EU AI Act Compliance

AI Act Provider vs Deployer Obligations: What Your Organization Actually Needs to Do

Updated 2026-07-19
Key Takeaways: Priverion is a Swiss-hosted GRC platform that helps multi-entity organizations classify AI Act roles, manage provider and deployer obligations, and maintain audit-ready evidence across subsidiaries.

The EU AI Act assigns fundamentally different obligations to providers and deployers. Misclassify your role and you'll build the wrong compliance program from day one.

"Priverion gave us centralized visibility across all our entities, so we stopped guessing which obligations applied where and started actually managing compliance."

Head of Data Protection

a healthcare provider, multi-entity healthcare group, 100% vendor risk assessment coverage

Swiss-hosted platform

ISO 27001-aligned infrastructure

Trusted by enterprises with 50+ entities

Get the AI Act Provider vs Deployer Obligations Checklist

A side-by-side breakdown of every obligation, sorted by role, risk category, and deadline. No fluff. Straight to your inbox.

No spam. Unsubscribe anytime. Data processed in Switzerland.

Know your AI Act obligations: provider or deployer.

Get the Checklist
Trusted by 50+ privacy teams across 14 countries
Healthcare
Aviation
Energy
Legal
Technology
Zurzach logo
AXA logo
Openmedical logo
Glencore logo
Pilatus logo
Liferay logo
CareerFairy logo
Voicepoint logo
Kellerhals Carrard logo
Aclaris logo
Avantec logo
Diakonie Bethanien logo
Liferay logo
CareerFairy logo
Zurzach logo
Voicepoint logo
Openmedical logo
Kellerhals Carrard logo
AXA logo
Aclaris logo
Avantec logo
Diakonie Bethanien logo
What Priverion Covers

Operationalize AI Act Obligations Across Every Entity Without the Spreadsheet Chaos

Whether you're classified as a provider, deployer, or both across different subsidiaries, Priverion gives your compliance team centralized control and audit-ready evidence.

Provider + Deployer

AI Register for EU AI Act Readiness

Catalog every AI system across your group with role classification (provider, deployer, or both), risk tier, and responsible entity, all in one register. No more chasing business units to find out who's using what.

AI-assisted classification flags when a subsidiary's modifications push them from deployer to provider under Article 25, so you catch reclassification triggers before regulators do.

5 roles

in the AI value chain tracked per system (provider, deployer, importer, distributor, authorized representative) as defined in Article 3, EU AI Act (Regulation 2024/1689)

Provider Obligations

Technical Documentation and Conformity Management

Providers of high-risk AI must maintain documentation covering 11 specific technical areas under Annex IV. Priverion structures this into guided workflows with version control, so your team fills in the substance while the platform handles the structure and audit trail.

Generate audit-ready evidence packages for supervisory authorities in minutes, not the weeks it takes when documentation lives across SharePoint folders and email threads.

200+ hours saved

A medical technology company saved 200+ hours preparing ISO 27001 documentation using Priverion's structured evidence workflows. The same approach is now extended to AI Act technical documentation

Deployer Obligations

Fundamental Rights Impact Assessments and Human Oversight

Deployers using high-risk AI in employment, credit scoring, or law enforcement must conduct fundamental rights impact assessments before deployment. Priverion's AI-assisted DPIA and FRIA workflows guide your team through the assessment with structured templates and risk scoring, so nothing gets missed.

Assign human oversight responsibilities per system, track competency requirements, and monitor for incidents, all linked back to the specific AI system in your register. AI assists the drafting; your team makes every decision.

100% coverage

A healthcare provider achieved 100% vendor risk assessment coverage using Priverion. The same centralized approach applied to AI deployer obligations across entities

Group-Wide Visibility

Cross-Entity AI Compliance Dashboards

One subsidiary is a provider. Another deploys the same system. A third modified it enough to trigger reclassification. Without centralized visibility, you're managing three different compliance approaches in three different spreadsheets, hoping they're consistent.

Priverion's board-ready dashboards show AI Act compliance status per entity, per system, per risk tier. Your CISO and Head of Legal see the same picture, and it's always current.

