Enterprise AI Glossary · Reviewed August 2026

Provider vs Deployer

EU AI Act roles: the provider places an AI system on the market; the deployer uses it under their authority.

What is Provider vs Deployer?

Most enterprises are deployers, not providers. Deployer duties (oversight, monitoring, fundamental-rights impact assessment) are different from provider duties (conformity assessment, technical documentation, post-market monitoring). Knowing which role you play for each system is the start of any compliance plan. See EU AI Act-Ready Architecture.

What is an example of Provider vs Deployer?

A company buying a recruitment tool is normally its deployer. If it substantially modifies the tool and offers the changed system under its own name, it may assume provider obligations for that system.

How is Provider vs Deployer different from related concepts?

Provider and deployer are regulatory roles, not synonyms for software vendor and end user. Importers, distributors, product manufacturers, authorized representatives, and operators have separate definitions.

What should enterprises evaluate for Provider vs Deployer?

  • Map the contracting parties, branding, development responsibility, intended-purpose decisions, modifications, and supply chain for each system.
  • Assign obligations and evidence to the correct legal entity rather than relying on a vendor’s general compliance statement.
  • Review the role whenever the system is fine-tuned, integrated into a product, repurposed, or offered to another organization.

Authoritative sources

Primary sources for the formal meaning, requirements, or original research behind Provider vs Deployer:

Putting Provider vs Deployer to work?

VDF AI runs governed AI agents on your own infrastructure — on-premises, sovereign cloud, or air-gapped. Book a working session to map the architecture.

Talk to VDF AI

Try VDF AI free →