption What actually decides it
We did not build the model, so we are not the provider Provider status attaches to placing a system on the market or into service under your name
We bought it, so the obligations are the vendor’s The vendor’s obligations cover the system as they specified it
Our contract says the supplier is responsible A contract allocates risk between the parties. It does not reassign a statutory role
It is only internal, so it is out of scope Scope turns on use and effect, including on your own employees

Contracts allocate responsibilities and risk between parties, but should be reviewed alongside statutory roles. Article 25 also recognises contractual arrangements in its branding provision. The organisation needs advice on those terms and the applicable conditions, rather than treating an indemnity as the complete role assessment.

Assemble the facts for the role review

For each AI system in the inventory, three questions and a written answer.

Whose name is on it, as the user encounters it? Not who built it — who does the person interacting with it believe they are dealing with.

What have we changed? Configuration, prompts, retrieval, fine-tuning, and anything that alters behaviour beyond what the supplier documented.

What is it being used for, and did the supplier specify that use? Compare against the actual documentation, not against the sales conversation.

Keep the assessment current through periodic review and material-change triggers. A new purpose or modification may alter the outcome, but not every extension changes the role. Retain the evidence and reasoning for the particular change.

Ask the product and engineering owners to confirm the record together. A supplier’s original description can become stale when the organisation changes the target users or workflow. Retain those differences for the reviewer rather than compressing them into an unchanged contract label.

What this does not tell you

Determining a role under the Act is a legal question about your specific facts, and this piece does not answer it for anyone. The categories are more nuanced than three branches, there are further roles in the value chain — importers, distributors, authorised representatives — and the interaction with the deferred high-risk timelines matters to what follows from the answer. That analysis belongs with your counsel.

The organisation can assemble the factual record internally: the system’s branding, documented purpose, modifications and actual use. That record is an input to legal analysis. Mark missing information as a gap rather than inferring that the existing role statement is correct.

The governance owner should test the stated role against the retained facts and the applicable provisions. Confirm the conclusion, request missing evidence or refer an unresolved change for legal review. Record the owner and reassessment trigger with the result.

Filed under · Governance · EU AI Act · Governance · Roles Inference Institute · 02 Oct 2026 (updated)

Related engagement

The decision behind this article

Governance your organisation can operate, with clear owners and decision criteria.

Explore AI Governance →

Bring us the question

Reading this because it is on your desk right now?

That is the conversation we are best at. Thirty minutes, a written summary, no obligation.