EU AI Act Entity Types: Provider, Deployer & Importer
Key Takeaways (TL;DR)
- Hierarchy of Roles: The EU AI Act defines six distinct entity types, each carrying separate legal burdens under Regulation (EU) 2024/1689.
- The Article 25 Trap: Modifying a third-party AI model or adding white-label branding automatically converts a Deployer into a Provider, assuming full liability.
- Mandatory EU Liaison: Non-EU AI providers must appoint an Authorised Representative in the EU before offering high-risk AI systems.
- Revised Timelines: While prohibited practice rules apply today, high-risk provider duties take effect in December 2027 under the Digital Omnibus Act.
About the Author & Editorial Review: Written by Thomas A. H. (Fractional CTO & Engineering Advisor). Learn more about our engineering practice or contact our team. Fact checked and reviewed by Ingenire Editorial.
Most tech founders start their EU AI Act preparation by assessing product risk tiers. However, European regulators begin with a more fundamental question: Who are you in the supply chain? The EU AI Act assigns legal duties based on your entity role. In our advisory work with US scale-ups, we often discover companies accidentally assuming heavy Provider liabilities through minor API customizations. Consequently, establishing your exact entity classification early is essential before building compliance workflows.
What are the primary entity types under the EU AI Act?
EU AI Act Entity Types refer to the legal classifications defined in Regulation (EU) 2024/1689 that assign specific responsibilities across the artificial intelligence supply chain (EUR-Lex, 2024). Specifically, the Act identifies six core entity roles:
| Entity Type | Primary Role | Key Legal Obligation | Relevant Article |
|---|---|---|---|
| 1. Provider | Develops / markets AI model | Risk system, data audit, CE mark | Articles 3(2) & 16 |
| 2. Deployer | Uses AI in business capacity | Follow instructions, human logs | Articles 3(4) & 26 |
| 3. Importer | Places non-EU AI on EU market | Verify CE mark & documentation | Article 27 |
| 4. Distributor | Sells AI in EU supply chain | Verify provider compliance | Article 28 |
| 5. Authorised Rep | Non-EU provider's EU liaison | Regulatory contact & audit checks | Article 22 |
| 6. Product Manufacturer | Integrates AI into safety product | Full provider compliance for product | Article 25 |
1. The Provider (The Architect)
EU AI Act Provider is any natural or legal person that develops an AI system (or has one developed) and places it on the market under its own name or trademark (Article 3(2), 2024). In our experience, fine-tuning an open-source model and selling API access classifies you as a Provider. For example, Providers bear the heaviest legal burden, including mandatory conformity assessments.
2. The Deployer (The Operator)
EU AI Act Deployer is any entity using an AI system under its authority in a professional capacity. For example, a bank screening loans with an AI algorithm or an enterprise using AI resume screeners acts as a Deployer. Deployers must operate systems according to provider instructions and maintain human oversight logs.
3. Importer, Distributor, and Authorised Representative
Importers bring non-EU AI software into the EU market, while Distributors handle supply chain sales. Crucially, non-EU Providers offering high-risk AI in Europe must appoint an Authorised Representative established within the EU to liaise with regulators at the European AI Office.
Citation Capsule: EU AI Act Entity Classifications
- Source: Regulation (EU) 2024/1689 of the European Parliament and of the Council
- Effective Date: August 2, 2024 (phased through 2027)
- URL: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689
- Retrieved: July 2026
How does Article 25 reclassify deployers into providers?
Article 25 of the EU AI Act contains a critical legal trigger: a Deployer, Importer, or Distributor is automatically reclassified as a Provider if they modify an existing system in three specific ways (EU AI Office Art. 25, 2025):
[Existing AI Model] + [Substantial Modification OR Own Branding] ----> [RECLASSIFIED AS PROVIDER]
- White-Labeling: Putting your own name or trademark on a third-party high-risk AI system.
- Substantial Modification: Making architectural changes that alter the model's performance or safety profile.
- Purpose Modification: Changing the intended purpose of a limited-risk system so that it becomes high-risk.
In our experience auditing white-label AI tools, putting your logo on an AI vendor's software transfers the full legal duty of a primary developer to your startup. Consequently, engineering teams should evaluate white-label contracts carefully before shipping.
What are the specific legal obligations for AI providers vs deployers?
The legal requirements differ significantly between Providers and Deployers of high-risk AI:
- Provider Obligations: Must create technical documentation, establish continuous risk management systems, ensure training data quality, undergo conformity assessments, and apply CE marking.
- Deployer Obligations: Must implement human oversight, monitor system performance against provider instructions, retain automated logs for at least six months, and conduct Data Protection Impact Assessments (DPIA) under GDPR.
Furthermore, for detailed operational guidance, consult our overview on what US startups need to build for the EU AI Act and our guide on GDPR LLM RAG architecture traps.
How do US startups choose the right entity classification?
To avoid misclassifying your company and over-spending on unnecessary legal checks, engineering leaders should follow a structured decision workflow:
1. Are you training or fine-tuning models under your brand? ----> YES: You are a Provider.
2. Are you using a SaaS AI tool internally for staff? ----> YES: You are a Deployer.
3. Are you a US company selling high-risk AI to EU clients? ----> YES: Appoint an EU Authorised Representative.
In practice, entity classification sits inside a broader European market entry strategy. Review our EU expansion decision sequence and our 90-day EU readiness sequence to align compliance with sales. As a result, learn more about our execution methodology on our about page or contact our team for a 30-minute teardown.
Frequently Asked Questions
What is the difference between a Provider and a Deployer under the EU AI Act?
A Provider develops or brands an AI system for market sale, assuming primary regulatory liability. A Deployer uses an AI system in a professional capacity, following provider operating instructions.
What triggers Article 25 reclassification?
White-labeling a high-risk AI system under your trademark or making substantial modifications to its intended purpose automatically reclassifies a Deployer into a Provider.
Does a US startup need an EU Authorised Representative?
Yes. Non-EU Providers offering high-risk AI systems to European users must appoint an Authorised Representative located within the EU.
When do Provider obligations for high-risk AI take effect?
High-risk Provider obligations become enforceable in December 2027 under the Digital Omnibus Act update. However, prohibited practice bans have applied since February 2025 (see the February 2025 milestone).