"Who is the provider of your AI system?" — the provider question
This question looks administrative. It is not. It tests whether you know which role — and therefore which obligations — you hold under Regulation (EU) 2024/1689, the EU AI Act. It is also the easiest question to get wrong, because the intuitive answer ("OpenAI is the provider, we just use the API") is usually wrong for the system you actually sell.
Why buyers ask this
The AI Act assigns different transparency duties to different roles. Under Article 50, disclosing that a person is interacting with an AI system (50(1)) and machine-readable marking of synthetic content (50(2)) sit with the provider; the disclosure duties for emotion recognition (50(3)) and deepfakes (50(4)) sit with the deployer. Your buyer will be a deployer of your product, so before signing they need to know which duties you cover and which land on them. These obligations apply from 2 August 2026 and were not postponed by the Digital Omnibus. A vendor who cannot say who the provider is cannot say who owes what — and buyer legal teams read that as risk.
The rule that decides the answer: the provider definition, Article 3(3)
Here is the part that is easy to miss. The role is settled by the definition in Article 3(3): the provider is whoever develops an AI system and places it on the market or puts it into service under its own name or trademark. A SaaS product that integrates GPT, Claude or Gemini via API and ships the feature under its own brand is therefore the provider of the resulting system, and the provider-side duties of Article 50 follow that role. Your model supplier is your upstream provider — and typically a name on your subprocessor list — but it is not the provider of your product. The buyer is asking about your product. (A separate reassignment rule exists in Article 25(1)(a)–(b), for putting a name or trademark on a system or substantially modifying it, but it applies only to high-risk systems and is not what puts Article 50 duties on you.)
The honest answer structure
Three moves: name your role for the system you sell, name your upstream supplier accurately, and map the split of duties between you and the customer.
Illustrative template — placeholders in brackets, verify every clause against your own facts before submitting.
"[Your product]'s AI features are built on [model, e.g. Claude / GPT-4.x], supplied by [model provider] via API under a [DPA/enterprise agreement]. For the purposes of Regulation (EU) 2024/1689, [your company] acts as the provider of the AI system placed on the market under the [your product] brand; [model provider] is our upstream model supplier and appears on our subprocessor list. Our customers act as deployers of [your product] in their own operations. Accordingly, the provider-side transparency duties of Article 50(1)–(2) — disclosure of AI interaction and, where applicable, machine-readable marking of synthetic content — sit with us, and we implement them through [disclosure notice / labelling measure]. Deployer-side duties under Article 50(3)–(4), where relevant to the customer's use, sit with the customer; our documentation supports this at [link]."
Two drafting notes. First, 50(1) has a statutory exception where the AI interaction is obvious to a "reasonably well-informed, observant and circumspect" person — if you rely on it, say so explicitly; using the Act's own standard signals you know the terrain. Second, if your product generates audio, image, video or text content, address 50(2) marking separately: it has a transitional window until 2 December 2026 for generative systems placed on the market before 2 August 2026, so state your current status and plan rather than a bare "compliant".
The mistake that costs deals
"The provider is OpenAI — we are only a user of their API." This is the #1 trap in AI questionnaires, and it fails three ways. It misstates your role under the Article 3(3) provider definition — and a legal reviewer will catch it against your own marketing, since the feature ships under your brand. It assigns your transparency duties to a party who will not perform them for you. And once one legal claim in the document is wrong, every other answer gets re-read with suspicion. The mirror-image mistake also exists: claiming all Article 50 duties, including deployer duties (50(3)–(4)) only your customer can perform. The credible answer is the split, stated precisely.
Mini-FAQ
If our product runs on GPT or Claude, isn't OpenAI or Anthropic the provider?
Not for the system you sell. Placing it on the market under your own name or trademark puts the provider role on you (Article 3(3)) — and with it the Article 50(1)–(2) duties. Your model supplier remains your upstream provider, typically named on your subprocessor list.
Can our company be a provider and a deployer at the same time?
Yes, for different systems: provider of the product you sell, deployer of the AI tools you use internally. A strong answer maps each duty to the party that owes it.
When do these provider obligations start to apply?
Article 50 applies from 2 August 2026 — not postponed by the Digital Omnibus. The only grace period is 50(2) marking, until 2 December 2026 for generative systems placed on the market before 2 August 2026. High-risk obligations run later, on one calendar per route of Article 6: from 2 December 2027 for Annex III systems and from 2 August 2028 for Annex I systems.
Not sure which duties your feature triggers? Run it through the free Article 50 checker (seven questions, no email), read the full role map in who owes what under Article 50, or start from the method for the whole AI section. Questionnaire just landed? The first-24-hours playbook. Next in the series: the human-oversight question.
- Regulation (EU) 2024/1689 — Art. 50(1)–(5), Art. 113
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), 8 July 2026, OJ 24 July 2026, in force 27 July 2026 (high-risk dates moved to 2 Dec 2027 for Annex III and 2 Aug 2028 for Annex I; Art. 50 unchanged; 50(2) marking grace until 2 Dec 2026)