One question decides most of your AI regulatory exposure: are you the provider of the system, or its deployer? The EU AI Act assigns different duties to each — and misreading your role inverts your compliance plan.

The definitions that bind

A provider develops an AI system (or has it developed) and places it on the market or puts it into service under its own name. A deployer uses an AI system under its own authority in the course of business. If you buy a chatbot and run it on your support desk, you are a deployer. If you white-label that chatbot under your own brand, you may have just become a provider — the Act's rebranding rule catches companies that put their name on someone else's system.

Why the distinction carries different duties

Providers carry the build-side obligations: technical documentation, conformity assessment, registration, post-market monitoring. Deployers carry the use-side obligations: use per instructions, human oversight, input data quality, transparency notices (Article 50), and — for high-risk uses from December 2027 — their own operational duties.

The trap cases

Three situations flip companies across the line without anyone deciding it: rebranding a vendor system as your own, substantially modifying a system (fine-tuning can qualify), and building on a GPAI model in ways that make you a provider of a derived system. Each is a fact pattern, not a vibe — and each changes which articles bind you.

What an operator does now

For every system in the inventory, write one line: provider, deployer, or unclear. The unclear ones are where counsel earns its fee — and they are almost always the rebranding and fine-tuning cases.

Independent regulatory intelligence — not legal advice. Matters with material exposure warrant counsel. Dates tracked on The Clock Board.