Compliance 10 min read

AI Act Supply Chain: Who Is Responsible for What?

The EU AI Act assigns different obligations to providers, deployers, importers, and distributors. Understanding your role in the AI supply chain is essential for compliance.

By Dr. Marcus Weber · Published

The AI Value Chain Under the AI Act

One of the most complex aspects of the EU AI Act is its supply chain approach to regulation. Unlike regulations that focus on a single entity, the AI Act distributes obligations across every organization in the AI value chain—from the developer who builds the model to the company that deploys it to end users.

Key Roles Defined

Provider (Developer)

The provider is any natural or legal person that develops an AI system or has an AI system developed and places it on the market under its own name. Providers carry the heaviest compliance burden: design and develop the system in compliance with AI Act requirements, conduct conformity assessments before market placement, prepare and maintain technical documentation (Annex IV), implement quality management systems (Article 17), register the system in the EU database (Article 49), affix CE marking upon successful conformity assessment, and conduct post-market monitoring and report serious incidents.

Deployer (User Organization)

The deployer is any organization that uses an AI system under its authority. Deployers must: use the system in accordance with the provider's instructions, ensure meaningful human oversight by appropriately trained individuals, monitor the system's operation for risks and report issues to the provider, conduct a Fundamental Rights Impact Assessment (FRIA) when required, inform individuals that they are subject to a high-risk AI system decision, and keep logs generated by the system for the required retention period.

Importer

An importer is any natural or legal person established in the EU that places an AI system from a third country on the EU market. Importers must verify that the provider has completed conformity assessment, ensure CE marking and EU Declaration of Conformity are present, confirm the provider has appointed an authorized representative in the EU, verify technical documentation is available and complete, and not place a system on the market if they believe it is non-compliant.

Distributor

A distributor is any natural or legal person in the supply chain (other than the provider or importer) that makes an AI system available on the EU market. Distributors must verify basic compliance indicators before making the system available.

When Roles Change: The "Becoming a Provider" Rule

Article 25 contains a critical provision: a deployer, distributor, or importer becomes a provider when they put their own name or trademark on a high-risk AI system, make a substantial modification to a high-risk AI system, or modify the intended purpose of an AI system in a way that makes it high-risk. This means if your organization fine-tunes a foundation model, customizes a vendor's AI system significantly, or repurposes an AI tool for a different use case, you may inherit the full provider obligations.

The Authorized Representative

Providers established outside the EU must appoint an authorized representative within the EU before placing their systems on the market. The authorized representative maintains copies of conformity documentation for at least 10 years, cooperates with national competent authorities, provides all necessary information on request, and terminates the mandate if they believe the provider is in violation.

Getting It Right

Supply chain compliance under the AI Act requires coordination across multiple organizational boundaries. Start by mapping your AI systems against the roles defined in the regulation, then systematically address each obligation.

Need expert guidance on AI supply chain compliance? Search our directory for consultants who specialize in AI Act supply chain obligations.