The AI Act chain of responsibility: how obligations are passed from the provider to the deployer
Throughout the lifecycle of an AI system, there may be many different actors, each of whom can influence how the system is developed, placed on the market, integrated, and used. From a user’s perspective, this may look like a single AI product. From a regulatory perspective, however, it is a chain of actors, each of whom may have their own obligations. Accordingly, AI compliance cannot be built around identifying a single party that is “responsible” for all risks.
Provider, deployer, importer, distributor: who is who?
Provider develops an AI system or has an AI system developed and places it on the market or puts it into service under its own name or trademark. A provider may use a third-party model, add its own interface, features, rules governing user interaction, and turn the underlying technology into a separate commercial product. In certain circumstances, such changes may be relevant to determining the actor’s role and the scope of its obligations under the AI Act.
Deployer is the party that uses an AI system under its authority. The context in which the system is used also matters. The same technology may simply be a tool in one company, while in another it may form part of a process that affects an individual’s rights or opportunities.
| Provider | Deployer |
| Ensures the compliance of the AI system | Ensures the compliance of the specific way in which the AI system is used |
The roles of importer and distributor are also distinguished: they have their own obligations at the stage of placing the system on the market and making it available. At the same time, a single company may perform several roles in a particular situation.
The role determines which requirements apply to the actor, what documentation it must have, what information it must pass further down the chain, what checks it must carry out, and where responsibility for a particular control lies.
Imagine that a provider has supplied documentation relating to a model. A company integrates it into its own product. It then changes the way the system is used, adds new data, and passes the product on to a distributor. Each participant may have their own part of the picture. But if no one checks how these parts fit together, compliance can easily remain merely a paper exercise.
What the provider must ensure
In the case of a high-risk AI system, a provider cannot simply state that its product “complies with the AI Act”. For providers of such systems, Article 16 of the AI Act establishes a comprehensive set of specific obligations:
- establish a quality management system;
- draw up technical documentation;
- ensure that records are kept;
- carry out a conformity assessment;
- draw up an EU declaration of conformity;
- affix the CE marking; and
- take the necessary corrective actions.
Taken together, these requirements are intended to ensure not merely formal compliance at the point when the system is placed on the market, but continued compliance with the AI Act throughout the system’s lifecycle.
Article 17 requires the provider to put in place a quality management system. This should cover the entire process of developing and maintaining the product, including change management, design verification, development, quality control, testing and validation, data management, risk management, post-market monitoring, the reporting and handling of serious incidents, and record-keeping.
It is equally important what information the provider passes on to the company that will use the system. Article 13 requires high-risk AI systems to be accompanied by clear and comprehensible instructions for use. These must include information on the intended purpose of the system, its capabilities and limitations, expected levels of accuracy, robustness, and cybersecurity, known risks, and the circumstances in which they may arise, as well as information necessary to enable appropriate human oversight.
Importantly, the provider’s responsibility does not end when the AI system is sold. The provider must not only place the system on the market, but also respond to identified problems. If it becomes known after deployment that the system does not comply with the requirements of the AI Act, the provider must take the necessary corrective actions, including, where appropriate, bringing the system into conformity, withdrawing it from the market, or recalling it.
For a company, this means that when selecting an AI solution, it is necessary to assess not only the product itself, but also the provider’s ability to maintain its compliance throughout the system’s lifecycle.
What remains the responsibility of the deployer
Once AI begins to be used in a specific process, a separate area of responsibility arises for the deployer – the company using the system under its authority. Article 26 of the AI Act shifts the focus from the technology itself to the conditions under which it is used. The deployer must ensure that the system is used in accordance with the provider’s instructions, organise human oversight, monitor its operation, keep the required logs, and respond to risks and incidents.
In practice, this means that the company should document:
- which processes the system is used for;
- who is authorised to work with it;
- what data is provided to it;
- what limitations have been specified by the provider; and
- in which circumstances the system’s output cannot be used without additional review.
An important point is that the provider’s instructions do not replace the company’s internal processes. If AI was purchased for one function but is subsequently used for another, the company should separately assess whether such use is consistent with the system’s original intended purpose and the provider’s instructions.
Where the deployer has control over the input data, it must, to the extent required by the AI Act, ensure that such data is relevant and sufficiently representative in view of the intended purpose of the high-risk AI system. For example, a provider may supply a system with specific data requirements. The company may change the source of the information, begin using incomplete data, or apply the system to a different category of persons. Even if the system itself technically complies with the requirements of the AI Act, the way in which the company uses it may create a compliance issue.
