The value chain: provider, deployer, and everyone in between
Lesson 1 of 5 in Who’s Who in AI Governance: Actors, Roles, and Responsibilities.
Every AI governance question eventually reduces to one sentence: who owes what to whom? A model is trained by one company, fine-tuned by a second, resold by a third, and used by a fourth on people who never chose any of them. When the system discriminates, hallucinates, or leaks data, five organisations point at each other. Role taxonomies exist to end that argument before the harm, by attaching specific duties to specific positions in the chain.
The vocabulary that has become the lingua franca comes from the EU AI Act. Two roles carry almost all of the weight: the provider (who develops the system or has it developed, and places it on the market under its own name) and the deployer (who uses it under its own authority in a professional context). Around them sit the supporting cast: the importer (brings a non-EU system into the Union), the distributor (makes it available without changing it), the authorised representative (an EU-based stand-in for a non-EU provider), and — with rights rather than duties — end users and affected persons.
Read those definitions the way a regulator does. Three details decide most real cases:
- “Has developed” counts. Commissioning a system from a contractor and shipping it under your brand makes you the provider — outsourcing the code does not outsource the duty.
- “Under its own name or trademark” is the trigger. You can become a provider without writing a line of code, just by white-labelling.
- Deployment is about authority, not ownership. A hospital using a vendor’s diagnostic AI on its patients is the deployer, even though it never touches the model — because the decision to point the system at real people was the hospital’s.
Why does the split matter so much? Because information and control live in different places. The provider knows the training data, the test results, the failure modes; the deployer knows the patients, the applicants, the local context. So frameworks assign duties where the capability to discharge them lives: providers owe design-time obligations (risk management, documentation, testing), deployers owe use-time obligations (oversight, monitoring, informing affected people). Getting your own role wrong is the single most expensive classification error an organisation can make — you comply with the wrong checklist.
Key terms: provider, deployer, importer (AI Act), distributor (AI Act), authorised representative, affected persons
One complication: every framework renamed the same cast. ISO/IEC 22989 (the AI vocabulary standard) speaks of AI producers and AI subjects; NIST’s AI RMF speaks of AI actors across the lifecycle; US state laws speak of developers and deployers. The roles rhyme but the edges differ — and in cross-border work you will translate between them weekly. This crosswalk is the reference table to come back to; the rest of the academy uses EU AI Act vocabulary unless a jurisdiction demands otherwise.
| Function in the chain | EU AI Act | ISO/IEC 22989 | NIST AI RMF | US state laws (CO, TX) |
|---|---|---|---|---|
Builds the model or system | Provider (Art 3(3)) — includes “has developed” and white-labelling under your own name | AI producer / AI provider (with sub-roles like AI platform provider, AI product provider) | AI design & development actors — data scientists, ML engineers, TEVV specialists | Developer (Colorado SB 26-189; Texas TRAIGA) |
Uses it on real people, professionally | Deployer (Art 3(4)) — “under its authority”, non-personal use | AI customer / AI user | AI deployment, operation & monitoring actors | Deployer |
Moves it to market without changing it | Importer, distributor, authorised representative (Arts 22–24) | AI partner (e.g. system integrator) | Third-party entities; procurement actors | Largely unaddressed — duties concentrate on developer and deployer |
Checks and evaluates it | Notified body (third-party conformity assessment, Art 31) | AI partner (AI evaluator, AI auditor) | TEVV actors (test, evaluation, verification, validation) | Independent auditors (cf. NYC Local Law 144 bias audits) |
Is affected by its outputs | Affected persons — complaint right (Art 85), explanation of individual decisions (Art 86) | AI subject (data subject and “other subject”) | Affected individuals and communities | Consumer — notice and appeal rights |
Sets and enforces the rules | AI Office (GPAI, coordination) + national competent authorities and market surveillance authorities | Relevant authorities (policy makers, regulators) | Governance & oversight actors (organisational, not governmental) | State attorneys general — exclusive enforcement, no private right of action |
Walk the logic: which role are you?
Interactive decision tree — outcomes:
- You are the provider
You own the heaviest duty stack: risk management, data governance, technical documentation, conformity assessment, post-market monitoring. “A contractor built it” changes nothing — Art 3(3) covers systems you had developed.
- You are the deployer
Your duties are use-time duties: use per the instructions, assign competent human oversight, monitor operation, keep logs, inform affected people — and for many high-risk uses, run a fundamental-rights impact assessment first.
- You just became the provider (Art 25)
Rebranding, substantial modification, or repurposing into high-risk transfers the provider role to you — full obligations included. The original provider must hand over the documentation you now need, but the accountability is yours.
- You are the importer
Before placing the system on the market you must verify the provider did its homework: conformity assessment done, documentation drawn up, authorised representative appointed, CE marking affixed (Art 23). You are the Union’s checkpoint at the border.
- You are the distributor
You verify the CE marking and documentation exist and must not supply a system you have reason to think is non-compliant (Art 24). Touch the system — rebrand or modify it — and you stop being a mere distributor.
Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.