SkarpSkarp

Chapter 6 of 25

Responsibility Across the AI Value Chain

AI compliance rarely rests with a single organisation. This module follows responsibility from providers and component suppliers through importers, distributors, product manufacturers and deployers, including circumstances that transfer provider status.

20 min readen

1. Start with the Provider: Accountability Is Not the Same as Development

One accountability point

Recital (79) says "a specific natural or legal person, defined as the provider, takes responsibility for the placing on the market or the putting into service of a high-risk AI system".

Provider is not necessarily developer

The responsible provider may be different from the person who designed or developed the high-risk AI system. Development activity alone does not determine this allocation.

Read the legal language carefully

This is a recital: it explains the Regulation's approach. Do not convert its explanatory wording into an article-level mandatory command that the text does not state here.

2. Provider Design Duties, Quality Systems, and Accessibility

Accessibility by design

Recital (80) says providers should ensure compliance with accessibility requirements by design, integrating necessary measures as much as possible into the high-risk AI system's design.

Universal design context

Universal design principles should support full and equal access for persons potentially affected by or using AI technologies, including persons with disabilities.

Compliance infrastructure

Under Recital (81), the provider should establish a quality management system, complete conformity assessment, create documentation, and establish robust post-market monitoring.

Existing sectoral systems

A provider subject to relevant sectoral Union-law quality-system duties should have the possibility to include the Regulation's elements in its existing system.

3. Example: Who Is Accountable for an Accessible Hiring System?

The scenario

A model developer, interface builder, and marketing company all contribute to a hiring platform. The marketing company brings the combined system to market under its own name.

Provider allocation

Recital (79) permits accountability to rest with the provider bringing the system to market or into service, even if that provider did not design or develop every component.

Accessibility is designed in

For a hiring platform, accessibility questions can include keyboard use, assistive-technology compatibility, and whether instructions exclude some users. Measures should be integrated as much as possible by design.

Document the lifecycle

A quality system, conformity assessment, documentation, and post-market monitoring form the compliance infrastructure described in Recital (81).

4. Union Contact Points and Cumulative Operator Roles

Third-country providers

Recital (82): "providers established in third countries should, by written mandate, appoint an authorised representative established in the Union."

Why the representative matters

The authorised representative supports compliance for relevant high-risk systems and serves as the provider's contact person established in the Union.

Roles can overlap

An operator may be both importer and distributor. In that situation, it should therefore fulfil cumulatively all relevant obligations associated with those roles.

5. Role-Mapping Activity: Find the Accountability Path

Map the actors before you decide who does what

Consider this chain:

  1. A Canadian company develops a model.
  2. A French company packages it into a high-risk AI system and places that system on the Union market.
  3. A Spanish company imports stock and also sells it to customers.
  4. A municipal authority puts the system into use for its own public-service process.

Pause and map the roles described in the recitals.

  • Which actor is the identifiable provider for the system placed on the market?
  • Which actor is established in a third country, and what does Recital (82) say it should do before making AI systems available in the Union?
  • Which company has two roles at once?
  • Which actor is a deployer in the concrete use setting?

Suggested reasoning: the French company is the likely provider in this scenario because it packages and places the high-risk system on the Union market. The Canadian developer may also need an authorised representative if it itself makes AI systems available in the Union; the recital's trigger is being a provider established in a third country. The Spanish company is both importer and distributor, so Recital (83) says relevant obligations should be fulfilled cumulatively. The municipal authority is the deployer because it puts the system into use.

Do not assume that one label erases another. The source specifically anticipates overlapping roles.

A company imports a high-risk AI system into the Union and also sells it onward to customers. Under Recital (83), which statement best matches the text?

  1. It may choose whether to act only as importer or only as distributor.
  2. It should fulfil cumulatively all relevant obligations associated with both roles.
  3. It automatically becomes the provider in every case.
  4. It has no role because the original provider remains responsible.
Show Answer

Answer: B) It should fulfil cumulatively all relevant obligations associated with both roles.

