# AI Value Chain Actors and Roles — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/ai-value-chain-actors
> Sources are cited per item. Verify against the official texts before relying on them.

The content focuses on responsibilities distributed across different actors in the AI value chain. A dedicated topic for understanding the various actors, their roles, and how they interact would be valuable for comprehensive AI Act compliance.

## Overview

## Legal Framework

The AI Act distributes compliance obligations across distinct actors in the AI value chain, principally providers and deployers. Recital 21 establishes that these obligations apply in a non-discriminatory manner to providers regardless of whether they are established within the Union or in a third country, and to deployers established within the Union. This extraterritorial reach mirrors the GDPR's approach and ensures that regulatory arbitrage through offshore establishment does not undermine the level playing field.

Article 50 of the AI Act imposes specific transparency obligations on both providers and deployers of certain AI systems. These obligations operate alongside, not in substitution of, GDPR transparency requirements under Article 13 GDPR, which require controllers to inform data subjects about processing activities including the legal basis, purposes, and retention periods. Where AI systems process special categories of personal data within the meaning of Article 22 GDPR, the default prohibition applies unless a specific exception can be invoked. Several exceptions under Article 22 GDPR have direct effect — namely subparagraphs a, c, d, e, and f — while others require a basis in national or Union law. Consent under Article 22 GDPR must manifest through a clear affirmative act, whether written, oral, or electronic, demonstrating freely given, specific, informed, and unambiguous agreement.

Article 62 of the AI Act introduces supportive measures for providers and deployers, with particular attention to SMEs and start-ups, acknowledging that compliance burdens must be calibrated to organizational capacity without diluting substantive protections.

## Key Developments

The Italian Data Protection Authority's enforcement action against Luka Inc. illustrates the practical convergence of AI Act and GDPR obligations. The €5,000,000 fine imposed on the company for its Replika chatbot demonstrates that authorities will scrutinize both the provider's design choices and the deployer's operational use of AI systems, particularly where vulnerable users and special category data are implicated.

The Dutch Data Protection Authority has signaled that AI regulatory sandboxes will become mandatory from August 2026, providing a structured environment for providers and deployers to test compliance assumptions under supervisory guidance. Transparency obligations under the AI Act take effect from 2 August 2025, and the Dutch regulator has advised organizations to adopt a voluntary code of practice in the interim, signaling that proactive engagement will be viewed favorably in enforcement contexts.

## Practical Guidance

- **Map your role precisely.** Determine whether your organization qualifies as a provider, deployer, or both under the AI Act, as this classification determines which obligations attach. A single entity may occupy different roles across different AI systems or use cases.

- **Audit special category data flows.** Where AI systems process data covered by Article 22 GDPR, identify the applicable exception before deployment. Relying on consent requires demonstrable, affirmative action by the data subject — passive acceptance or pre-ticked boxes are insufficient.

- **Implement layered transparency.** Satisfy both AI Act Article 50 and GDPR Article 13 through coordinated notices that distinguish AI-specific disclosures from general data protection information, avoiding contradictory or duplicative statements.

- **Document cross-border transfers.** Where processing involves actors outside the Union, record the transfer mechanism relied upon and evidence serious efforts to identify an adequate basis under GDPR Articles 45, 46, or 49 before invoking residual exceptions.

- **Engage with sandbox frameworks.** For SMEs and start-ups, Article 62 measures and national sandbox programs offer a pathway to test compliance under supervisory oversight, reducing enforcement risk for novel applications.

## Legislation (full text of key provisions)

### Transparency obligations for providers and deployers of certain AI systems

*Source: AI Act, aiact-art-50-en, 2024-06-12 — https://overview.legal/posts/92746*

### Fines for providers of general-purpose AI models

*Source: AI Act, aiact-art-101-en, 2024-06-12 — https://overview.legal/posts/93587*

### Responsibilities along the AI value chain

*Source: AI Act, aiact-art-25-en, 2024-06-12 — https://overview.legal/posts/92363*

### Obligations of deployers of high-risk AI systems

*Source: AI Act, aiact-art-26-en, 2024-06-12 — https://overview.legal/posts/92382*

### Authorised representatives of providers of high-risk AI systems

*Source: AI Act, aiact-art-22-en, 2024-06-12 — https://overview.legal/posts/92312*

### Enforcement of the obligations of providers of general-purpose AI models

*Source: AI Act, aiact-art-88-en, 2024-06-12 — https://overview.legal/posts/93401*

### Obligations for providers of general-purpose AI models

*Source: AI Act, aiact-art-53-en, 2024-06-12 — https://overview.legal/posts/92790*

### Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems

*Source: AI Act, aiact-art-72-en, 2024-06-12 — https://overview.legal/posts/93175*

### Obligations of providers of high-risk AI systems

*Source: AI Act, aiact-art-16-en, 2024-06-12 — https://overview.legal/posts/92242*

