We value your privacy

We use necessary cookies to run the site and, with your consent, analytics and marketing cookies to improve it. You can change your choice anytime. Privacy Policy

  • Security
  • Pricing
Book a scoping call
Back to glossary
Glossary6 min read

Provider (EU AI Act)

A Provider under the EU AI Act develops an AI system or GPAI model and places it on the market under its own name. Learn the definition, test, and duties.

Provider (EU AI Act)
Under the EU AI Act, a Provider is the party that builds an AI system or general-purpose AI (GPAI) model and puts it on the market under its own name. More precisely, Article 3(3) defines a provider as a natural or legal person, public authority, agency or other body that develops an AI system or a GPAI model — or has one developed — and places it on the market or puts it into service under its own name or trademark, whether for payment or free of charge. The provider carries the heaviest set of obligations in the Act, because it is the party that shapes what the system does before anyone else uses it.

The definition in plain language

The EU AI Act organizes responsibility around the roles that different parties play in an AI system's life, and the provider sits at the origin of that chain. Read plainly, Article 3(3) has two parts that must both be true.

First, the party develops the AI system or GPAI model, or has it developed on its behalf. Commissioning a system built to your specification counts — you do not have to write the code yourself to be its provider.

Second, the party places it on the market or puts it into service under its own name or trademark. Placing on the market means making the system available in the EU for the first time; putting into service means supplying it for first use, including for the provider's own internal use. The commercial model is irrelevant: the definition applies whether the system is sold, licensed, or given away for free.

Both limbs matter. A party that develops a system but never releases it under its own name is not, on that basis, a provider. A party that attaches its name to a system it releases is, even if a third party did the engineering.

Provider vs deployer: the test

The cleanest way to understand a provider is to contrast it with a deployer — the party that uses an AI system under its own authority in the course of its activity. A company that buys a hiring-screening tool and runs candidates through it is a deployer. The company that built that tool and sells it under its brand is the provider.

The distinguishing test is the "under its own name or trademark, and places on the market or puts into service" condition. Ask two questions:

  • Does the party release the system under its own name or trademark? Branding and holding out the system as your own is the hallmark of a provider.
  • Does the party make it available to others (or put it into service), rather than merely use what someone else supplied? Supplying the system is a provider act; using it is a deployer act.

If the answer to both is yes, the party is a provider. If the party is simply operating a system that another organization supplied, it is a deployer. Both are operators under the Act — an umbrella term the Act also uses for importers, distributors, and authorised representatives — but the obligations attached to each role differ sharply. Our operator entry maps how the roles fit together.

The duties that attach to providers

The reason the provider distinction matters is that the Act loads the substantive compliance duties onto the provider — most heavily for high-risk AI systems. A provider of a high-risk system must, before placing it on the market, put in place and be able to evidence:

  • a risk management system running across the AI system's lifecycle;
  • data governance practices covering the training, validation, and testing data;
  • technical documentation demonstrating conformity;
  • automatic record-keeping (logging) of events over the system's lifetime;
  • transparency and clear information to deployers;
  • effective human oversight designed into the system;
  • appropriate accuracy, robustness, and cybersecurity;
  • a conformity assessment and CE marking, registration in the EU database, and a post-market monitoring system to track real-world performance and report serious incidents.

Not every AI system is high-risk. For certain systems that interact with people or generate content, the lighter Article 50 transparency duties apply instead: telling people when they are interacting with an AI system, and — for generative AI — marking AI-generated or manipulated output in a machine-readable way so it can be detected as artificially produced. Providers of GPAI models carry their own tailored set of documentation and transparency obligations.

This entry is informational and not legal advice; which obligations apply to a specific system depends on its risk classification and how it is used. For a fuller walk-through, see our EU AI Act guide.

How the provider relates to the other operators

A provider does not exist in isolation. Around it sit the deployer, the importer (who brings a third-country provider's system into the EU), the distributor (who makes it available down the supply chain), and the authorised representative (an EU-based party a non-EU provider must appoint to act on its behalf). Each has its own, lighter obligations, largely about verifying that the provider did its job.

