Last updated:
The EU AI Act provision creating a direct obligation chain between providers and deployers of high-risk AI systems, including responsibility transfer when systems are substantially modified.
Article 25 establishes that organizations deploying third-party high-risk AI systems bear deployer obligations regardless of vendor promises. Critically, a deployer that modifies an AI system in ways that change its intended purpose may legally become the provider, inheriting the full provider obligation set. This is the primary anchor for AI vendor risk assessment under the EU AI Act and the basis for procurement diligence on any third-party AI.
Real world example:
A bank deploys a third-party credit scoring AI but customizes the risk thresholds for its own portfolio. Under Article 25 this customization may trigger provider status - requiring the bank to produce its own technical documentation and conformity assessment.




