The definition in plain language
The EU AI Act organizes responsibility around the roles that different parties play in an AI system's life, and the provider sits at the origin of that chain. Read plainly, Article 3(3) has two parts that must both be true.
First, the party develops the AI system or GPAI model, or has it developed on its behalf. Commissioning a system built to your specification counts — you do not have to write the code yourself to be its provider.
Second, the party places it on the market or puts it into service under its own name or trademark. Placing on the market means making the system available in the EU for the first time; putting into service means supplying it for first use, including for the provider's own internal use. The commercial model is irrelevant: the definition applies whether the system is sold, licensed, or given away for free.
Both limbs matter. A party that develops a system but never releases it under its own name is not, on that basis, a provider. A party that attaches its name to a system it releases is, even if a third party did the engineering.
Provider vs deployer: the test
The cleanest way to understand a provider is to contrast it with a deployer — the party that uses an AI system under its own authority in the course of its activity. A company that buys a hiring-screening tool and runs candidates through it is a deployer. The company that built that tool and sells it under its brand is the provider.
The distinguishing test is the "under its own name or trademark, and places on the market or puts into service" condition. Ask two questions:
- Does the party release the system under its own name or trademark? Branding and holding out the system as your own is the hallmark of a provider.
- Does the party make it available to others (or put it into service), rather than merely use what someone else supplied? Supplying the system is a provider act; using it is a deployer act.
If the answer to both is yes, the party is a provider. If the party is simply operating a system that another organization supplied, it is a deployer. Both are operators under the Act — an umbrella term the Act also uses for importers, distributors, and authorised representatives — but the obligations attached to each role differ sharply. Our operator entry maps how the roles fit together.
The duties that attach to providers
The reason the provider distinction matters is that the Act loads the substantive compliance duties onto the provider — most heavily for high-risk AI systems. A provider of a high-risk system must, before placing it on the market, put in place and be able to evidence:
- a risk management system running across the AI system's lifecycle;
- data governance practices covering the training, validation, and testing data;
- technical documentation demonstrating conformity;
- automatic record-keeping (logging) of events over the system's lifetime;
- transparency and clear information to deployers;
- effective human oversight designed into the system;
- appropriate accuracy, robustness, and cybersecurity;
- a conformity assessment and CE marking, registration in the EU database, and a post-market monitoring system to track real-world performance and report serious incidents.
Not every AI system is high-risk. For certain systems that interact with people or generate content, the lighter Article 50 transparency duties apply instead: telling people when they are interacting with an AI system, and — for generative AI — marking AI-generated or manipulated output in a machine-readable way so it can be detected as artificially produced. Providers of GPAI models carry their own tailored set of documentation and transparency obligations.
This entry is informational and not legal advice; which obligations apply to a specific system depends on its risk classification and how it is used. For a fuller walk-through, see our EU AI Act guide.
How the provider relates to the other operators
A provider does not exist in isolation. Around it sit the deployer, the importer (who brings a third-country provider's system into the EU), the distributor (who makes it available down the supply chain), and the authorised representative (an EU-based party a non-EU provider must appoint to act on its behalf). Each has its own, lighter obligations, largely about verifying that the provider did its job.
The role is not permanently fixed to whoever first built the system. Under Article 25, a deployer, distributor, or importer becomes a provider — inheriting the full provider obligations — in defined situations: if it puts its own name or trademark on a high-risk system already on the market, if it substantially modifies such a system, or if it modifies the intended purpose of a system so that it becomes high-risk. In other words, rebranding or materially changing someone else's high-risk system can move the heaviest duties onto you.
That shift is easy to trigger without noticing, which is why the provider question is worth settling early. Understanding whether your organization is a provider, a deployer, or another operator is the first step in scoping what the EU AI Act actually requires of you.
