All posts16 June 2026

Provider or deployer: the EU AI Act question that decides your duties

Providers develop AI systems and put their own name on them. Deployers use them at work. Most UK SMEs are deployers, and the two roles owe different things.

W. Akram9 min readai · regulation

General information, not legal advice. Regulatory duties need your own competent advice.

The EU AI Act splits everyone who touches an AI system into two roles. You are a provider if you develop one and place it on the EU market under your own name. You are a deployer if you use one under your own authority at work. Providers carry the engineering and documentation load. Deployers mostly carry oversight and disclosure. Most UK SMEs are deployers.

Provider and deployer, in one sentence each

A deployer is any organisation that uses an AI system under its own authority in the course of its work. That is the whole test. Buying it, licensing it, configuring it, or putting a vendor's model behind your own login all leave you in the same place.

A provider develops an AI system, or has one developed, and then places it on the EU market or puts it into service under its own name or trademark (Article 3). Two phrases in that definition do more work than people expect. "Puts it into service" covers putting it into service for your own use, so an internal tool you built counts even though you never sold it. And "under its own name or trademark" means the label on the box decides, not who wrote the code.

Both roles usually sit in the same company.

Almost all the published guidance is written for providers, because that is where conformity assessments and CE marking live, and conformity assessments are billable. If you are a 40-person firm running three tools you bought from other people, most of it does not describe you, and reading it costs you a fortnight of anxiety you did not need to spend.

The four cases we get asked about

What you are doingYour roleWhy
Running a vendor's AI chatbot on your websiteDeployerThe vendor developed it and placed it on the market. You use it under your authority.
Reselling an AI tool under your own brandProviderThe definition turns on whose name is on it, and the name is yours.
Fine-tuning a model on your data and putting the result to workProvider, and deployer of the same systemYou had a system developed and put it into service for your own use.
Building AI features into a product you sellProviderThe product goes to market under your name with the feature inside it.

The chatbot case has a twist. The duty to tell people they are talking to a machine sits on the provider, not on you: Article 50(1) requires providers to design systems so users are informed they are interacting with an AI, unless it is obvious (EU AI Act transparency guide, 14 May 2026). Plenty of guidance gets this backwards and tells deployers to label their chatbots. The distinction matters less than it looks, because your customers meet your bot, not your vendor's contract.

Put your logo on someone else's tool and you have become its provider, with the whole provider obligation set attached if the system is high-risk. Founders who thought they were resellers discover they are manufacturers.

The last case is ours. When we build an AI feature inside a client's product, the client is the provider: the product carries their name and they place it on the market. We wrote it, which under Article 3 is a different thing. What that changes is who writes the paperwork. Provider technical documentation has to come from whoever knows how the system works, so it comes from us and ships with the code, as a deliverable rather than as something a lawyer asks for in 2027.

What each role owes, and when

WhenProvider owesDeployer owes
Since 2 February 2025AI literacy among staff operating AI on your behalf; no prohibited practicesThe same two duties, in the same words
From 2 August 2026Tell people a system is talking to them (Art 50(1)); mark generative output in a machine-readable format (Art 50(2))Disclose deepfakes and AI-generated text published to inform the public (Art 50(4)); tell people exposed to emotion recognition or biometric categorisation (Art 50(3))
From 2 December 2027, where the system is high-riskRisk management, data governance, technical documentation, logging, human oversight designed in, conformity assessment, CE marking, registrationUse it in line with the provider's instructions, assign competent human oversight, keep the logs, monitor for incidents, inform affected workers

The row most companies have already missed is the first one. Article 4 has bound every provider and deployer since February 2025, at every risk tier, including a ten-person firm whose only AI use is staff on a general chatbot. There is no measurement obligation and no required governance structure, no AI officer and no AI board, which is exactly why nobody did anything about it. No fine attaches to Article 4 directly, but from August 2025 civil liability is in play if badly trained staff cause harm (Latham and Watkins on the training obligation).

The cheap response is a record: an hour of training, a note of who attended, one page on what the tools are for and what must never be typed into them. Keeping the record is the part that turns an afternoon into evidence.

