Article 25(1)
UpcomingConditional timingAssume Provider Responsibilities When Your Actions Make You the Provider of a High-Risk AI System
Applies to Distributor; Importer; Deployer; Other Third Party; High-Risk AI.
- Actors
- DeployerDistributorImporterThird-Party Supplier
- AI class
- High-Risk AI
- Themes
- Third Parties & Supply ChainGovernance & Accountability
Tracker Networks Guidance
If your organization is a distributor, importer, deployer or other third party and it puts its name or trademark on an existing high-risk AI system, substantially modifies a high-risk AI system so that it remains high-risk, or changes the intended purpose of an AI system so that it becomes high-risk, Article 25(1) treats your organization as the provider. In that case, assume the applicable Article 16 provider obligations and manage the resulting provider responsibilities before the affected system is placed on the market, put into service or otherwise operated under your responsibility.
Official text
1. Any distributor, importer, deployer or other third-party shall be considered to be a provider of a high-risk AI system for the purposes of this Regulation and shall be subject to the obligations of the provider under Article 16, in any of the following circumstances: (a) they put their name or trademark on a high-risk AI system already placed on the market or put into service, without prejudice to contractual arrangements stipulating that the obligations are otherwise allocated; (b) they make a substantial modification to a high-risk AI system that has already been placed on the market or has already been put into service in such a way that it remains a high-risk AI system pursuant to Article 6; (c) they modify the intended purpose of an AI system, including a general-purpose AI system, which has not been classified as high-risk and has already been placed on the market or put into service in such a way that the AI system concerned becomes a high-risk AI system in accordance with Article 6.
Timing depends on the system
- 2 Dec 2027 — Article 6(2) / Annex III high-risk AI
- 2 Aug 2028 — Article 6(1) / Annex I Section A high-risk AI
- 2 Dec 2027 — Pre-existing Annex III high-risk AI type/model first placed on the market or put into service before 2027-12-02
- 2 Aug 2028 — Pre-existing Article 6(1) / Annex I high-risk AI type/model first placed on the market or put into service before 2028-08-02
- 2 Aug 2030 — Pre-existing high-risk AI intended to be used by public authorities
Suggested controls
AI Value Chain Contracting and Technical Handover
Define information, technical access, assistance and handover responsibilities across the high-risk AI value chain.
AI Inventory and Use-Case Classification
Maintain an inventory of AI systems/use cases and classify them by regulatory role, use, risk category and relevant conditions.
Related risks
AI Value Chain Compliance Failure
Suppliers, importers, distributors or authorised representatives may not provide the information, controls or cooperation needed for high-risk AI compliance.