By Rafael Luque Ocaña

When you stop being the deployer and become the provider: the three scenarios under Article 25

This whole series explains obligations that don't fall on you because they belong to the provider. Article 25 says when they do — and there are three closed-list circumstances, not a grey area.

Five articles in this series say the same thing in different words: the Article 17 quality management system, the Article 18 documentation retention duty, Annex IV, the Article 72 post-market monitoring duty and the Article 73 serious incident reporting duty are not obligations of the deployer.

This one closes the series by saying the opposite: when they are. Because there are three circumstances in which the deployer becomes the provider, and with that change, all the previous ones land on them.

The three scenarios, closed list

Article 25(1) is explicit: any distributor, importer, deployer or other third-party shall be considered to be a provider — and shall be subject to the obligations of Article 16 — in any of these circumstances:

“a) when they put their name or trademark on a high-risk AI system already placed on the market…, without prejudice to contractual arrangements stipulating that the obligations are otherwise allocated.”

“b) when they make a substantial modification to a high-risk AI system that has already been placed on the market… in such a way that it remains a high-risk AI system.”

“c) when they modify the intended purpose of an AI system… which has not been classified as high-risk… in such a way that the AI system concerned becomes a high-risk AI system.”

There are three, and there is no fourth. Integrating, customising, configuring or using something heavily isn't enough. The grey area many people imagine isn't in the article.

Letter (b) doesn't mean 'any change'

It's worth pausing here, because "substantial modification" sounds like an everyday phrase, and it has its own definition:

“a change to an AI system after its placing on the market… which is not foreseen or planned in the initial conformity assessment carried out by the provider and as a result of which the compliance… is affected, or results in a modification to the intended purpose for which the AI system has been assessed.”

Two conditions narrow the scenario considerably. The first: the change must not have been foreseen in the initial conformity assessment. Configuring parameters the product offers, activating modules the manufacturer already contemplated, or adjusting thresholds within what was foreseen doesn't count, because the provider already assessed it.

The second: the change must affect compliance with the requirements or change the intended purpose. A change that touches neither of the two isn't substantial, however much work it took.

Put the other way round: substantially modifying a system means doing something to it that its manufacturer didn't contemplate and that alters what it was assessed for. It isn't customising it.

Letter (c) is the easiest one to cross without noticing

And it doesn't require touching the software.

It's enough to change what a system is used for when it wasn't high-risk, so that it becomes one. The tool is the same; the intended purpose is different; the classification changes — and whoever changed the purpose becomes the provider.

It's exactly the question that stayed open when we talked about staffing agencies: a firm that offers its clients, as its own service, a system built on third-party tools may fall under letter (a) or letter (c) without ever having explicitly decided which. And the answer isn't in the use: it's in under what brand the service is provided and what it's said to do.

What happens to the initial provider, which is what closes the split

Article 25(2) answers the question the series left hanging, and it does so bluntly:

“…the provider that initially placed the AI system on the market… shall no longer be considered to be a provider of that specific AI system… That initial provider shall closely cooperate with new providers and shall make available the necessary information and provide the reasonably expected technical access and other assistance…”

So the role transfers, it doesn't duplicate. Whoever takes on the brand or the substantial modification keeps the obligations; the original provider exits, and in exchange is bound to cooperate and provide what's needed.

With one caveat worth knowing before signing anything:

“This paragraph shall not apply in cases where the initial provider has clearly specified that its AI system is not to be changed into a high-risk AI system and therefore does not fall under the obligation to hand over the documentation.”

In other words: if the manufacturer expressly warned that its product must not become high-risk, whoever turns it into one takes on the role without the right to be handed the documentation. They're left with the provider's obligations and without the material to meet them. That warning, when it exists, is usually found in the product's terms.

And the fine-tuning case

It deserves a mention because it's the question that comes up most, and it already has its own article covering the full ladder — using, modifying, rebranding — and the threshold the Commission set. It isn't repeated here.

What this one adds is the framework: fine-tuning doesn't change your role on its own. It changes it if it puts you in one of the three circumstances of Article 25(1), so the useful question isn't "how much have I fine-tuned?" but "under what brand does this go out, and what do I say it's for?"

The three questions that settle it

Under what brand is it provided? If it's yours, on top of someone else's high-risk system, letter (a) — subject to the express reservation the article itself makes for contractual arrangements.

Have you changed it beyond what the manufacturer contemplated? And if so, does it affect the requirements or the assessed purpose?

Are you using it for something different from what it was placed on the market for? It's the quietest of the three routes, because it leaves no technical trace.

If all three answers are no, you remain the deployer, and the five obligations that open this article don't fall on you. If any is yes, it isn't one that falls on you: they all do.

Content in accordance with Articles 3, 16 and 25 of Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744 (Official Journal of the EU, 24 July 2026).

This article is for informational purposes only and does not constitute legal advice.

Get analysis like this in your inbox

Alethexis regulatory and product news. No noise.

I agree to receive communications from Alethexis: content about AI and regulation, and product news. I can unsubscribe at any time.

Controller: ALETHEXIS, S.L. (CIF B88758057). Purpose: to send you the Alethexis newsletter (content about AI and regulation, and product news). Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time. Retention: until you unsubscribe or after 24 months of inactivity. Rights of access, rectification, erasure, objection, restriction and portability: [email protected]. You may lodge a complaint with the Spanish Data Protection Authority (AEPD, www.aepd.es). More information in the privacy policy.