EU AI Act Compliance Guide

AI Act Provider vs Deployer Obligations: What Your Organization Actually Needs to Do

Updated 2026-07-19
Key Takeaways: Priverion is a Swiss-hosted GRC platform that operationalizes EU AI Act provider and deployer obligations across multi-entity corporate groups.

The EU AI Act assigns fundamentally different obligations depending on whether you're classified as a provider or deployer, and getting it wrong doesn't just mean non-compliance. It means building the wrong internal processes, assigning the wrong teams, and wasting months of effort. This guide breaks down exactly what each role requires, where they overlap, and how multi-entity organizations can operationalize compliance without drowning in spreadsheets.

Download the Provider vs Deployer Obligations Checklist

Free PDF, no sales call required. Just a business email.

Trusted by 50+ privacy teams across 14 countries
Healthcare
Aviation
Energy
Legal
Technology
Zurzach logo
AXA logo
Openmedical logo
Glencore logo
Pilatus logo
Liferay logo
CareerFairy logo
Voicepoint logo
Kellerhals Carrard logo
Aclaris logo
Avantec logo
Diakonie Bethanien logo
Liferay logo
CareerFairy logo
Zurzach logo
Voicepoint logo
Openmedical logo
Kellerhals Carrard logo
AXA logo
Aclaris logo
Avantec logo
Diakonie Bethanien logo
Key Capabilities for AI Act Compliance

How Priverion Operationalizes Provider and Deployer Obligations Across Every Entity

Whether you classify as a provider under Article 16 or a deployer under Article 26 (or both, across different subsidiaries), these capabilities turn regulatory text into auditable, repeatable workflows.

Provider + Deployer

AI Register for EU AI Act Classification

Maintain a centralized inventory of every AI system across your group, with per-entity classification as provider, deployer, or both. The register maps each system to its risk category, applicable obligations, and responsible business unit so nothing falls through the cracks when one subsidiary provides and another deploys the same model.

Covers: Article 3 classification, Article 49 EU database registration, Annex III high-risk categorization

5 distinct roles

tracked per AI system, per entity, as defined across the AI Act value chain (Article 3, Regulation EU 2024/1689)

Provider Obligation

AI-Assisted DPIA and Fundamental Rights Impact Assessments

Generate conformity-ready impact assessments with AI-assisted drafting that pre-populates risk factors, mitigation measures, and regulatory references. Every output is reviewed by your team before it becomes a compliance record. AI assists, humans decide. Deployers conducting fundamental rights impact assessments for high-risk employment or credit scoring systems get purpose-built templates aligned to Article 27.

Covers: Article 9 risk management, Article 27 FRIA, Annex IV technical documentation

11 technical areas

covered in provider documentation requirements per Annex IV of the EU AI Act

Deployer Obligation

Human Oversight and Monitoring Workflows

Article 26 requires deployers to assign competent, trained individuals to exercise human oversight of high-risk AI systems. Priverion tracks oversight assignments per system, per entity, and automates recertification so you can prove to supervisory authorities that the right people are monitoring the right systems, not just on paper, but in practice.

Covers: Article 14 human oversight design, Article 26 deployer monitoring, serious incident reporting

100% recertification rate

achieved by AXA using Priverion's automated recertification workflows for ROPA (the same engine now extended to AI oversight tracking)

Group-Wide Visibility

Cross-Entity Compliance Dashboards

When one subsidiary is a provider and another deploys the same system, you need one place to see both sets of obligations. Board-ready dashboards show AI Act compliance posture per entity, per AI system, and per risk category, so your DPO, CISO, or head of legal can report group-wide status without consolidating data from a dozen different trackers.

Covers: Multi-entity oversight, audit-readiness, regulatory reporting to supervisory authorities

50+ entities

managed by Priverion enterprise customers across multiple jurisdictions (validated through current customer deployments)

Provider Obligation

Quality Management System Documentation

Providers of high-risk AI systems must establish and maintain a quality management system under Article 17. Priverion generates audit-ready evidence packages that map your existing privacy and information security controls (ISO 27001, ISO 27701, NIST) to AI Act requirements, so you build on what you have instead of starting from scratch.

