Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Who does the EU AI Act apply to - provider, deployer, importer and distributor roles

Who Does the EU AI Act Apply To? Provider vs. Deployer

“Who does the EU AI Act apply to?” is the first question every business should ask — and the answer is broader than most expect. The Act applies by role and reaches organizations far beyond the EU’s borders. If you build, sell, distribute, or simply use AI that touches the European market, you are likely in scope.

Who does the EU AI Act apply to - provider, deployer, importer and distributor roles

This guide breaks down exactly who the Act covers, the difference between a provider and a deployer, and a quick way to tell whether your organization has obligations. For the full picture, see our complete EU AI Act guide.

The EU AI Act’s global reach

Like the GDPR, the EU AI Act is extraterritorial. It applies to any provider that places an AI system on the EU market, and to providers or deployers whose AI system output is used within the EU — regardless of where the organization is headquartered. A US or Asian company serving European customers is squarely covered. Because the Act is a Regulation (Regulation (EU) 2024/1689), it also applies uniformly across all member states with no national variations to track.

The four roles the Act regulates

Obligations attach to roles, not just companies — and one organization can hold several roles at once. Mapping your role for each AI system is the essential first step.

Providers

Those who develop an AI system (or have it developed) and place it on the market or put it into service under their own name or trademark. Providers carry the heaviest obligations, especially for high-risk systems.

Deployers

Those who use an AI system under their own authority in a professional capacity. Most businesses adopting third-party AI are deployers — and they have real duties too, including human oversight and using systems strictly as instructed.

Importers and distributors

Those who bring an AI system from outside the EU into the market, or make it available along the supply chain. They must verify that the provider has met its obligations before the system changes hands.

Product manufacturers

Those who place an AI system on the market together with their product and under their own name take on provider-level responsibility for that system.

Provider vs. deployer: why the distinction matters

The provider/deployer line is where most confusion — and most risk — sits. Providers must build conformity in: risk management, technical documentation, data governance, and conformity assessment. Deployers inherit a lighter but real set of duties: operating the system as intended, ensuring meaningful human oversight, monitoring performance, keeping logs, and in some cases completing a fundamental rights impact assessment. Crucially, a deployer that substantially modifies a high-risk system, or puts its own name on it, can become a provider in the eyes of the Act — inheriting the full obligation set.

A quick scope self-check

Ask three questions. Do you develop or brand any AI system? Then you are a provider. Do you use AI tools in your operations — from CV screening to customer chatbots? Then you are a deployer. Is any of that activity connected to people or markets in the EU? Then the Act applies. If you answered yes to the first or second question and yes to the third, you have obligations to map now.

Know your role, prove your compliance.

Our EU AI Act Toolkit includes role-based policies, provider and deployer responsibility matrices, and the documentation you need whichever hat you wear — editable in Word and Excel.

Explore the EU AI Act Toolkit →

Frequently asked questions

Does the EU AI Act apply to companies outside the EU?

Yes. Any provider placing an AI system on the EU market, and any provider or deployer whose AI output is used in the EU, is in scope regardless of location.

Can one company be both a provider and a deployer?

Yes. Roles attach per system. You might deploy a third-party AI tool (deployer) while also developing your own AI feature (provider) — each with its own obligations.

Are deployers really regulated, or just the AI vendors?

Deployers are regulated. Even if you only use AI, you must ensure human oversight, follow the provider’s instructions, and monitor the system — treating the Act as “a vendor problem” is a common and costly mistake.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.