Back to blog

Blog / Getting started

Provider vs Deployer vs GPAI Provider under the EU AI Act

Published 21 July 2026·Last updated 21 July 2026·8 min read
Author: ActBrief Editorial·Reviewer: Methodology pending external legal review

Not legal advice. This article is a preliminary technical guide for AI SaaS teams. Always confirm classification and obligations with qualified counsel. Effective dates reflect the Digital Omnibus updates as of July 2026.

Changelog
Updated 21 July 2026: Annex III standalone high-risk obligations deferred to 2 December 2027; Annex I embedded high-risk to 2 August 2028 (Council approval 29 June 2026). Art. 50 transparency remains 2 August 2026.

Why role analysis comes first

Risk category answers what obligations might apply. Role answers who must do the work. Mixing them up produces wrong checklists (and wrong counsel questions).

Quick definitions (operational)

RolePlain-English test
ProviderYou develop / place an AI system on the market under your name
DeployerYou use an AI system under your authority
GPAI providerYou place a general-purpose AI model on the market

Many SaaS companies are providers of a system that uses a third-party GPAI model. That is not “OpenAI is the only provider.”

Common SaaS patterns

1. Wrapper chatbot on GPT

2. HR ranking SaaS

3. Customer uses your AI inside their HR process

What to ask counsel

  1. For each AI feature, who is provider vs deployer?
  2. Does integrating GPAI change our obligations?
  3. Do we need an authorised representative as a non-EU provider?
  4. Which Art. 50 duties apply from 2 August 2026 regardless of Annex III?

Next step

Map roles in one page, then run a free readiness brief. Related: AI deployer obligations.


Not legal advice. Role labels are fact-specific.

Official sources

Ready for legal review?

Get a free readiness brief for your product — not a commodity risk label.

Get a free readiness brief for your product