Back to KISYN

Roles under the AI Act

Are we a provider or a deployer under the AI Act?

Most Norwegian organisations are deployers: they use AI systems that someone else built. Providers develop an AI system, or place one on the market under their own name. The distinction matters because providers carry the heavy obligations, and because you can become a provider without intending to — by putting your own name on a system, or by substantially modifying one.

By Yassin BahriPublished and reviewed 1 August 20268 min read

A note on the Norwegian term

The English term is deployer. Norwegian usage has not settled: idriftsetter, ibruktaker and simply bruker are all in circulation, and Nkom has used more than one. The final wording will be decided when the Norwegian act is adopted. All of them refer to the same role, so do not read a difference into the choice of word.

  • Provider — leverandør. The one who develops or markets the system under their own name.
  • Deployer — idriftsetter, ibruktaker or bruker. The one who uses it professionally.
  • Importer — importør. Places a system from outside the EU on the EU market.
  • Distributor — distributør. Makes a system available without being provider or importer.

How to tell which role you have

Ask who the system is held out as coming from. If your organisation buys a licence and uses the tool as delivered, you are a deployer. If your organisation develops the system, or takes a third-party system and puts it on the market under your own name or trade mark, you are a provider.

Private use is outside the scope entirely. The deployer role covers use in a professional context, not an employee using a chatbot at home.

  • You licence a tool and use it as sold: deployer.
  • You build the system yourself: provider.
  • You resell a system under your own brand: provider.
  • You use AI purely privately: outside the regulation.

How a deployer becomes a provider

This is the trap. A deployer takes on the provider's obligations if it puts its own name or trade mark on a high-risk system, makes a substantial modification to one, or changes the intended purpose of a system so that it becomes high-risk.

Building an internal assistant on top of a commercial model, and giving it to staff under a company name, is exactly the pattern that can cross the line.

  • Rebranding a high-risk system under your own name makes you the provider.
  • Substantially modifying a high-risk system makes you the provider.
  • Repurposing a system so it becomes high-risk makes you the provider.
  • The original provider's obligations then transfer to you.

What each role has to do

Providers of high-risk systems carry the bulk of the regulation: a risk management system, data governance, technical documentation, logging, conformity assessment, CE marking and registration. Deployers carry a smaller, more practical set.

Both roles are subject to the AI literacy duty in Article 4, which has applied since February 2025 and does not depend on risk class.

  • Deployer: use the system according to its instructions.
  • Deployer: assign human oversight to someone competent and supported.
  • Deployer: keep logs and inform affected people where required.
  • Both: ensure staff working with AI have adequate AI literacy.

Frequently asked questions

Is a Norwegian company that only uses ChatGPT a provider?

No. Using a commercial tool as delivered makes you a deployer. You would only become a provider if you put your own name on a high-risk system, modified one substantially, or changed its purpose so that it became high-risk.

What is the Norwegian word for deployer?

It is not settled. Idriftsetter, ibruktaker and bruker are all used in Norwegian sources, including by Nkom, and the final term will be fixed when the Norwegian act is adopted. They all describe the same role: the organisation that uses an AI system in a professional context.

Can we be a provider and a deployer at the same time?

Yes. An organisation that builds an AI system for its own use is both the provider and the deployer of that system, and carries both sets of obligations. This is common in public bodies and larger companies with internal development.

Does the role matter if we are not high-risk?

Less, but not nothing. Most of the heavy obligations attach to high-risk systems. The AI literacy duty in Article 4 and the transparency duties in Article 50 apply regardless of role, and knowing your role is what tells you which duties would land if a use case turns out to be high-risk.

Does the role apply per system or per organisation?

Per system. The same organisation can be a deployer of a purchased recruitment tool and the provider of an assistant it built itself. This is why an inventory of AI use, rather than a single company-wide label, is the practical starting point.

Free orientation tool

Understand how the EU AI Act may apply

Answer plain-language questions, get explanations as you go, and see the official legal basis behind your result.

Start the AI Act assessment