Providers of high-risk AI systems shall:

### Obligations of providers of general-purpose AI models with systemic risk

*Source: AI Act, aiact-art-55-en, 2024-06-12 — https://overview.legal/posts/92830*

## Guidance

### Statement 3/2024 on data protection authorities’ role in the Artificial Intelligence Act framework

*Source: EDPB, statement-32024-on-data-protection-authorities-role-in-the-en, 2024-07-16 — https://overview.legal/posts/125732 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-32024-on-data-protection-authorities-role-in-the_en*

Final 1 Statement 3/2024 on data protection authorities’ role in the Artificial Intelligence Act framework Adopted on 16 July 2024 The European Data Protection Board has adopted the following statement: 1 BACKGROUND AND PURPO SE OF THIS STATEMENT 1. On 12 July 2024, Regulation (EU) 2024/1689 laying down harmonised rules on a rtificial i ntelligence (Artificial Intelligence Act, hereinafter the “ AI Act ”) and amending certain Union Legislative Acts was published in the Official Journal 1 . 2.…

### Statement on the Digital Services Package and Data Strategy

*Source: EDPB, statement-on-the-digital-services-package-and-data-en, 2021-11-18 — https://overview.legal/posts/125982 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-on-the-digital-services-package-and-data_en*

1 Adopted Statement on the D igital Services Package and Data Strategy Adopted on 18 November 2021 The European Data Protection Board has adopted the following statement: Since November 2020 , the European Commission has presented several legislative proposals as part of its digital and data strategies, most notably the Digital Services Act (DSA), the Digital Markets Act (DMA), the Data Governance Act (DGA) and the Regulation on a European appr oach for A rtificial I ntelligence (AIR). A fifth…

### Guidelines 8/2020 on the targeting of social media users

*Source: EDPB, edpb-guidelines-on-the-targeting-of-social-media-users, 2021-04-13 — https://overview.legal/posts/38073 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-82020-on-the-targeting-of-social-media-users_en*

The EDPB adopted Guidelines 8/2020 on the targeting of social media users to clarify the roles, responsibilities, and legal obligations of the various actors involved in social media targeting, including social media providers, targeters, and users. The guidelines analyze different targeting mechanisms—based on provided, observed, and inferred data—and address controller determinations, legal bases, transparency requirements, DPIAs, and the processing of special categories of data. No fines are imposed, as this is interpretive guidance intended to assist stakeholders in achieving GDPR compliance.

### EDPB Annual Report 2025

*Source: EDPB, edpb-annual-report-2025-en, 2026-04-09 — https://overview.legal/posts/125683 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-annual-report-2025_en*

Clarity in action: Supporting stakeholders through guidance and dialogue Annual Report 2025 Foreword 3 Highlights 4 1. The EDPB Secretariat 6 1.1 Mission And Activities 8 2. European Data Protection Board – Activities in 2025 12 2.1 Bridging Fundamental Rights and Digital Innovation Through GDPR Compliance 12 2.1.1 Helsinki high-level meeting: enhanced clarity, support and engagement 12 2.1.2 Regulation on procedural rules and Omnibus regulation on the record of processing 14 2.1.3 Cross…

### Report on stakeholder event on processing of personal data to target or deliver political advertisements

*Source: EDPB, report-on-stakeholder-event-on-processing-of-personal-data-en, 2026-03-27 — https://overview.legal/posts/125684 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/report-on-stakeholder-event-on-processing-of-personal-data_en*

Report on stakeholder event on processing of personal data to target or deliver political advertisements 27 March 2026 1. Background The EDPB organised an online stakeholder event on 27 March 2026 to collect stakeholders’ input on processing of personal data to target or deliver political advertisements. The objective was to engage with stakeholders at an early stage of drafting the EDPB Guidelines on the processing of personal data to target or deliver political advertisements (Chapter III of…

### EDPB Annual Report 2021

*Source: EDPB, edpb-annual-report-2021-en, 2022-05-12 — https://overview.legal/posts/125941 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-annual-report-2021_en*

Enhancing the depth and breadth of data protection 2 EDPB Annual Report 2021 2 ENHANCING THE DEPTH AND BREADTH OF DATA PROTECTION An Executive Summary of this report, which provides an overview of key EDPB activities in 2021, is also available. Further details about the EDPB can be found on our website at edpb.europa.eu. 3 EDPB Annual Report 2021 3 GLOSSARY 7 FOREWORD 10 2021 - HIGHLIGHTS 13 3.1. STRATEGY 2021-2023 AND WORK PROGRAMME 2021-2022 13 3.2. EDPB OPINIONS ON DRAFT UK ADEQUACY…

