regulacyjna · 11 min czytania ·

AI Act — Provider vs Deployer: Who Is Responsible for What in the AI Supply Chain

The AI Act splits responsibility between the provider (vendor) and the deployer (AI user). Polish SMEs are most often deployers — they have fewer obligations but still concrete ones. A complete role map.

The AI Supply Chain Has Many Roles — and Each Carries a Different Obligation Package

Most Polish SMEs are not AI model providers. They are their customers — they buy Copilot, use Salesforce with AI modules, deploy HR-tech tools with CV screening functionality. In the AI Act terminology, this role is called a deployer — and it carries a narrower but concrete set of obligations that cannot be shifted to the vendor by contract.

The other side — the provider — is the entity that develops an AI system or commissions its development and places it on the market under its own brand. The provider package is heavier, but that does not mean the deployer can rest easy. In particular, Article 25 describes situations where a deployer becomes a provider — and this status change is one of the biggest operational risks when modifying third-party AI.

In this article we break down the supply chain into the five roles defined in Article 3, show the obligations per role, and close with five scenarios typical for Polish SMEs.

Five Roles Under Article 3

Article 3 of Regulation 2024/1689 defines:

  • Provider (point 3): a natural or legal person, public authority, agency or other entity that develops an AI system or GPAI model or commissions its development and places it on the market or puts it into service under its own name or trade mark, for payment or free of charge.
  • Deployer (point 4): a natural or legal person, public authority, agency or other entity using an AI system under its own responsibility — except for personal non-professional use.
  • Authorised representative (point 5): an entity established in the EU that has received written authorisation from a non-EU provider to act on its behalf regarding AI Act obligations.
  • Importer (point 6): an entity established in the EU that places on the market an AI system bearing the name or trade mark of a non-EU entity.
  • Distributor (point 7): an entity in the supply chain, other than the provider or importer, that makes an AI system available on the EU market.

The most common roles in a Polish SME are provider (if you build an AI product) or deployer (if you buy and use AI). Importer and distributor are relevant for distributors of American or Asian software in the EU.

Provider Obligations for High-Risk Systems — Arts. 16–21

Article 16 is a compliance checklist. A provider of a high-risk system must:

  • ensure the system’s compliance with the requirements in Chapter III, Section 2 (Arts. 8–15);
  • indicate on the system the provider’s name, registered trade name or trade mark and address;
  • have an implemented quality management system (Art. 17);
  • retain documentation (Art. 18) and logs (Art. 19);
  • carry out a conformity assessment (Art. 43) before placing on the market;
  • draw up an EU declaration of conformity (Art. 47);
  • affix CE marking (Art. 48);
  • register the system in the EU database (Arts. 49, 71);
  • take corrective action and notify authorities of non-conformities (Art. 20);
  • cooperate with supervisory authorities (Art. 21).

This is a package that cannot be built in a week. A realistic timeline for an SME provider is six to twelve months for the first cycle, with significant legal and technical consulting involvement.

Deployer Obligations for High-Risk Systems — Article 26

Article 26 imposes the following obligations on deployers:

  • use the system in accordance with the provider’s instructions (para. 1);
  • assign human oversight to persons with appropriate competence, training and support (para. 2);
  • to the extent the deployer controls input data — ensure that it is relevant and sufficiently representative (para. 4);
  • monitor the system’s operation and notify the provider and supervisory authority of risks or serious incidents (para. 5);
  • retain logs automatically generated by the system — for at least six months, unless EU or national law requires otherwise (para. 6);
  • before deploying a high-risk system in the workplace, inform workers’ representatives and the workers affected (para. 7);
  • register in the EU database if the deployer is a public authority or acting on their behalf (para. 8);
  • where the system’s decision concerns a natural person — inform that person that they are subject to a high-risk system (para. 11);
  • cooperate with supervisory authorities (para. 12).

For certain deployers, a FRIA (Fundamental Rights Impact Assessment) obligation under Article 27 applies — see further below.

When a Deployer Becomes a Provider — Article 25

Article 25(1) is clear: a distributor, importer, deployer or other third party is considered a provider of a high-risk system — and takes over all obligations under Article 16 — in three situations:

  • they place their name or trade mark on a high-risk system already placed on the market (rebranding, white-labelling);
  • they make a substantial modification to the system (as defined in Article 3(23));
  • they change the intended purpose of an AI system in a way that brings it into the high-risk category.

This is the trap that SMEs most frequently fall into unknowingly. A classic scenario: you purchase a GPT model from an external provider, fine-tune it on your own dataset for CV screening, and sell it under your own brand as “MyHR AI.” Under the AI Act, you have become a high-risk provider — with the full package of Arts. 16–21, Art. 43, Art. 71.

