Who Is Regulated Under the EU AI Act? Understanding Providers, Deployers, Importers, Distributors and Other Operators
Understand who is regulated under the EU AI Act. This guide explains providers, deployers, importers, distributors, authorized representatives, product manufacturers, and how an organization’s role in the AI value chain determines its obligations.
The EU Artificial Intelligence Act does not regulate only the companies that develop artificial intelligence. It distributes responsibility across the AI value chain, assigning different legal roles to organizations depending on what they do with an AI system or general-purpose AI model.
This distinction matters because an organization's obligations under the AI Act depend not only on the type and risk classification of the AI involved, but also on the organization's role in relation to that technology. The Act therefore uses the umbrella concept of an “operator” to capture several participants in the AI ecosystem.
Those roles include providers, deployers, authorized representatives, importers, distributors and product manufacturers. Importantly, the roles are not mutually exclusive: the same organization may qualify for more than one role depending on its activities.
Understanding these categories is therefore one of the first steps in determining whether—and how—the EU AI Act applies to an organization.
Operator classifications are functional rather than permanent. A company may begin as a distributor, importer or deployer and later assume the obligations of a provider because of what it does to the system.
Status Can Shift Along the AI Value Chain
For example, Article 25 can shift provider responsibilities where another operator substantially modifies a high-risk AI system or places its own name or trademark on it.
Practice Tip: Organizations should not determine their AI Act role only when they first purchase or deploy an AI system. Material changes to the system, its intended purpose, branding, distribution model or position in the supply chain can require the classification to be revisited.
Perhaps the most important practical point is that these classifications should not be treated as boxes from which an organization selects only one. A company might, for example:
- provide one AI system that it develops itself;
- deploy another system purchased from a third-party provider;
- distribute another company's AI product; and
- become the provider of a previously acquired system after substantially modifying it.
The roles are not mutually exclusive.
The analysis may even differ across products, business units and individual AI systems within the same organization.
Practice Tip: Perform this analysis system by system and based on actual functions rather than contractual labels. Operator classification determines which AI Act obligations apply and should be revisited when the system, its intended purpose, branding, or the organization’s position in the AI value chain changes.

Providers
Article 3(3); Article 25
The provider is the central regulated actor under much of the AI Act. A provider is a natural or legal person, public authority, agency or other body that:
- develops an AI system or a general-purpose AI (GPAI) model, or has one developed; and
- places it on the market or puts the AI system into service under its own name or trademark, whether for payment or free of charge.
Being a provider is not necessarily synonymous with being the programmer who wrote the code.
A company may qualify as the provider because it had the system developed by somebody else and then markets or deploys it under its own identity. Conversely, the fact that a company technically developed some or all of an AI system does not necessarily resolve the provider analysis without considering how the system is subsequently placed on the market or put into service.
Practice Tip: Organizations acting as providers of high-risk AI systems should expect to carry the primary compliance burden under the AI Act. Provider status is therefore a critical threshold determination when assessing an organization’s obligations.
Quasi-Providers: A Company Can Become a Provider Later
Provider status can also arise after an AI system has already entered the market.
Article 25 addresses circumstances in which another participant in the AI value chain effectively takes over the responsibilities of the original provider.
For example, a distributor, importer, deployer or other third party may become subject to the obligations of a provider when it:
- puts its name or trademark on a high-risk AI system already placed on the market or put into service;
- makes a substantial modification to a high-risk AI system; or
- changes the intended purpose of an AI system in a way that causes it to become a high-risk AI system.
This rule is particularly important for companies customizing or repurposing third-party AI. Buying an AI product from another provider does not necessarily mean that the purchaser will remain only a deployer. What the purchaser subsequently does with the system can change its regulatory status.
Deployers
Article 3(4); Article 26
A deployer is a natural or legal person, public authority, agency or other body that uses an AI system under its authority, except where the AI system is used in the course of a personal, non-professional activity.
Deployers are organizations that use AI in their operations rather than developing or marketing the underlying system.
For example, an employer using an AI recruitment system, a bank using AI to assess customers, or a public authority using an AI system in delivering public services may qualify as deployers.
By contrast, an individual using an AI application solely for personal purposes generally does not become a deployer under the Act.
Who Is the Deployer in a SaaS Relationship?
Cloud and software-as-a-service arrangements can make the analysis less intuitive.
The key issue is who uses the AI system under its authority. In a conventional SaaS arrangement, the customer using the system will generally be the deployer rather than the SaaS provider.
But the analysis can change where an AI platform enables customers to assemble their own AI systems from models, software modules, tools or other components. Depending on how the platform operates and who exercises control, the platform itself may potentially assume a deployer role.
Practice Tip: The practical lesson is that contractual labels such as “vendor,” “customer,” or “platform” do not determine operator status. The analysis turns on the parties' actual functions in relation to the AI system.
Importers
Article 3(6); Article 23
The importer concept connects the AI Act to the EU's traditional product-safety framework.
An importer is a person located or established in the EU that places on the EU market an AI system bearing the name or trademark of a natural or legal person established outside the EU.
In practical terms, the importer is the EU-based participant responsible for bringing a third-country provider's AI system into the EU market.