Recital (83) says that an operator acting in more than one role should fulfil cumulatively all relevant obligations associated with those roles. It gives an operator acting as distributor and importer at the same time as its example.

6. When Provider Status Can Shift

The conditional rule

Recital (84): "any distributor, importer, deployer or other third-party should be considered to be a provider of a high-risk AI system and therefore assume all the relevant obligations."

Trigger 1: own name or trademark

Provider reassignment can arise where the party puts its name or trademark on a high-risk AI system already placed on the market or put into service.

Triggers 2 and 3: change the system

It can also arise after a substantial modification where the system remains high-risk, or after changing intended purpose so a previously non-high-risk system becomes high-risk.

External currency note

PE-CONS 30/26 of July 8, 2026 affects Article 25 but is signed pending publication. It is not yet in force; the supplied source text remains the applicable position today.

7. Example: Relabelling, Modification, and Embedded Safety Components

Relabelling

Putting a distributor's own trademark on an already marketed high-risk system is one Recital (84) condition for considering that party a provider.

New intended purpose

Changing the intended purpose of an already marketed non-high-risk system so that it becomes high-risk is another stated condition. Each element of that condition matters.

The former provider still assists

Under the stated conditions in Recital (86), the former provider should cooperate and provide information, reasonably expected technical access, and other assistance.

Embedded safety component

Where the AI safety component is not independently marketed or put into service, the product manufacturer should meet provider obligations for the embedded AI.

8. Cooperation, Components, Open Source, and Contractual Support

General-purpose AI cooperation

Recital (85): providers of general-purpose AI systems should closely cooperate with relevant high-risk-system providers and competent authorities, unless the Regulation provides otherwise.

Written-agreement assistance

Suppliers should provide by written agreement this provider with the necessary information, capabilities, technical access and other assistance needed for compliance.

IP and trade-secret boundary

That assistance is based on the generally acknowledged state of the art, but should not compromise the supplier's intellectual property rights or trade secrets.

Open-source limitation

Publicly accessible free and open-source tools, services, processes, and components other than general-purpose AI models should not be mandated to meet these value-chain responsibilities.

9. Deployer Responsibilities: Use, Oversight, Workers, and Information

Use according to instructions

Recital (91): "Deployers should in particular take appropriate technical and organisational measures to ensure they use high-risk AI systems in accordance with the instructions of use".

Competent human oversight

People implementing instructions and human oversight should have adequate AI literacy, training, and authority to fulfil their tasks properly.

Workplace information

Recital (92) preserves existing worker-information and consultation duties, and describes an additional information requirement where conditions under other instruments are not fulfilled.

Inform affected people where applicable

Under Recital (93), relevant deployers should, where applicable, tell natural persons they are subject to the system's use, its intended purpose, decision type, and right to an explanation.

10. Fundamental Rights Impact Assessment Before Use

Biometric safeguards

Recital (95) says post-remote biometric identification should be proportionate, legitimate, strictly necessary, and targeted, and should not lead to indiscriminate law-enforcement surveillance.

Who should assess?

Recital (96): bodies governed by public law, private entities providing public services, and deployers of certain listed systems such as banking or insurance entities should carry out a fundamental rights impact assessment prior to putting it into use.

What the assessment covers

It should identify use processes, purpose, duration and frequency, affected people and groups, and specific fundamental-rights harms, then determine measures if risks materialise.

Update, notify, involve

The assessment should be updated when relevant factors change; after it is performed, the deployer should notify the relevant market-surveillance authority. Stakeholder involvement could be appropriate.

11. Quiz: Keep Conditions and Legal Strength Intact

Select the most accurate statement

This question tests two core skills: preserving the conditions that trigger provider reassignment, and retaining the source text's use of should, may, and could.

Which statement most accurately reflects Recital (84)?