### Report on stakeholder event on anonymisation and pseudonymisation of 12 December 2025

*Source: EDPB, report-on-stakeholder-event-on-anonymisation-and-en, 2026-02-18 — https://overview.legal/posts/125688 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/report-on-stakeholder-event-on-anonymisation-and_en*

Report on stakeholder event on anonymisation and pseudonymisation of 12 December 2025 1. Background The EDPB organise d a remote stakeholder event on 12 December 2025 to collect stakeholders’ input on anonymisation and pseudonymisation , following the Court of Justice of the European Union ( “ CJEU ” ) judgment in case EDPS v SRB 1 . The objective was to engage with stakeholders to inform the EDPB’s ongoing work on its guidelines 01/2025 on pseudonymisation and f orthcoming guidelines on…

### EDPB Work Programme 2024-2025

*Source: EDPB, edpb-work-programme-2024-2025-en, 2024-10-09 — https://overview.legal/posts/125711 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-work-programme-2024-2025_en*

The European Data Protection Board (EDPB) is an independent European body established by the General Data Protection Regulation (GDPR). The EDPB has the following main tasks: 1. In line with the Article 29 of the EDPB Rules of Procedure. This Work Programme is valid from 8 October 2024 until 31 December 2025 and supersedes, for the remaining part of 2024, the previous Work Programme 2023–2024. 2. https://www.edpb.europa.eu/system/files/2024-04/edpb_strategy_2024-2027_en.pdf EDPB Work Programme…

## Enforcement decisions

### Luka Inc.: Niet-naleving van de algemene principes voor gegevensverwerking.

*Source: Italian Data Protection Authority (Garante), 2025-04-10 — https://overview.legal/posts/52327*

De Italiaanse gegevensbeschermingsautoriteit heeft Luka Inc. een boete van 5.000.000 euro opgelegd. Het bedrijf heeft een chatbot genaamd Replika ontwikkeld, met een tekst- en spraakinterface. Deze chatbot is gebaseerd op een generatief AI-systeem, specifiek een LLM-model, dat voortdurend wordt aangevuld en verbeterd door interacties met gebruikers. Replika is bedoeld als een "virtuele metgezel" die de stemming en het emotionele welzijn van gebruikers verbetert door hen te helpen hun eigen psyche te begrijpen. Replika kan worden ingesteld als een vriend, therapeut, romantische partner of mentor. De controle...

## Recent developments

### AP adviseert Twitch-gebruikers: zet instellingen uit voor delen van data met Amazon AI

*Source: Autoriteit Persoonsgegevens, 2026-08-20 — https://overview.legal/posts/291397 — original: https://autoriteitpersoonsgegevens.nl/actueel/ap-adviseert-twitch-gebruikers-zet-instellingen-uit-voor-delen-van-data-met-amazon-ai*

Streamingplatform Twitch heeft bekendgemaakt dat Amazon persoonsgegevens van Twitch-gebruikers gebruikt om AI-modellen mee te trainen. Gebruikers die niet willen dat Amazon hun streams, afbeeldingen en andere persoonsgegevens gebruikt, kunnen dit nu uitzetten. De Autoriteit Persoonsgegevens (AP) roept mensen op dat te doen.

### Secret scoring: Join the CRIF class action now!

*Source: noyb - European Center for Digital Rights, 2026-06-09 — https://overview.legal/posts/53124 — original: https://noyb.eu/en/secret-scoring-join-crif-class-action-now*

Credit Scoring CRIF is one of the largest credit reference agencies in Austria. It has built up a largely unknown "shadow registry" containing the names, dates of birth and addresses of almost all adults in Austria. CRIF uses this data to assign people a score. For 90% of those affected, this score is based primarily on address, gender and age. Although this data does not allow for any real conclusions to be drawn about a person’s creditworthiness, the CRIF score often determines whether someone

### LinkedIn locks your GDPR rights behind a paywall

*Source: noyb - European Center for Digital Rights, 2026-05-05 — https://overview.legal/posts/53127 — original: https://noyb.eu/en/linkedin-locks-your-gdpr-rights-behind-paywall*

Data Subject Rights LinkedIn tracks the visits to profile pages. However, if you want to see who has visited your own profile, you have to pay. The Microsoft subsidiary uses these and other ‘insights’ as an incentive for people to sign up for its paid Premium membership. It is unclear whether this tracking of visitors is legal. What is clear, however, is that if this data is displayed as part of a premium membership, it should also be accessible in response to an access request under Article 15

### noyb win: Conde Nast fined €750,000 for placing cookies without consent

*Source: noyb - European Center for Digital Rights, 2025-11-27 — https://overview.legal/posts/49180 — original: https://noyb.eu/en/noyb-win-conde-nast-fined-eu750000-placing-cookies-without-consent*

