Art 25: when you become the provider

Lesson 4 of 5 in The Value Chain: Providers, Deployers, Importers, Distributors.

Roles are not tattoos — they are functions, and functions change hands. Art 25 is the Act’s musical-chairs rule: do certain things to a system, and the full provider burden — Arts 8–15, conformity assessment, CE marking, registration, the 10-year file — lands on you, whatever your business card says.

Any distributor, importer, deployer or other third party is deemed a provider of a high-risk system if it does one of three things:

  • (a) Rebrands — puts its name or trademark on a high-risk system already on the market or in service (contract clauses can allocate tasks differently, but the deemed-provider status itself follows the trademark).
  • (b) Substantially modifies — makes a substantial modification to a high-risk system such that it remains high-risk.
  • (c) Repurposes upward — modifies the intended purpose of a system (including a GPAI system) that was not high-risk, such that it becomes high-risk.

Three practical consequences follow. First, white-labelling is provider status: buying a high-risk system wholesale and selling it under your brand transfers the entire compliance burden to you, and the original provider steps out of the provider role for that system — while owing you a statutory duty of cooperation, documentation and technical access (unless it expressly forbade high-risk conversion).

Second, upstream contracts become compliance infrastructure. Art 25(4) requires the provider of a high-risk system and third parties supplying AI systems, tools, services, components or processes used or integrated into it to specify, by written agreement, the information, capabilities, technical access and assistance the provider needs to comply — the AI Office may publish model contractual terms. One carve-out: the duty does not bind third parties supplying tools or components other than GPAI models to the public under a free and open-source licence.

Third, the trap runs both ways for deployers: a bank that takes a general-purpose chatbot and wires it into creditworthiness decisions has changed the intended purpose of a non-high-risk system into an Annex III one — trigger (c) — and is now a provider, not merely a deployer.

Have you just become the provider? Walk Art 25

Interactive decision tree — outcomes:

  • You are now the provider (Art 25(1))

    The full provider stack is yours: Arts 8–15 compliance, Art 17 QMS, conformity assessment (a new one, for substantial modifications — Art 43(4)), declaration of conformity, CE marking, registration, 10-year documentation. The initial provider is released for this specific system but must cooperate, hand over information and give reasonably expected technical access (Art 25(2)) — unless it clearly excluded high-risk conversion. Get the written agreement in place before you touch the system, not after.

  • Your original role stands

    No Art 25 trigger fired: no rebranding, and any change stays within what the provider foresaw and assessed. You keep your existing duties — importer verification, distributor checks, or the Art 26 deployer set. Stay inside the instructions for use: drifting from them is how deployers wander into trigger (b) or (c) by accident.

  • No provider switch — but reclassify anyway

    Art 25 governs switches involving high-risk systems, so no provider status lands here. But you changed the system: re-run the classification analysis and, if it interacts with people or generates content, check the Art 50 transparency duties. Document the assessment — the burden of showing the system is not high-risk sits with whoever claims it.

Key terms: substantial modification, intended purpose, white labelling, fine-tuning

Interactive checkpoint quiz (1 questions) — open this page in a browser to take it.