  1. Every deployer automatically becomes a provider as soon as it uses a high-risk AI system.
  2. A third party should be considered a provider where it makes any change at all to a high-risk AI system.
  3. A third party should be considered a provider under stated conditions, including putting its name or trademark on an already marketed high-risk system, making a substantial modification while it remains high-risk, or changing intended purpose so a previously non-high-risk system becomes high-risk.
  4. A contractual arrangement always prevents provider status from changing.
Show Answer

Answer: C) A third party should be considered a provider under stated conditions, including putting its name or trademark on an already marketed high-risk system, making a substantial modification while it remains high-risk, or changing intended purpose so a previously non-high-risk system becomes high-risk.

Recital (84) is conditional. It lists specific triggers, including own branding, substantial modification with the stated high-risk result, and a change of intended purpose that makes a previously non-high-risk system high-risk. It does not say every deployer automatically becomes a provider, nor that any change is enough.

12. Flashcards: Value-Chain Recall

Flip each card and restate the rule in your own words

Pay special attention to conditions and to the source's legal strength: should is not the same as shall; may and could are permissive.

Provider responsibility
Recital (79): "a specific natural or legal person, defined as the provider, takes responsibility for the placing on the market or the putting into service of a high-risk AI system" regardless of whether that person designed or developed it.
Third-country representative
Recital (82): "providers established in third countries should, by written mandate, appoint an authorised representative established in the Union."
Overlapping operator roles
An operator acting in more than one role should fulfil cumulatively all relevant obligations associated with those roles; Recital (83) gives importer and distributor as an example.
Provider reassignment
Recital (84): "any distributor, importer, deployer or other third-party should be considered to be a provider of a high-risk AI system and therefore assume all the relevant obligations" under its stated conditions.
Supplier assistance
Recital (88): suppliers "should provide by written agreement this provider with the necessary information, capabilities, technical access and other assistance" while not compromising IP rights or trade secrets.
Deployer use measures
Recital (91): "Deployers should in particular take appropriate technical and organisational measures to ensure they use high-risk AI systems in accordance with the instructions of use".
Fundamental rights impact assessment
Recital (96): certain deployers "should carry out a fundamental rights impact assessment prior to putting it into use." It should be updated when the deployer considers relevant factors have changed.

Key Terms

deployer
An operator that uses a high-risk AI system in a concrete setting. Recitals (91)-(96) describe responsibilities connected with use, oversight, monitoring, information, and in specified situations a fundamental rights impact assessment.
importer
A relevant operator along the AI value chain. Recital (83) notes that an importer may also act as a distributor and should then fulfil cumulatively the obligations associated with both roles.
provider
The specific natural or legal person identified in Recital (79) as taking responsibility for placing on the market or putting into service a high-risk AI system, regardless of whether that person designed or developed it.
distributor
A relevant operator along the AI value chain. Under the stated conditions in Recital (84), a distributor can be considered a provider.
intended purpose
The use purpose of an AI system. Under Recital (84), changing intended purpose can trigger provider reassignment where a previously non-high-risk AI system thereby becomes high-risk in accordance with the Regulation.
post-market monitoring
The robust monitoring system that Recital (81) says the provider should establish after the system is on the market or in service.
substantial modification
One of the stated Recital (84) conditions that can cause a third party to be considered a provider when it modifies an already marketed or put-into-service high-risk system and the system remains high-risk.
authorised representative
A representative established in the Union that a provider established in a third country should appoint by written mandate before making AI systems available in the Union, according to Recital (82).
quality management system
The sound system that Recital (81) says the provider should establish, alongside conformity assessment, documentation, and robust post-market monitoring.
fundamental rights impact assessment
An assessment that specified deployers should carry out prior to putting a high-risk AI system into use, to identify risks to affected people or groups and measures if those risks materialise.

Finished reading?

Test your understanding with a custom practice exam on this chapter.

Test yourself