We value your privacy

We use necessary cookies to run the site and, with your consent, analytics and marketing cookies to improve it. You can change your choice anytime. Privacy Policy

  • Security
  • Pricing
Book a scoping call
Back to glossary
Glossary6 min read

Operator (EU AI Act)

An operator is the EU AI Act's umbrella term for any party in the AI value chain: provider, product manufacturer, deployer, authorised representative, importer, or distributor.

Operator (EU AI Act)

Under the EU AI Act, an operator is the collective term for any party involved in placing an AI system on the market or putting it into use. Article 3(8) defines it precisely: an operator is a provider, product manufacturer, deployer, authorised representative, importer, or distributor. When a rule applies to any of these roles at once, the Regulation says "operator" rather than listing all six each time. It is not a seventh role you can be assigned — it is the umbrella that ties the other six together across the AI value chain.

Why the AI Act needs an umbrella term

The EU AI Act assigns obligations along the AI value chain — from the organization that builds a system to the one that ultimately uses it. Many duties, however, apply to more than one of those parties. Rather than repeat "provider, product manufacturer, deployer, authorised representative, importer or distributor" every time such a duty arises, the Regulation introduces one word that stands in for all of them: operator.

So when you read that "operators shall ensure a sufficient level of AI literacy among their staff," the obligation reaches everyone in the chain. The term is a drafting convenience with real consequences: it is a signal that a requirement is not confined to a single role.

The six roles an operator can be

Each of the six roles has its own definition and its own set of obligations. The umbrella term does not blur them — it collects them.

Provider

The provider is the party that develops an AI system (or has one developed) and places it on the EU market or puts it into service under its own name or trademark. Providers carry the heaviest obligations under the Act, especially for high-risk systems.

Product manufacturer

The product manufacturer places a product on the market together with an AI system that is a safety component of it, under the manufacturer's own name or trademark. In that case the manufacturer takes on the provider's high-risk obligations for the embedded AI system.

Deployer

The deployer is the party that uses an AI system under its own authority in a professional capacity — for example, a company running a recruitment-screening tool. Deployers must use systems as instructed and, for high-risk systems, ensure human oversight and monitor operation.

Authorised representative

The authorised representative is a natural or legal person in the EU, mandated in writing by a provider established outside the Union, to carry out the provider's obligations and act as the contact point for authorities.

Importer

The importer is a party established in the EU that places on the market an AI system bearing the name or trademark of a person established outside the Union. Importers must verify that the provider has met its obligations before the system enters the market.

Distributor

The distributor is any party in the supply chain, other than the provider or importer, that makes an AI system available on the EU market. Distributors must check that the required conformity markings and documentation are in place.

How the roles relate as a value chain

Read together, the six roles trace the path an AI system travels. The provider — or a product manufacturer embedding AI in a product — builds the system and puts it on the market. If that provider sits outside the EU, an authorised representative stands in for it inside the Union, and an importer brings the system across the border. A distributor then moves it further along the supply chain until a deployer puts it to use in a real setting. One system, many hands — and the Act attaches duties at each step.

The Article 25 rule: roles can shift

The most important thing to understand about these roles is that they are not fixed labels. Article 25 sets out when a deployer, distributor, or importer takes on the obligations of a provider. This happens when a party:

  • puts its own name or trademark on a high-risk AI system already on the market;
  • makes a substantial modification to a high-risk system in a way that keeps it high-risk; or
  • changes the intended purpose of a system (including a general-purpose one) so that it becomes high-risk.

In each case, the original provider is, in effect, replaced for compliance purposes. A distributor that rebrands a high-risk system as its own is no longer merely a distributor — it inherits the full provider obligations. This is why the umbrella term matters in practice: your role, and therefore your duties, can change with what you actually do to a system.

Why the distinction matters

The EU AI Act attaches obligations to your role, not to your industry or size. Working out which of the six roles you occupy for a given AI system is the first step in any compliance assessment — because the answer determines what you must do.

Two points make this harder than it looks:

  • One organization can hold more than one role. A company might be a deployer of a third-party tool, a distributor of another, and — the moment it rebrands or substantially modifies a high-risk system — a provider. Each relationship is assessed separately.
  • Roles are activity-based, not self-declared. You do not get to choose your role; it follows from what you do with the system. Calling yourself "just a deployer" does not shield you from provider obligations if your actions meet the Article 25 tests.

Getting the classification right is foundational. Every downstream requirement — documentation, risk management, human oversight, transparency, record-keeping — flows from it.

