There is a question in the EU AI Act that decides most of your obligations, and it is not "is my system high-risk?"
It is "what am I?"
The Act assigns duties by role in the value chain. The gap between the roles is enormous, and answering wrong costs money in both directions — either you budget for work you never owed, or you miss work you did.
The four roles
| Role | Definition | What you owe |
|---|---|---|
| Provider | You develop an AI system, or have one developed, and place it on the EU market or put it into service under your own name or trademark | The full set where high-risk: Articles 9–15, 17, quality management, conformity assessment, CE marking, EU database registration, post-market monitoring, incident reporting |
| Deployer | You use an AI system under your own authority, in the course of your professional activity | Article 26 only. Plus Article 27 fundamental-rights assessment if you are a public body or provide public services |
| Importer | You place on the EU market a system bearing the name of a provider established outside the EU | Article 23 — verify the provider did their work before you bring it in |
| Distributor | You make a system available on the EU market without being the provider or importer | Article 24 — verification and due care |
The whole thing turns on the phrase "under your own name or trademark". Not who wrote the code. Not who trained the model. Whose name is on the thing when it reaches the market.
The mistake founders make most often
"We built it, so we're a provider."
Sometimes true. Often not, and the distinction is worth real money.
If the AI system itself belongs to someone else — a hiring tool you licensed, a support model you call through an API, a scoring product you resell inside your platform — and you are using it in your operations, you are a deployer of that system. You did build something. You built a product around someone else's AI system, and the Act cares about which of those is the AI system in question.
What that removes is substantial. No conformity assessment. No CE marking. No Annex IV technical file. No EU database registration. Those are the expensive, slow, notified-body-dependent obligations, and deployers simply do not have them.
I have seen teams get a conformity assessment quote, budget for it across two quarters, and turn out to be deployers. The quote was real. The obligation was not.
The mistake that runs the other way
Two routes take you into provider duties without you deciding to become a provider.
1. Substantial modification — Article 25
You become the provider of a system that was previously someone else's if you:
- put your own name or trademark on a high-risk system already on the market;
- make a substantial modification to a high-risk system such that it remains high-risk; or
- modify the intended purpose of a system — including one not previously classified as high-risk — so that it becomes high-risk.
That third limb is the one that catches people. Take a general-purpose classification tool, point it at CV screening, ship it to employers under your brand, and you have created a high-risk system with you as its provider. Nobody sent a notification. The original vendor's obligations did not transfer to you — a new set attached to you.
White-labelling is the same trap in a friendlier suit. Reselling under your own brand puts your name on it, and the Act reads names.
2. GPAI — Article 53
A separate question with a separate answer. What did you do to the model?
- API calls or prompting — downstream. Article 53 duties sit with the model provider. Not yours.
- Light fine-tune, same domain, modest dataset — still downstream in the ordinary case.
- Substantial retrain, major parameter change, or a new task domain — you may be a GPAI provider: Annex XI technical documentation, Annex XII downstream information, a copyright and TDM policy, and a public summary of training data.
Applied from August 2025, enforceable from 2 August 2026. The exposed group is teams who did a serious fine-tune in 2025 for performance reasons, when there was no regulatory reason to think about it. More on where that threshold sits.
You are probably both
Most companies of any size hold both roles simultaneously, and the Act does not mind — it just means two obligation sets.
A realistic example. A twenty-person HR-tech company:
- Provider of its own CV-ranking system, sold to employers under its own brand. High-risk under Annex III point 4. Full provider duties by 2 December 2027.
- Deployer of an off-the-shelf AI notetaker used in its own internal hiring. Article 26 duties, and if that notetaker is high-risk, they apply to this company as a user of it.
- Deployer of a support chatbot on its marketing site. Limited risk, Article 50 disclosure, live now.
Three systems, three positions, one company. This is why "what tier is my company?" is not a question the Act can answer. Roles and tiers attach to systems, not to organisations. Every assessment is per system, and a company with three AI systems has three assessments.
Article 26 in full — what deployers actually owe
Worth reading, because it is shorter than people fear:
- Use the system according to the provider's instructions for use
- Assign human oversight to a natural person with the competence, training and authority to exercise it — and the ability to override
- Ensure input data is relevant and sufficiently representative for the intended purpose, to the extent you control it
- Monitor operation and suspend use if the system presents a risk
- Report serious incidents to the provider and the authority
- Keep automatically generated logs for at least six months where they are within your control
- Inform workers and their representatives before putting a high-risk system into use in the workplace
- Inform affected individuals where the system makes or assists decisions about them
- Cooperate with authorities
Real obligations. But no notified body, no CE mark, no technical file, and no eighteen-month runway required.
How to settle it in twenty minutes
- List your AI systems separately. Not products — systems. The chatbot, the ranking model, the internal notetaker are three entries.
- For each, ask: whose name is on it when it reaches the market? Yours means provider. Someone else's, and you're using it, means deployer.
- For each, ask: did we change what it is for? If you repurposed a system into a high-risk use, you are likely its provider now.
- Separately, ask: did we substantially modify a general-purpose model? Yes means check Article 53.
- Write down each answer with one sentence of reasoning, and date it.
That last step is the one people skip and the one that has value. A dated page saying "this system, this role, this reasoning" is precisely what an enterprise buyer's legal team is asking for when they send the questionnaire. It is also what makes the difference between "we assessed this" and "we assumed".
Not sure counts as an answer, for now. "Not sure" flagged and dated is a defensible interim position. What is not defensible is never having asked — and that is the state most companies are in.
Find out which one you are
Role in the value chain is the first question the free scan asks, because everything downstream depends on it.
Start the free scanNo card, no account. Full gap report from €59. See a real report first.
Self-assessment, not legal advice. This page and the Reglynn report are a structured self-assessment based on the EU AI Act (Regulation 2024/1689, as amended by the June 2026 Omnibus). They indicate where you likely stand and what to verify with a qualified advisor. Reglynn is not a notified body and issues no certification.
How this was made. Reglynn reports are generated by an AI system and reviewed before delivery. Reglynn is a Limited Risk AI system under Article 50; we disclose AI involvement wherever it occurs, including in our chat assistant. Our own self-assessment.