The distinction is generally easier to understand where AI is incorporated into a physical product. It can become considerably more complicated where the AI system consists of software supplied digitally into the EU. This is an area where determining who qualifies as the importer may raise questions.
Importers of high-risk AI systems have their own compliance responsibilities, including verification, documentation, reporting, labeling, storage and cooperation obligations.
Distributors
Article 3(7); Article 24
A distributor is a person in the AI supply chain, other than the provider or importer, that makes an AI system available on the EU market.
The distinction between an importer and distributor largely concerns the participant's position in the supply chain.
An importer introduces an AI system associated with a non-EU provider into the EU market. A distributor makes an AI system available after it has already been placed on that market.
Like importers, distributors of high-risk AI systems have independent obligations. These include verifying certain compliance requirements before making the system available, addressing identified risks, ensuring appropriate storage and transport, taking corrective measures where necessary and cooperating with supervisory authorities.
Importantly, an organization that performs both functions can be subject to both sets of obligations.
Practice Tip: Think of the AI supply chain as potentially moving from Provider → Importer → Distributor → Deployer, but do not assume every arrangement follows this sequence. Map the actual functions performed by each participant, as real-world AI supply chains may be more complex and an organization may occupy more than one role.
Authorized Representatives
Article 3(5); Article 22
An authorized representative is an EU-established person that has received and accepted a written mandate from a provider to perform specified obligations and procedures under the AI Act on the provider's behalf.
This mechanism is particularly important because the AI Act has significant extraterritorial reach. A provider does not necessarily need to be established in the EU to fall within the Act.
Where the relevant conditions apply, a non-EU provider must designate an authorized representative established in the EU. The representative provides an EU-based point of contact through which regulators can interact with the provider and performs the tasks specified in its written mandate.
Practice Tip: An authorized representative should therefore not be understood simply as a commercial representative or reseller. It is a specific regulatory role created by the AI Act.
Product Manufacturers
Article 25(3)
AI increasingly operates as part of another product—a medical device, machine, toy or other regulated product. The AI Act therefore also addresses product manufacturers.
Where a high-risk AI system is a safety component of a product covered by certain EU harmonization legislation and the AI system is placed on the market or put into service together with that product under the product manufacturer's name or trademark, the product manufacturer assumes the obligations of the AI system's provider.
This rule prevents responsibility from becoming fragmented simply because one company developed an AI component while another markets the finished product.
The AI Act itself does not generally define who is a “manufacturer.” That question may instead depend on the relevant EU product legislation governing the underlying product.
What Is an “Operator” Under the EU AI Act?
The AI Act uses operator as an umbrella term for several participants involved in developing, supplying, placing on the market, putting into service, distributing or using AI systems.
Rather than asking simply whether an organization “uses AI,” the better questions are:
- Did the organization develop the AI?
- Did it have the AI developed for it?
- Under whose name or trademark is the system offered?
- Who places the system on the EU market?
- Who uses the system and under whose authority?
- Has someone modified an existing AI system?
- Is the AI incorporated into another regulated product?
The answers determine the organization's role and, consequently, its obligations.
The distinction is particularly important for high-risk AI systems because responsibility for compliance with the AI Act's substantive requirements depends in significant part on the operator's position in the value chain.
Additional Resources and Legal Citations
For readers who want to go directly to the relevant provisions of the EU Artificial Intelligence Act, the following provisions are particularly useful for understanding the different operator roles and their responsibilities:
- Regulation (EU) 2024/1689 (EU AI Act), Article 3 — Definitions. Defines the principal actors discussed in this article, including provider (Art. 3(3)), deployer (Art. 3(4)), authorized representative (Art. 3(5)), importer (Art. 3(6)), distributor (Art. 3(7)), and operator (Art. 3(8)).
- Article 16 — Obligations of Providers of High-Risk AI Systems. Establishes the principal obligations applicable to providers of high-risk AI systems, including ensuring compliance with the requirements applicable to those systems.
- Article 22 — Authorized Representatives of Providers of High-Risk AI Systems. Addresses the designation, mandate, and responsibilities of authorized representatives established in the EU.
- Article 23 — Obligations of Importers. Establishes the obligations of importers before placing a high-risk AI system on the EU market and their responsibilities when they have reason to believe a system is not compliant.
- Article 24 — Obligations of Distributors. Establishes the verification and other responsibilities applicable to distributors before making a high-risk AI system available on the EU market.
- Article 25 — Responsibilities Along the AI Value Chain. Particularly important for determining when a distributor, importer, deployer, or other third party becomes subject to the obligations of a provider, including because it places its name or trademark on a high-risk AI system, makes a substantial modification, or modifies the system's intended purpose in a manner that makes it high-risk. Article 25 also addresses certain product manufacturers incorporating high-risk AI systems into regulated products.
- Article 26 — Obligations of Deployers of High-Risk AI Systems. Establishes obligations applicable to organizations using high-risk AI systems under their authority.
- Article 53 — Obligations for Providers of General-Purpose AI Models. Establishes requirements specifically applicable to providers of GPAI models, an important distinction from the operator framework applicable to AI systems.
