Short answer. A provider builds or rebrands an AI system and places it on the market. A deployer uses that system under its own authority in a professional setting. Under Article 3 of the EU AI Act these two roles carry different duties, and for high-risk systems both sets apply from 2 August 2026. A bank that licenses a credit-scoring model is a deployer. A bank that builds one, or puts its own name on a vendor’s model, becomes a provider and inherits the heavier obligations of Article 16.
The provider and deployer split decides who does what. A provider, defined in Article 3(3), develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark. A deployer, defined in Article 3(4), uses an AI system under its authority in the course of a professional activity. The same company is often both, on different systems.
For a high-risk system the two roles map to two articles. Article 16 lists the provider duties: a quality management system, technical documentation, a conformity assessment, CE marking, an EU declaration of conformity, registration in the EU database, and corrective action when the system fails. Article 26 lists the deployer duties: use the system according to the provider’s instructions, assign competent human oversight, monitor operation, keep logs, and run a fundamental rights impact assessment where required.
In financial services the role you hold sets your compliance workload and your liability. AI systems that evaluate the creditworthiness of natural persons or set a credit score are high-risk under Annex III, point 5(b), with an exception for fraud detection. Most banks and insurers in Central Europe buy these models from vendors, which makes them deployers. That does not make the obligations light. Deployer duties under Article 26 cannot be shifted to the vendor by contract.
The dates are fixed. High-risk obligations under Annex III apply from 2 August 2026. Deployers of credit-scoring and insurance-pricing systems, Annex III points 5(b) and 5(c), must complete a fundamental rights impact assessment before first use. DORA already requires financial entities to govern the ICT third parties behind these models, so the provider and deployer question also decides which contract clauses and monitoring duties you own.
A provider builds or rebrands an AI system and places it on the market; a deployer uses it under its own authority (Article 3).
Article 16 sets the heavier load. A provider of a high-risk system runs a quality management system, keeps technical documentation current, passes a conformity assessment before the system reaches the market, draws up an EU declaration of conformity, affixes the CE marking, and registers the system in the EU database. The provider keeps logs, monitors the system after release through a post-market monitoring plan, and takes corrective action or withdraws the system when it stops meeting the requirements. These duties sit with whoever placed the system on the market under their name, whether they wrote the code or commissioned it.
Article 26 defines the deployer’s duties. The deployer uses the system according to the provider’s instructions for use, assigns human oversight to people with the competence, training, and authority to exercise it, and makes sure input data is relevant for the intended purpose. The deployer monitors operation, suspends use and informs the provider when the system presents a risk to health, safety, or fundamental rights, keeps the automatically generated logs for at least six months, and informs people when a high-risk system is used in decisions about them. Where the system is listed in Annex III, the deployer runs a fundamental rights impact assessment first.
Article 25 draws the line. A deployer, distributor, or importer becomes a provider, and takes on the full Article 16 obligations, in three cases: it puts its own name or trademark on a high-risk system already on the market, it makes a substantial modification to such a system, or it changes the intended purpose so that a system becomes high-risk. When this happens the original provider must cooperate and hand over the information and technical access the new provider needs. For a bank, white-labelling a vendor’s scoring model under its own brand is enough to cross this line.
A bank that licenses a credit-scoring model from a vendor and runs it on its own customers is a deployer. The vendor that built and sells the model is the provider. The bank still owns the Article 26 duties: human oversight, monitoring, logging, informing rejected applicants, and a fundamental rights impact assessment before go-live. The moment the bank rebrands the model, retrains it into a materially different system, or repurposes a general model into credit scoring, Article 25 turns it into a provider with the full conformity-assessment and CE-marking load.
No. Deployer obligations under Article 26 stay with the deployer. A contract can allocate commercial risk and require the vendor to supply documentation, but it cannot move the legal duty to run human oversight, keep logs, or complete a fundamental rights impact assessment. Regulators hold the deployer accountable for how the system is used in production. This is why the role question is a board-level decision, not a procurement footnote.
Ableneo shipped 34 production AI projects in 2025, about 4 of 5 reaching production, across banking and insurance clients in Slovakia, the Czech Republic, and Austria. That work starts with a plain question for each AI system: are you the provider or the deployer, and what does that role require by 2 August 2026. We map every model in a client’s estate to a role, then to the specific Article 16 or Article 26 obligations it triggers, so the governance is documented before an auditor asks. See our AI transformation FAQ for the connected questions on high-risk classification and conformity assessment.
Key takeaways
Planning AI in a regulated business? Ableneo takes systems from classification to governed production.