The dates as they now stand

DateWhat starts applyingMoved by the Digital Omnibus?
1 August 2024AI Act entered into forceNo
2 February 2025Prohibited practices (Art 5) and AI literacy (Art 4)No
2 August 2025Governance rules and general-purpose AI model obligationsNo
2 August 2026General application, including Article 50 transparencyNo
December 2026Prohibition on AI-generated non-consensual intimate imagery and child sexual abuse materialNo
2 December 2027High-risk systems in the Annex III areasYes, from 2 August 2026
2 August 2028High-risk AI inside regulated products (Annex I)Yes

Dates from the European Commission's AI Act page; the two moves confirmed by Gibson Dunn, 27 May 2026.

Since the Omnibus deal in May we have heard two opposite readings of it, and both are wrong. The first is that high-risk rules still start in August 2026. They do not. The second is that the AI Act has been delayed, so nothing happens this year. That one is worse, because Article 50 transparency and general application land on 2 August 2026 exactly as scheduled, and those are the obligations that touch ordinary business software. The only reprieve on transparency is for providers of generative AI systems already on the EU market before 2 August 2026, who have until 2 December 2026 to bring machine-readable marking into conformity (Jones Walker AI Law Blog, 2026).

What being a small company gets you

Article 99 sets three ceilings: up to €35m or 7% of worldwide annual turnover for prohibited practices, up to €15m or 3% for most operator obligations including transparency, and up to €7.5m or 1% for giving authorities incorrect or misleading information. For SMEs and start-ups, each fine is capped at whichever of the two numbers is lower, the reverse of the rule everyone else lives under. On £4m of turnover the 3% tier is roughly £120,000 rather than €15m. Still a bad day, still not the end of the company, and worth knowing before you decide how much legal advice to buy.

SMEs and start-ups also get priority access to regulatory sandboxes free of charge (small business guide to the AI Act), though the Omnibus pushed the member state deadline for running one back a year to 2 August 2027, so in most countries there is nothing to apply to yet. The Commission's AI Act Service Desk went live on 8 October 2025 with a free Compliance Checker that asks these questions in this order. The Omnibus extends the simplified compliance framework beyond SMEs to small mid-caps as well, reported as firms up to 750 employees and €150m turnover (Legal Nodes, 2026); check those thresholds against the published text before you lean on them.

The note we write before an AI feature ships

Half a page per feature, written when the feature is designed rather than when someone asks:

  • what the feature does, in one sentence a non-engineer can check
  • whose name it goes to market under
  • which role that puts us in
  • who is exposed to its output, including people who never agreed to anything
  • the date, and the person who wrote the note

The last line is the one that earns its place. A classification with no date and no author is not evidence of anything, and the question comes back every time the feature changes. The change that matters is rarely a change to the model. It is the day a feature that drafted something starts deciding it, which usually arrives as a small product improvement nobody thought to reclassify.

Half an hour, when the feature is still fresh in somebody's head. Considerably longer once the reasoning has to be reconstructed from a pull request eighteen months old, which is the version most companies end up writing.

Questions we get asked

Can we be a provider and a deployer at the same time?

Yes, and it is the normal case for anyone shipping software. You are a provider of the AI features you build into your own product and a deployer of every AI tool you bought for your team. The roles attach to systems, not to companies, so classify system by system.

Does the Act apply to us if we have no EU entity?

Yes, in two situations: when you place an AI system on the EU market, and when you or your customers are outside the EU but the output of the system is used inside it (Article 2). A UK company selling software to European users is inside the scope whatever its company registration says.

Our staff use a general chatbot. Does that make us a deployer?

Yes. Using an AI system under your own authority for work is the whole definition, and no threshold of seriousness applies. The practical consequence is small: the AI literacy duty under Article 4, plus a look at whether anything staff put into the tool should not be leaving the building.

Who has to label the chatbot, us or the vendor?

Article 50(1) puts the design duty on the provider, so on the vendor. Your exposure is commercial rather than regulatory: it is your brand on the conversation. Ask for their disclosure wording in writing before 2 August 2026 and add your own if the answer is vague.

What are the fines for a company our size?

Article 99 caps SME and start-up fines at whichever is lower of the fixed sum or the percentage of worldwide turnover, rather than whichever is higher. The transparency and operator-obligation tier is €15m or 3%, so a small company is exposed to the percentage rather than the headline number.

Let's talk

Ready to build the thing?

Book a free 30-minute call. We'll dig into your idea, your stack and your timeline, and give you an honest read on what it will take to build and launch. You'll leave with a clearer plan whether or not you hire us.

Free 30-min call. No pitch.