Covers: Article 17 QMS, post-market monitoring, conformity assessment preparation

200+ hours saved

by Medtec during ISO 27001 preparation using Priverion's documentation and evidence generation capabilities

Trust + Sovereignty

Swiss Data Sovereignty for AI Compliance Data

Your AI Act compliance records (risk assessments, classification decisions, incident logs, oversight documentation) contain some of the most sensitive operational data in your organization. All data is processed and stored within Swiss infrastructure. No customer data is used for AI model training. In a post-Schrems II landscape, Swiss-hosted is not a marketing claim. It is a legal architecture decision.

Covers: European data residency, Swiss FADP compliance, cross-border data transfer confidence

Zero customer data

used for AI model training. Priverion's AI transparency commitment, verified through Swiss-hosted infrastructure and documented data processing agreements

Download the Provider vs Deployer Obligations Checklist

Free PDF checklist that maps every obligation to the responsible role in your organization

200+

Hours saved on ROPA management

Medtec: hours redirected from manual ROPA tracking to strategic privacy work during ISO 27001 preparation

60%

Lower total cost vs. legacy platforms

Based on Aircraft manufacturer's first-year TCO comparison, no per-user fees, no per-module expansion traps

3 mo

Ahead of schedule on ISO 27001

Medtec: automated evidence packaging and audit-ready documentation cut months off their certification timeline

Competitor-Aware

Why mid-market teams are leaving OneTrust for Priverion

OneTrust serves Fortune 500 organizations with broader GRC scope and dedicated privacy teams. If you're managing privacy across a multi-entity group without a 20-person compliance team, you need something different, not something smaller.

The OneTrust experience

Per-module, per-user pricing

Costs escalate every time you add a subsidiary, a user, or a module. Budget predictability disappears after year one.

US-headquartered, global infrastructure

Post-Schrems II, data flowing through US-owned infrastructure creates transfer risk, even with EU data centers. CLOUD Act applicability (18 U.S.C. §2713) remains an open legal question.

Enterprise complexity

Built for teams of 20+ compliance specialists. Mid-market DPOs report months of implementation and ongoing admin overhead just to maintain configurations.

200+ integrations, mostly shallow

Impressive connector count, but most require custom configuration and ongoing maintenance. Breadth without depth creates more work, not less.

Feature sprawl beyond privacy

ESG, ethics hotlines, cookie consent, third-party risk: you're paying for an empire of modules when you need focused privacy program management.

The Priverion experience

Predictable pricing by company size

Based on number of entities and organizational size, not per-user or per-module. Add subsidiaries, add users, add capabilities. Your invoice stays predictable.

Swiss-built, Swiss-hosted. Full stop.

All data processing within Swiss infrastructure. European data residency by default, not as a premium add-on.

Operational in weeks, not months

Aircraft manufacturer achieved 60% reduction in compliance admin time within the first 6 months. AXA reached 100% ROPA recertification rate, fully automated.

Aircraft manufacturer, first 6 months post-implementation | AXA, post-deployment metrics

Deep integrations where they matter

We integrate deeply with HR, procurement, and IT asset management systems: the actual workflows that create privacy obligations. Not 200 shallow connectors that create maintenance overhead.

Purpose-built for privacy programs

ROPA, DPIA, vendor assessments, incident management, DSR handling, cross-entity data mapping: everything a DPO needs across a multi-entity group. We don't cover ESG or cookie consent, and that's by design.

Switching doesn't have to be painful. Most teams are fully operational within weeks.

Book a 30-min walkthrough

Stop managing privacy in spreadsheets

See what group-wide privacy management looks like when it actually works

In 30 minutes, we'll walk you through how organizations like Aircraft manufacturer cut compliance admin time by 60%, and how your team can stop chasing business units and start doing strategic privacy work.

Weeks, not months

Average time to go live

No per-user pricing

Predictable costs, no expansion traps

100% Swiss-hosted

European data residency guaranteed

Book a 30-minute walkthrough

No commitment required. We'll show you the platform with your use case in mind.

