Mein kostenloses KI-Audit buchen
    Wir verwenden Cookies, um die Nutzung der Website zu analysieren und Ihr Erlebnis zu verbessern. Ohne Ihre Zustimmung findet kein Tracking statt.

    EU AI Act: Provider or Deployer? The 5-Minute Test

    (Aktualisiert am )
    AI Compliance
    EU AI Act: Provider or Deployer? The 5-Minute Test

    Quick answer: Under Article 3 of the EU AI Act you are a provider if you place an AI system on the EU market or put it into service under your own name or trademark, and a deployer if you use one under your own authority in a professional activity. The same Luxembourg company holds different roles for different systems. Four questions decide it: did you train the model, did you fine-tune or substantially modify one, did you rebrand a system as yours, or do you just use it as delivered? The classification is now urgent for a different reason than it was in June: Article 50 transparency duties fall on both roles and have applied since 2 August 2026, while the heavy high-risk obligations moved to 2 December 2027 under Regulation (EU) 2026/1744.

    Last verified 7 August 2026.

    Why this got more important, not less, when the deadline moved

    For most of 2026 the reason to classify your systems was 2 August. That date has now passed, and it did not land the way the trade press said it would.

    The Digital Omnibus on AI — Regulation (EU) 2026/1744, in force since 27 July 2026 — deferred the high-risk obligations for stand-alone Annex III systems to 2 December 2027 and for product-embedded AI to 2 August 2028. What did take effect on 2 August 2026 is the Article 50 transparency regime, and Article 50 is split precisely along the provider/deployer line:

    Article 50 dutyFalls on
    50(1) Design the system so people know they are interacting with AIProvider
    50(2) Mark generative outputs in machine-readable form (grace to 2 Dec 2026 for systems already on the market)Provider
    50(3) Inform people exposed to emotion recognition or biometric categorisationDeployer
    50(4) Disclose deepfakes and AI-generated public-interest textDeployer

    So the question "am I the provider or the deployer of this chatbot?" is no longer a planning question for a future deadline. It decides which of these duties you are in breach of today if the disclosure is missing. And the answer is not always the one companies assume — a Luxembourg firm that wrapped a foundation model in its own branded assistant is very often the provider of that system, and therefore owes 50(1) and 50(2), not just 50(4).

    We have written about the corrected timeline, high-risk systems, Article 4 literacy, GPAI obligations, and Article 5 prohibitions. This is the one that has to be answered before any of the others apply to you.

    Five minutes, four questions, four edge cases, one defensible classification. Print it, send it to your COO, take it to your board.

    Why the classification matters more than anything else in the AI Act

    The AI Act assigns obligations by role, not by industry. The same Luxembourg company can be a provider for one AI system, a deployer for another, both for a third, and neither for a fourth. Until you know which role you hold for each system, you cannot:

    • Work out which Article 50 disclosures you owe right now
    • Estimate your compliance budget for the December 2027 wave
    • Decide whether you need an authorised representative
    • Decide whether you need a quality management system
    • Decide whether you need technical documentation, post-market monitoring, or incident reporting
    • Decide whether you need to register the system in the EU database under Article 49 (there is no Luxembourg national registry — that claim circulates widely and is wrong)

    Get it wrong and you either over-spend dramatically on obligations that do not apply to you, or — far more dangerously — under-spend and end up unable to defend your posture when a supervisory authority asks.

    The two roles, in one line each:

    • Provider: you put an AI system on the EU market, or put it into service in the EU, under your own name or trademark — whether for payment or for free, and whether you developed it or had it developed.
    • Deployer: you use an AI system in the course of a professional activity, under your own authority.

    Both definitions sit in Article 3. The hard part is that the same action — wrapping a large language model in a chatbot on your website — can put you on either side of the line depending on decisions you may not have noticed making.

    The 5-minute test — four questions

    Answer in order. The first "yes" wins; do not skip ahead.

    Question 1 — Did you train the underlying model?

    If your company actually trained the model from scratch — own data, own compute, own weights — you are a provider of that model. Most Luxembourg SMEs answer "no", because the model layer is dominated by OpenAI, Anthropic, Google, Mistral, Meta and a handful of European specialists.

    If yes, the obligations are heavy: technical documentation, quality management system, conformity assessment where high-risk, CE marking, post-market monitoring, EU database registration. Companies in this position generally know it.

    If no, proceed to Question 2.

    Question 2 — Did you fine-tune, substantially modify, or change the intended purpose of an existing model?

    This is where the majority of Luxembourg companies actually live.

