---
title: "AI Act: does your proprietary AI make you a provider or a deployer?"
description: Understand your role under the AI Act as a provider or deployer and navigate your obligations effectively to avoid penalties and reputational risks.
image: https://blog.hyntelo.com/hubfs/3.%20Blog/Blog%20Images/AI%20ACT.png
---

[![Hyntelo_LogoP](https://blog.hyntelo.com/hubfs/Hyntelo_LogoP.svg "Hyntelo_LogoP")](https://hyntelo.com/)

Open main menu Close main menu

- [Products](https://hyntelo.com/products/)
- [Solutions](https://hyntelo.com/solutions/)
- [Case Studies](https://hyntelo.com/case-studies/)
- [Industries](https://hyntelo.com/industries/)
- [SOLUTIONcamps](https://hyntelo.com/solution-camps/)
- About Open the submenu 
    - [Company](https://hyntelo.com/company/)
    - [Culture & People](https://hyntelo.com/culture-people/)
    - [Partnerships](https://hyntelo.com/partnerships/)
    - [Sustainability](https://hyntelo.com/sustainability/)
    - [Work with us](https://hyntelo.com/work-with-us/)
- [Insights](https://blog.hyntelo.com)
- [Contact us](https://hyntelo.com/contact-us/)

[AI](https://blog.hyntelo.com/tag/ai)

# AI Act: does your proprietary AI make you a provider or a deployer?

![Christine Lipkau](https://blog.hyntelo.com/hs-fs/hubfs/Blog/Blog%20Authors/HS_Lipkau.png?width=45&name=HS_Lipkau.png) 

[Christine Lipkau](https://blog.hyntelo.com/author/christine-lipkau)

[twitter icon](https://twitter.com/intent/tweet?text=I+found+this+interesting+blog+post&url=https://blog.hyntelo.com/ai-act-does-your-proprietary-ai-make-you-a-provider-or-a-deployer) [facebook-f icon](http://www.facebook.com/share.php?u=https://blog.hyntelo.com/ai-act-does-your-proprietary-ai-make-you-a-provider-or-a-deployer) [linkedin-in icon](http://www.linkedin.com/shareArticle?mini=true&url=https://blog.hyntelo.com/ai-act-does-your-proprietary-ai-make-you-a-provider-or-a-deployer)

![](https://blog.hyntelo.com/hubfs/3.%20Blog/Blog%20Images/AI%20ACT.png)

The [**AI Act**](https://ai-act-service-desk.ec.europa.eu/en) doesn't treat every company the same way: whoever puts an AI system on the market (the **provider**) carries much heavier obligations than whoever simply uses it inside a company (the **deployer**). Have company-wide ChatGPT, Claude or Copilot licenses made you one or the other? In most cases, no — but understanding which side you're on, **system by system**, still matters.

## Do AI licenses at my company already make us a regulated entity?

Whenever licenses for these LLMs come up internally, this is almost always the concern that lands on the CISO's or the Head of Governance's desk. The short answer is no: for standard use — writing emails, summarizing documents, drafting a first version — the company is simply the **deployer** of a general-purpose system, and today that carries one minimal obligation: staff **AI literacy** (Art. 4), already in force since 2025\[1,2\]. No conformity assessment, no technical documentation: that stays with whoever provides the model. But what matters isn't having the licenses — it's what you do with them.

## What do we really mean by "proprietary AI"?

Not just AI built from scratch in-house. Under the AI Act, any system your company assembles, configures or makes available for its own purpose counts as "proprietary" — even when the underlying model or LLM comes from an external provider. An agent built on a third-party model, a custom GPT, an API integration inside your own product: in every one of these cases, the question is no longer "which tool am I using," but "**what role am I playing in this system**" — provider or deployer.

## The three criteria that actually shift the obligation

Apply them to each AI system, not to the company as a whole:

- **Did you build or configure something on top of the model?** An agent, a custom GPT, an API integration that you make available to others for your own purpose: if yes, you risk being the **provider** of a new system.
- **Does it interact directly with external people, or generate public content?** Text, images, video, audio: if yes, the **transparency obligation** kicks in, already active\[1\].
- **Does the output decide or influence something about a person?** A hiring decision, a loan, access to a service: if yes, you're in **high-risk** territory — even if the calendar gives you more time than you think.
- **Externally**: a customer, a partner, or a journalist who discovers that a chatbot never disclosed it was AI, or that a screening system rejected candidates without any human review.
- **Internally**: employees discovering that the company let "homegrown" agents run unsupervised for months — that undermines trust in internal governance, not just the company's public image.

## Same tool, different outcomes

It's not the tool that decides what you need to do — it's how you use it. Here are five concrete cases, with the risk, obligation and typical role for each. Two companies with the exact same tool can end up in completely different boxes. It's not the tool that decides — it's the use.

### EXAMPLES OF AI USE CASES IN THE COMPANY

![](https://blog.hyntelo.com/hs-fs/hubfs/undefined.jpeg?width=814&height=541&name=undefined.jpeg)

## What's already in force, and what's actually been postponed?

This is where the second misconception hides, the opposite of the first: it's not true that "everything has slipped to 2027," and it's not true that "everything has already kicked in" either. **Prohibited practices** have been in force since February 2025\[1,3\]. Obligations on general-purpose models, since August 2025\[1\]. **Transparency obligations** — the ones covering chatbots and synthetic content — have been in force since last **August 2, 2026**\[1,5\]. What the Digital Omnibus actually postponed is **high-risk**: **December 2027** for standalone systems (hiring, credit, education...), **August 2028** for AI embedded in products already regulated\[6,2\]. Postponed, not eliminated.

