Provider and deployer (AI Act roles)
The EU AI Act allocates obligations according to an operator's role in the AI value chain, defined in Art. 3. A provider is a natural or legal person, public authority, agency or other body that develops an AI system or a general-purpose AI model, or has one developed, and places it on the market or puts it into service under its own name or trademark, whether for payment or free of charge (Art. 3(3)). A deployer is any such person or body using an AI system under its authority, except where the use is in the course of a personal non-professional activity (Art. 3(4)). Importers and distributors handle systems from third-country providers, and non-EU providers of high-risk systems must appoint an authorised representative in the Union (Art. 22).
Providers of high-risk systems carry the bulk of the obligations (Art. 16): compliance with the Chapter III Section 2 requirements, quality management system, documentation, conformity assessment, CE marking, registration, corrective actions, cooperation with authorities and post-market monitoring. Deployers (Art. 26) must use systems according to the instructions, ensure human oversight by competent persons, ensure relevant input data, monitor operation, keep logs, inform workers and affected persons, and in some cases perform a fundamental rights impact assessment. Under Art. 25, a deployer, distributor or importer becomes a provider, taking over all provider obligations, if it puts its own name or trademark on a high-risk system, makes a substantial modification to it, or modifies the intended purpose of a system (including a non-high-risk one) such that it becomes high-risk; the original provider must then cooperate and hand over documentation.
Life sciences companies often occupy several roles at once. A MedTech company developing an AI diagnostic is a provider; the hospital using it is a deployer; a pharmaceutical company that fine-tunes a general-purpose model into a pharmacovigilance case-processing tool and uses it internally is both the provider (it developed the system) and the deployer, even though it never sells it; a CRO running a vendor's AI-based patient recruitment tool for a sponsor is a deployer, and possibly a provider if it rebrands or repurposes it. Role determination should be documented for each system in the AI inventory, in parallel with the controller or processor analysis under the GDPR, since the two frameworks allocate responsibilities on different criteria (control over the system versus control over purposes and means of data processing). iliomad's AI compliance services include role mapping and contractual allocation along the value chain.