The deployer’s obligations also do not end once the AI system has been purchased and implemented.
The company must monitor the operation of a high-risk AI system in accordance with the provider’s instructions and keep logs generated by the system where such logs are under its control.
Where there are grounds to consider that the use of the system presents a risk, the AI Act provides, depending on the circumstances, for the obligation to take appropriate measures, inform the provider and the market surveillance authority, and, where appropriate, suspend the use of the system.
For certain high-risk systems used to make decisions or assist in making decisions concerning natural persons, the AI Act also requires those persons to be informed that they are subject to the use of the system in the cases specified by the AI Act. In other words, deploying AI requires updates to internal procedures, notices to employees, and communications with individuals affected by decisions made with the assistance of the system.
For certain categories of deployers, Article 27 establishes a separate requirement to carry out a fundamental rights impact assessment (FRIA) before deploying certain high-risk AI systems. Such an assessment must be linked to the specific way in which the system will be used, including:
- who is affected by the system;
- what risks arise;
- how human oversight is organised; and
- what measures will be taken if a risk materialises.
| Question | Provider’s responsibility | Deployer’s responsibility |
| What is the actor responsible for? | Ensuring that the high-risk AI system is developed, documented, assessed, and placed on the market in accordance with the AI Act | Ensuring that the system is used after deployment in accordance with the AI Act |
| Intended purpose of the system | Defines and documents the intended purpose of the system and ensures its conformity with that intended purpose | Uses the system in accordance with the instructions and the specified intended purpose |
| Documentation and instructions | Must provide the required documentation and instructions for use | Must organise the use of the system in accordance with the documentation and instructions |
| Human oversight | Must design the system so that human oversight can be exercised effectively | Must assign specific personnel to human oversight and ensure that they have the necessary competence, training, authority, and support |
| Monitoring | Must establish the necessary mechanisms following the placing of the system on the market, including mechanisms for monitoring and responding to problems | Must monitor the operation of the system in its own environment and respond to risks and incidents |
| Risk or incident | Must have mechanisms in place to identify, document, and respond to problems with the system | Where it has reason to consider that the use of the system presents a risk, the deployer must take the required measures and, where necessary, inform the provider and the market surveillance authority, and suspend use |
| Fundamental rights impact assessment | General compliance of the system with the requirements of the AI Act | For certain categories of deployers, a separate fundamental rights impact assessment before deploying the system, as required by Article 27 |
Responsibility from launch to use
To build an AI Act compliance programme, a company needs to understand the entire chain of responsibility: who is the provider, who is the deployer, what obligations arise for each party, at what stage they must be fulfilled, and what documents demonstrate compliance.
For this reason, it is advisable to create a separate responsibility map for each system. It should follow the system from the moment it is developed or selected through to the end of its use.
| Stage | Provider | Deployer |
| Before launch | Ensures that the system complies with the requirements of the AI Act and prepares the required documentation and instructions. | Reviews the documentation and determines the purpose of use, responsible persons, human oversight, and rules for handling data. |
| Before deployment | Fulfils the requirements relating to conformity assessment, CE marking, registration, and other obligations applicable to the provider. | Verifies that the system is ready to be used in the specific business process. |
| After launch / During use | Carries out post-market monitoring of the system under Article 72 and assesses its continued compliance with the AI Act. | Monitors the operation of the system in its environment in accordance with the instructions. |
| In the event of changes | Assesses the impact of changes to the system on its compliance with the AI Act. | Checks whether the intended purpose, data, use process, or risks have changed. |
| Where problems are identified | Takes the necessary corrective actions in accordance with Article 20. Notifies the market surveillance authority and carries out the necessary investigations and corrective actions under Article 73. | Where the use of the system may present a risk, a deployer informs the provider and, where required, the market surveillance authority. Suspends use where necessary. |
Conclusions
The AI Act does not place all responsibility for AI solely on the provider or the deployer. Responsibility is distributed throughout the chain: the provider must ensure that the AI solution itself complies with the requirements of the AI Act and provide the necessary documentation and prescribed control mechanisms. The deployer is responsible for ensuring that the system is used appropriately: for its intended purpose, with appropriate human oversight, suitable data, and risk monitoring.
At the same time, the boundary between these roles is not always static. In certain circumstances, a company that initially only uses a system may acquire provider status and, accordingly, become subject to a new set of obligations under the AI Act.