Get the Provider vs Deployer Obligations Checklist

A free PDF that maps every AI Act obligation to the responsible role in your organization (provider, deployer, or both). Built for DPOs and compliance leads managing multi-entity groups.

Free PDF, no sales call required. We'll send it straight to your inbox.

About this page: references, definitions, and FAQs

Key Takeaways: EU AI Act Provider vs Deployer Obligations

The EU AI Act (Regulation EU 2024/1689) assigns distinct compliance obligations depending on whether an organization is classified as a provider (Article 3(3)) or a deployer (Article 3(4)) of an AI system. Providers bear upstream responsibilities including conformity assessments, quality management systems, and EU database registration. Deployers must ensure human oversight, fundamental rights impact assessments, and incident reporting. Multi-entity groups often hold both roles simultaneously across subsidiaries, requiring centralized compliance orchestration.

What is an AI system provider under the EU AI Act?

AI system provider is defined in Article 3(3) of Regulation (EU) 2024/1689 as a natural or legal person that develops an AI system or a general-purpose AI model and places it on the market or puts it into service under its own name or trademark. Providers of high-risk AI systems must comply with Articles 8 to 17, including risk management, data governance, technical documentation, transparency, human oversight design, accuracy, robustness, and cybersecurity. Source: EUR-Lex, Regulation (EU) 2024/1689

What is an AI system deployer under the EU AI Act?

AI system deployer is defined in Article 3(4) of Regulation (EU) 2024/1689 as a natural or legal person that uses an AI system under its authority, except where the AI system is used in the course of a personal non-professional activity. Deployers of high-risk AI systems must comply with Article 26, which requires human oversight by trained personnel, input data relevance monitoring, record-keeping, and informing affected natural persons. For certain use cases (employment, creditworthiness), deployers must also conduct fundamental rights impact assessments under Article 27. Source: EUR-Lex, Regulation (EU) 2024/1689

What is a fundamental rights impact assessment (FRIA) under Article 27?

A fundamental rights impact assessment is required under Article 27 of the EU AI Act for deployers of high-risk AI systems used in employment, worker management, access to essential services, or creditworthiness evaluation. The FRIA must assess the impact on fundamental rights of affected persons, describe safeguards, and be completed before the high-risk AI system is put into use. Source: EUR-Lex, Regulation (EU) 2024/1689

What is a quality management system (QMS) under Article 17?

A quality management system under Article 17 of the EU AI Act is a documented set of policies, procedures, and instructions that providers of high-risk AI systems must establish and maintain. The QMS must cover risk management, post-market monitoring, data management, record-keeping, resource management, accountability frameworks, and communication with competent authorities. Source: EUR-Lex, Regulation (EU) 2024/1689

Provider vs Deployer Obligations: Comparison Table

ObligationProvider (Article 16)Deployer (Article 26)
Risk management systemRequired (Article 9)Not required to establish; must use system as intended
Data governanceRequired (Article 10)Must ensure input data relevance
Technical documentationRequired (Annex IV: 11 areas)Must retain logs generated by the system
Conformity assessmentRequired (Article 43)Not required
EU database registrationRequired (Article 49)Required for certain deployers (Article 49(3))
Quality management systemRequired (Article 17)Not required
Human oversightMust design for human oversight (Article 14)Must implement human oversight with trained personnel (Article 26(2))
Fundamental rights impact assessmentNot requiredRequired for employment, credit scoring, essential services (Article 27)
Incident reportingRequired (Article 62)Required for serious incidents (Article 26(5))
Post-market monitoringRequired (Article 72)Must monitor performance and report malfunctions
Penalties (maximum)Up to €35M or 7% global turnoverUp to €15M or 3% global turnover

Key Statistics on AI Act Compliance

According to the EU AI Act (Regulation EU 2024/1689), penalties for prohibited AI practices can reach €35 million or 7% of global annual turnover, whichever is higher, exceeding the GDPR maximum of €20 million or 4%. The Act identifies 8 categories of prohibited AI practices (Article 5) and defines high-risk systems across 8 domains in Annex III. Provider technical documentation must cover 11 distinct areas per Annex IV. According to a 2024 IAPP survey, fewer than 30% of organizations had begun formal AI governance programs by mid-2024, underscoring the urgency of compliance preparation before the August 2026 deadline for high-risk system obligations. Source: IAPP

Frequently Asked Questions

What is the difference between an AI Act provider and a deployer?

