Key Takeaways: EU AI Act Provider vs Deployer Obligations
The EU AI Act (Regulation EU 2024/1689) assigns distinct compliance obligations depending on whether an organization is classified as a provider (Article 3(3)) or a deployer (Article 3(4)) of an AI system. Providers bear upstream responsibilities including conformity assessments, quality management systems, and EU database registration. Deployers must ensure human oversight, fundamental rights impact assessments, and incident reporting. Multi-entity groups often hold both roles simultaneously across subsidiaries, requiring centralized compliance orchestration.
What is an AI system provider under the EU AI Act?
AI system provider is defined in Article 3(3) of Regulation (EU) 2024/1689 as a natural or legal person that develops an AI system or a general-purpose AI model and places it on the market or puts it into service under its own name or trademark. Providers of high-risk AI systems must comply with Articles 8 to 17, including risk management, data governance, technical documentation, transparency, human oversight design, accuracy, robustness, and cybersecurity. Source: EUR-Lex, Regulation (EU) 2024/1689
What is an AI system deployer under the EU AI Act?
AI system deployer is defined in Article 3(4) of Regulation (EU) 2024/1689 as a natural or legal person that uses an AI system under its authority, except where the AI system is used in the course of a personal non-professional activity. Deployers of high-risk AI systems must comply with Article 26, which requires human oversight by trained personnel, input data relevance monitoring, record-keeping, and informing affected natural persons. For certain use cases (employment, creditworthiness), deployers must also conduct fundamental rights impact assessments under Article 27. Source: EUR-Lex, Regulation (EU) 2024/1689
What is a fundamental rights impact assessment (FRIA) under Article 27?
A fundamental rights impact assessment is required under Article 27 of the EU AI Act for deployers of high-risk AI systems used in employment, worker management, access to essential services, or creditworthiness evaluation. The FRIA must assess the impact on fundamental rights of affected persons, describe safeguards, and be completed before the high-risk AI system is put into use. Source: EUR-Lex, Regulation (EU) 2024/1689
What is a quality management system (QMS) under Article 17?
A quality management system under Article 17 of the EU AI Act is a documented set of policies, procedures, and instructions that providers of high-risk AI systems must establish and maintain. The QMS must cover risk management, post-market monitoring, data management, record-keeping, resource management, accountability frameworks, and communication with competent authorities. Source: EUR-Lex, Regulation (EU) 2024/1689
Provider vs Deployer Obligations: Comparison Table
| Obligation | Provider (Article 16) | Deployer (Article 26) |
|---|
| Risk management system | Required (Article 9) | Not required to establish; must use system as intended |
| Data governance | Required (Article 10) | Must ensure input data relevance |
| Technical documentation | Required (Annex IV: 11 areas) | Must retain logs generated by the system |
| Conformity assessment | Required (Article 43) | Not required |
| EU database registration | Required (Article 49) | Required for certain deployers (Article 49(3)) |
| Quality management system | Required (Article 17) | Not required |
| Human oversight | Must design for human oversight (Article 14) | Must implement human oversight with trained personnel (Article 26(2)) |
| Fundamental rights impact assessment | Not required | Required for employment, credit scoring, essential services (Article 27) |
| Incident reporting | Required (Article 62) | Required for serious incidents (Article 26(5)) |
| Post-market monitoring | Required (Article 72) | Must monitor performance and report malfunctions |
| Penalties (maximum) | Up to €35M or 7% global turnover | Up to €15M or 3% global turnover |
Key Statistics on AI Act Compliance
According to the EU AI Act (Regulation EU 2024/1689), penalties for prohibited AI practices can reach €35 million or 7% of global annual turnover, whichever is higher, exceeding the GDPR maximum of €20 million or 4%. The Act identifies 8 categories of prohibited AI practices (Article 5) and defines high-risk systems across 8 domains in Annex III. Provider technical documentation must cover 11 distinct areas per Annex IV. According to a 2024 IAPP survey, fewer than 30% of organizations had begun formal AI governance programs by mid-2024, underscoring the urgency of compliance preparation before the August 2026 deadline for high-risk system obligations. Source: IAPP
Frequently Asked Questions
What is the difference between an AI Act provider and a deployer?
