Compliance · 6 min read

Deployer or provider? The EU AI Act role that decides your obligations

Published 18 May 2026 · last updated 12 June 2026

Under the EU AI Act you are a provider if you developed an AI system, substantially modified it, or place it on the market under your own name — and a deployer if you simply use AI that someone else built and supports. Most Irish SMEs are deployers, and the distinction decides almost everything: providers carry the heavy product-compliance regime, while deployers carry a shorter, operational set of duties.

The two roles, defined

Article 3 of the AI Act defines a provider as the person or organisation that develops an AI system (or has it developed) and places it on the market or puts it into service under its own name or trademark. A deployer is anyone using an AI system under its own authority in the course of business. Buy Microsoft Copilot licences and roll them out to staff: deployer. Build a chatbot on an API and sell it to customers under your brand: provider. The Act also has roles for importers and distributors, but for an Irish SME buying software, the provider/deployer line is the one that matters.

Why the difference matters so much

For high-risk systems, providers carry the full product-compliance regime of Articles 9 to 17: risk management, data governance, technical documentation, conformity assessment and CE marking. Deployers carry Article 26: use the system per the provider’s instructions, assign trained human oversight, check input data, retain logs, inform affected workers, and monitor for incidents. Demanding, but a fraction of the provider burden — which is why knowing your role is the second question in any AI Act compliance exercise, right after the inventory.

How a deployer accidentally becomes a provider

The line can move under you. Under Article 25, a deployer of a high-risk system can take on provider obligations if it:

  • Puts its own name or trademark on a high-risk system someone else built — white-labelling a vendor’s tool as your own product.
  • Makes a substantial modification to a high-risk system — changing how it fundamentally works, not adjusting its settings.
  • Changes a system’s intended purpose so that it becomes high-risk — repurposing a general document tool to score job applicants, for example.

What does not cross the line: configuring an off-the-shelf tool, writing prompts and templates, connecting your own data, or branding the surrounding service you sell. Routine adoption stays on the deployer side.

The GPAI confusion

A separate provider regime has applied to general-purpose AI models since 2 August 2025 — technical documentation, copyright policies, training-data summaries under Articles 53 to 55. This causes regular confusion, so to be plain: subscribing to ChatGPT Team, Copilot, Claude or Gemini does not make you a GPAI provider. That regime applies to the companies that train and supply the models. You would only enter it by training and releasing a general-purpose model yourself.

Practical steps for the typical Irish SME

  1. Record your role for each system in your AI register — per system, not per company, because a firm can be deployer of ten tools and provider of one.
  2. Get the provider’s instructions for use and confirm your actual use matches them — Article 26(1), and the first question in vendor due diligence.
  3. Watch the Article 25 triggers: white-labelling, substantial modification, repurposing. Flag any roadmap item that goes near them.
  4. Check the high-risk categories — especially recruitment and worker management, where deployer duties bite hardest.

Get the role right, and the rest follows

AI Register Ireland asks the role question first for every system you record, then attaches the obligations that follow from the answer. For the wider Irish picture, see the EU AI Act in Ireland.

Put your AI register in place

Inventory, classification, obligations and an evidence trail. Join the waitlist for early access.

Join the waitlist