    If you took a foundation model and:

    • Fine-tuned it on your proprietary data such that it now performs your specific task; or
    • Substantially modified its behaviour through a wrapper that materially changes how it operates; or
    • Repurposed it for a use that was not its intended purpose (took a general chat model and turned it into a medical triage assistant) —

    then under Article 25 you can be considered a provider of the resulting AI system. Even though you did not train the base model. Even though you are paying by the token.

    Note that the omnibus moved certain Article 25 cooperation and information duties into the €15 million / 3% penalty band. The value-chain provisions got sharper, not softer.

    If yes, you are a provider for that system. Proceed no further.

    If no, proceed to Question 3.

    Question 3 — Are you placing the AI system on the EU market under your own name or trademark?

    If you are reselling, integrating, branding or shipping an AI system as part of your own product — even without training it or substantially modifying it — you can be a provider.

    The classic Luxembourg example: a fintech that ships a customer-facing AI feature inside its own product, even though the underlying engine is a thin wrapper over a foundation model. From the customer's perspective the feature is "the fintech's". From the AI Act's perspective, the fintech is on the market with an AI system under its own name. That is a provider position — and it carries the Article 50(1) design duty that applies today.

    Same logic for a SaaS reselling an AI feature, a consultancy productising a workflow assistant, an accounting firm offering a co-branded AI tool to clients, or an integrator packaging an AI service under their own product name.

    If yes, you are a provider. Proceed no further.

    If no, proceed to Question 4.

    Question 4 — Are you using an AI system in the course of your professional activity, under your own authority?

    If you got here, you are almost certainly a deployer. You did not train it, you did not substantially modify it, you did not put it on the market under your own name — you use it inside your business.

    Examples: a Luxembourg law firm using Microsoft Copilot to draft contracts. A wealth manager using a CRM with a built-in AI summariser. A pharmacy using a prescription-OCR product from a supplier. A real estate agency using ChatGPT Enterprise to draft listings. A fund administrator using a third-party NAV-reporting tool that ships AI inside.

    What a deployer actually owes — and when

    Deployer obligations are lighter than provider obligations. They are not light.

    Applying now (Article 50, since 2 August 2026):

    • Inform people exposed to an emotion recognition or biometric categorisation system that it is operating.
    • Disclose that image, audio or video content constituting a deep fake was artificially generated or manipulated.
    • Disclose AI-generated text published to inform the public on matters of public interest — unless it underwent human review and a person or organisation holds editorial responsibility.

    Applying now (Article 4, since 2 February 2025, as amended): take measures to support the development of AI literacy among staff and others operating AI on your behalf. The omnibus softened the wording from "ensure, to their best extent, a sufficient level" to "support the development of". Documented, role-proportionate, cheap. Do it.

    Applying from 2 December 2027 for Annex III high-risk systems (Article 26):

    • Use the system in accordance with the provider's instructions for use.
    • Assign human oversight to natural persons with the necessary competence, training and authority.
    • Ensure input data is relevant and sufficiently representative for the intended purpose, to the extent you control it.
    • Monitor operation; inform the provider and the market surveillance authority of risks and serious incidents.
    • Keep the automatically generated logs for at least six months.
    • Inform workers and their representatives before putting the system into service in the workplace — in Luxembourg, that means engaging the delegation du personnel before procurement closes, not after.

    And Article 27 — the one deployers in this market miss. A Fundamental Rights Impact Assessment is required not only from public bodies and private operators providing public services, but from any deployer of an Annex III point 5(b) or 5(c) system: creditworthiness evaluation and credit scoring of natural persons, and risk assessment and pricing in life and health insurance. If you are a Luxembourg lender or a life/health insurer, the FRIA is yours — public or private — from 2 December 2027.

    Note what is not in scope: AI used to detect financial fraud is expressly carved out of Annex III 5(b), and non-life insurance pricing is outside 5(c). Precision saves money in both directions.

    The four edge cases that catch Luxembourg SMEs out

    Edge case 1 — The "internal use only" exception that isn't

    A Luxembourg company builds an AI workflow for internal use only. No external customers. They assume they are a deployer because nothing leaves the building.

    If they fine-tuned the model or changed its intended purpose (Question 2), they are still a provider. The "internal only" framing does not exempt you — putting a system into service under your own name inside your own organisation is squarely within the definition. Get the Question 2 answer right first.

    Edge case 2 — The white-labelled SaaS

    A Luxembourg SME white-labels a third-party AI tool, brands it as their own, and offers it to clients. The third-party SaaS bears the technical burden — but the white-labeller is the one putting it on the market under their own name or trademark (Question 3). Both companies can be providers of the same system, with overlapping obligations and an Article 25 relationship to document contractually.

