AI Act Roles: Provider, Distributor, Importer and Deployer

Who is a provider, distributor, importer or deployer under the AI Act? We explain their roles, key obligations and responsibilities.

An AI system rarely exists on its own. Someone develops it and places it on the market, someone imports it into the EU, someone distributes it, and someone uses it in their professional activities.

Although all these companies interact with the same technology in one way or another, their roles and obligations under the EU Artificial Intelligence Act (AI Act) may differ significantly.

The AI Act distinguishes, among others, providers, importers, distributors, and deployers. Therefore, for a business, it is not enough simply to determine whether it uses AI and which risk category a particular system falls into. It is equally important to answer another question: what exactly is our role in relation to this AI system?

Provider: the party behind the AI system

Under the AI Act, a provider is a natural or legal person, public authority, agency, or other body that develops an AI system or a general-purpose AI model, or has such a system or model developed, and places it on the market or puts the AI system into service under its own name or trademark.

There is an important nuance here: you do not necessarily have to develop the entire system yourself to qualify as a provider.

If a company commissions a third-party developer to create an AI solution but offers it under its own name or brand, the company itself may qualify as a provider under the AI Act.

For example, a SaaS company hires a contractor to develop AI functionality for automatically analysing CVs, then integrates that functionality into its own HR platform and offers it to customers under its own brand. The mere fact that the code was written by an external contractor does not necessarily mean that the contractor will be the provider under the AI Act.

A significant portion of the requirements relating to the AI system itself rests with the provider, although the specific obligations depend on the type of system and its level of risk.

For high-risk AI systems, the provider must, among other things, ensure that the system complies with the applicable requirements, establish a quality management system, maintain the necessary documentation and logs, carry out the relevant conformity assessment procedure, draw up an EU declaration of conformity, affix the CE marking, and comply with the applicable registration requirements.

Importer: the party that brings a foreign AI system onto the EU market

An importer is a natural or legal person located or established in the EU that places on the Union market an AI system bearing the name or trademark of a company established in a third country.

For example, a US company develops an AI solution under its own brand, while a European company places that solution on the EU market. In such circumstances, the European company may act as the importer.

The importer’s role is not limited to simply acting as an intermediary between the foreign provider and customers in the EU.

For high-risk AI systems, the importer performs a kind of control function: before placing the system on the market, it must verify whether the provider has complied with a number of key AI Act requirements.

In particular, the importer must verify whether the required conformity assessment has been carried out, whether the technical documentation has been prepared, whether the system bears the required CE marking, and whether the EU declaration of conformity and instructions for use are available. Where necessary, the importer must also verify whether the provider has appointed an authorised representative in the EU.

The importer must also indicate its own contact details on the system, its packaging, or the accompanying documentation, and retain certain documents for the required period.

If there are sufficient grounds to believe that a high-risk AI system does not comply with the AI Act, the importer must not place it on the market until the non-compliance has been remedied.

Distributor: not simply “resell and forget”

A distributor is an operator in the supply chain, other than the provider or importer, that makes an AI system available on the EU market.

The simplest example is a reseller or another partner that sells customers a ready-made AI solution developed by another company.

At first glance, the distributor’s role may seem purely commercial: receive a finished product and pass it on to the customer. However, in the case of high-risk AI systems, the AI Act also imposes its own control obligations on distributors.

Before making such a system available on the market, the distributor must, among other things, verify the presence of the required CE marking, the EU declaration of conformity, and the instructions for use, as well as verify compliance with certain obligations by the provider and importer.

If the distributor has sufficient grounds to believe that the system does not comply with the AI Act, it must not make it available on the market until the non-compliance has been remedied. Where the system presents the relevant risk, the distributor may also be required to inform the provider or importer and the competent authorities.

Deployer: the party that uses AI

A deployer is a natural or legal person, public authority, agency, or other body using an AI system under its authority. However, the use of AI in the course of a personal, non-professional activity does not fall within this definition.

For example, if a person uses generative AI to plan a personal trip or come up with a dinner recipe, they do not become a deployer within the meaning of the AI Act.

The situation is different when an AI system is used by a business in the course of its activities.

For example:

  • an employer uses an AI system to assess job applicants;
  • a bank uses AI to carry out certain assessments of customers;
  • a company uses an AI solution to analyse employee performance;
  • a marketing agency uses generative AI to create content for clients.

In such cases, the company may act as the deployer.

It is also important to remember that the deployer is not necessarily the individual employee who clicks a button or enters a prompt. If employees use an AI system under the control of and on behalf of the company, the relevant role will generally belong to the organisation itself.

With regard to high-risk AI systems, the deployer must, among other things, use the system in accordance with the instructions provided, ensure appropriate human oversight, and assign that oversight to persons with the necessary competence, training, authority, and support.

