Skip to main content

EU AI Act Explained: Are You a Deployer or a Provider, or does it matter?

by Ville Valtonen

3 Min Read

Understanding your role is the first step to meeting compliance of Article 4 and building AI literacy and responsible AI use.

Illustration titled “EU AI Act”: a deployer working on a laptop next to a provider building an AI system

As the EU AI Act enters into force, many organizations are asking a simple but important question: Am I a provider or a deployer? The answer matters – not just for legal compliance, but for knowing what responsibilities you hold when using or building AI systems.

The EU AI Act introduces a risk-based regulatory framework for artificial intelligence. To manage these risks, it assigns different responsibilities to actors involved in developing and using AI.

Two of the most important roles are:

  • Providers: those who develop and place AI systems on the market
  • Deployers: those who use AI systems in their operations

Understanding which role your organization plays helps determine your obligations, especially around AI literacy, transparency, and oversight.

Who Is a Provider?

According to the EU AI Act, a provider is any natural or legal person who develops an AI system or has it developed with the intention of placing it on the EU market under their own name or trademark.

Typical examples:

  • A software company creating a recruitment screening tool powered by AI.
  • A startup developing a generative AI chatbot and offering it as a SaaS product.
  • An IT consultancy packaging a third-party AI model with their own interface and selling it to clients.

Key obligations of providers:

  • Ensure the AI system complies with requirements before release.
  • Provide documentation and instructions for use.
  • Take steps to ensure AI literacy for anyone who will use or interact with the system on their behalf (Article 4).

Who Is a Deployer?

A deployer is an organization or individual that uses an AI system in the course of their professional activities. This includes any company that integrates or applies AI systems into their own workflows, even if they didn’t build the system themselves.

Typical examples:

  • A small business using ChatGPT to generate content for social media marketing
  • An HR department applying AI for candidate filtering.
  • A retailer using AI-powered analytics to optimize pricing.

Key obligations of deployers:

  • Use AI systems in accordance with the provider’s instructions.
  • Ensure proper human oversight, especially for high-risk systems.
  • Provide training and AI literacy for staff interacting with AI tools (also Article 4).

Why It’s Not Always Either–Or

In practice, an organization can be both a provider and a deployer. For instance, a company may develop an internal AI tool (making it a provider) and also use it across departments (making it a deployer).

What matters is recognizing the different contexts in which your organization engages with AI and ensuring you meet the appropriate obligations in each case.

The AI Literacy Requirement: A Shared Responsibility

One of the most practical takeaways from both roles is the shared obligation under Article 4: ensuring a sufficient level of AI literacy for anyone operating or using AI systems on your behalf.

That means:

  • Training internal staff, external contractors, and relevant third parties.
  • Tailoring content to the person’s role and technical background.
  • Documenting that learning outcomes have been achieved—not just offering materials.

Smooth Adoption Starts with a Clear AI Policy

Employees and AI champions need clear instructions about the AI tools in use, responsibilities and limitations as well as the the key people to contact. We’ve put together a free AI policy template to get you started.

by Ville Valtonen