Provider or deployer — which are you?

Under the EU AI Act a provider develops an AI system, or has it developed, and puts it on the market under its own name. A deployer uses one under its own authority in a professional capacity. Article 50's disclosure duty for conversational AI binds the provider; deployers carry the duties on emotion recognition and deepfakes.

General guidance, not legal advice. This page summarises publicly available material on Regulation (EU) 2024/1689 and links the primary sources. It is not a substitute for advice from a qualified lawyer on your own circumstances. Confirm anything you intend to rely on with counsel.

Last reviewed 25 August 2026.

Two roles, two sets of duties

The AI Act does not treat everyone touching an AI system alike. It defines roles, and Article 50 hands each role a different list. The Commission's FAQ sets the definitions out, and the Article itself allocates the paragraphs.

A provider develops an AI system or has one developed, and places it on the market or puts it into service under its own name or trademark. Providers carry paragraphs 1 and 2: disclosing AI interaction, and marking synthetic output in a machine-readable way.

A deployer uses an AI system under its own authority in the course of a professional activity — which is nearly every business running a bought-in tool. Deployers carry paragraphs 3 and 4: telling people when they are exposed to emotion recognition or biometric categorisation, and disclosing deepfakes and certain AI-generated text.

Why this matters more than it sounds

Read that allocation against a clinic that has bought an AI receptionist. The obligation everyone associates with the AI Act — tell the caller they are speaking to a machine — is a paragraph 1 duty. Paragraph 1 is a provider duty. The clinic is a deployer.

Meanwhile the duties the clinic does carry, paragraphs 3 and 4, are about emotion recognition, biometric categorisation and deepfakes. An agent that answers the phone, checks a diary and books an appointment is doing none of those things.

The practical conclusion is unglamorous: for a large number of businesses deploying a straightforward AI receptionist, direct Article 50 exposure is thinner than the volume of compliance marketing suggests. That is not a reason to ignore it. It is a reason to ask your vendor the right question instead of buying a product you do not need.

Where a deployer drifts into being a provider

The line is not fixed. You can start as a deployer and end up carrying provider obligations. The usual routes are putting the system on the market under your own name or trademark — white-labelling it as your own product — or modifying it substantially rather than configuring it.

Loading your services, prices, opening hours and a custom greeting is configuration. Rebuilding the model's behaviour, or reselling the agent to your own customers as your product, is the kind of thing that invites the question. If you are anywhere near that line, it is a question for counsel rather than for a vendor's website.

What to ask a vendor

Since the disclosure duty is theirs, the useful posture is verification rather than construction. Four questions cover most of it:

  • Does the agent disclose that it is an AI at the start of every call, in the language of the call?
  • Can I hear a recording of that disclosure on my own scenarios before I commit?
  • Are call recordings and transcripts retained in a way that evidences the disclosure was made?
  • Where is call data processed and stored, and does that survive a procurement review?

The openings we use are written out here, and the Article 50 timing and the December date are covered here.

Common questions

What is the difference between a provider and a deployer under the AI Act?
Under the EU AI Act a provider develops an AI system, or has it developed, and puts it on the market under its own name. A deployer uses one under its own authority in a professional capacity. Article 50's disclosure duty for conversational AI binds the provider; deployers carry the duties on emotion recognition and deepfakes.
If I buy an AI receptionist, am I a provider?
Normally no. Buying a system and configuring it for your business — your services, your calendar, your greeting — leaves you a deployer. You would move toward the provider role if you put the system on the market under your own name or trademark, or modified it substantially.
Do my employees count as deployers?
No. The Commission's FAQ is explicit that employees acting under their employer's instruction are not separate deployers. The employer remains the responsible party.
Does the AI Act apply if my vendor is outside the EU?
Yes. The obligations reach providers placing systems on the EU market regardless of where they are established, so a non-EU vendor selling into the EU is still within scope.
As a deployer, what do I actually owe under Article 50?
Paragraphs 3 and 4: informing people exposed to emotion-recognition or biometric-categorisation systems, and disclosing deepfakes and certain AI-generated text. A plain booking receptionist usually triggers neither, which is why many deployers have little direct Article 50 exposure.

Related

Want to hear a compliant opening?

We will run our agent against your own call scenarios during a free two-week proof-of-concept, disclosure included, so you can judge it on your line rather than in a demo.

Book a proof-of-concept