    Edge case 3 — The "we're just using ChatGPT" assumption

    A Luxembourg firm deploys ChatGPT Enterprise, builds a custom GPT (system prompt, tool integrations, knowledge base), and offers it to all staff. They assume deployer.

    If the custom GPT changes the intended purpose, or the system-prompt-plus-tools-plus-knowledge-base wrapper constitutes a substantial modification, they may have crossed into provider territory under Question 2 — even paying per token. The cautious posture: a custom GPT with a non-trivial system prompt and tool access should be assessed against the substantial-modification test, not waved through as "just a wrapper". If it is customer-facing, the Article 50(1) disclosure duty follows the provider classification and applies today.

    Edge case 4 — The MeluXina-hosted or private deployment

    A Luxembourg company deploys an open-weight model (Mistral, Llama, Qwen) on MeluXina or a private cluster, with its own fine-tuning, serving stack and API. This is unambiguously a provider position. The private deployment piece covers the architecture; the regulatory side is full provider obligations, including conformity assessment if the system is high-risk under Annex III — on the 2 December 2027 clock.

    Führen Sie ein Luxemburger KMU?

    Buchen Sie ein kostenloses 30-minütiges KI-Audit — wir sagen Ihnen ehrlich, wo sich KI für Sie lohnt und wo nicht.

    Kostenloses KI-Audit buchen

    What to do with your classification — by Tuesday morning

    For every AI system your company uses or ships, write down on one page:

    1. System name — the internal name your team uses
    2. Classification — provider, deployer, both, or to be re-assessed
    3. Triggering question (1, 2, 3 or 4) plus a one-line evidence note
    4. Article 50 status — which disclosure duties attach, and whether they are live on the product today
    5. Annex III? — high-risk, Article 6(3) filter applies, or clearly out (see the high-risk guide)
    6. Owner — a named person

    This page is your AI Act register. Every Luxembourg company should hold it at board level. If you do not have it, the fastest path is a two-to-three-hour internal workshop using the four-question test above.

    Four things that will still surprise you

    • Your classification can change on a Tuesday. The moment you fine-tune, re-purpose or rebrand, you can move from deployer to provider. The classification is per-system and per-version, not per-company.
    • Both roles usually apply to the same company. A Luxembourg fintech is typically a provider for its customer-facing AI feature and a deployer for the tools it uses internally. The register lists both.
    • Article 4 literacy applies to both. Whichever side you sit on. See the literacy implementation piece.
    • Article 5 prohibitions apply to both, absolutely. Two new prohibitions — non-consensual intimate imagery and CSAM generation — join the list on 2 December 2026. The Article 5 sweep applies to your provider systems and your deployer systems.

    Get the classification signed, dated and defensible

    A classification you have thought about but not written down is worth nothing in front of a supervisor, a client's procurement team, or your own insurer.

    The 20 More AI Act Readiness Assessment. Fixed scope, ten working days. You leave with:

    1. The per-system register — every AI system and AI feature, including the ones procurement never saw, with the Article 3 role determination made and evidenced against the four-question test, dated and signed.
    2. The Article 50 gap report — which disclosure duty attaches to which system given its role, mapped to the exact chatbot flows, voice-agent scripts, screens and published content that are missing it. This is the part that is legally due today.
    3. The Annex III exposure list — which systems become high-risk on 2 December 2027, whether the Article 6(3) filter applies and on what reasoning, whether Article 27 FRIA is yours, and the sized work programme against that date.
    4. A one-page board memo — the document you hand to the CNPD, the CSSF or a client without further translation.

    We work alongside your DPO, internal counsel or external compliance support. We do not replace them — we sequence and produce the operational work they need to sign.

    See the AI Act readiness service, or book the 30-minute scoping call. Bring your three most uncertain systems and we will classify them live on the call.


    Related reading:

    Ist Ihr KI-Projekt für bis zu 70 % Luxemburger Förderung qualifiziert?

    Bis zu 17.500 € pro Projekt. Sofortige Schätzung — 4 kurze Fragen, keine E-Mail nötig.

    Förderung prüfen (2 Min.)

    Bereit, das umzusetzen?

    Zwei Wege zum Start — wählen Sie, was zu Ihrem Zeitplan passt.

    Tags:
    Luxembourg
    EU AI Act
    Compliance
    Governance
    Provider Deployer

    Verwandte Ressourcen

    KI-Implementierung in Luxemburg

    Unser umfassender Leitfaden zu KI-Einführung, Implementierung und Governance in Luxemburg.

    Leitfaden lesen

    Mit einem KI-Berater in Luxemburg arbeiten

    Sehen Sie, was wir bauen, was es kostet und wie Projekte bis zu 70 % KMU-Kofinanzierung erhalten.

    KI-Berater in Luxemburg