Under the EU AI Act (Regulation EU 2024/1689), a provider is the entity that develops or places an AI system on the market (Article 3(3)), while a deployer is the entity that uses an AI system under its authority (Article 3(4)). Providers bear heavier obligations including conformity assessments, quality management systems, and EU database registration. Deployers must ensure human oversight, conduct fundamental rights impact assessments for high-risk systems, and monitor AI system performance. Source: EUR-Lex
What are the key obligations of AI Act providers under Article 16?
AI Act providers of high-risk AI systems must establish a quality management system (Article 17), maintain technical documentation covering 11 areas per Annex IV, ensure conformity assessment (Article 43), register systems in the EU database (Article 49), implement risk management (Article 9), and conduct post-market monitoring. Providers must also ensure their systems meet accuracy, robustness, and cybersecurity requirements before placing them on the market. Source: EUR-Lex
What are the key obligations of AI Act deployers under Article 26?
Deployers of high-risk AI systems must assign competent individuals for human oversight (Article 14), monitor system performance, conduct fundamental rights impact assessments for employment and credit scoring use cases (Article 27), inform affected individuals, and report serious incidents to supervisory authorities. Deployers must also ensure input data is relevant and representative. Source: EUR-Lex
Can an organization be both a provider and deployer under the AI Act?
Yes. Under Article 25 of the EU AI Act, an organization can be classified as both provider and deployer across different AI systems or subsidiaries. For example, a corporate group may develop an AI system in one subsidiary (provider) and deploy it in another (deployer). Each entity must fulfill the obligations corresponding to its role for each specific AI system. This dual classification is common in multi-entity groups and requires centralized compliance tracking. Source: EUR-Lex
When do EU AI Act obligations take effect?
The EU AI Act entered into force on 1 August 2024. Prohibited AI practices apply from 2 February 2025. Obligations for general-purpose AI models apply from 2 August 2025. Most high-risk AI system obligations for providers and deployers apply from 2 August 2026, with certain high-risk systems in Annex I having until 2 August 2027. Organizations should begin compliance preparation well in advance of these deadlines. Source: EUR-Lex
What penalties apply for non-compliance with the EU AI Act?
Non-compliance penalties under the EU AI Act can reach up to €35 million or 7% of global annual turnover for prohibited AI practices, up to €15 million or 3% for other violations, and up to €7.5 million or 1.5% for supplying incorrect information. These are among the highest regulatory fines in EU law, exceeding GDPR maximums. SMEs and startups may receive proportionate penalties. Source: EUR-Lex
How does the AI Act interact with GDPR?
The EU AI Act operates alongside the GDPR and does not replace it. AI systems processing personal data must comply with both frameworks simultaneously. Article 10 of the AI Act explicitly references GDPR requirements for training data. Deployers conducting fundamental rights impact assessments under Article 27 should coordinate with their existing GDPR Data Protection Impact Assessments (DPIAs) under Article 35 GDPR. Organizations already maintaining ROPA and DPIA processes can leverage existing governance structures for AI Act compliance.
How does Priverion help with AI Act compliance for multi-entity groups?
Priverion provides a centralized AI register for classifying each AI system as provider, deployer, or both across subsidiaries. The Swiss-hosted platform includes AI-assisted DPIA and fundamental rights impact assessment templates aligned to Articles 9 and 27, human oversight tracking with automated recertification, cross-entity compliance dashboards, and quality management system documentation that maps existing ISO 27001 and ISO 27701 controls to AI Act requirements. All data is processed within Swiss infrastructure with zero customer data used for AI model training.