Provider
Article 3, point 3, of Regulation (EU) 2024/1689:
a natural or legal person, public authority, agency or other body that develops an AI system or a general-purpose AI model or that has an AI system or a general-purpose AI model developed and places it on the market or puts the AI system into service under its own name or trademark, whether for payment or free of charge.
Whoever develops an AI system — or has it developed — and places it on the market or puts it into service under its own name or trademark.
It is whoever develops the system, or has it developed, and puts it on the market under its own name or trademark.
Which obligations it carries
It is not an obligation: it is a role, and it is the role on which the Regulation places almost everything. Article 4 is a legal obligation of providers and deployers applicable from 2 February 2025, as a measures-based obligation. Article 50(1) — informing that one is interacting with an AI system — is a legal obligation of the provider applicable from 2 August 2026. Post-market monitoring and the reporting of serious incidents under Articles 72 and 73 are a legal obligation of the provider applicable from 2 December 2027.
What it is not
It is not “the manufacturer of the software you buy”. One is a provider because of what one does with a system, not for being in the software business. A company that commissions an agency to develop a system and puts it into service under its own brand is the provider of that system, even without writing a line of code: Article 3, point 3, says “or that has an AI system … developed”. And it is not a company-wide role: it is assigned per system. The same organisation can be the deployer of twelve tools and the provider of one.
The nuance almost nobody captures
There are two distinct routes to becoming a provider, and confusing them produces the most costly error in the allocation of roles. Article 3, point 3 — developing or commissioning and placing on the market under one’s own brand — is not limited to high risk: it operates on any system. Article 25(1) — becoming the provider of a system that was already on the market — is so limited, in all three of its points. Hence “Article 25 only operates on high risk” is true and does not mean “on minimal risk you are never a provider”.
Related terms
To find out more
- Annex IV is not an obligation: it's the index of someone else's document
- The Article 17 quality management system isn't yours to set up
- Keeping ten years of documentation you don't generate
- When you stop being the deployer and become the provider: the three scenarios under Article 25
- The 'you're talking to an AI' notice is the provider's job, not yours
- Post-market monitoring: the system belongs to the provider, the information is yours
- Serious incidents: the provider reports, but the clock starts when you find out