Home · EU AI Act · Articles · Article 25
EU AI Act · Engineering reference

Article 25 — Provider vs Deployer Trigger

A deployer that makes substantial modifications, rebrands, or repurposes an AI system becomes the provider — and takes on the full Articles 9-15 obligation stack.

Audit-survivable
26%
of 50 EU-exposed enterprises in MindMap's 2026 readiness benchmark

What the Article requires

Article 25 closes the escape hatch most enterprises think they have. Three triggers convert a deployer into a provider: (a) substantial modification of the system, (b) putting the system on the market under one's own name or trademark, (c) substantially modifying the intended purpose. Once provider status attaches, the full Articles 9-15 evidence stack applies — the customer can no longer rely on the upstream vendor's compliance posture.

In engineering terms

Across MindMap's audit of regulated enterprise AI portfolios, 70% contain at least one Article 25 trigger — typically a fine-tuned foundation model in a credit-scoring pipeline, a vendor LLM repurposed for a regulated use case, or an AI feature white-labelled and shipped under the enterprise's brand. Each trigger turns an integrator into a provider in the regulator's eyes.

Compliance checklist

  • ✓Inventory of fine-tuned models, rebranded vendor systems and repurposed AI
  • ✓Article 25 classification for each AI system
  • ✓Provider-stack evidence collection for triggered systems
  • ✓Vendor disclosures validated against actual customer use
  • ✓Cross-functional sign-off on Article 25 determinations

Terms used here

Article 25 (Provider vs Deployer)EU AI ActAnnex III high-risk AI

All Articles in the reference · The EU AI Act compliance architecture

Need audit-survivable evidence for Article 25?

MindMap runs a 90-day path from standing start to audit-survivable evidence. Talk to the engineering team.

Download the whitepaper →Check your tier →Book a scoping call →