Operationally, this means one rule: any project that modifies, rebrands or redirects a third-party AI system requires a separate status assessment before the project starts.

GPAI Provider Obligations — Arts. 53–55

Providers of general-purpose AI models — GPAI — have a separate package, independent of the high-risk category. Article 53 requires:

  • technical documentation of the model, including the training process and evaluation;
  • making information and documentation available to downstream providers (i.e. Polish SMEs integrating these models);
  • a procedure for compliance with EU copyright law;
  • publication of a sufficiently detailed summary of training data according to the AI Office template.

Article 55 adds additional obligations for GPAI with systemic risk — in practice this concerns the largest models, with compute above the Art. 51 thresholds. For Polish SMEs this is relevant indirectly — as a recipient of these models through an API, you receive documentation that previously had to be extracted through contractual pressure.

FRIA — Fundamental Rights Impact Assessment — Article 27

Article 27 imposes on certain deployers the obligation to carry out a fundamental rights impact assessment (FRIA) before the first deployment of a high-risk system. The obligation applies to:

  • public authorities and entities providing public services;
  • deployers of systems under Annex III, points 5(b) and 5(c) (credit scoring, life and health insurance pricing).

The FRIA covers a description of the process in which the system is used, the period and frequency of use, the categories of persons exposed, specific risks, human oversight measures, and procedures in the event of risk materialisation. The FRIA outcome must be transmitted to the supervisory authority.

For an SME deployer in fintech or insurance, this is a new compliance artefact — one worth building in parallel with the DPIA under GDPR Article 35. Synergies are discussed further in our article on the joint NIS-2 + AI Act compliance stack.

Five Polish SME Scenarios

Scenario 1: you purchase Copilot for your team. Microsoft is the provider; your company is the deployer. Copilot is not classified as a high-risk system — it falls into the limited-risk category (transparency towards the end user, Art. 50). Your obligations are minimal — employee notification, usage monitoring.

Scenario 2: you deploy HR-tech AI for CV screening. The HR-tech vendor is a high-risk provider (Annex III, point 4). Your company is a high-risk deployer — with the full package under Art. 26: notification to candidates and employees, logging, human oversight, FRIA (if you fall within Art. 27(1) — most private-sector SME employers do not, but verification is required).

Scenario 3: you integrate GPT-4 as a copilot for your customer service team. OpenAI is a GPAI provider. Your company — if it uses the model only through the API, in a function not covered by Annex III — is a limited-risk deployer. Obligations: informing end users that they are interacting with an AI system (Art. 50).

Scenario 4: you fine-tune an open-source model for credit scoring and sell it under your own brand. You have become a high-risk provider — through the combination of substantial modification of the model with an Annex III, point 5(b) intended purpose. Full package of Arts. 16–21, Art. 27(1)(b) for your deployers (financial institution customers).

Scenario 5: you are a distributor of a US SaaS with AI in the EU. If the SaaS is high-risk and the vendor has no authorised representative in the EU — you may be treated as an importer (Art. 23) or authorised representative (Art. 22) — with specific obligations including verifying that the provider has carried out a conformity assessment and prepared the documentation.

QA10 — Where We Verify This

In the AiP Audit we assign roles for each AI system in the client’s stack — who is the provider, who is the deployer, and whether there is a risk of the deployer taking on the provider role under Article 25. For deployers in Annex III, point 5 categories, we also prepare the first iteration of the FRIA.

NEWSLETTER // MONTHLY AI DIGEST FOR BUSINESS

What next // you read the article · time to talk?

Do these topics apply to your company?

30 minutes with the CEO. No sales rep. We will check together whether what you read applies to you.

Book a call with the CEO Check ROI calculator
Paleta poleceń
  • Strona główna/
  • Kontakt/kontakt/
  • Kalkulator ROI/kalkulator/
  • Audyt AiP/audyt-aip/
  • QDeployment/qdeployment/
  • QCare/qcare/
  • Pełen proces/proces/
  • MenToR — AI dla uczelni/mentor/
  • Engineering Lab/engineering-lab/
  • Venture Projects/projekty/
  • O nas/o-nas/
  • Case Studies/case-studies/
  • Baza wiedzy/baza-wiedzy/
  • Umów diagnostykę 30 min/kontakt/#booking
  • Oblicz ROI/kalkulator/
  • Kalkulator Dig.IT/kalkulator/
  • dlaNGO MVP demo/projekty/#dlango-mvp
  • LSO:ATOM/o-nas/#lso-atom
  • FAQ /projekty//projekty/#faq
CtrlK|Esc|Enter19