The Act begins with the actor
Article 3 of the EU AI Act assigns roles by the act performed. A provider places an AI system or general-purpose model on the market under its name, while a deployer uses an AI system under its own authority.1
The allocation means that the company using a system can carry an obligation even though another company made the model.
“Foundation model” is a market term for a reusable model, while the Act defines a “general-purpose AI model” by its ability to perform a wide range of tasks and be integrated into downstream systems. Model weights are the numerical settings learned during training; they belong to the model rather than a later deployment decision.
A model provider has model-level duties
The Act directly regulates providers of general-purpose AI models, requiring them to give downstream system providers information needed to understand the model and comply with the Act. Additional obligations apply when a model presents systemic risk, the Act's category for risks that can cause significant harm across the Union because of the model's capabilities or reach.2
Those obligations applied to models placed on the market after 2 August 2025, and the Commission's enforcement powers became applicable on 2 August 2026. The model provider is therefore a current regulatory target where the issue concerns model documentation or systemic risk.
It does not follow that the same provider controls every downstream use because the model may be adapted inside a product that the original developer neither operates nor sells to the final user. Regulation has to follow the act that creates the exposure in question.
Deployment can change the legal role
Article 25 shows how responsibility can move along the value chain: a deployer or other third party can become the provider of a high-risk system when it makes a substantial modification. The same can happen when it changes the intended purpose so that an existing system becomes high-risk.3
The practical question is who changed the system or put it to the regulated purpose, not who trained the general-purpose model. A procurement contract may need to secure technical access from an upstream supplier so the company carrying the provider duty can meet it.
A July 2026 amending measure extended the application dates for the AI Act's high-risk provisions. The role allocation remains in the Regulation, but a compliance statement must use the amended dates rather than the original timetable.4
The output can shift the target
Article 50 separates duties at the point where content is generated from duties at the point where it is shown, requiring a provider of a covered generative system to support machine-readable marking. A deployer publishing specified deepfakes or public-interest text may have to disclose that use to people.5
The underlying model may be unchanged, yet the duty differs because one company designed the system while another controls the publication act. Machine-readable provenance supplied upstream does not by itself satisfy every user-facing disclosure duty downstream.
This fits the real decision because the deployer knows where the content appears and whether people will encounter it as part of a professional service. The model provider may be unable to determine that context from an API call alone.
A platform can be the target
On 14 May 2026, the UK Competition and Markets Authority opened an investigation into whether Microsoft has strategic market status in its business-software ecosystem. The case concerns a platform position that joins business software with cloud services, not the legal classification of one model.6
The inquiry illustrates a different point of control because a company can shape customer choices through the terms that govern access to its software and cloud service. A rule aimed only at model design would leave those switching constraints untouched.
Competition law and the AI Act ask different legal questions. The value of the comparison is structural: each regime chooses an actor by reference to the decision it can affect.
The contract must follow the role
The model provider remains the target for documentation and model risks that only it can assess. Article 25 can still make a downstream company the provider when that company changes the system or its intended purpose.
Before making that change, the downstream company should identify the technical information it would need to perform the resulting duty. If the upstream supplier will not provide access, the downstream company has to decide before deployment whether it can accept the provider role.