Who is the provider? The question that decides your obligations
Determine the organisation’s AI Act role from the system, intended use and changes it makes. Branding, substantial modification or a new high-risk purpose can require reassessment, with the applicable conditions checked by legal advisers.
Keep sources linked to the record used for review. The diagram does not represent automatic approval.
A readiness assessment should show the evidence behind the organisation’s stated role. “We are a deployer” is a conclusion to check against the actual system and activity. Retain the supplier documentation, modification record and intended use that support it.
Provider and deployer obligations differ under the EU AI Act. Article 25 addresses specified changes along the value chain. Check its official conditions rather than treating any branding, fine-tuning or configuration change as an automatic transfer of role.
Reassess role when a material system or purpose change occurs. The legal outcome depends on the Act’s conditions, including high-risk classification and the nature of the modification. Product labels and a party’s self-description cannot settle it.
The three that move the line
Have you done any of these to a system somebody else built?
- You may hold provider obligations for it. Assess a high-risk system under the branding provision and relevant contractual conditions.
- You may hold provider obligations for the modified system. Assess substantial modification of a high-risk system that remains high risk.
- A general-purpose system pointed at a high-risk use is a different system. Assess whether the changed purpose makes the system high risk under Article 6.
Changing the purpose of an existing system so it becomes high risk can trigger provider obligations under Article 25. A drafting assistant redirected to an application-screening task therefore needs a fresh assessment. The task label alone does not establish classification, and the supplier’s obligations must be assessed alongside the modified use.
Bring the role review into the change process. Record the proposed purpose, affected population and difference from the supplier’s documented use before approving it. Refer the facts for legal determination where the classification or role is uncertain.
Distinguish assumptions from the role assessment
| The assumption | What actually decides it |
|---|---|
| We did not build the model, so we are not the provider | Provider status attaches to placing a system on the market or into service under your name |
| We bought it, so the obligations are the vendor’s | The vendor’s obligations cover the system as they specified it |
| Our contract says the supplier is responsible | A contract allocates risk between the parties. It does not reassign a statutory role |
| It is only internal, so it is out of scope | Scope turns on use and effect, including on your own employees |
Contracts allocate responsibilities and risk between parties, but should be reviewed alongside statutory roles. Article 25 also recognises contractual arrangements in its branding provision. The organisation needs advice on those terms and the applicable conditions, rather than treating an indemnity as the complete role assessment.
Assemble the facts for the role review
For each AI system in the inventory, three questions and a written answer.
Whose name is on it, as the user encounters it? Not who built it — who does the person interacting with it believe they are dealing with.
What have we changed? Configuration, prompts, retrieval, fine-tuning, and anything that alters behaviour beyond what the supplier documented.
What is it being used for, and did the supplier specify that use? Compare against the actual documentation, not against the sales conversation.
Keep the assessment current through periodic review and material-change triggers. A new purpose or modification may alter the outcome, but not every extension changes the role. Retain the evidence and reasoning for the particular change.
Ask the product and engineering owners to confirm the record together. A supplier’s original description can become stale when the organisation changes the target users or workflow. Retain those differences for the reviewer rather than compressing them into an unchanged contract label.
What this does not tell you
Determining a role under the Act is a legal question about your specific facts, and this piece does not answer it for anyone. The categories are more nuanced than three branches, there are further roles in the value chain — importers, distributors, authorised representatives — and the interaction with the deferred high-risk timelines matters to what follows from the answer. That analysis belongs with your counsel.
The organisation can assemble the factual record internally: the system’s branding, documented purpose, modifications and actual use. That record is an input to legal analysis. Mark missing information as a gap rather than inferring that the existing role statement is correct.
The governance owner should test the stated role against the retained facts and the applicable provisions. Confirm the conclusion, request missing evidence or refer an unresolved change for legal review. Record the owner and reassessment trigger with the result.