Many organisations assume that the classification as provider or deployer is a one-off matter: a system is purchased somewhere, and that determines your organisation's role. In practice, this is more nuanced. The role you hold in relation to an AI system depends on what you do with it, not on where the system comes from. The same organisation can be a deployer for one system and, without anyone naming it as such, a provider for another.
The key question is not who built the system, but who places it on the market or deploys it under their own name. An organisation that acquires a ready-made AI system and uses it for its own process is generally a deployer. As soon as that same organisation modifies the system, develops it further, relabels it, or offers it to others under its own name, that picture shifts. The degree of control over the model also plays a role: who determines what data it is trained on, who sets the parameters, who bears responsibility for the system's behaviour in production. These questions are not answered once at the time of purchase, but remain relevant for as long as the system is in use.
An organisation's role is therefore not a fixed label, but an outcome of actual use. This means that internal changes — a new application of an existing system, a modification by the organisation's own IT department, passing on an AI function to a customer or subsidiary — can change the classification without any formal decision preceding it. What this means in practice, and at what point a role actually shifts, is explained further on the page about the moment your role in relation to an AI system changes. It is important that this shift often goes unnoticed, because it takes place at department level, far from where policy is set.
The question of whether you are a provider or deployer does not stand on its own. It is intertwined with the question of what risk level an application has, and with the question of whether an application falls within the scope of regulation. A system deployed as a deployer with low impact may call for different treatment than when that same organisation further modifies the system and thereby moves closer to the role of provider. What a higher risk level concretely means for the organisation is described on the page about what a high risk level means for your own organisation. Not every application falls within the scope of the same requirements either; which applications fall outside it and what that depends on is set out on the page about which applications fall outside scope.
The reason this classification remains unclear for many organisations is not that the rules are missing. The current text and the precise criteria are set out elsewhere and are not changed by this piece. The problem lies earlier: to know which role applies, it must first be known which AI systems are actually in use, by whom, and to what degree of modification. That inventory is missing in most organisations. The official list of IT-approved tools rarely describes what is actually being used. Departments adopt tools, adapt models with their own data, or build an AI function into an internal process, without any of this being recorded centrally anywhere. Anyone who wants to know whether the organisation is a provider or deployer must therefore first know what is running — and that is a question that is not answered with a policy document, but with an inventory that dares to ask people what they use, without attaching a reckoning to it.
Because an organisation's role can shift without a formal decision, it is important for management and supervisory bodies that reporting moves with it. A governance approach that assumes a static division of roles misses the moment when an internal change actually places the organisation in a different position. How an AI policy can be drawn up in such a way that it makes this kind of shift visible instead of hiding it, and is actually read by those responsible for it, is discussed on the page about an AI policy that fits practice instead of sitting in a drawer.
The question of whether your organisation is a provider or deployer is about responsibility and obligations. It does not yet say anything about what AI means for the work itself: which tasks are taken over, changed, or supported by it. That question follows on from determining the role, but requires a different perspective — not on governance, but on the content of the work. FTE TO AI's work scan calculates, per task, what proportion of the work can be taken over by AI, regardless of which role the organisation holds in relation to the underlying system.
Vraag maar. Governance begint bij weten wat er draait — ook wat niemand heeft goedgekeurd.
Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.