Where Qadar AI fits

Whatever role your organization holds, the EU AI Act expects you to know how AI systems are used across your business and to be able to show it. Qadar AI gives you visibility into how AI tools are used across browser, desktop, mobile, and agent runtimes, enforces data-handling policy at the AI interaction layer, and records a tamper-evident audit trail — the kind of operational evidence that oversight, record-keeping, and transparency duties increasingly depend on.

For the full framework and how the pieces fit together, see our EU AI Act glossary entry and the more detailed EU AI Act guide.

This article is an educational explainer, not legal advice. Whether a given obligation applies to your organization depends on your specific circumstances; consult qualified counsel for a compliance assessment.

On this page

  • Why the AI Act needs an umbrella term
  • The six roles an operator can be
  • Provider
  • Product manufacturer
  • Deployer
  • Authorised representative
  • Importer
  • Distributor
  • How the roles relate as a value chain
  • The Article 25 rule: roles can shift
  • Why the distinction matters
  • Where Qadar AI fits

Share

Product and governance updates — see our privacy policy.

Frequently asked questions

Frequently asked questions

No. An operator is not a seventh role. Article 3(8) defines it as the collective term for the six actual roles — provider, product manufacturer, deployer, authorised representative, importer, and distributor. The Regulation uses "operator" as shorthand whenever an obligation applies to any of those parties, so that it does not have to list all six each time.

Yes. A single organization frequently holds several roles at once — for example, deploying one third-party AI system, distributing another, and acting as a provider for a system it has rebranded or substantially modified. Each relationship is assessed on its own, and the obligations for each role apply independently.

Under Article 25, a deployer, distributor, or importer takes on the provider's obligations if it puts its own name or trademark on a high-risk AI system already on the market, makes a substantial modification that keeps the system high-risk, or changes the intended purpose of a system so that it becomes high-risk. In each case, that party inherits the full set of provider duties.

Because the EU AI Act attaches obligations to your role, not to your sector or size. Identifying which of the six roles you occupy for each AI system determines exactly what you must do — the documentation, risk management, oversight, and transparency requirements all follow from that classification. Roles are activity-based, so they are judged by what you actually do with a system.

Qadar AI gives you visibility into how AI tools are used across browser, desktop, mobile, and agent runtimes, enforces data-handling policy at the AI interaction layer, and keeps a tamper-evident audit trail of every AI interaction. Whichever operator role you hold, that operational evidence supports the record-keeping, oversight, and transparency expectations the Regulation places on parties in the AI value chain.

Natali Craig
Olivia Rhye
Drew Cano

Still have questions?

Can’t find the answer you’re looking for? Talk to our team and we’ll help you get started.

Get in touch

Related terms

Provider (EU AI Act)Glossary

Provider (EU AI Act)

A Provider under the EU AI Act develops an AI system or GPAI model and places it on the market under its own name. Learn the definition, test, and duties.

Read more
Deployer (EU AI Act)Glossary

Deployer (EU AI Act)

A deployer under the EU AI Act is any organization using an AI system under its own authority. Learn the deployer's duties, how it differs from a provider, and more.

Read more
EU AI Act (Artificial Intelligence Act)Glossary

EU AI Act (Artificial Intelligence Act)

The EU AI Act is the EU's risk-based law for artificial intelligence. A plain-language summary of what it regulates, when it applies, and who must comply.

Read more

See how Qadar AI implements these concepts at runtime

A product specialist will reply within one business day

Book a demo

Subscribe to our newsletter

Product and governance updates — see our privacy policy.

AI security and control for every model your team uses.

Built in Dubai. Designed for teams operating across regions, models, and regulatory environments.

  • Product

    • Shield Web
    • Shield Control
    • Shield Desktop
    • Shield Mobile
    • Pricing
    • Download
  • Solutions

    • For CISOs
    • For Operations
    • For AI Teams
  • Use Cases

    • AI Governance
    • AI Agent Security
    • LLM Access Control
    • Secure AI Deployment
    • Enterprise Operations
    • Financial Services
    • HR & Recruiting
  • Resources

    • Help Center
    • Blog
    • Guides
    • Glossary
    • Changelog
    • Compare
    • FAQ
  • Company

    • About
    • Careers
    • Security & Trust
    • Contact
  • Tools

    • Disclose
    • AI Risk Calculator
    • EU AI Act Checker

© 2026 Qadar AI. All rights reserved.

  • ·Legal
  • ·Privacy
  • ·Terms
  • ·Partner Terms
  • ·GDPR / DPA
  • ·