Under the EU AI Act (Regulation EU 2024/1689), a provider is the entity that develops or places an AI system on the market (Article 3(3)), while a deployer is the entity that uses an AI system under its authority (Article 3(4)). Providers bear heavier obligations including conformity assessments, quality management systems, and EU database registration. Deployers must ensure human oversight, conduct fundamental rights impact assessments for high-risk systems, and monitor AI system performance. Source: EUR-Lex

What are the key obligations of AI Act providers under Article 16?

AI Act providers of high-risk AI systems must establish a quality management system (Article 17), maintain technical documentation covering 11 areas per Annex IV, ensure conformity assessment (Article 43), register systems in the EU database (Article 49), implement risk management (Article 9), and conduct post-market monitoring. Providers must also ensure their systems meet accuracy, robustness, and cybersecurity requirements before placing them on the market. Source: EUR-Lex

What are the key obligations of AI Act deployers under Article 26?

Deployers of high-risk AI systems must assign competent individuals for human oversight (Article 14), monitor system performance, conduct fundamental rights impact assessments for employment and credit scoring use cases (Article 27), inform affected individuals, and report serious incidents to supervisory authorities. Deployers must also ensure input data is relevant and representative. Source: EUR-Lex

Can an organization be both a provider and deployer under the AI Act?

Yes. Under Article 25 of the EU AI Act, an organization can be classified as both provider and deployer across different AI systems or subsidiaries. For example, a corporate group may develop an AI system in one subsidiary (provider) and deploy it in another (deployer). Each entity must fulfill the obligations corresponding to its role for each specific AI system. This dual classification is common in multi-entity groups and requires centralized compliance tracking. Source: EUR-Lex

When do EU AI Act obligations take effect?

The EU AI Act entered into force on 1 August 2024. Prohibited AI practices apply from 2 February 2025. Obligations for general-purpose AI models apply from 2 August 2025. Most high-risk AI system obligations for providers and deployers apply from 2 August 2026, with certain high-risk systems in Annex I having until 2 August 2027. Organizations should begin compliance preparation well in advance of these deadlines. Source: EUR-Lex

What penalties apply for non-compliance with the EU AI Act?

Non-compliance penalties under the EU AI Act can reach up to €35 million or 7% of global annual turnover for prohibited AI practices, up to €15 million or 3% for other violations, and up to €7.5 million or 1.5% for supplying incorrect information. These are among the highest regulatory fines in EU law, exceeding GDPR maximums. SMEs and startups may receive proportionate penalties. Source: EUR-Lex

How does the AI Act interact with GDPR?

The EU AI Act operates alongside the GDPR and does not replace it. AI systems processing personal data must comply with both frameworks simultaneously. Article 10 of the AI Act explicitly references GDPR requirements for training data. Deployers conducting fundamental rights impact assessments under Article 27 should coordinate with their existing GDPR Data Protection Impact Assessments (DPIAs) under Article 35 GDPR. Organizations already maintaining ROPA and DPIA processes can leverage existing governance structures for AI Act compliance.

How does Priverion help with AI Act compliance for multi-entity groups?

Priverion provides a centralized AI register for classifying each AI system as provider, deployer, or both across subsidiaries. The Swiss-hosted platform includes AI-assisted DPIA and fundamental rights impact assessment templates aligned to Articles 9 and 27, human oversight tracking with automated recertification, cross-entity compliance dashboards, and quality management system documentation that maps existing ISO 27001 and ISO 27701 controls to AI Act requirements. All data is processed within Swiss infrastructure with zero customer data used for AI model training.