The answer in thirty seconds
If you use an AI tool in your professional activity, it applies to you — but almost always as a deployer, the least demanding role. The heavy obligations target the provider. So the whole question is which of the two you are, tool by tool, and there are three situations in which you become a provider without realising it.
The five-question test
Take one tool, just one, and answer:
- Did you develop it? If so, you are its provider.
- Do you sell or distribute it under your own name or trade mark? If so, you become its provider, even if someone else built it.
- Have you substantially modified its intended purpose? Diverting a tool from its intended use can make you its provider.
- Do you simply use it in your work? Then you are a deployer.
- Do you bring it into the Union from a third country? You are an importer, with verification obligations.
The same tool can put you in two roles depending on what you do with it, and the same company can be a deployer for ten tools and a provider for one. That is the most common situation, and the most misunderstood.
The white-label trap
This is the situation that surprises people most. A services firm builds an off-the-shelf model into its own software, sells it to its clients under its own name, and believes it is merely a user. In the eyes of the regulation, it is a provider: it is its name on the product. If the use is high-risk, the full obligations fall on it — technical documentation, risk management, data quality, human oversight, keeping of logs.
A real example
A fifteen-person accountancy firm uses a generative assistant to draft letters: deployer. It offers its clients a ‘preliminary accounts analysis tool’ that is only a layer on top of an existing model, sold under the firm’s name: provider for that tool. It has bought a scoring module from an American vendor and brings it into the Union: importer. Three roles, one company, fifteen employees.
What you can do tomorrow
- Take your list of tools and write your role next to each one.
- Spot the ones that carry your name in front of the client: those are the only ones that can cost you dearly.
- For those, ask the original vendor for its technical documentation and its declaration of conformity — now is the time to do it, not on the day of an inspection.
Common mistakes
‘We don’t do AI, we only buy software.’ The deployer has obligations, lighter but real, and the tool you bought can be high-risk when it touches recruitment or credit.
‘Our provider is compliant, so we are.’ Its compliance covers the system, not your use. You are the one who has to inform people, oversee decisions and document what you do with it.
‘We are too small.’ The regulation sets no headcount threshold. It does, however, set a fine ceiling more favourable to SMEs, and simplified documentation.
Your next step
Compare this page with how you actually work, then ask the community if anything is still unclear.
Ask the community →Reference sources
Going further
This page is based on the consolidated text of Regulation (EU) 2024/1689 in its version of 27 July 2026. Verified 26 August 2026. General information: it does not constitute individual legal advice.