50+ entities

Priverion serves enterprise groups managing 50+ entities across multiple jurisdictions with centralized compliance oversight

Incident + Monitoring

Incident Management and Regulatory Reporting

Both providers and deployers must report serious incidents involving high-risk AI systems. Providers additionally need post-market monitoring systems. Priverion connects incident workflows to your AI register, so when something goes wrong, you know which system, which entity, and which obligations apply.

Automated log retention ensures deployers meet the minimum 6-month requirement for system-generated logs, without manual backup processes.

24/7 support

Data Sovereignty

Swiss-Hosted Infrastructure With No Data Used for AI Training

Your AI Act compliance records (risk assessments, technical documentation, incident reports) contain some of the most sensitive operational data in your organization. It should not leave European jurisdiction, and it should never train someone else's model.

All Priverion data processing happens within Swiss infrastructure. AI-assisted features help your team draft faster and catch gaps, but no customer data is ever used for model training. AI assists, humans decide.

0 data points

used for model training. Priverion's transparency commitment. All AI outputs require human review before becoming compliance records.

"We went from spending 60% of compliance admin time chasing business units for ROPA updates across subsidiaries to fully automated recertification in six months. Our DPO now focuses on strategic privacy work, not spreadsheet maintenance."

Data Protection Officer, Aircraft manufacturer

Result achieved within first 6 months of Priverion deployment

See how Priverion handles AI Act compliance for multi-entity organizations

Download the Obligations Checklist

Measurable results from real customers

What changes when you stop managing privacy in spreadsheets

200+

Hours saved on ROPA management

A medical technology company redirected 200+ hours from manual ROPA updates to ISO 27001 preparation, completing certification 3 months ahead of schedule.

60%

Lower cost vs. OneTrust

Aircraft manufacturer achieved enterprise-grade group compliance at a fraction of the cost, with pricing based on entities, not per-user expansion traps.

3 mo.

Ahead of schedule on ISO 27001

A medical technology company used Priverion's audit-ready evidence packages to accelerate ISO 27001 certification by three months.

"We went from chasing business units for weeks to having a live, accurate ROPA across every subsidiary. Our Friday afternoons are ours again."

Data Protection Officer, Aircraft manufacturer (after 6 months with Priverion)

Competitor Comparison

Why mid-market privacy teams are switching from OneTrust

Enterprise-grade compliance shouldn't require an enterprise-grade budget or a six-month implementation.

Typical enterprise platform experience

Per-user, per-module pricing

Costs balloon as you onboard subsidiaries. Budget conversations happen every quarter, not every year.

US-hosted infrastructure

Post-Schrems II, US hosting creates a compliance liability for the very tool meant to manage your compliance. Additional SCCs required for your compliance platform itself.

200+ shallow integrations

Hundreds of connectors that need constant maintenance. Most teams use five or fewer but pay the complexity cost of all 200.

6+ month implementation

Dedicated implementation consultants, extensive training programs, and ongoing professional services budgets before you see any value.

Feature overload

ESG modules, ethics hotlines, cookie consent, GRC: you're paying for a platform that does everything, when you need one that does privacy management exceptionally well.

The Priverion experience

Predictable per-company pricing

Based on number of entities and organizational size, not per-user or per-module. Onboard your entire team without watching costs escalate.

Swiss-built, Swiss-hosted

All data processed within Swiss infrastructure. European data residency guaranteed. Your compliance platform shouldn't create its own compliance problem.

Deep integrations that matter

Focused integrations with HR, procurement, and IT asset management systems, the workflows that actually drive privacy compliance. No maintenance overhead from connectors you'll never use.

Operational in weeks

Intuitive UX designed for privacy professionals, not IT departments. A medical technology company saved 200+ hours in ISO 27001 preparation, starting within weeks of onboarding.

A medical technology company, ISO 27001 preparation phase

Purpose-built for privacy

ROPA, DPIA/TIA, vendor risk, incident management, DSR handling, and AI Act readiness: everything a group DPO needs. Nothing they don't. We don't cover ESG, ethics hotlines, or cookie consent, and that's intentional.

"We evaluated OneTrust and two other platforms before choosing Priverion. The difference was immediate: we had group-wide visibility across all entities within the first month, not the first year. Our compliance admin time dropped by 60% in six months."

