Skip to content
Topic Contested in court

AI Value Chain Actors and Roles

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

The content focuses on responsibilities distributed across different actors in the AI value chain. A dedicated topic for understanding the various actors, their roles, and how they interact would be valuable for comprehensive AI Act compliance.

145 linked items 87 Laws9 Guidance2 Enforcement15 News31 Literature

Overview

18 sources · Sep 25, 2026

Legal Framework

The AI Act structures compliance around a chain of actors—providers, authorised representatives, deployers, importers, and distributors—each bearing distinct statutory obligations. For high-risk AI systems, Article 22 requires third-country providers to appoint an EU-established authorised representative by written mandate before market access. That representative must verify conformity documentation, retain technical records for ten years, and cooperate with competent authorities upon reasoned request. A parallel regime applies to general-purpose AI models under Article 54, with the AI Office replacing market surveillance authorities as the primary interlocutor.

Deployers of high-risk systems carry their own obligations under Article 26, including operational monitoring, human oversight, and input-data quality duties:

"Deployers of high-risk AI systems shall take appropriate technical and organisational measures to ensure they use such systems in accordance with the instructions for use accompanying the systems"
— AI Act Art. 26(1)

Transparency obligations under Article 50 cut across the provider-deployer divide. Providers must design interactive AI systems so that individuals know they are interacting with AI; deployers of emotion recognition or biometric categorisation systems must inform exposed persons directly.

Key Developments

Enforcement remains early but already signals that data protection authorities will scrutinise AI actors through both the AI Act and GDPR lenses. The Italian Garante's decision against Luka Inc. illustrates how a provider's failure to establish a valid legal basis for personal data processing can trigger substantial penalties independently of AI Act provisions:

"Replika is bedoeld als een "virtuele metgezel" die de stemming en het emotionele welzijn van gebruikers verbetert door hen te helpen hun eigen psyche te begrijpen."
— Luka Inc. §1

The EDPB-EDPS joint opinion reinforces that obligations on providers and deployers are cumulative, not substitutive. Staff AI literacy obligations, for instance, apply to both categories of actors:

"AI systems providers and deployers should not be released from their obligation to ensure that their staff have a sufficient level of AI literacy"
— EDPB-EDPS Joint Opinion 1/2026 §6

The same opinion notes that public registration of high-risk exemptions enables deployers to conduct proper due diligence before adopting an exempted system, underscoring that the value chain functions only when each actor can verify the compliance posture of upstream participants.

Status of the Debate

This topic is regulator-defined. The AI Act's role-based architecture is new and has not yet been tested in litigation. No court has interpreted the boundary between provider and deployer obligations, nor the scope of an authorised representative's verification duties under Articles 22 and 54. The doctrinal landscape is shaped chiefly by regulatory guidance and DPA enforcement decisions that apply GDPR principles to AI systems. What would resolve the open questions is structured enforcement: a market surveillance authority action clarifying the division of responsibility between providers and deployers for input-data quality under Article 26(4), or a ruling on whether an authorised representative's failure to verify conformity documentation creates independent liability.

Practical Guidance

  • Map your role before assuming obligations. A single entity can be both provider and deployer depending on context; determine your role per system under Articles 22, 26, and 50 before allocating compliance resources.
  • Third-country providers must appoint EU representatives early. Articles 22 and 54 require written mandates before market access; ensure representatives can verify conformity documentation and retain records for ten years.
  • Deployers must operationalise oversight and monitoring. Under Article 26(2), assign human oversight to competent personnel with necessary authority, and under Article 26(5), establish incident-reporting channels to providers and market surveillance authorities.
  • Transparency is a shared obligation. Providers must design AI systems to signal their nature to users under Article 50(1); deployers must inform individuals exposed to emotion recognition or biometric categorisation systems under Article 50(3).
  • Verify upstream compliance before deployment. Deployers should request and review provider conformity documentation and EU declarations of conformity, as the EDPB emphasises that public registration enables deployer due diligence.
Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section
Is the AI Act caging ChatGPT and other General Purpose Artificial Intelligence systems? > The growth of generative artificial intelligence systems has led EU lawmakers to focus on General Purpose AI in drafting the AI Act, which will set the framework governing… News Gaming Tech Law Mar 2023 Obligations of value chain actors
why this is here
providers of GPAI and responsibilities for the different economic actors involved

The document explicitly discusses responsibilities of different economic actors, including providers, distributors, and importers, which is central to this topic.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

This is the top of each pile — all 87 Laws · all 31 Literature