The cast of characters — and the duty to understand AI

Lesson 4 of 5 in The EU AI Act at a Glance: Purpose, Scope, and the Risk Pyramid.

Article 3 is sixty-eight definitions long, and the whole Act hangs on a handful of them. You already know the first: the OECD-aligned AI system definition from the Foundations domain — machine-based, varying autonomy, possible adaptiveness, and above all inference from inputs to outputs. The Act reuses that definition verbatim as its gateway: no inference, no AI system, no Act.

The next set defines who owes what. The Act never says "companies must…" — it assigns every obligation to a named role, and the same organisation can hold different roles for different systems (or switch roles mid-stream, as you will see in the value-chain module).

The operator taxonomy (Art 3) — learn these cold
RoleDefinition in one lineInstant example

Provider

Develops an AI system or GPAI model — or has one developed — and places it on the market under its own name or trademark

The vendor whose logo is on the hiring tool

Deployer

Uses an AI system under its authority in a professional context

The HR department running that hiring tool

Importer

EU-established entity placing a system from a third-country provider on the Union market

The Amsterdam subsidiary bringing a US vendor’s system into the EU

Distributor

Makes a system available on the market without being provider or importer

A software marketplace reselling the licence

Authorised representative

EU-established person mandated in writing by a non-EU provider to perform its duties

The Dublin firm acting for a Singapore model developer

Operator

Umbrella term: any of the above

Used when the Act addresses the whole chain at once

Four more definitions do outsized work, and each one anchors a later module:

Intended purpose — the use the provider states in the instructions and documentation. Classification, risk management, and deployer duties all key off it. Its shadow twin, reasonably foreseeable misuse, forces providers to plan for predictable off-label use — the teenager’s homework chatbot used for medical advice.

Substantial modification — a change not foreseen in the provider’s conformity assessment that affects compliance or purpose. Cross that line and the modifier can become the provider, inheriting everything (Art 25).

Deep fake — AI-generated or manipulated image, audio, or video that resembles real people, places, or events and would falsely appear authentic. Triggers the Art 50(4) labelling duty.

Serious incident — an incident causing death, serious harm to health, serious and irreversible disruption of critical infrastructure, infringement of fundamental-rights obligations, or serious harm to property or the environment. This definition starts the reporting clocks you will meet in the conformity module.

Article 4 is the Act’s sleeper provision — and it has applied since 2 February 2025, alongside the prohibitions, well before most other obligations. Note what it does and does not do. It binds both providers and deployers, for all AI systems, not just high-risk ones. "Sufficient" is contextual: a radiologist supervising diagnostic AI needs different literacy than a marketer using a text generator, and the assessment must consider the people the system is used on, not only the people using it. It extends beyond employees to contractors and agents acting on the organisation’s behalf.

There is no standalone fine tier for breaching Art 4 — but do not read that as toothlessness. Literacy failures surface as evidence in everything else: an untrained reviewer undermines the human-oversight case under Art 14, weakens the deployer’s Art 26 defence, and colours any liability claim after an incident. The Commission maintains a living repository of AI-literacy practices to show what "sufficient" looks like in the field. For most organisations, Art 4 was the first AI Act obligation they actually had to act on — and, conveniently for you, an AI-governance training programme like this one is exactly the kind of measure it demands.

Key terms: provider, deployer, intended purpose, substantial modification, AI literacy, serious incident

Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.