## What's at stake if you get the classification wrong?

The penalty tiers are real — up to **€35 million or 7% of global turnover** for prohibited practices, **€15 million or 3%** for most of the other obligations, transparency included\[1,2\]. But for most companies the most immediate risk isn't the fine: it's **reputational**, and it plays out on two fronts.

## Whose responsibility is this, inside the company?

You don't solve this by appointing "an AI Act owner." According to Gartner, **85%** of organizations still don't have formalized AI governance\[4\] — often because everyone looks for a single person to handle a problem that has to be managed **system by system**, with different owners case by case: the **product/engineering lead** for an internally built agent, the **HR lead** for a candidate-screening tool, the **marketing lead** for a synthetic-content generator, the CISO or Head of Governance for the overall view and cross-cutting risk.

## What to do, in practice, starting now?

Apply this framework to every AI system you have — not to the company as a whole — and assign an owner to each one. You don't need to reinvent everything to take the first steps: categories of tools built exactly for this already exist, from **AI system inventories/discovery tools** (to find out what's actually running in the company, "homegrown" agents included) to [**AI gateways** that monitor and track usage](https://hyntelo.com/hyntelo-ai-gateway/), from **automated risk-assessment tools** to **AI training and literacy** platforms for staff.

![](https://blog.hyntelo.com/hs-fs/hubfs/undefined-1.jpeg?width=807&height=530&name=undefined-1.jpeg)

**Provider** or **deployer** isn't decided once for the whole company: it's checked system by system, and it can change if the use changes. That's the real deadline to respect — more than any date on the calendar.

[![Hyntelo banner AI gateway](https://blog.hyntelo.com/hs-fs/hubfs/Hyntelo%20banner%20AI%20gateway.png?width=1200&height=300&name=Hyntelo%20banner%20AI%20gateway.png)](https://hyntelo.com/hyntelo-ai-gateway/)

### Sources

\[1\] Regulation (EU) 2024/1689 (AI Act), consolidated text — EUR-Lex

\[2\] P4I – Osservatori.net, "AI Act: gli impatti della normativa e le prossime scadenze", webinar, May 27, 2026

\[3\] Gartner, "Getting Ready for the EU AI Act, Phase 1: Discover & Catalog", October 28, 2025 (ID G00839788)

\[4\] Gartner, "Navigating the EU AI Act: 5 Key Actions for GC", May 13, 2026 (ID G00850911)

\[5\] Cooley LLP, "EU AI Act: Transparency Obligations Take Effect 2 August 2026", August 3, 2026

\[6\] Gibson Dunn, "EU AI Act Omnibus Agreement — Postponed High-Risk Deadlines and Other Key Changes"

## Related Articles

[![AI & Customers' understanding](https://blog.hyntelo.com/hubfs/Blog/Blog%20Images/AI%20%26%20customers%20understanding.png)](https://blog.hyntelo.com/how-ai-can-help-to-understand-your-customers)

[R&D](https://blog.hyntelo.com/tag/rd) [Brainiacs](https://blog.hyntelo.com/tag/brainiacs)

### [How AI can help to understand your customers](https://blog.hyntelo.com/how-ai-can-help-to-understand-your-customers)

Nowadays a key factor for the success of companies is to understand their customers: **what** **they think and feel**. This is crucial when launching a new product...

![Nunzia Squicciarini](https://blog.hyntelo.com/hs-fs/hubfs/Blog%20authors/HS_Squicciarini.png?width=45&name=HS_Squicciarini.png) 

[Nunzia Squicciarini](https://blog.hyntelo.com/author/nunzia-squicciarini) 

[Read More](https://blog.hyntelo.com/how-ai-can-help-to-understand-your-customers)

[![PoR CreO](https://blog.hyntelo.com/hubfs/Blog/Blog%20Images/PoR%20CreO.png)](https://blog.hyntelo.com/sixth-sense-per-safeguard-progetto-co-finanziato-dalla-regione-toscana)

[News](https://blog.hyntelo.com/tag/news)

### [Hyntelo per Safeguard, progetto co-finanziato dalla Regione Toscana](https://blog.hyntelo.com/sixth-sense-per-safeguard-progetto-co-finanziato-dalla-regione-toscana)

 SAFEGUARD è un sistema in Cloud per il monitoraggio e controllo da remoto per la sicurezza di luoghi e lavoratori in ambiente industriale.

![Hyntelo](https://blog.hyntelo.com/hs-fs/hubfs/Blog/Blog%20Authors/cropped-favicon-192x192.png?width=45&name=cropped-favicon-192x192.png) 

[Hyntelo](https://blog.hyntelo.com/author/hyntelo) 

[Read More](https://blog.hyntelo.com/sixth-sense-per-safeguard-progetto-co-finanziato-dalla-regione-toscana)

#### About

- Menu Item One
- Menu Item Two
- Menu Item Three

#### Services

- Menu Item One
- Menu Item Two
- Menu Item Three

#### News

- Menu Item One
- Menu Item Two
- Menu Item Three

Follow us on Facebook Follow us on LinkedIn Follow us on Twitter Follow us on Instagram

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Christine Lipkau",
    "url" : "https://blog.hyntelo.com/author/christine-lipkau"
  },
  "dateModified" : "2026-09-15T15:55:20.568Z",
  "datePublished" : "2026-08-31T13:40:04.000Z",
  "headline" : "AI Act: does your proprietary AI make you a provider or a deployer?",
  "image" : [ "https://blog.hyntelo.com/hubfs/3.%20Blog/Blog%20Images/AI%20ACT.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.hyntelo.com/ai-act-does-your-proprietary-ai-make-you-a-provider-or-a-deployer",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.hyntelo.com/hubfs/HYNTELO/Hyntelo%20loghi/Hyntelo_positivo%20colore.png"
    },
    "name" : "Hyntelo"
  }
}
```