01
Who must participate in AI governance
The AI Act distinguishes roles with distinct obligations: the provider that develops or places an AI system on the market, the deployer that uses it under its own authority, and the authorized representative when the provider is not established in the Union. Alongside these, an internal accountability framework involves senior management and operational staff.
02
The Regulation's key definitions
- Provider: a person or body that develops or has developed an AI system and places it on the market under its own name or trademark
- Deployer: a person or body that uses an AI system under its own authority, excluding non-professional personal use
- Authorized representative: an entity established in the EU with a written mandate to fulfil obligations on behalf of the provider
- National competent authority: a notifying authority or market surveillance authority that receives relevant communications
03
How to distribute responsibilities within the company
Steps
- Identify whether the company acts as provider, deployer or both for each AI system
- Define an accountability framework that assigns tasks to senior management and involved staff
- Link responsibilities to data management, risk management and post-market monitoring systems
- Set up procedures for reporting serious incidents and communicating with national competent authorities
- Ensure an adequate level of AI literacy for those operating the systems on the company's behalf
04
Hypothetical example
A company that develops an AI system for personnel selection acts as a provider toward its clients. The client that uses it to hire acts as deployer. Both must ensure that involved staff have sufficient literacy about how the system works, while the providing company's management assigns responsibilities for data management and post-market monitoring.
05
Checking the roles involved
- Is it clear whether the company is provider, deployer, or both for each AI system in use?
- Is there an accountability framework assigning specific tasks to management and staff?
- Do staff operating the AI systems have an adequate level of literacy about them?
- Are procedures defined for communicating with national competent authorities in case of an incident?
06
How software can support role governance
A company can configure, together with its software partner, a register of AI systems indicating for each one the role assumed (provider or deployer), the responsible people, and evidence of staff literacy. This is a suggested operational choice, not a requirement described as a guaranteed feature.
It is also useful to keep a record of periodic reviews of the accountability framework and of the designated contacts for communication with competent authorities, so that who approved what and when can be verified.
07
Frequently asked questions about roles
A company can be both provider and deployer if it develops an AI system and uses it internally under its own authority.
The authorized representative comes into play only when the provider is not established in the European Union and has received a written mandate.
The accountability framework must be proportionate to the size of the provider's organization.
08
Next step
Map your company's AI systems, indicating for each one the role assumed, the designated responsible parties, and the status of staff literacy.
FAQ
Frequently asked questions
What distinguishes a provider from a deployer under the AI Act?
The provider develops or places an AI system on the market under its own name or trademark; the deployer uses it under its own authority in a professional context.
Who assigns internal responsibilities for AI management?
The accountability framework required by the Regulation defines the tasks of management and other staff, implemented proportionately to the size of the organization.
Does AI literacy only concern technical staff?
No, it also concerns any other person dealing with the operation and use of the systems on the company's behalf, taking into account their knowledge and training.
✓