Provider vs. Deployer: Who's Responsible?

Provider vs. Deployer: Who's Responsible?

A compliant vendor product does not make you compliant.

What Is Provider vs. Deployer: Who's Responsible??

The EU AI Act splits obligations between the provider who builds an AI system and the deployer who puts it to work, and buying a compliant product does not transfer the deployer's duties to the vendor. You'll separate the two roles, work out which obligations are yours, and evaluate vendor compliance documentation during procurement so gaps surface before a contract is signed rather than during an audit.

What You'll Learn in Provider vs. Deployer: Who's Responsible?

Provider vs. Deployer: Who's Responsible? — Training Steps

  1. Provider vs. Deployer

    The EU AI Act assigns different obligations depending on your role in the AI value chain: Provider - The company that develops an AI system, or has one developed, and places it on the market or puts it into service under its own name. Responsible for conformity assessment, CE marking, and technical documentation. Deployer - The company that uses an AI system under its own authority. Responsible for human oversight, monitoring, keeping logs, informing the people affected, and incident reporting. Public bodies, public-service providers and credit or insurance scoring deployers must also run a Fundamental Rights Impact Assessment (Article 27). BrightPath Consulting is a deployer. When the company buys a vendor's AI tool, the vendor's compliance does not absolve BrightPath of its own legal obligations under the Act.

  2. Email from IT Director

    An email arrives from Rachel Kim, BrightPath's IT Director. Three AI vendors have submitted proposals, and Alice needs to evaluate their compliance posture before procurement decisions are made.

  3. Vendor 1: TalentMatch AI

    Alice clicks the TalentMatch AI link in Rachel's email to open the vendor's compliance documentation. This vendor has done their provider obligations well: conformity assessment completed, CE marking obtained, technical documentation available, and intended purpose clearly stated. The system is classified as High Risk under Annex III area 4 (employment).

  4. Deployer Obligations for High-Risk AI

    Even though TalentMatch AI is a compliant vendor, BrightPath as the deployer has its own set of mandatory obligations under the EU AI Act. These obligations exist independently of the vendor's compliance status. Alice opens the Deployer Obligations Checklist linked in Rachel's email.

  5. Knowledge Check: Deployer Responsibility

  6. Vendor 2: QuickReply Bot

    The next vendor is QuickReply Bot, a customer service chatbot. Alice clicks the QuickReply Bot link in Rachel's email. This is a Limited Risk AI system. Its main duty is transparency: the provider must build the bot so customers know they are talking to AI, not a human, and it is built that way. BrightPath's part as deployer is simpler: keep that disclosure visible in its own chat widget.

  7. Vendor 3: InsightIQ

    The final vendor is InsightIQ, an AI-powered employee performance analytics platform. Alice clicks the InsightIQ link in Rachel's email to open the product page. Something about this vendor's claims should raise a red flag.

  8. The Misclassification Problem

    InsightIQ processes employee performance data to make promotion and team composition recommendations. This is employment-related AI decision-making, which is High Risk under Annex III of the EU AI Act. The vendor either deliberately misclassified the product to avoid compliance costs, or genuinely does not understand the regulation. Either way, BrightPath cannot rely on the vendor's self-classification. As a deployer, the company has an independent duty to verify risk classification before deployment.

  9. Knowledge Check: Misclassified Vendor

  10. Send Procurement Recommendations

    Alice replies to Rachel with a per-vendor recommendation: which tools BrightPath can deploy, under what deployer conditions, and which one must be rejected outright.

Security Framework Coverage

NIST CSF

  • PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind

EU AI Act

  • Art. 16 Obligations of providers of high-risk AI systems
  • Art. 26 Obligations of deployers of high-risk AI systems