Provider
A provider is a natural or legal person that develops an AI system or a general-purpose AI model, or has one developed, and places it on the market or puts it into service under its own name or trademark, whether for payment or free of charge. Providers bear the Regulation's most extensive package of obligations: risk management, data governance, documentation, conformity assessment, CE marking.
The concept is defined in Article 3(3). The decisive test is placing the system on the market under one's own name or trademark — not where development physically took place, nor who wrote the code. The vast majority of Hungarian SMEs are not providers but deployers: they use a purchased or subscribed AI tool. A deployer can nonetheless become a provider through several routes: by offering a procured system under its own brand (white-labelling), by substantially modifying it, or by changing its intended purpose so that it becomes high-risk. For high-risk systems, providers carry the twelve-point obligation package of Article 16: risk management system, data governance, technical documentation, logging, quality management, conformity assessment, CE marking, EU database registration, and post-market monitoring. Two obligations, however, also apply to deployers: the AI literacy duty of Article 4 and part of the transparency rules of Article 50.
This is the costliest misunderstanding: a company that believes it is "just" a deployer because it uses a purchased tool can easily slide into the provider's obligation package if it brands, modifies, or repurposes the system.
Need documented AI-literacy training?
Article 4 is a duty of diligence: what counts is not knowledge in the abstract, but demonstrable, documented effort. Our starter package lets you begin free.
Start freeRelated terms
- DeployerA deployer is a person that uses an AI system under its own authority in the course of a professional activity — unless the system is used in the course of a purely personal, non-professional activity. Mere use, however intensive, does not make a company a provider; deployers are subject to the far narrower Article 26.
- Substantial modificationA substantial modification is a change to an AI system after it has been placed on the market or put into service, which is not foreseen or planned in the initial conformity assessment, and which affects compliance with the high-risk requirements or modifies the intended purpose for which it was assessed. Anyone who makes a substantial modification to a system already on the market becomes a provider under Article 25.
- EU declaration of conformityThe EU declaration of conformity is the provider's written statement that a high-risk AI system meets the applicable requirements of the Regulation. It must be drawn up per system, made available to the market surveillance authority, and kept for at least ten years after the system is withdrawn from the market.
- CE markingThe CE marking is the high-risk AI system provider's declaration that the system complies with the Regulation's requirements. It must be affixed, after the conformity assessment procedure is completed, visibly, legibly and indelibly to the system or its packaging, or — where this is not possible — to the accompanying documentation.
Related questions in the knowledge base (Hungarian)
- Szolgáltató vagy alkalmazó a cégem az AI Act szerint, és miért számít ez?Szolgáltató az, aki AI-rendszert fejleszt vagy fejlesztet, és azt saját neve vagy védjegye alatt hozza forgalomba. Alkalmazó az, aki saját felügyelete alatt használ egy rendszert szakmai tevékenységben. A puszta használat, bármilyen intenzív, nem tesz szolgáltatóvá. A szolgáltatóra a 8–22. cikk teljes csomagja hárul, az alkalmazóra a jóval szűkebb 26. cikk.
- Mikor válik egy AI-t használó cégből szolgáltató az AI Act szerint?A 25. cikk (1) bekezdése három esetben telepíti át a szolgáltatói státuszt: ha a cég saját nevét vagy védjegyét helyezi el egy már forgalomban lévő magas kockázatú rendszeren, ha lényegesen módosítja azt, vagy ha a rendeltetés megváltoztatásával tesz magas kockázatúvá egy addig nem annak minősülő rendszert. Szerződéses kikötés ezen nem változtat.
- Mi a szolgáltató kötelezettségeinek teljes listája magas kockázatú AI-rendszernél?A 16. cikk tizenkét pontban sorolja fel őket, két rétegben. A termék-réteg a 8–15. cikk: kockázatkezelés, adatkormányzás, műszaki dokumentáció, naplózás, átláthatóság, emberi felügyelet, pontosság és kiberbiztonság. A szervezeti réteg a 17–21., 43. és 47–49. cikk: minőségirányítás, dokumentumőrzés tíz évig, megfelelőségértékelés, EU-megfelelőségi nyilatkozat, CE-jelölés és regisztráció.
- Mit örököl a cég, ha az AI Act szerint szolgáltatóvá válik?A teljes 16. cikkes kötelezettségcsomagot, nem részlegesen: kockázatkezelés, adatkormányzás, műszaki dokumentáció, naplózás, alkalmazói tájékoztatás, emberi felügyelet tervezése, pontosság és kiberbiztonság, minőségirányítási rendszer, megfelelőségértékelés, EU-megfelelőségi nyilatkozat, CE-jelölés, regisztráció, forgalomba hozatal utáni nyomon követés és incidensbejelentés. Az eredeti szolgáltató ilyenkor megszűnik az adott rendszer szolgáltatója lenni.