Article 25 · Article 26 · Article 53

Provider or deployer?

The role you hold decides most of what you owe. Teams budget for conformity assessments they never owed, and inherit provider duties they never noticed.

Last updated 7 August 2026 · Regulation (EU) 2024/1689 as amended by the June 2026 Omnibus · Self-assessment, not legal advice

There is a question in the EU AI Act that decides most of your obligations, and it is not "is my system high-risk?"

It is "what am I?"

The Act assigns duties by role in the value chain. The gap between the roles is enormous, and answering wrong costs money in both directions — either you budget for work you never owed, or you miss work you did.

The four roles

RoleDefinitionWhat you owe
Provider You develop an AI system, or have one developed, and place it on the EU market or put it into service under your own name or trademark The full set where high-risk: Articles 9–15, 17, quality management, conformity assessment, CE marking, EU database registration, post-market monitoring, incident reporting
Deployer You use an AI system under your own authority, in the course of your professional activity Article 26 only. Plus Article 27 fundamental-rights assessment if you are a public body or provide public services
Importer You place on the EU market a system bearing the name of a provider established outside the EU Article 23 — verify the provider did their work before you bring it in
Distributor You make a system available on the EU market without being the provider or importer Article 24 — verification and due care

The whole thing turns on the phrase "under your own name or trademark". Not who wrote the code. Not who trained the model. Whose name is on the thing when it reaches the market.

The mistake founders make most often

"We built it, so we're a provider."

Sometimes true. Often not, and the distinction is worth real money.

If the AI system itself belongs to someone else — a hiring tool you licensed, a support model you call through an API, a scoring product you resell inside your platform — and you are using it in your operations, you are a deployer of that system. You did build something. You built a product around someone else's AI system, and the Act cares about which of those is the AI system in question.

What that removes is substantial. No conformity assessment. No CE marking. No Annex IV technical file. No EU database registration. Those are the expensive, slow, notified-body-dependent obligations, and deployers simply do not have them.

I have seen teams get a conformity assessment quote, budget for it across two quarters, and turn out to be deployers. The quote was real. The obligation was not.

The mistake that runs the other way

Two routes take you into provider duties without you deciding to become a provider.

1. Substantial modification — Article 25

You become the provider of a system that was previously someone else's if you:

That third limb is the one that catches people. Take a general-purpose classification tool, point it at CV screening, ship it to employers under your brand, and you have created a high-risk system with you as its provider. Nobody sent a notification. The original vendor's obligations did not transfer to you — a new set attached to you.

White-labelling is the same trap in a friendlier suit. Reselling under your own brand puts your name on it, and the Act reads names.

2. GPAI — Article 53

A separate question with a separate answer. What did you do to the model?

Applied from August 2025, enforceable from 2 August 2026. The exposed group is teams who did a serious fine-tune in 2025 for performance reasons, when there was no regulatory reason to think about it. More on where that threshold sits.

You are probably both

Most companies of any size hold both roles simultaneously, and the Act does not mind — it just means two obligation sets.

A realistic example. A twenty-person HR-tech company:

Three systems, three positions, one company. This is why "what tier is my company?" is not a question the Act can answer. Roles and tiers attach to systems, not to organisations. Every assessment is per system, and a company with three AI systems has three assessments.

Article 26 in full — what deployers actually owe

Worth reading, because it is shorter than people fear:

Real obligations. But no notified body, no CE mark, no technical file, and no eighteen-month runway required.

How to settle it in twenty minutes

  1. List your AI systems separately. Not products — systems. The chatbot, the ranking model, the internal notetaker are three entries.
  2. For each, ask: whose name is on it when it reaches the market? Yours means provider. Someone else's, and you're using it, means deployer.
  3. For each, ask: did we change what it is for? If you repurposed a system into a high-risk use, you are likely its provider now.
  4. Separately, ask: did we substantially modify a general-purpose model? Yes means check Article 53.
  5. Write down each answer with one sentence of reasoning, and date it.

That last step is the one people skip and the one that has value. A dated page saying "this system, this role, this reasoning" is precisely what an enterprise buyer's legal team is asking for when they send the questionnaire. It is also what makes the difference between "we assessed this" and "we assumed".

Not sure counts as an answer, for now. "Not sure" flagged and dated is a defensible interim position. What is not defensible is never having asked — and that is the state most companies are in.

Find out which one you are

Role in the value chain is the first question the free scan asks, because everything downstream depends on it.

Start the free scan

No card, no account. Full gap report from €59. See a real report first.

Self-assessment, not legal advice. This page and the Reglynn report are a structured self-assessment based on the EU AI Act (Regulation 2024/1689, as amended by the June 2026 Omnibus). They indicate where you likely stand and what to verify with a qualified advisor. Reglynn is not a notified body and issues no certification.

How this was made. Reglynn reports are generated by an AI system and reviewed before delivery. Reglynn is a Limited Risk AI system under Article 50; we disclose AI involvement wherever it occurs, including in our chat assistant. Our own self-assessment.