Under the EU AI Act, an operator is the collective term for any party involved in placing an AI system on the market or putting it into use. Article 3(8) defines it precisely: an operator is a provider, product manufacturer, deployer, authorised representative, importer, or distributor. When a rule applies to any of these roles at once, the Regulation says "operator" rather than listing all six each time. It is not a seventh role you can be assigned — it is the umbrella that ties the other six together across the AI value chain.
Why the AI Act needs an umbrella term
The EU AI Act assigns obligations along the AI value chain — from the organization that builds a system to the one that ultimately uses it. Many duties, however, apply to more than one of those parties. Rather than repeat "provider, product manufacturer, deployer, authorised representative, importer or distributor" every time such a duty arises, the Regulation introduces one word that stands in for all of them: operator.
So when you read that "operators shall ensure a sufficient level of AI literacy among their staff," the obligation reaches everyone in the chain. The term is a drafting convenience with real consequences: it is a signal that a requirement is not confined to a single role.
The six roles an operator can be
Each of the six roles has its own definition and its own set of obligations. The umbrella term does not blur them — it collects them.
Provider
The provider is the party that develops an AI system (or has one developed) and places it on the EU market or puts it into service under its own name or trademark. Providers carry the heaviest obligations under the Act, especially for high-risk systems.
Product manufacturer
The product manufacturer places a product on the market together with an AI system that is a safety component of it, under the manufacturer's own name or trademark. In that case the manufacturer takes on the provider's high-risk obligations for the embedded AI system.
Deployer
The deployer is the party that uses an AI system under its own authority in a professional capacity — for example, a company running a recruitment-screening tool. Deployers must use systems as instructed and, for high-risk systems, ensure human oversight and monitor operation.
Authorised representative
The authorised representative is a natural or legal person in the EU, mandated in writing by a provider established outside the Union, to carry out the provider's obligations and act as the contact point for authorities.
Importer
The importer is a party established in the EU that places on the market an AI system bearing the name or trademark of a person established outside the Union. Importers must verify that the provider has met its obligations before the system enters the market.
Distributor
The distributor is any party in the supply chain, other than the provider or importer, that makes an AI system available on the EU market. Distributors must check that the required conformity markings and documentation are in place.
How the roles relate as a value chain
Read together, the six roles trace the path an AI system travels. The provider — or a product manufacturer embedding AI in a product — builds the system and puts it on the market. If that provider sits outside the EU, an authorised representative stands in for it inside the Union, and an importer brings the system across the border. A distributor then moves it further along the supply chain until a deployer puts it to use in a real setting. One system, many hands — and the Act attaches duties at each step.
The Article 25 rule: roles can shift
The most important thing to understand about these roles is that they are not fixed labels. Article 25 sets out when a deployer, distributor, or importer takes on the obligations of a provider. This happens when a party:
- puts its own name or trademark on a high-risk AI system already on the market;
- makes a substantial modification to a high-risk system in a way that keeps it high-risk; or
- changes the intended purpose of a system (including a general-purpose one) so that it becomes high-risk.
In each case, the original provider is, in effect, replaced for compliance purposes. A distributor that rebrands a high-risk system as its own is no longer merely a distributor — it inherits the full provider obligations. This is why the umbrella term matters in practice: your role, and therefore your duties, can change with what you actually do to a system.
Why the distinction matters
The EU AI Act attaches obligations to your role, not to your industry or size. Working out which of the six roles you occupy for a given AI system is the first step in any compliance assessment — because the answer determines what you must do.
Two points make this harder than it looks:
- One organization can hold more than one role. A company might be a deployer of a third-party tool, a distributor of another, and — the moment it rebrands or substantially modifies a high-risk system — a provider. Each relationship is assessed separately.
- Roles are activity-based, not self-declared. You do not get to choose your role; it follows from what you do with the system. Calling yourself "just a deployer" does not shield you from provider obligations if your actions meet the Article 25 tests.
Getting the classification right is foundational. Every downstream requirement — documentation, risk management, human oversight, transparency, record-keeping — flows from it.
Where Qadar AI fits
Whatever role your organization holds, the EU AI Act expects you to know how AI systems are used across your business and to be able to show it. Qadar AI gives you visibility into how AI tools are used across browser, desktop, mobile, and agent runtimes, enforces data-handling policy at the AI interaction layer, and records a tamper-evident audit trail — the kind of operational evidence that oversight, record-keeping, and transparency duties increasingly depend on.
For the full framework and how the pieces fit together, see our EU AI Act glossary entry and the more detailed EU AI Act guide.
This article is an educational explainer, not legal advice. Whether a given obligation applies to your organization depends on your specific circumstances; consult qualified counsel for a compliance assessment.
