A side-by-side comparison of Provider and Deployer. Understand who develops or places an AI system on the market and who uses it under their authority.
Provider identifies a regulated AI supply-chain role under the EU AI Act and related governance obligations.
Context: Most relevant when mapping design-phase duties, product documentation, conformity work, and vendor responsibilities.
Deployer identifies a regulated AI supply-chain role under the EU AI Act and related governance obligations.
Context: Most relevant when mapping operational use, user-side controls, instructions for use, and workplace or public-sector deployment.
| Aspect | Provider | Deployer |
|---|---|---|
| Legal role | A provider develops, has developed, places on the market, or puts into service an AI system or GPAI model under its own name or trademark. | A deployer uses an AI system under its authority, excluding personal non-professional use. |
| Lifecycle position | Provider responsibilities arise around development, market placement, and putting the system into service. | Deployer responsibilities arise around organizational use, operation, and oversight of the AI system. |
| Main obligations | Provider obligations usually focus on design, documentation, conformity, instructions, and making the system available responsibly. | Deployer obligations usually focus on using the system as intended, applying instructions, monitoring use, and controlling organizational risks. |
| Documentation duties | Provider documentation should explain the system, model, intended purpose, limitations, and compliance evidence relevant to market placement or service entry. | Deployer documentation should show use context, governance decisions, user training, monitoring, and adherence to instructions for use. |
| Common mistake | Assuming the original developer is always the only provider can miss cases where another actor supplies the system under its own name. | Assuming the customer has no AI Act role can miss deployer responsibilities once the system is used under its authority. |
| Contracting focus | Provider clauses should address technical documentation, system limits, update responsibilities, and support for downstream compliance. | Deployer clauses should address permitted use, instructions, monitoring, incident handling, and evidence access. |
In practice, contracts should not simply say vendor and customer. They should map the legal role, the lifecycle phase, and the evidence each party must maintain.
Calling every vendor a provider without checking whether the actor places the system on the market under its name.
Treating deployers as passive users with no governance duties.
Failing to separate provider technical documentation from deployer operational records.
Ignoring that role allocation can change when a system is rebranded or materially modified.
Use Provider when describing the actor responsible for developing, supplying, placing on the market, or putting the AI system or GPAI model into service under its own name. The term is especially important for vendor due diligence, conformity planning, technical documentation, and product responsibility mapping.
Use Deployer when describing the organization or public body that uses an AI system under its own authority. The term is especially important for procurement, internal governance, user training, operational monitoring, and use-case risk assessment.
The provider-deployer distinction is central to EU AI Act responsibility allocation. It also supports ISO/IEC 42001 role mapping and NIST AI RMF governance by clarifying who owns design evidence and who owns operational use controls.
Yes. An organization can provide an AI system under its own name and also deploy it internally or for its own operations, depending on the facts.
Not always, but a customer that uses an AI system under its authority will often fit the deployer concept. Pure personal non-professional use is excluded under the EU AI Act definition.
Procurement must identify which party supplies compliance evidence and which party controls real-world use. Without this mapping, contracts and audit files often miss critical obligations.
No recently viewed comparisons yet.