top of page

Providers, Deployers and High-Risk AI Under the EU AI Act

A customer asking an AI vendor to “comply with the EU AI Act” is asking the vendor to follow the law. The request does not explain which duties belong to the vendor and which belong to the customer. That answer depends on each party's role for a specific AI system and on how the system is used.


For an applicant-scoring service, the HR technology company is generally the provider and the employer using the scores is generally the deployer. Applicant scoring is named on the Act's high-risk list because it can affect a person's access to a job.


Term

Plain-language meaning

Provider

The company responsible for bringing the AI system to market, or first using it itself, under its own name.

Deployer

The company or public body that uses the AI system in its work.

High-risk AI

AI used for safety functions or sensitive decisions in areas listed by the Act, including hiring, education, credit, and essential services.




Example role map for "applicant scoring" use-case


The role follows what each organization does rather than the labels the parties use, who pays for the service, or who hosts the model.


The following are examples of roles which could apply in an Applicant Scoring AI System:

  • HR technology company: Usually the provider because it develops or has the applicant-scoring system developed and supplies it under its own name.

  • Employer: Usually the deployer because it uses the system to support recruitment decisions.

  • Recruiter employed by the customer: Not usually a separate deployer because the recruiter acts on the employer's behalf.

  • External model or API company: A provider of an underlying model or system. Its role does not replace the HR company's provider role for the finished applicant-scoring system.

  • White-label seller or customer making major changes: A potential provider when it rebrands, makes a major change to, or repurposes a high-risk system.

One organization can hold different roles for different systems. An HR company may be the provider of its applicant-scoring product and the deployer of an AI coding assistant used by its own employees.



What is a provider?


In plain terms, the provider is the organization responsible for an AI system offered or first used under its own name. The Act's formal definition covers a company that develops the system itself or has another company develop it. Providing the system free of charge still counts.


A provider is not necessarily the company that trained the underlying model. A software company can become the provider by adding an external model to its own product and selling the finished system under its name. The model company may remain a provider for the underlying model.


For high-risk AI, the provider is responsible for the system's product compliance.

It must:

  • define what the system is intended to do and classify it;

  • test and manage risks, including risks in the data;

  • create technical records and automatic logs;

  • build in human oversight and give customers clear instructions;

  • meet accuracy, reliability, and cybersecurity requirements;

  • complete the required compliance assessment, registration, and CE marking; and

  • monitor the system after launch and act when problems occur.


The provider defines the intended purpose through its instructions, product documentation, website, and sales claims. A product presented as an applicant-scoring or candidate-ranking service is being sold for a high-risk purpose.



What is a deployer?


A deployer is the business or public body that puts the AI system to work. The employer using applicant scores is the deployer, while the individual recruiter is usually acting on the employer's behalf rather than becoming a separate deployer.


A customer does not become a deployer merely because it signs a licence agreement or sees an AI feature in an administrator console. The role arises when the organization uses the AI system under its authority. The same customer can be a deployer for one use and outside the role for an unused feature.


For a high-risk system, Article 26 requires the deployer to:

  • use the system in accordance with the provider's instructions;

  • assign oversight to trained people who have enough authority and support to challenge the system;

  • check that the input data it controls is suitable for the intended use;

  • monitor the system and report risks and serious incidents;

  • keep automatically generated logs under its control for at least six months, unless another law provides otherwise;

  • tell workers and their representatives before using high-risk AI in the workplace; and

  • tell people, including job candidates, when listed high-risk AI makes or supports a decision about them.


Some deployers must also document how the system could affect people's rights, register their use, or meet industry-specific rules. Data protection, employment, equality, and consumer law continue to apply.


The provider must supply enough information and capability for the deployer to perform these tasks. The deployer remains responsible for how it operates the system.



Provider and deployer roles can change


A customer or other third party can take on the provider role under Article 25 when it:

  • puts its own name or trademark on the system;

  • makes a major change that affects compliance or the intended purpose; or

  • changes the intended purpose so that a system which was not high-risk becomes high-risk.


For example, a customer that turns a general document-analysis tool into a candidate-ranking system may become the provider of the resulting system. An employer that configures an applicant-scoring service within the provider's instructions will generally remain the deployer.


The names the parties use for themselves do not override the roles created by the Act.



How high-risk classification works


Being a provider or deployer does not automatically make the AI system high-risk. The role describes what the organization does, while the classification describes what the system does and how much it can affect people or safety.


The Act has two main high-risk categories:


  1. AI used for product safety. The AI is a product or safety component covered by EU product law, and the product requires an independent compliance assessment. Examples can include medical devices, vehicles, toys, and lifts.

  2. AI used for decisions listed in Annex III.  These uses cover areas such as biometrics, critical infrastructure, education, employment, credit, essential services, law enforcement, migration, justice, and elections.


