Security

Deployer vs provider under the AI Act: operational checklist for SMEs

5 min read
Deployer vs provider under the AI Act: operational checklist for SMEs

For most Italian SMEs, the relevant AI Act role is deployer: you use AI systems under your authority; you do not place them on the market as your own product. Understanding the difference avoids both underestimation and useless over-compliance.

General information, not legal advice.

Clear definitions (without legalese)

According to Article 3 of the AI Act:

  • Provider: a natural or legal person that develops an AI system (or a GPAI model) or has it developed and places it on the market or puts it into service under its own name or trademark, for payment or free of charge.
  • Deployer: a natural or legal person that uses an AI system under its authority, except where the system is used in the course of a personal non-professional activity.

Typical examples:

| Scenario | Most frequent role | |---|---| | You use Microsoft Copilot / ChatGPT Enterprise at work | Deployer | | You have a customer chatbot on a third-party model API, branded as yours and offered as a product | Often provider (or duties to assess carefully) | | A partner builds an internal assistant on your corpus, used only by you | Usually you are deployer; the partner may be provider | | You fine-tune/rebrand a system substantially and put it back on the market | Possible shift toward provider duties |

The boundary can move if you substantially modify the system or put it into service under your own name. When in doubt: inventory + professional advice.

Deployer SME checklist (8 points)

Use it as an operational list, not a certification.

  1. Tool and use-case inventory
    Tool name, process, owner, data touched, users.

  2. Professional vs personal use
    Company accounts, not private logins on work data (Shadow AI pattern).

  3. Transparency toward external users
    If a system talks to people (chatbot), it must be clear they are interacting with AI. From 2 August 2026, these transparency duties are central to European enforcement (Commission press release).

  4. Staff AI literacy
    Proportionate measures already due under Art. 4 (from 2 February 2025).

  5. Data rules
    What must not be uploaded; GDPR alignment; retention.

  6. Human oversight on critical points
    Especially if output influences decisions about people, money, or compliance.

  7. Ownership and escalation
    Who is accountable if the output is wrong (accountability post).

  8. High-risk screening
    Check whether any use falls into sensitive categories (HR, credit, access to essential services, etc.) described by the Commission. Full Annex III obligations have a later horizon (December 2027 after Omnibus), but waiting “in the dark” is not a strategy.

When an SME also becomes a provider

You become a provider, or approach provider duties, if for example:

  • you develop an AI system and sell or offer it to third parties under your brand;
  • you put a system into service under your name on the EU market;
  • you integrate a model and turn it into your own AI product.

In that case documentation, duties toward downstream deployers, and for some systems broader conformity paths change. That is not the typical scenario of “using Copilot in the office,” but it is typical of a software house or an AI SaaS product.

Italy: the national framework does not erase EU roles

Law 132/2025 designates AgID and ACN as national authorities and introduces sector specifics (work, professions, public administration). It does not rewrite the European definitions of provider and deployer: those remain the AI Act’s.

FAQ

We are an SME that only uses ChatGPT: are we deployers?
In a professional context, yes under the typical reading of Art. 3 definitions. Literacy, data rules, and—if you expose AI to third parties—transparency still apply.

Does the model vendor handle everything?
No. The model/system provider has its own duties; the deployer remains responsible for use under its authority.

Do we need a 40-page legal checklist?
To start, you need a real inventory and 8–10 operational rules. Legal depth rises with the risk of the use case.

What should we do this week?
List the tools, name an owner for each, close personal-account uses with company data, and check whether chatbots correctly disclose that they are AI.

Sources

Dig deeper in the series

If you want a short session to classify your use cases (deployer vs provider) and leave with a prioritised checklist, we can run it on your real perimeter. Write to info@zendata.it or visit zendata.it.

Pietro Ciattaglia, CEO of Zendata AI, Rome