← Blog

Provider or Deployer Under the EU AI Act? The Role Question for Software Built for Others

Marco Masut

A deployer, under the EU AI Act, is a natural or legal person that uses an AI system under its own authority, except in a personal non-professional activity. A provider is whoever develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark. Those are the Article 3 definitions of Regulation (EU) 2024/1689. For a software house, the role depends on what it delivers, not on the tool it writes code with: using an assistant like Claude Code, Cursor, or Copilot makes you a deployer of that tool, which has a different provider. You become a provider only if what you deliver is, or contains, an AI system that goes out under your name, for example an AI feature built into a product you sell to several clients. This piece explains how to tell which box you are in, without promising compliance.

For what the Act covers in general, see the piece on the EU AI Act for software houses. Here we only deal with the role.

Which Two Boxes Does the Regulation Define?

Regulation (EU) 2024/1689 names several roles: provider, deployer, importer, distributor, authorised representative. For a software house the first two matter most. The Article 3 definitions in short (text consulted on October 3, 2026):

RoleHow Article 3 defines itPractical question
ProviderDevelops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark, for payment or free of chargeDoes the system go out under my name?
DeployerUses an AI system under its own authority, except in a personal non-professional activityAm I using a system built by someone else, for work?

Note that the provider definition includes whoever has the system developed by others: what counts is who places it on the market under their own name, not who physically wrote the lines.

The Typical Case: Building Software for a Client With AI Tools

Here you are a deployer of the tools, not a provider. Claude Code, Cursor, and Copilot are AI systems developed and placed on the market by others; you use them under your own authority, in a professional capacity. Using them to write a back-office app, an online shop, or an integration does not turn that software into an AI system, and does not make you a provider of anything. As a deployer you have one obligation that already applies: since February 2, 2025, Article 4 asks for an adequate level of AI literacy among the people who use these tools on your behalf.

If your role stops there, the Regulation asks little of you. The client will still ask what the agent did and who checked it: that is a question of proof, not of role.

When Do You Become a Provider Without Noticing?

It happens when what you deliver is, or contains, an AI system that goes out under your name. Three situations to recognise:

  • You sell several clients, under your own brand, a product with an integrated AI function (an assistant, scoring, automatic classification): for that function you are the provider.
  • You take an AI system already on the market and put your own brand on it.
  • You substantially modify a high-risk AI system already on the market, or change its intended purpose so that it becomes high-risk.

The last two come from Article 25, which has a precise condition: it applies to high-risk systems. Per the text, whoever puts their name or trademark on such a system, makes a substantial modification, or changes the intended purpose so that the system becomes high-risk is considered the provider of that system, and the initial provider no longer is for that system (consulted October 3, 2026). For most software house projects this scenario does not arise. If the client works in areas like hiring or credit scoring, stop and clarify it before writing code.

One case the Regulation does not settle in a single line: you build an AI function on commission and hand it to the client, who uses it under their own brand. Typically the client is the provider, because they put it into service under their own name, but the reading depends on the contract and the facts. That calls for legal review, not a general rule.

What Changes in Practice Between the Two Roles?

For high-risk systems, Article 26 lists the deployer's obligations. The main ones (consulted October 3, 2026): take appropriate technical and organisational measures to use the system according to the provider's instructions; assign human oversight to people with the necessary competence, training, and authority; monitor operation and report risks or serious incidents to the provider; keep the automatically generated logs for at least six months; inform affected workers and the people subject to decisions. The provider carries heavier obligations, on technical documentation, conformity assessment, and risk management. The deadlines for high-risk systems were moved by the Digital Omnibus, as explained in the general piece.

These obligations concern high-risk systems. If your product is not one, the gap between the two roles narrows a lot, but the question of who the provider is still belongs in writing.

The Three Lines to Put in the Contract

You do not need chapters. You need three sentences, written before anyone disputes them:

  1. Who is the provider of any AI system included in the delivery, and under what name it is put into service.
  2. Who guarantees human oversight and log retention, if the system is high-risk.
  3. Which AI tools the team used to develop it, and who reviewed and approved the code before release.

The third is the one no rule usually imposes directly, and the prudent client asks for first. Proving it takes a record of what an agent produced and what a person checked, like a bill of materials for AI-generated code or AI-assisted code review.

This piece is not legal advice and does not promise compliance: it shows how to read the definitions, not how to apply them to your contract. For the proof side, Detent, the end-to-end delivery system (detent-ai.com), keeps intent, authorised context, execution, and human signature together from signal to release, so the question "who approved what" has a documented answer. How that works, measured, is on the bench page.