Machinery is now treated separately. Regulation (EU) 2026/1744 moved the Machinery Regulation (EU) 2023/1230 from Section A to Section B of Annex I. Machinery therefore does not follow the ordinary direct high-risk route described above: only the limited AI Act provisions identified in Article 2(2) apply directly, while AI-specific safety requirements are to be incorporated into machinery law.


The Act allows some Annex III tools that perform only narrow administrative or preparatory tasks to be classified as not high-risk. This is possible only when the system does not meaningfully influence the decision or create a significant risk to people. The exception does not apply when the system profiles a person, meaning it uses personal data to assess aspects of that person. The provider must document and register a not-high-risk conclusion.


A human making the final decision does not by itself remove the high-risk classification. The analysis depends on what the system does and how its output affects the decision.



Which AI use cases are high-risk?


The current Annex III list covers the following use areas:


Biometrics

Identifying people at a distance, grouping people by certain sensitive or protected traits, and recognizing emotions in situations where the use is not prohibited.

Critical infrastructure

AI safety controls for critical digital infrastructure, road traffic, water, gas, heating, or electricity.

Education and vocational training

Admissions, access and placement, evaluating learning outcomes, assigning education levels, and monitoring prohibited behaviour during tests.

Employment and work

Targeting job advertisements, filtering applications, evaluating candidates, promotion and termination decisions, task allocation based on personal characteristics or behaviour, and worker monitoring or evaluation.

Essential private and public services

Eligibility for public assistance, personal credit scoring other than fraud detection, life and health insurance risk assessment or pricing, and emergency-call evaluation, dispatch, and triage.

Law enforcement

Uses such as assessing risks to people, evaluating evidence, and profiling in criminal investigations, where the law permits the use.

Migration, asylum, and border control

Risk assessments, application reviews, identity support, and monitoring or detecting people at borders.

Justice and democratic processes

Helping courts research and apply the law, and influencing election or referendum outcomes or voting behaviour.


This list is use-specific. A meeting assistant that only transcribes an internal project call is not classified in the same way as a feature that scores a candidate from an interview transcript. A general-purpose label such as “assistant,” “analytics,” or “decision support” does not settle the classification.


High-risk systems are permitted when the relevant requirements are met, while prohibited practices are a separate category. For example, using AI to infer emotions in the workplace is generally prohibited except for medical or safety reasons, while applicant scoring is generally high-risk.


This list is use-specific. A meeting assistant that only transcribes an internal project call is not classified in the same way as a feature that scores a candidate from an interview transcript. A general-purpose label such as “assistant,” “analytics,” or “decision support” does not settle the classification.


High-risk systems are permitted when the relevant requirements are met, while prohibited practices are a separate category. For example, using AI to infer emotions in the workplace is generally prohibited except for medical or safety reasons, while applicant scoring is generally high-risk.



When the relevant obligations apply


Rules on AI literacy, which require staff to have suitable knowledge for their AI work, and the original Article 5 prohibited-practice rules have applied since 2 February 2025.


Article 50's transparency duties apply from 2 August 2026 to all systems within its scope, regardless of when they were placed on the market. The only grace period runs to 2 December 2026 and applies solely to the Article 50(2) marking and detection duty for generative systems placed on the market before 2 August 2026. The Article 50(1) duty to tell people when they are interacting directly with an AI system has no corresponding grace period.


The amended high-risk dates are now law. The Digital Omnibus, Regulation (EU) 2026/1744, was adopted on 8 July 2026, published in the Official Journal on 24 July, and entered into force on 27 July. It sets 2 December 2027 for listed uses such as applicant scoring and 2 August 2028 for AI connected to regulated products.


The later high-risk dates do not postpone obligations that already apply, and they do not change the meaning of provider and deployer. Before those dates, organizations can establish the classification, provider evidence, deployer controls, and change process required for each system.



A practical role and classification record


A practical starting point is one record for each AI system and use:


  1. Identify the specific AI capability and version rather than only the software product.

  2. Record the intended purpose, actual use, affected people, decisions, and data.

  3. Map each organization to its role for that system.

  4. Assess prohibited practices, the two high-risk categories, disclosure rules, and other applicable law.

  5. Link the provider's instructions and evidence to the deployer's controls.

  6. Reassess when the system, claims, provider instructions, or organizational use changes.


This record gives procurement, legal, compliance, HR, and product teams a shared basis for their decisions and operating controls.



How Validaitor supports role and classification decisions


Validaitor helps organizations define the AI system and its intended use, map provider and deployer roles, assess high-risk classifications, connect provider evidence to deployer controls, and monitor changes that can alter the conclusion.


For a review of the roles and obligations around an AI product or organizational use, talk to us.




Author: Art Richards, Berlin


This post is general information, not legal advice. Legal sources checked on 30 July 2026.

bottom of page