Summary: Under the EU AI Act, a deployer uses an AI system under its authority, except for personal non-professional use. A U.S. bank with EU customers can be a deployer even when a vendor is the provider, if the output is used in the Union. White-labeling or a change of intended purpose can make the bank the provider. The calendar is a separate page.
The statutory definition of deployer and provider
Regulation (EU) 2024/1689 defines a deployer as a natural or legal person, public authority, agency or other body using an AI system under its authority, except for personal non-professional use. A provider develops an AI system or a general-purpose AI model, or has one developed, and places it on the market or puts it into service under its own name or trademark.
Intended purpose is the use the provider intends, as set out in the instructions, promotional materials, and technical documentation. A substantial modification is a change after placing on the market that was not planned in the initial conformity assessment, and that either affects Chapter III, Section 2 compliance or modifies the intended purpose.
A bank that buys a vendor agent and runs it under its own authority is the deployer.
Why a U.S. bank with EU customers is in scope
The Regulation applies to deployers established or located within the Union. It also applies to providers and deployers in a third country where the output produced by the AI system is used in the Union. A bank with no Union establishment can still be a deployer when that output is used in the Union.
The European Commission describes the AI Act as setting out risk-based rules for AI developers and deployers. Once a system is on the market, deployers ensure human oversight and monitoring, and providers keep a post-market monitoring system.
The three flips that turn a deployer into a provider
Article 25 treats a deployer as a provider of a high-risk AI system, with the provider obligations under Article 16, in three cases.
First, they put their name or trademark on a high-risk AI system already placed on the market or put into service. White-labeling a vendor agent under the bank’s brand is this line.
Second, they make a substantial modification to a high-risk AI system already placed on the market or put into service so that it remains high-risk.
Third, they modify the intended purpose of an AI system, including a general-purpose AI system, that has not been classified as high-risk, so that the system becomes high-risk.
What a deployer of a high-risk system actually owes
Article 26 requires deployers of high-risk AI systems to use those systems in accordance with the instructions for use, and to assign human oversight to people with the necessary competence, training, authority, and support. Article 14 requires the system to arrive so those people can override or reverse output and can stop the run. That duty sits next to human-in-the-loop design.
Where the deployer controls input data, that data must be relevant and sufficiently representative. Deployers must monitor operation and keep automatically generated logs under their control for at least six months. For financial institutions subject to internal-governance rules under Union financial-services law, monitoring is deemed fulfilled by those rules, and the logs sit in that documentation.
Platform provider, system provider, and deployer on an agent stack
Singapore’s Model AI Governance Framework for Agentic AI v1.5 separates platform providers from system providers or app developers. An organisation that develops its own agents and then deploys them plays both the system-provider and deployer roles.
The framework states that as deployers, organisations and humans remain accountable for the decisions and actions of agents. A bank that wraps or hosts an agent platform can sit in both roles. AI governance is the control system around that split.