AI Act for business

Provider or deployer? Your company’s AI Act role

How to determine whether a business is an AI Act provider or deployer when using ChatGPT, delivering AI-assisted services or building an AI SaaS product.

AI ACT · ROLES AND RESPONSIBILITIES

The same company can be a deployer in one process and a provider in another. Its role is not determined by company size or by using a well-known model, but by what it builds, places on the market and controls in each use.

Why the role must be determined for each use

The AI Act distributes obligations among several actors: provider, deployer, importer, distributor, authorised representative and provider of a general-purpose AI model. A modern technical chain may simultaneously include the company training the model, the infrastructure provider, the business building the application, the agency configuring the workflow and the client using it. [EU-REG] [EU-GPAI-G]

The role is assessed for the specific system and intended purpose. Being the provider of an application does not automatically make a company the provider of the integrated GPAI model. Conversely, buying a licence does not turn every user into a responsibility-free consumer. An organisation professionally using the system under its authority will generally be the deployer for that use. [EU-A50] [EU-GPAI-G]

What a deployer is

The Regulation defines a deployer as a person or organisation using an AI system under its authority, except for personal, non-professional activity. In practice, this may be a business allowing its marketing team to use a generative tool, a retailer using demand forecasting or a department automatically classifying incoming messages. [EU-REG] [EU-A50]

Employees operating the tool under company instructions do not each become separate deployers. The legal entity remains the relevant actor. The same principle may continue when the organisation uses contractors or freelancers on its behalf and under its control: outsourcing execution does not automatically outsource the role and responsibility. [EU-A50]

What a provider is

A provider is the actor that develops an AI system or general-purpose AI model, or has it developed, and places it on the market or puts it into service under its own name or trademark. The definition also covers situations where technical development is contracted to someone else. Decisive elements include control over the product, the name under which it is offered and the act of placing it on the market or putting it into service. [EU-REG]

This leads to an important SaaS conclusion: integrating an external API does not remove the possibility that the company is the provider of the AI system offered to the customer. It may remain merely a user of the upstream model while being responsible as provider for its own product’s interface, purpose, instructions, integration and behaviour. [EU-REG] [EU-GPAI-G]

Five common SME scenarios

The first scenario is internal use of ChatGPT or a similar tool for research, summaries and draft variants. The company is generally a deployer: it determines who uses the tool, which data may be entered and how the output is checked. The model and service provider remains a separate actor in the chain. [EU-A50]

The second is an agency delivering AI-assisted content or analysis to a client. The agency may be the deployer of a tool in its own workflow, while the client may become a deployer of a system it operates directly. Contract terms, editorial approval and effective control must be examined; the label “outsourced service” does not adequately describe the chain. [EU-A50] [EU-REG]

The third is a SaaS application using an external model to generate recommendations or execute steps. The SaaS company may be the provider of the resulting system even though it did not train the foundation model. The customer configuring and using the product may be a deployer. Upstream provider documentation becomes a necessary input for evaluating the company’s own system. [EU-GPAI-G] [EU-REG]

The fourth is a white-label or rebranded solution. For certain high-risk systems, a distributor, importer, deployer or other third party may be considered the provider if it places its name or trademark on the system, substantially modifies it or changes its intended purpose so that it becomes high-risk. This mechanism should not be extended mechanically to every colour or configuration change. [EU-REG] [EU-RISK]

The fifth is modification or fine-tuning of a GPAI model. Commission guidance explains that minor modifications will not normally turn the actor into the provider of the GPAI model, with model-provider obligations arising only in exceptional cases of significant modification assessed under the guidance criteria. This is separate from responsibility for an application built on top of that model. [EU-GPAI-G]

The GPAI model and the system built on it are not the same

A general-purpose model is a component capable of supporting many tasks and being integrated into many systems. An AI system is the product or process using that capability for a concrete purpose. In a WordPress agent, for example, the model may generate or interpret language, while the application determines which data it receives, which tools it can call, which actions it executes and what the user sees. [EU-GPAI-G] [EU-REG]

That is why the statement “we use someone else’s model” does not close the assessment. A downstream system provider must understand the model’s capabilities and limitations, define the product purpose, test the integration and provide relevant information to the user. At the same time, it should not claim to own or have trained the upstream model. [EU-GPAI-G]

How to assess AYSA.RO and AYSA.AI without rushed verdicts

In an agency such as AYSA.RO, using AI tools for research, analysis and assisted production primarily indicates a deployer role for the internal workflow. If the agency installs and configures a system operated by the client, responsibilities should be separated through architecture, instructions and contract rather than inferred from the commercial name of the service. [EU-A50] [EU-REG]

For AYSA.AI, the relevant question is not only which model is underneath, but which system is offered under the company’s own brand: purpose, interface, users, automations, actions, limits and control. A documented assessment may identify different roles for different components. This article does not declare the product compliant or non-compliant and does not replace a technical and legal assessment of the version actually released. [EU-GPAI-G] [EU-REG]

A seven-question working test

The role should be recorded in the AI-system register together with the reasoning and documents used. A one-time “provider/deployer” checkbox is not enough: a change in branding, purpose, model, autonomy or audience can change the assessment. [EU-DESK] [EU-REG]

  • Who defined the system’s concrete purpose and users?
  • Under whose name or trademark is the product offered?
  • Who controls the interface, instructions and available actions?
  • Are we using a finished system or building a system on top of a model?
  • Have we materially changed the purpose, functionality or model?
  • Who operates the system and who approves its outputs?
  • What documentation do we receive upstream and what information do we provide downstream?

Official sources and verification date

  1. Regulation (EU) 2024/1689 — Artificial Intelligence Act
  2. European Commission — transparency obligations under Article 50
  3. European Commission — guidelines on transparency obligations
  4. European Commission — guidelines for general-purpose AI model providers
  5. European Commission — high-risk AI system classification
  6. European Commission — AI Act Service Desk and Compliance Checker