Legal roles under Article 3
Article 3 of the EU AI Act assigns roles by the act performed. A provider places an AI system or general-purpose model on the market under its name, while a deployer uses an AI system under its own authority.1
A company using the system may therefore carry a duty even if another company made the model. I would start by identifying the company that performs the act regulated by the provision.
“Foundation model” is a market term. The Act instead defines a “general-purpose AI model” by its ability to perform a wide range of tasks and be integrated into downstream systems.
General-purpose model providers
The Act directly regulates providers of general-purpose AI models, requiring them to give downstream system providers information needed to understand the model and comply with the Act. Additional obligations apply when a model presents systemic risk, the Act's category for risks that can cause significant harm across the Union because of the model's capabilities or reach.2
Those obligations applied to models placed on the market after 2 August 2025. Since 2 August 2026, the Commission can enforce the provider's documentation and systemic-risk duties.
Another company may adapt the model inside a product that the original developer neither operates nor sells to the final user. Duties tied to that use may apply to the company operating the product.
Role changes under Article 25
Article 25 can make a deployer the provider of a high-risk system after a substantial modification. The same can happen when another party changes the system's intended purpose so that it becomes high-risk.3
The company taking on the provider role may need technical information from its upstream supplier. The contract should secure that access before the system is changed.
A July 2026 amending measure extended the application dates for the AI Act's high-risk provisions. It changed the timetable but left Article 25's role allocation in place.4
Marking and disclosure under Article 50
Article 50 assigns machine-readable marking to the provider of a covered generative system. A deployer publishing specified deepfakes or public-interest text may have to disclose the use.5
Machine-readable marking does not satisfy a deployer's separate disclosure duty for covered publication.
The deployer knows where the content appears and whether people will encounter it as part of a professional service. The model provider may be unable to determine that context from an API call alone.
The CMA investigation
On 14 May 2026, the UK Competition and Markets Authority opened an investigation into whether Microsoft has strategic market status in its business-software ecosystem. The investigation concerns Microsoft's position across business software and cloud services.6
The CMA is examining Microsoft's licensing and access terms under competition law, including whether customers can switch software or cloud provider.