Ownware
Guide · Sep 6, 2026

Harness, model, deployer: who is the provider? The definitions, side by side

You wired a self-hosted application to a model you do not own. The AI Act assigns obligations to providers and to deployers, and the two definitions do not turn on who wrote the code or where it runs. Article 3(3) and 3(4) quoted from the 27 July 2026 consolidated text, read 6 September 2026, with t

You are running an application you host. It calls a model you do not own, made by somebody else, over an API. Somewhere in that arrangement the AI Act's obligations attach to somebody — and the Regulation splits them between two roles with different names.

This page puts the two definitions side by side and asks the questions that separate them. It does not tell you which one you are, because that is a question about your contracts and your product, and it is not one a software vendor should be answering for you.

We are not your adviser and this is not advice.

Where these words come from

From the consolidated text of Regulation (EU) 2024/1689, CELEX 02024R1689-20260727 ("02024R1689 — EN — 27.07.2026 — 001.001"), read on 6 September 2026 from the Publications Office CELLAR, the datastore behind EUR-Lex. It incorporates Regulation (EU) 2026/1744, OJ L 2026/1744 of 24.7.2026. The consolidated text "is meant purely as a documentation tool and has no legal effect".

The two definitions

Article 3(3):

'provider' means a natural or legal person, public authority, agency or other body that develops an AI system or a general-purpose AI model or that has an AI system or a general-purpose AI model developed and places it on the market or puts the AI system into service under its own name or trademark, whether for payment or free of charge;

Article 3(4):

'deployer' means a natural or legal person, public authority, agency or other body using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity;

What the wording does and does not turn on

Set the two definitions against the questions people usually ask, and notice how few of them the text actually answers.

It does not turn on who wrote the code. The provider definition covers a body that "develops" an AI system or "has an AI system … developed". Commissioning is inside the wording.

It does not turn on payment. The provider definition ends "whether for payment or free of charge".

It does not turn on where the software runs. Neither definition mentions hosting, servers or infrastructure. Self-hosting appears nowhere in either sentence. This is worth saying plainly on a self-hosted-software vendor's website: running it on your own hardware is not, on the face of these definitions, a fact that decides your role.

It does turn on a name. The provider definition requires placing on the market or putting into service "under its own name or trademark". That phrase is doing more work than any other in the sentence, and it is a question about branding and contracts as much as about engineering.

And it turns on authority. The deployer definition is "using an AI system under its authority", with the carve-out for personal non-professional use.

On watermarking, we are saying nothing

There is a great deal of confident writing about whether AI output is or is not detectable, marked, or watermarked, in both directions. We are not adding to it. What the Regulation says about marking is in Article 50(2), which requires providers of systems generating synthetic content to ensure outputs "are marked in a machine-readable format and detectable as artificially generated or manipulated", with technical solutions that are "effective, interoperable, robust and reliable as far as this is technically feasible".

That is the obligation as drafted. We make no claim about whether any particular model, service or output satisfies it, and no claim that any content is or is not marked. If somebody tells you that content from a given system is detectable — or that it is not — that is a claim about a technical fact, and it needs technical evidence rather than a citation to this Article.

Questions for your adviser

  • Whose name is on the service the end user sees? Not who built it, not who hosts it — whose name.
  • Did we modify, fine-tune or otherwise develop the model, or only call an API with our own prompt and our own system instructions?
  • Is there a contract with the model vendor that allocates these roles, and does what it says match what Article 3(3) and 3(4) describe?
  • Are we, in the words of 3(4), "using an AI system under its authority" — and does anyone other than us have authority over how it behaves in our product?
  • If the model vendor changes the model underneath us, does our answer to any of the above change, and would we find out?
  • For the specific obligations we think attach, have we checked whether they are addressed to the provider or to the deployer? Article 50 assigns paragraphs 1 and 2 to providers and paragraphs 3 and 4 to deployers, and the difference is not cosmetic.

What we sell, and what we do not

We do not sell an AI-Act tool. Confida covers whistleblowing under Directive (EU) 2019/1937; Cyresora covers incident-reporting clocks under NIS2 and the CRA. Neither addresses the question on this page. The compliance suite is what we actually make.

Consolidated text read 6 September 2026 from the Publications Office CELLAR (CELEX 02024R1689-20260727). No legal effect; the authentic version is the Official Journal text. Read Article 3 and Article 50 yourself before relying on anything here.

Own your tools

Stop renting your own business.

Every tool in this store is a one-time purchase: install it on your own server, keep your own data, and never see a renewal invoice.

Affiliate program
Recommend tools people own — earn 35% on every sale. 90-day tracking, instant delivery, payouts by Lemon Squeezy.
Become an affiliate →