Provider or deployer? The role that almost always applies to you

The AI Act (Regulation (EU) 2024/1689) draws a precise line between two roles in Article 3. A provider (Article 3(3)) is whoever develops an AI system — or has one developed — and places it on the market or puts it into service under its own name or trademark. A deployer (Article 3(4)) is whoever uses an AI system under its own authority, except for purely personal, non-professional use.

If your firm uses ChatGPT, Copilot, or any third-party generative AI to draft reports, analyze documents, do legal or tax research, or prepare contract drafts, you are a deployer, not a provider. The one real exception — rare in practice — would be a firm that trains or substantially modifies its own model and markets it under its own brand.

This distinction isn't academic. The heaviest obligations in the Regulation — Annex IV technical documentation, conformity marking, registration in the EU database — fall on the provider. As a deployer, your obligations are lighter, but they exist, and it's worth knowing them precisely rather than assuming either "none of this applies" or "all of it applies."

When does what you do become "high-risk"?

Annex III of the AI Act sets out a closed list of eight categories treated as high-risk: biometrics, critical infrastructure, education, employment, access to essential services, law enforcement, migration/asylum/border management, and the administration of justice and democratic processes. That last category — point 8 — is narrower than it sounds: it only covers AI systems used by a judicial authority to research and interpret facts and apply the law to specific cases. It does not cover a private firm advising its clients.

In practice, this means general-purpose generative AI — what most consultancies use internally to draft, summarize, or research — typically does not fall into any of the eight high-risk categories. That doesn't mean nothing applies: Article 4 (AI literacy) applies regardless of risk level, and Article 50 (transparency) kicks in if you generate content intended for the public without genuine human editorial oversight.

In one line: most consultancies don't handle high-risk systems under Annex III, but they have had, since February 2025, an obligation to ensure a sufficient level of AI literacy among staff (Article 4) — an obligation that applies regardless of whether the system is high-risk.

Offering AI Act consulting to your clients: what you need, and what you don't

Many legal, tax, and labor advisory firms, and management consultancies, are considering adding the AI Act to their service catalog: helping clients understand their obligations, mapping which AI systems they use, drafting internal AI usage policies, or preparing the documentation a market surveillance authority would request. This is regulatory compliance consulting, and the Regulation requires no specific accreditation to provide it — similar to how data-protection consulting worked before the certified DPO figure existed.

That's different from the role of notified bodies (Article 43): entities formally designated and accredited by the relevant national authority to carry out the formal conformity assessment of third parties' high-risk systems — a demanding technical-regulatory regime, equivalent to CE marking for other products. Advising a client on its obligations is not the same as certifying the conformity of its AI system, and the two services shouldn't be blurred together or presented as interchangeable. If you need to verify whether notified bodies are already operational in your jurisdiction, the European Commission's NANDO database is the official source to check.

Client data confidentiality: the risk nobody regulates for you

The AI Act doesn't specifically address what happens when someone pastes a client's contract, a tax file, or a payslip into the free consumer version of a generative AI tool. That risk — handing confidential information to a third party whose retention and possible model-retraining terms need reviewing before use — is a matter of good practice and professional confidentiality, not an obligation that flows directly from the Regulation.

The industry is already moving in this direction independently of the AI Act. The guide on responsible AI use in the legal profession published by the Ilustre Colegio de la Abogacía de Madrid (ICAM) on October 7, 2025 is direct on this point: "technology is a support tool, but it does not and should not replace the lawyer or their professional judgment." The guide calls for data protection and confidentiality protocols when using these tools, and underscores a principle that applies equally to tax and labor advisory firms and management consultancies: "delegating the technology cannot mean delegating the responsibility."

Four practical steps to get this in order

Step 1 — Map which AI tools you use and with what data

Inventory the generative AI tools your team uses — including the ones nobody formally approved — and what kind of client data goes into each one: case files, contracts, payslips, tax information.

Step 2 — Train the team (Article 4)

The AI literacy obligation has existed since February 2, 2025 and is proportionate to context: it doesn't require a certified formal program, but it does require concrete, documented measures — especially for staff handling client data with these tools daily.

Step 3 — Choose versions with a data processing agreement, not the free consumer tier

Professional or enterprise versions of generative AI tools usually include a data processing agreement and options to exclude your data from model retraining — something the free consumer version typically doesn't offer.

Step 4 — Document the usage

Keep a written record of which tools the firm uses, for which cases, with what confidentiality controls, and who has been trained. That documentation is what a market surveillance authority would request — and it's also your own reference point when advising clients on the same questions.

National Authority Inspection Response Kit Prepare the documentation a market surveillance authority would request — also useful when advising your clients on what they'll be asked for. €9.99, VAT incl.
Buy →

Frequently asked questions

If we use ChatGPT or Copilot to draft reports, are we AI "providers"?

No, you're a deployer under Article 3(4) of the AI Act — a provider is whoever develops the system and places it on the market under its own name or brand, not whoever uses it as a work tool.

Do we need accreditation to advise clients on the AI Act?

There's no specific accreditation regime under the Regulation for compliance consulting. "Notified body" accreditation (Article 43) is a separate, far more technical process, reserved for the formal conformity assessment of high-risk systems.

Do we have to give mandatory AI training to all staff?

Article 4 has required proportionate AI literacy measures, tailored to context and risk, since February 2, 2025 — but it doesn't require a certified formal program or a guaranteed individual skill level for every person.

If we produce a report using AI and hand it to a client, do we have to disclose that AI wrote it?

It depends. Article 50 requires labeling AI-generated content of public interest that lacks substantive human editorial review; text with real human editorial control — the usual case at a consultancy — is exempt from that labeling requirement.