Home · Glossary · Article 25 (Provider vs Deployer)
Enterprise AI glossary · Compliance & Regulation

Article 25 (Provider vs Deployer)

The EU AI Act provision that converts a deployer of an AI system into a provider — and therefore subject to the full Articles 9–15 stack — when they make substantial modifications, rebrand, or change the intended purpose.

Definition

What Article 25 (Provider vs Deployer) means in practice

Article 25 of the EU AI Act closes the escape hatch most enterprises think they have: "we just use AI, we don't provide it, so the lighter deployer obligations apply." The Article triggers provider status in three ways: substantial modification of an AI system, rebranding the system as one's own, or putting the system into service for a purpose materially different from the vendor's intended use. Across MindMap's audit of regulated enterprise AI portfolios, 70% contain at least one Article 25 trigger — a fine-tuned model in a credit-scoring pipeline, a vendor LLM repurposed for a regulated use case, an AI feature white-labelled and shipped under the enterprise's brand. The implication is that the enterprise carries the full Articles 9–15 obligations, not the lighter deployer stack.

Go deeper
EU AI Act compliance architecture →

All 62 terms, in plain language

Sovereign AI, RAG, agentic AI, IDP, MLOps and the regulations that shape enterprise AI.

Browse the glossary →Talk to an engineer →