
Image AI-generated. All text human-written
The EU AI Act has generated plenty of noise — risk categories, fines, governance frameworks. Underneath it, one basic question is still routinely answered wrongly inside companies: who actually has to comply? Responsibility under the Act does not fall evenly on everyone who touches AI. It follows the role an organisation occupies in the value chain — and misreading that role is the most expensive mistake available, because every duty, every date and every exposure flows from it. Four positions cover the field.
Providers — the heaviest duties, and a wider category than people think
A provider develops an AI system — or has one developed — and places it on the market or puts it into service under its own name or trademark. That last clause is the trap: take a third-party system, brand it as your own, and you become its provider, with everything that follows. The category covers AI SaaS companies selling into the EU, companies embedding AI in their products, manufacturers shipping AI inside regulated goods — and every white-labeller who assumed the vendor kept the responsibility.
For a provider whose system is high-risk, the duty set is the full programme: lifecycle risk management, data governance, technical documentation, logging and human oversight, conformity assessment, an EU declaration of conformity and CE marking before market placement. Governance, for providers, is a market access requirement. The timing — stated precisely, because most commentary is wrong: those heavy duties apply from 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for AI embedded in regulated products, under Article 113 as amended. What is live for providers now: the Article 50 transparency duties — interactive systems disclosing themselves, generated content machine-readably marked — enforceable since 2 August 2026. Two clocks. Confusing them is how companies end up over-prepared for 2027 and exposed today.
Deployers — a far bigger club than the label suggests
A deployer is any organisation using an AI system under its own authority in a professional context — not, as often summarised, only users of high-risk systems. The bank scoring credit, the employer screening CVs, the insurer underwriting: deployers. So is the company whose marketing team generates campaign content, and the firm running a licensed chatbot. Only purely personal, non-professional use falls outside the Act.
What deployers must do depends on what they deploy. For high-risk systems, Article 26 sets the operational duties: use the system in accordance with the provider’s instructions, assign oversight to people with the competence, training and authority to intervene, monitor operation, keep the logs, report serious incidents. Note what is not on that list: verifying the provider’s conformity work — conformity is the provider’s job; the deployer’s job is deploying responsibly and being able to prove it. And for the many deployers with nothing high-risk at all, the live duties are the Article 50 disclosures — which is why “we don’t run high-risk AI” is the beginning of the analysis, not the end.
Suppliers into the chain — structure matters, but not the way vendors say
Companies supplying models, components and APIs sit in the most misunderstood position. The clean rule: place an AI system on the market yourself and you are its provider; supply components others build into their systems and you carry a narrower position. For high-risk systems the Act organises the chain — suppliers of integrated third-party elements must give the downstream provider, by written agreement, the information and assistance needed for compliance. What a contract cannot do is relocate a role: no organisation can sign itself out of being the provider or deployer it factually is. Contracts organise cooperation and allocate costs; the Act attaches the duties — and a regulator enforces against whoever holds the role, whatever the paperwork says.
Individuals at the end of the chain
People interacting with AI systems — customers, applicants, employees using tools their employer provides — carry no compliance duties. They are rights-holders and, increasingly, complainants: the enforcement system is designed to be triggered from below, and the cheapest obligations to test — the disclosure duties — can be tested from outside the building. The responsibility sits higher in the chain. So does the exposure.
The real risk is misclassification
In the audits ExecLevel has run, organisations rarely fail because they refused to comply. They fail because they answered the two threshold questions late or not at all: which role do we hold, per system — and is any of it high-risk? Those two answers determine every duty, every date and every document, and companies typically confront them only when procurement demands evidence, an investor asks the governance question, or a regulator’s information request arrives. A classification record cannot be backfilled to before the question was asked. The most dangerous position under the EU AI Act is not non-compliance. It is not knowing which category you are in while the clock that applies to you runs.
That classification — role by role, system by system, traced to the text — is the first deliverable of a defensible governance record, and accountability for having one sits with the CEO: role classification decides market access, and market access is not delegable.
Find out which roles your company actually holds — a free assessment conversation at www.execlevelai.eu
Disclaimer: This article is for general informational purposes only and does not constitute legal or compliance advice. EU AI Act requirements may vary depending on your organisation, AI system, and use case. For advice on EU AI Act compliance, visit www.exclevelai.eu