Data Protection Team, Aircraft manufacturer

Aircraft manufacturer, first 6 months post-implementation

60%

reduction in compliance admin time

Aircraft manufacturer, 6-month measured outcome

100%

ROPA recertification rate

A Swiss insurer, fully automated

100%

vendor risk coverage

A healthcare provider

24/7

DPO support across entities

200+

hours saved on ISO 27001 prep

A medical technology company

Book a 30-min walkthrough

See how Priverion compares for your specific group structure, no commitment required

Stop managing privacy in spreadsheets. Start managing it as a program.

See how Priverion gives multi-entity organizations group-wide compliance visibility, automated recertification, and audit-readiness, in a 30-minute walkthrough tailored to your structure.

"We went from chasing business units across subsidiaries for ROPA updates to fully automated recertification. Our DPO finally focuses on strategic privacy work instead of spreadsheet maintenance."

Privacy Lead, Aircraft manufacturer

60% reduction in compliance admin time within the first 6 months

Weeks

Time to go live

Avg. across customer base

200+

Hours saved on ISO 27001

A medical technology company, certification prep

100%

Vendor risk coverage

A healthcare provider, first year

See Priverion in action

Book a 30-Min Walkthrough
About this page: references, definitions, and FAQs

Key Takeaways

The EU AI Act (Regulation 2024/1689) assigns fundamentally different compliance obligations depending on whether an organization is classified as a provider or a deployer of an AI system. Providers bear the heaviest burden, including conformity assessments, technical documentation across 11 areas under Annex IV, and post-market monitoring. Deployers must conduct fundamental rights impact assessments, ensure human oversight, and retain system-generated logs for at least six months. Under Article 25, a deployer can be reclassified as a provider if it substantially modifies a system or puts its own branding on it. Multi-entity organizations need centralized visibility to manage these obligations consistently across subsidiaries and jurisdictions.

Definitions

What is an AI system provider under the EU AI Act?

AI system provider is defined in Article 3(3) of the EU AI Act as a natural or legal person that develops an AI system or a general-purpose AI model, or that has an AI system or model developed, and places it on the market or puts it into service under its own name or trademark. Providers of high-risk AI systems bear the most extensive obligations, including conformity assessment, technical documentation, quality management, and post-market monitoring. Source: Regulation (EU) 2024/1689, Article 3

What is an AI system deployer under the EU AI Act?

AI system deployer is defined in Article 3(4) as a natural or legal person that uses an AI system under its authority, except where the AI system is used in the course of a personal non-professional activity. Deployers of high-risk AI systems must ensure human oversight, conduct fundamental rights impact assessments (Article 27), and maintain logs generated by the system for a minimum of six months (Article 26). Source: Regulation (EU) 2024/1689, Article 3

What is a high-risk AI system?

A high-risk AI system is an AI system that falls within one of the use cases listed in Annex III of the EU AI Act, including biometric identification, critical infrastructure management, employment and worker management, access to essential services (credit scoring), law enforcement, migration and border control, and administration of justice. These systems are subject to the full set of provider and deployer obligations under Title III, Chapter 2 and Chapter 3. Source: Regulation (EU) 2024/1689, Annex III

Frequently Asked Questions

What is the difference between an AI Act provider and a deployer?

Under Article 3 of the EU AI Act (Regulation 2024/1689), a provider develops or places an AI system on the market under its own name, while a deployer uses an AI system under its authority. Providers must perform conformity assessments, maintain technical documentation covering 11 areas under Annex IV, implement quality management systems, and conduct post-market monitoring. Deployers must ensure human oversight, conduct fundamental rights impact assessments for certain use cases, and retain system-generated logs for at least six months. Source: Regulation (EU) 2024/1689

When does a deployer become a provider under the EU AI Act?

Article 25 of the EU AI Act specifies three reclassification triggers: (1) the deployer puts its own name or trademark on a high-risk AI system already on the market, (2) the deployer makes a substantial modification to the system, or (3) the deployer modifies the intended purpose of the system in a way that makes it high-risk. Upon reclassification, the former deployer assumes the full set of provider obligations, including conformity assessment and technical documentation. Source: Regulation (EU) 2024/1689, Article 25

What are the penalties for non-compliance with the EU AI Act?

