AIPolicyTracker
Legal requirement Governance and accountability European Union Partially applicable

Deployers, distributors and importers must assume provider duties when they rebrand or substantially modify high-risk AI

Context fileUnder EU AI Act, Article 25(1) and 25(2)

Source-linked Open official source

What does it require?

A distributor, importer, deployer or other third party is treated as the provider of a high-risk AI system, with all Article 16 duties, if it puts its own name or trademark on a system already on the market, makes a substantial modification to a high-risk system that stays high-risk, or changes the intended purpose of a system so that it becomes high-risk. The original provider then ceases to be provider for that system but must cooperate and supply the information and access needed for the new provider to comply.

Practical action

Add a reclassification check to change control so that white-labelling, fine-tuning or repurposing a high-risk system triggers the provider workstream.

Who does it apply to?

Any organisation in the value chain that rebrands, substantially modifies or repurposes a high-risk AI system; original providers owe the cooperation duty.

Applies from:

Which controls meet this duty?

Satisfies: the control, operated properly, does the work the duty asks for. Supports: it contributes but the duty needs more. Each control page lists every other duty it serves, so work done once can be counted once.

  • satisfiesProcessRelease manager · at launch and on material change
    Model release and change-management gate

    Serves 5 recorded duties · evidence: Release or change approval record, Release and change-classification procedure

    The gate flags substantial modification, rebranding and repurposing and opens the provider duties.

  • supportsProcessAI governance lead · continuous
    AI system inventory and classification

    Serves 11 recorded duties · evidence: AI system register, Risk-tier classification sign-off, AI intake and classification procedure

    Inventory records the organisation's role for each system.

  • supportsContractual termLegal counsel · once per ai system
    Contractual allocation of AI duties across the supply chain

    Serves 8 recorded duties · evidence: AI supplier clause set, AI customer or deployer clause set, Contract clause index against the AI register

    Contracts set out cooperation from the original provider.

What evidence would a reviewer expect?

Evidence examples
EvidenceTypeNotes
Change-control reclassification assessmentrecordDocumented decision on whether a modification or rebranding triggers provider status.
Cooperation clause with original providerdocument

Framework mappings

Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.

See every European Union duty mapped this way →

Framework mappings
FrameworkReferenceNoteConfidence
ISO/IEC 42001:2023Clause 4.1; Annex A.10.2Determining the organisation's role and allocating responsibilities along the chain.medium
NIST AI RMF 1.0GOVERN 6.1, MAP 1.1Roles across the AI supply chain and context of use.medium

Cite this record

AIPolicyTracker (2026). “Deployers, distributors and importers must assume provider duties when they rebrand or substantially modify high-risk AI (EU AI Act)”. https://aipolicytracker.org/obligations/eu-ai-act-art-25-value-chain-becoming-provider (accessed 24 September 2026). Data licensed CC BY 4.0.

Cite the official text alongside it: Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence, Official Journal of the European Union, https://eur-lex.europa.eu/eli/reg/2024/1689/oj.

Similar obligations in other instruments

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.