The role is not permanently fixed to whoever first built the system. Under Article 25, a deployer, distributor, or importer becomes a provider — inheriting the full provider obligations — in defined situations: if it puts its own name or trademark on a high-risk system already on the market, if it substantially modifies such a system, or if it modifies the intended purpose of a system so that it becomes high-risk. In other words, rebranding or materially changing someone else's high-risk system can move the heaviest duties onto you.

That shift is easy to trigger without noticing, which is why the provider question is worth settling early. Understanding whether your organization is a provider, a deployer, or another operator is the first step in scoping what the EU AI Act actually requires of you.

On this page

  • The definition in plain language
  • Provider vs deployer: the test
  • The duties that attach to providers
  • How the provider relates to the other operators

Share

Product and governance updates — see our privacy policy.

Frequently asked questions

Frequently asked questions

A provider is any natural or legal person, public authority, agency, or other body that develops an AI system or a general-purpose AI model — or has one developed — and places it on the market or puts it into service under its own name or trademark, whether for payment or free of charge. Both limbs must be met: developing the system and releasing it under your own name.

A provider builds an AI system and makes it available under its own name or trademark. A deployer uses an AI system under its own authority in the course of its activity. The test is whether the party releases the system as its own and supplies it to others (provider) or simply uses a system that another organization supplied (deployer). Providers carry the heavier compliance burden.

Yes. Under Article 25, a deployer, distributor, or importer becomes a provider — with the full provider obligations — if it puts its own name or trademark on a high-risk system already on the market, substantially modifies such a system, or changes a system's intended purpose so that it becomes high-risk. Rebranding or materially altering someone else's high-risk system can move the heaviest duties onto you.

Before placing a high-risk system on the market, a provider must implement risk management, data governance, technical documentation, automatic logging, transparency to deployers, human oversight, and appropriate accuracy, robustness, and cybersecurity — then complete a conformity assessment, register the system, and run post-market monitoring. Providers of generative AI also carry Article 50 transparency duties, including machine-readable marking of AI-generated output. This is informational, not legal advice.

Natali Craig
Olivia Rhye
Drew Cano

Still have questions?

Can’t find the answer you’re looking for? Talk to our team and we’ll help you get started.

Get in touch

Related terms

Deployer (EU AI Act)Glossary

Deployer (EU AI Act)

A deployer under the EU AI Act is any organization using an AI system under its own authority. Learn the deployer's duties, how it differs from a provider, and more.

Read more
Operator (EU AI Act)Glossary

Operator (EU AI Act)

An operator is the EU AI Act's umbrella term for any party in the AI value chain: provider, product manufacturer, deployer, authorised representative, importer, or distributor.

Read more
EU AI Act (Artificial Intelligence Act)Glossary

EU AI Act (Artificial Intelligence Act)

The EU AI Act is the EU's risk-based law for artificial intelligence. A plain-language summary of what it regulates, when it applies, and who must comply.

Read more

See how Qadar AI implements these concepts at runtime

A product specialist will reply within one business day

Book a demo

Subscribe to our newsletter

Product and governance updates — see our privacy policy.

AI security and control for every model your team uses.

Built in Dubai. Designed for teams operating across regions, models, and regulatory environments.

  • Product

    • Shield Web
    • Shield Control
    • Shield Desktop
    • Shield Mobile
    • Pricing
    • Download
  • Solutions

    • For CISOs
    • For Operations
    • For AI Teams
  • Use Cases

    • AI Governance
    • AI Agent Security
    • LLM Access Control
    • Secure AI Deployment
    • Enterprise Operations
    • Financial Services
    • HR & Recruiting
  • Resources

    • Help Center
    • Blog
    • Guides
    • Glossary
    • Changelog
    • Compare
    • FAQ
  • Company

    • About
    • Careers
    • Security & Trust
    • Contact
  • Tools

    • Disclose
    • AI Risk Calculator
    • EU AI Act Checker

© 2026 Qadar AI. All rights reserved.

  • ·Legal
  • ·Privacy
  • ·Terms
  • ·Partner Terms
  • ·GDPR / DPA
  • ·