Where the deployer exercises control over the input data, it must also ensure that the data is relevant and sufficiently representative in view of the intended purpose of the system. In addition, the deployer must monitor the operation of the system and respond to identified risks and serious incidents.

For certain deployers and certain high-risk AI systems, there may also be an obligation to carry out a fundamental rights impact assessment before the system is used.

Therefore, saying “we do not develop anything, we only use ready-made AI” does not in itself mean that the AI Act imposes no obligations on the company.

What if we integrate someone else’s AI model into our own product?

This is where the boundaries between roles become more interesting.

Imagine that a company does not develop its own large language model but instead uses another provider’s model via an API and builds its own AI product on top of it.

For example, a legal platform uses a third-party language model but builds its own interface and functionality around it and offers customers a ready-made AI assistant under its own brand.

In this case, the fact that the underlying model was developed by another company does not necessarily mean that the business is merely a deployer.

A company may use someone else’s model and at the same time act as the provider of the final AI system that it builds on top of that model and offers under its own name.

When can a distributor, importer, or deployer become a provider?

Roles under the AI Act do not always remain unchanged.

Under certain circumstances, a distributor, importer, deployer, or other third party may itself be considered the provider of a high-risk AI system and take on the corresponding obligations.

This may happen where they:

  • put their name or trademark on a high-risk AI system that has already been placed on the market or put into service;
  • make a substantial modification to a high-risk AI system while the system continues to qualify as high-risk;
  • modify the intended purpose of an AI system that was not previously considered high-risk in such a way that, as a result of the new intended purpose, it becomes a high-risk system.

For example, a company purchases a ready-made AI system, substantially modifies it, adds its own branding, and begins offering it to customers as its own solution.

In such a situation, saying “we only purchased another developer’s technology” may not be enough. Depending on the specific circumstances, the company’s role under the AI Act may change.

One company = one role? Not necessarily

Another important point is that the AI Act does not assign every company only one role.

On the contrary, in different situations, the same organisation may perform several roles at the same time and therefore have obligations associated with each of them. The AI Act itself expressly recognises that a single operator may act in more than one role.

For example, a company:

  • uses a third-party AI system in its own internal processes;
  • resells a ready-made AI solution from another provider to customers;
  • at the same time develops its own AI assistant and offers it under its own brand.

With respect to the first system, it may be a deployer; with respect to the second, a distributor; and with respect to the third, a provider.

Therefore, the role should be determined not for the company as a whole, but separately for each AI system and each specific scenario in which it is used or distributed.

What about high-risk AI systems now?

The AI Act is being applied in stages.

The main part of the Regulation applies from 2 August 2026. However, following changes to its implementation timeline, certain requirements for high-risk AI systems apply at a later stage.

For systems classified as high-risk under Article 6(2) and Annex III, the relevant provisions of Sections 1–3 of Chapter III will apply from 2 December 2027, while for high-risk systems related to products listed in Annex I under Article 6(1), they will apply from 2 August 2028.

However, this does not mean that companies can postpone identifying their roles until those dates. Other AI Act requirements already apply, and understanding who is the provider, importer, distributor, or deployer is an essential starting point for identifying the next compliance steps.

How can you determine your role in practice?

A useful starting point is to ask several questions.

Who developed the AI system or commissioned its development? Under whose name or trademark is it offered? Are we placing on the EU market a system belonging to a company established in a third country? Are we simply reselling a ready-made solution? Are we using it in the course of our own professional activities? Are we integrating a third-party model into our own product? Have we changed the intended purpose or substantially modified a ready-made system?

In straightforward cases, the role will be obvious. In others, the same business process may require a more detailed analysis of the entire supply chain and the agreements between its participants.

In practice, this can be reduced to a simple framework:

AI system → how we obtained it → what we do with it → under whose brand it is used or offered → our role → corresponding obligations.

In short…

Under the AI Act, what matters is not only which AI a company uses, but also what exactly it does with it.

Developing a system or commissioning its development and selling it under your own brand, importing a foreign product into the EU, reselling a ready-made solution, or using AI in your own activities are legally different situations.

Moreover, a company’s role may change if it substantially modifies a system, changes its intended purpose, or starts offering a high-risk solution under its own brand.

A good starting point for AI compliance is therefore an inventory: which AI systems the company uses or offers, what they are used for, and which role the company performs in relation to each of them.

Once that role has been determined, the next question becomes much easier to answer: which specific AI Act requirements apply to the business in each particular case?

Tags
  • AI Act
Do you have any questions for the lawyers?
up to 500 characters
An error occurred
The request has been sent Thank you for your message! We will process it as soon as possible.