What the EU AI Act actually requires — a role-by-role map
18 June 2026 · Euridium
Most summaries of the EU AI Act start with the risk pyramid — prohibited, high-risk, limited, minimal. That’s the right mental model, but it hides the question that actually decides your obligations: what is your role in the value chain?
The same high-risk system carries very different duties depending on whether you built it or merely use it.
Provider vs deployer
- A provider develops an AI system (or has it developed) and places it on the market under its own name or trademark. Providers of high-risk systems carry the heavy obligations: risk management (Art. 9), data governance (Art. 10), technical documentation (Art. 11), logging (Art. 12), transparency to deployers (Art. 13), human-oversight design (Art. 14), and accuracy/robustness/cybersecurity (Art. 15) — plus a quality-management system and conformity assessment.
- A deployer uses a high-risk system under its own authority. The duties are lighter but real (Art. 26): use the system per the instructions, assign competent human oversight, keep logs for at least six months, inform workers before workplace use, and — for public bodies and some others — run a fundamental-rights impact assessment (Art. 27).
The trap: you can become a provider without meaning to. Under Article 25, putting your name on a system, substantially modifying it, or repurposing it into a high-risk use flips you into provider status — with all the obligations that follow.
Why role beats tier
If you only know your risk tier, you still don’t know what to do. Role scoping is what turns “this system is high-risk” into “here are the eleven things you specifically must produce.” That’s the difference between a checklist and a plan.
The honest caveat
None of this is legal advice, and the classification logic has genuine grey zones — the Article 6(3) exemption and its profiling carve-out chief among them. Treat any tool (including ours) as decision support that shows its reasoning, not a verdict that hides it.