Article 25 (Provider vs Deployer)
The EU AI Act provision that converts a deployer of an AI system into a provider — and therefore subject to the full Articles 9–15 stack — when they make substantial modifications, rebrand, or change the intended purpose.
What Article 25 (Provider vs Deployer) means in practice
Article 25 of the EU AI Act closes the escape hatch most enterprises think they have: "we just use AI, we don't provide it, so the lighter deployer obligations apply." The Article triggers provider status in three ways: substantial modification of an AI system, rebranding the system as one's own, or putting the system into service for a purpose materially different from the vendor's intended use. Across MindMap's audit of regulated enterprise AI portfolios, 70% contain at least one Article 25 trigger — a fine-tuned model in a credit-scoring pipeline, a vendor LLM repurposed for a regulated use case, an AI feature white-labelled and shipped under the enterprise's brand. The implication is that the enterprise carries the full Articles 9–15 obligations, not the lighter deployer stack.
Related terms
EU AI Act →
The European Union's AI Act — risk-tiered regulation of AI systems, with high-risk-system requirements that effectively mandate auditability, human oversight and conformity assessment.
Annex III high-risk AI →
The schedule in the EU AI Act listing AI use cases automatically classified as high-risk — biometric ID, credit scoring, HR screening, healthcare diagnostic support, critical infrastructure, education, justice.
GPAI (General-Purpose AI) →
The EU AI Act category covering general-purpose AI models (foundation LLMs) — Article 53 sets baseline obligations on every provider, Article 55 adds systemic-risk obligations above a 10^25 FLOP training-compute threshold.
More in this category
All 62 terms, in plain language
Sovereign AI, RAG, agentic AI, IDP, MLOps and the regulations that shape enterprise AI.