Deployers, distributors and importers must assume provider duties when they rebrand or substantially modify high-risk AI
Context fileUnder EU AI Act, Article 25(1) and 25(2)
What does it require?
A distributor, importer, deployer or other third party is treated as the provider of a high-risk AI system, with all Article 16 duties, if it puts its own name or trademark on a system already on the market, makes a substantial modification to a high-risk system that stays high-risk, or changes the intended purpose of a system so that it becomes high-risk. The original provider then ceases to be provider for that system but must cooperate and supply the information and access needed for the new provider to comply.
Practical action
Add a reclassification check to change control so that white-labelling, fine-tuning or repurposing a high-risk system triggers the provider workstream.
Who does it apply to?
Any organisation in the value chain that rebrands, substantially modifies or repurposes a high-risk AI system; original providers owe the cooperation duty.
- Sectors
- Cross-sector / all sectors
Applies from:
Which controls meet this duty?
Satisfies: the control, operated properly, does the work the duty asks for. Supports: it contributes but the duty needs more. Each control page lists every other duty it serves, so work done once can be counted once.
-
satisfiesProcessRelease manager · at launch and on material changeModel release and change-management gate
Serves 5 recorded duties · evidence: Release or change approval record, Release and change-classification procedure
The gate flags substantial modification, rebranding and repurposing and opens the provider duties.
-
supportsProcessAI governance lead · continuousAI system inventory and classification
Serves 11 recorded duties · evidence: AI system register, Risk-tier classification sign-off, AI intake and classification procedure
Inventory records the organisation's role for each system.
-
supportsContractual termLegal counsel · once per ai systemContractual allocation of AI duties across the supply chain
Serves 8 recorded duties · evidence: AI supplier clause set, AI customer or deployer clause set, Contract clause index against the AI register
Contracts set out cooperation from the original provider.
What evidence would a reviewer expect?
| Evidence | Type | Notes |
|---|---|---|
| Change-control reclassification assessment | record | Documented decision on whether a modification or rebranding triggers provider status. |
| Cooperation clause with original provider | document |
Framework mappings
Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.
See every European Union duty mapped this way →
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| ISO/IEC 42001:2023 | Clause 4.1; Annex A.10.2 | Determining the organisation's role and allocating responsibilities along the chain. | medium |
| NIST AI RMF 1.0 | GOVERN 6.1, MAP 1.1 | Roles across the AI supply chain and context of use. | medium |
Cite this record
AIPolicyTracker (2026). “Deployers, distributors and importers must assume provider duties when they rebrand or substantially modify high-risk AI (EU AI Act)”. https://aipolicytracker.org/obligations/eu-ai-act-art-25-value-chain-becoming-provider (accessed 24 September 2026). Data licensed CC BY 4.0.
Cite the official text alongside it: Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence, Official Journal of the European Union, https://eur-lex.europa.eu/eli/reg/2024/1689/oj.
Similar obligations in other instruments
- Non-EU providers of GPAI models must appoint an EU authorised representative — EU AI Act, European Union
- Providers must meet the full set of provider duties for high-risk AI — EU AI Act, European Union
- Use high-risk AI as instructed, monitor it and inform affected people — EU AI Act, European Union
- Providers must supply conformity evidence and log access to authorities on request — EU AI Act, European Union
- Non-EU providers must appoint an EU authorised representative for high-risk AI — EU AI Act, European Union
- Law-enforcement deployers must obtain authorisation for post-remote biometric identification and report annually — EU AI Act, European Union
- Providers of GPAI models must notify the Commission within two weeks of meeting the systemic-risk threshold — EU AI Act, European Union
- Operators of high-impact AI must prepare user-protection measures and keep records of their safety and trust measures — Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust, South Korea
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.