AI Act: does your proprietary AI make you a provider or a deployer?
The AI Act doesn't treat every company the same way: whoever puts an AI system on the market (the provider) carries much heavier obligations than whoever simply uses it inside a company (the deployer). Have company-wide ChatGPT, Claude or Copilot licenses made you one or the other? In most cases, no — but understanding which side you're on, system by system, still matters.
Do AI licenses at my company already make us a regulated entity?
Whenever licenses for these LLMs come up internally, this is almost always the concern that lands on the CISO's or the Head of Governance's desk. The short answer is no: for standard use — writing emails, summarizing documents, drafting a first version — the company is simply the deployer of a general-purpose system, and today that carries one minimal obligation: staff AI literacy (Art. 4), already in force since 2025[1,2]. No conformity assessment, no technical documentation: that stays with whoever provides the model. But what matters isn't having the licenses — it's what you do with them.
What do we really mean by "proprietary AI"?
Not just AI built from scratch in-house. Under the AI Act, any system your company assembles, configures or makes available for its own purpose counts as "proprietary" — even when the underlying model or LLM comes from an external provider. An agent built on a third-party model, a custom GPT, an API integration inside your own product: in every one of these cases, the question is no longer "which tool am I using," but "what role am I playing in this system" — provider or deployer.
The three criteria that actually shift the obligation
Apply them to each AI system, not to the company as a whole:
- Did you build or configure something on top of the model? An agent, a custom GPT, an API integration that you make available to others for your own purpose: if yes, you risk being the provider of a new system.
- Does it interact directly with external people, or generate public content? Text, images, video, audio: if yes, the transparency obligation kicks in, already active[1].
- Does the output decide or influence something about a person? A hiring decision, a loan, access to a service: if yes, you're in high-risk territory — even if the calendar gives you more time than you think.
- Externally: a customer, a partner, or a journalist who discovers that a chatbot never disclosed it was AI, or that a screening system rejected candidates without any human review.
- Internally: employees discovering that the company let "homegrown" agents run unsupervised for months — that undermines trust in internal governance, not just the company's public image.
Same tool, different outcomes
It's not the tool that decides what you need to do — it's how you use it. Here are five concrete cases, with the risk, obligation and typical role for each. Two companies with the exact same tool can end up in completely different boxes. It's not the tool that decides — it's the use.
EXAMPLES OF AI USE CASES IN THE COMPANY

What's already in force, and what's actually been postponed?
This is where the second misconception hides, the opposite of the first: it's not true that "everything has slipped to 2027," and it's not true that "everything has already kicked in" either. Prohibited practices have been in force since February 2025[1,3]. Obligations on general-purpose models, since August 2025[1]. Transparency obligations — the ones covering chatbots and synthetic content — have been in force since last August 2, 2026[1,5]. What the Digital Omnibus actually postponed is high-risk: December 2027 for standalone systems (hiring, credit, education...), August 2028 for AI embedded in products already regulated[6,2]. Postponed, not eliminated.
What's at stake if you get the classification wrong?
The penalty tiers are real — up to €35 million or 7% of global turnover for prohibited practices, €15 million or 3% for most of the other obligations, transparency included[1,2]. But for most companies the most immediate risk isn't the fine: it's reputational, and it plays out on two fronts.
Whose responsibility is this, inside the company?
You don't solve this by appointing "an AI Act owner." According to Gartner, 85% of organizations still don't have formalized AI governance[4] — often because everyone looks for a single person to handle a problem that has to be managed system by system, with different owners case by case: the product/engineering lead for an internally built agent, the HR lead for a candidate-screening tool, the marketing lead for a synthetic-content generator, the CISO or Head of Governance for the overall view and cross-cutting risk.
What to do, in practice, starting now?
Apply this framework to every AI system you have — not to the company as a whole — and assign an owner to each one. You don't need to reinvent everything to take the first steps: categories of tools built exactly for this already exist, from AI system inventories/discovery tools (to find out what's actually running in the company, "homegrown" agents included) to AI gateways that monitor and track usage, from automated risk-assessment tools to AI training and literacy platforms for staff.

Provider or deployer isn't decided once for the whole company: it's checked system by system, and it can change if the use changes. That's the real deadline to respect — more than any date on the calendar.
Sources
[1] Regulation (EU) 2024/1689 (AI Act), consolidated text — EUR-Lex
[2] P4I – Osservatori.net, "AI Act: gli impatti della normativa e le prossime scadenze", webinar, May 27, 2026
[3] Gartner, "Getting Ready for the EU AI Act, Phase 1: Discover & Catalog", October 28, 2025 (ID G00839788)
[4] Gartner, "Navigating the EU AI Act: 5 Key Actions for GC", May 13, 2026 (ID G00850911)
[5] Cooley LLP, "EU AI Act: Transparency Obligations Take Effect 2 August 2026", August 3, 2026
[6] Gibson Dunn, "EU AI Act Omnibus Agreement — Postponed High-Risk Deadlines and Other Key Changes"