deslopify.me

EU AI Act

EU AI Act

Provider or deployer? Roles when you build on an LLM API

Almost every obligation in the AI Act attaches to a role, not to a technology. Get the role wrong and you'll read the wrong half of the law. The short version: if you offer an AI feature under your own name, you're a provider — even though the model belongs to someone else.

The two roles the Act cares about

A provider develops an AI system, or has one developed, and places it on the market under its own name or trademark — payment or free of charge makes no difference. A deployeruses an AI system under its own authority in a professional context. Purely personal, non-professional use is outside the Act entirely. Most obligations you'll care about — including the transparency duties in Article 50 — name one of these two roles explicitly.

Calling a model API makes you a provider

The intuition "Anthropic built the model, so it's their problem" is wrong, and the Commission's transparency guidelines say so plainly: whoever offers a generative or interactive AI application on the EU market under their own name is the provider responsible for Article 50 compliance, regardless of whether the underlying model is licensed from someone else. Your product is an AI system; the model inside it is a general-purpose AI model. You are the downstream provider of the system. That's the role we hold for our own scoring and rewriting features — the model API is a component, not a shield.

What stays with the model provider

The model vendor keeps the general-purpose-model obligations of Chapter V — training-data summaries, model documentation, copyright policy — which have applied to them since August 2025 and never transfer to you. The ecosystem also leans on them for tooling: both the GPAI code of practice and the transparency code of practice push model providers to supply marking and watermarking machinery that downstream providers can adopt. Until your vendor ships that, your marking duty is bounded by technical feasibility — documented in writing, as we describe in our own case study.

Article 25: repurposing shifts responsibility

Roles aren't permanent. Under Article 25, whoever substantially modifies a system or changes its intended purpose becomes the provider of the result. This cuts both ways. It protects you: if a school takes a writing-style tool and uses it to grade students, the school has created a new — and likely high-risk — system and owns those obligations. And it disciplines you: your intended purpose is what you define through your interface, your terms, and your documentation, so define it explicitly. Our limitations page states outright that the score is not for evaluating people; one sentence like that is your Article 25 boundary marker.

You can be both at once

Roles attach per system, not per company. You're the provider of the AI features you ship — and simultaneously a deployer of the AI you merely use: the coding assistant in your editor, the AI text you publish on your own blog (that's Article 50(4) territory). Inventory your systems on both sides of the line; the obligations differ. The self-check walks you through exactly this sorting.

Not legal advice

These pages and the self-check share practitioner experience from making our own product compliant. They are technical orientation, not legal advice — for legal questions about your specific situation, talk to a lawyer.