01

The short answer

The AI Act distinguishes roles with different obligations: the provider that develops or places an AI system on the market, the deployer that uses it under its own authority, and the authorised representative that acts on the provider's behalf in the Union.

For high-risk systems, the regulation also requires an accountability framework defining the tasks of senior management and other staff across all aspects of system management.

02

Why these roles are defined by the regulation

The provider is whoever develops an AI system or a general-purpose AI model, or has one developed, and places it on the market under its own name or trademark. The deployer is whoever uses it under its own authority, except for personal non-professional use.

The authorised representative is a natural or legal person established in the Union who has accepted a written mandate to carry out the regulation's obligations on the provider's behalf.

03

How to structure internal governance

Steps

  1. Identify, for each AI system in use, whether the company acts as provider, deployer or both.
  2. Assign an accountability framework defining the tasks of senior management and staff for data management, risk and monitoring.
  3. Set up systems and procedures for data management, including collection, labelling and retention.
  4. Activate a risk management system and post-market monitoring.
  5. Define procedures for reporting serious incidents and communicating with competent authorities.

04

Hypothetical example

A European company that integrates a general-purpose AI system supplied by another company acts as a downstream provider if it places it on the market under its own name, and as a deployer if it uses it internally under its own authority.

In this hypothetical case, senior management should define who is responsible for data management, who for post-market monitoring, and who for communication with competent national authorities, in line with the accountability framework required by the regulation.

05

Checks before activating a new system

  • Is it clear whether the company is provider, deployer or both for this AI system?
  • Is there an accountability framework assigning tasks to senior management and staff?
  • Are data management and record-keeping procedures defined?
  • Is a risk management system and post-market monitoring in place?
  • Does the involved staff have a sufficient level of AI literacy?

06

What a company can set up with management software

A company can ask a software partner to support an inventory of AI systems with the assigned role (provider or deployer), named responsible persons, and review dates, keeping track of decisions made by senior management.

Suggested operational choices include: traceability of data and risk management procedures, visible assignment of tasks under the accountability framework, and a log of staff literacy sessions, so the compliance path can be demonstrated if requested.

07

Frequently asked questions

Who is the deployer under the AI Act? Whoever uses an AI system under its own authority, excluding personal non-professional use.

Can a company be both provider and deployer? Yes, if it develops or has a system developed and also uses it internally under its own authority.

Who oversees implementation of the regulation at EU level? The AI Office, a function of the Commission, contributes to implementation, monitoring and oversight of AI governance.

08

Next step

Map the AI systems in use, assign the correct role (provider or deployer) to each, and define an accountability framework with names and tasks before the next internal review.

FAQ

Frequently asked questions

What is the difference between provider and deployer under the AI Act?

The provider develops or has an AI system developed and places it on the market under its own name or trademark. The deployer uses it under its own authority, except for personal non-professional use.

What must the accountability framework required for high-risk systems contain?

It must define the responsibilities of senior management and other staff for data management, risk, monitoring, incident reporting and communication with authorities.

Who is the authorised representative and when is one needed?

A natural or legal person established in the Union with a written mandate from the provider to carry out the obligations and procedures required by the regulation on its behalf.

Sources and verification