Cookie Banners Today, the French data protection authority CNIL has fined the French magazine publisher Conde Nast €750.000 for violating the consent requirements on its Vanity Fair website. noyb had originally filed a complaint against Conde Nast in 2019 (!). The decision by the French data protection authoritynoyb’s original complaints from 2019Background. In December 2019, noyb had filed complaints against three providers of French websites, because they had implemented cookie banners that tu

### noyb WIN: YouTube ordered to honour user’s right of access

*Source: noyb - European Center for Digital Rights, 2025-08-29 — https://overview.legal/posts/53142 — original: https://noyb.eu/en/noyb-win-youtube-ordered-honour-users-right-access*

Data Subject Rights noyb has achieved a win against YouTube, the video platform provided by Google. After five and a half years, the Austrian data protection authority (DSB) has finally issued a decision siding with noyb – and ordering YouTube to comply with the complainant’s access request in accordance with Article 15 GDPR. Until now, the company withheld a large amount of data, including information about the purpose of the processing, storage periods, data recipients and the tracking cookies

## Literature

### General-Purpose AI under the EU AI Act: A Conceptual Allocation of Duties across the Value Chain

*Source: SCRIPTed A Journal of Law Technology & Society, 2026-06-30 — https://overview.legal/posts/132370 — original: https://doi.org/10.2218/scrip.12300*

This article examines how the final version of the EU Artificial Intelligence Act (“AI Act”, adopted 2024) allocates obligations across the AI value chain, with a focus on general-purpose AI (“GPAI”) or foundation models. It proposes a taxonomy of key actors – foundation model providers, fine-tuners, integrators, and deployers – and analyses the interfaces between them, including documentation tools (model cards, system cards) and logging requirements. Building on principles of control, foreseea

### A Comparative Analysis of Korea’s Framework Act on Artificial Intelligence and the EU AI Act from a Fundamental Rights Perspective

*Source: DONG-A LAW REVIEW, 2026-02-28 — https://overview.legal/posts/132618 — original: https://doi.org/10.31839/dalr.2026.02.110.341*

### Artificial Intelligence in Decision-making: A Test of Consistency between the “EU AI Act” and the “General Data Protection Regulation”

*Source: Athens Journal of Law, 2025-01-02 — https://overview.legal/posts/132443 — original: https://doi.org/10.30958/ajl.11-1-3*

The recent Regulation that sets down harmonised rules on Artificial Intelligence in the European Union, known as the "AI Act," includes a significant requirement for human oversight in high-risk AI systems during their use (art. 14). This requirement embodies the "human-in-command" approach, ensuring both legal and ethical compliance. The AI Act is intended to complement the General Data Protection Regulation (hereinafter GDPR), thereby forming a consistent and comprehensive legal framework. Thi

### The First Global AI Treaty: Analyzing the Framework Convention on Artificial Intelligence and the Eu AI Act

*Source: SSRN Electronic Journal, 2025-01-01 — https://overview.legal/posts/132614 — original: https://doi.org/10.2139/ssrn.5069335*

### Regulating General Purpose Artificial Intelligence (GPAI) within the EU AI Act: Challenges and Considerations

*Source: SSRN Electronic Journal, 2025-01-01 — https://overview.legal/posts/132615 — original: https://doi.org/10.2139/ssrn.5122935*

## Tools

### EU AI Act Compliance Checker

*Source: Future of Life Institute, 2026-07-17 — https://overview.legal/posts/125619 — original: https://artificialintelligenceact.eu/assessment/eu-ai-act-compliance-checker/*

Interactive self-assessment that walks providers, deployers and importers through the AI Act's scoping questions: whether a system is in scope, its risk classification (prohibited / high-risk / limited / minimal), and which obligations and deadlines follow from that classification.

## Related topics

- **Artificial Intelligence** — https://overview.legal/topics/ai
  AI systems and their implications for data protection
- **High-Risk AI Classification** — https://overview.legal/topics/high-risk-ai-classification
  The content specifically addresses classification rules for high-risk AI systems under the AI Act, which is a distinct regulatory concept requiring its own dedi
- **AI Risk Assessment** — https://overview.legal/topics/ai-risk-assessment
  The AI Act employs a risk-based regulatory approach to determine which practices are prohibited, requiring assessment and classification of AI system risks, whi
- **Annex III Amendments** — https://overview.legal/topics/annex-iii-amendments
  This new topic is needed because amendments to Annex III represent specific regulatory changes to the AI Act's classification framework that warrant dedicated t
- **GPAI Systemic Risk** — https://overview.legal/topics/general-purpose-ai-models-systemic-risk
  This new topic is needed because the content specifically addresses the classification and identification of general-purpose AI models that present systemic ris
- **Monitoring** — https://overview.legal/topics/monitoring
  Systematic observation and tracking of individuals

---
Generated by overview.legal · https://overview.legal/topics/ai-value-chain-actors · 2026-08-22
