← Responsible AI Governance

Provider or Deployer? Classifying Your AI Systems Under the AI Act

Under the AI Act, whether an organisation is a provider or a deployer is determined per AI application, based on whether it built or markets the system or simply uses it within its own operations. Most organisations are deployers for most of their tools, but that's not automatically true for every system, particularly any internally built or heavily customised applications, so the classification has to be checked system by system, not assumed for the organisation as a whole.

Why one company can be both provider and deployer at once

A company using a commercial AI tool for internal operations is a deployer of that tool. If the same company also builds and sells an AI-powered feature to its own customers, it's a provider for that specific system, the two classifications sit side by side for different systems in the same organisation.

Where internal customisation blurs the line

Heavily fine-tuning or substantially modifying a third-party AI model can shift an organisation's role from deployer toward provider for that specific application, since the modification means the organisation is effectively putting a new version of the system into use. This is one of the most commonly missed classification issues.

Why getting this wrong matters

Provider and deployer obligations differ substantially under the Act, misclassifying a system means preparing for the wrong set of requirements, which surfaces either as unnecessary compliance work or, worse, a genuine gap discovered too late.

Your Employees Are Already Using AI Tools Nobody Approved. That's Where Most Real Usage Actually Lives.

The Responsible AI Scan builds a complete use-case inventory, classifies every system under the EU AI Act, and sets up governance that keeps working after the audit, not just on delivery day.