The EU AI Act establishes a tiered penalty structure under Article 99: up to €35 million or 7% of global annual turnover for prohibited AI practices (Article 5 violations), up to €15 million or 3% for violations of other provider or deployer obligations, and up to €7.5 million or 1% for supplying incorrect information to authorities. For SMEs and startups, the lower of the two amounts applies. Source: Regulation (EU) 2024/1689, Article 99

What is a fundamental rights impact assessment (FRIA) under the AI Act?

Article 27 requires deployers of high-risk AI systems used in employment, credit scoring, essential public services, and law enforcement to conduct a fundamental rights impact assessment before putting the system into use. The FRIA must describe the deployer's processes, the period and frequency of use, categories of affected persons, specific risks to fundamental rights, human oversight measures, and actions to be taken if risks materialize. The assessment must be notified to the relevant market surveillance authority. Source: Regulation (EU) 2024/1689, Article 27

What technical documentation must providers of high-risk AI systems maintain?

Annex IV of the EU AI Act requires providers to maintain documentation covering 11 areas: (1) general system description, (2) detailed description of elements and development process, (3) monitoring, functioning, and control information, (4) risk management system description, (5) data governance and management practices, (6) description of changes throughout the lifecycle, (7) performance metrics and robustness measures, (8) cybersecurity measures, (9) description of the quality management system, (10) description of the conformity assessment procedure, and (11) EU declaration of conformity. Source: Regulation (EU) 2024/1689, Annex IV

How does the EU AI Act apply to Swiss organizations?

Under Article 2, the EU AI Act has extraterritorial reach. It applies to providers placing AI systems on the EU market regardless of establishment location, and to deployers located within the EU. It also covers providers and deployers in third countries where the AI system's output is used in the EU. Swiss organizations that deploy AI systems whose outputs affect EU-based individuals (for example, in hiring, credit decisions, or customer service) must comply with the applicable deployer obligations. According to the Swiss Federal Data Protection and Information Commissioner (FDPIC), Swiss companies should proactively assess their AI Act exposure given the close economic ties between Switzerland and the EU.

EU AI Act Compliance Timeline

DateMilestoneWho Is Affected
2 February 2025Prohibited AI practices ban takes effect (Article 5)All operators
2 August 2025General-purpose AI model obligations apply (Chapter V)GPAI providers
2 August 2026Full high-risk AI obligations apply (Annex III systems)Providers & deployers of high-risk AI
2 August 2027Obligations for high-risk AI in Annex I (EU harmonisation legislation)Providers of Annex I systems

Provider vs Deployer Obligations Comparison

ObligationProviderDeployer
Conformity assessmentRequired before placing on marketNot required
Technical documentation (Annex IV)Must create and maintain across 11 areasMust have access to provider documentation
Quality management systemRequired (Article 17)Not required
Post-market monitoringRequired (Article 72)Not required
Fundamental rights impact assessmentNot requiredRequired for certain use cases (Article 27)
Human oversightMust design for human oversightMust implement and ensure human oversight
Log retentionMust enable automatic loggingMust retain logs for minimum 6 months
Serious incident reportingRequired (Article 73)Required (Article 26(5))
EU database registrationRequired (Article 49)Required for certain use cases (Article 49)

Statistics and Industry Context

According to a 2024 IAPP survey on AI governance, only 30% of organizations have a formal AI governance framework in place, despite growing regulatory pressure. The EU AI Act is the world's first comprehensive AI regulation, covering an estimated 6,000 to 7,000 high-risk AI systems already deployed across the EU according to European Commission impact assessment estimates. ENISA's 2024 AI threat landscape report highlights that supply chain risks in AI systems are among the top concerns for organizations deploying third-party AI, reinforcing the need for deployers to maintain robust vendor oversight. Source: ENISA AI Security

The EU AI Act (Regulation 2024/1689) entered into force on 1 August 2024. As noted by the European Commission, "the AI Act is the first-ever comprehensive legal framework on AI worldwide, which addresses the risks of AI and positions Europe to play a leading role globally."