Chapter 5. Whose fault: provider, deployer and roles in the supply chain | Grigoriy Dobryakov

Grigoriy Dobryakov

Course · AI Compliance

Chapter 5AI Compliance course

Chapter 5. Whose fault: provider, deployer and roles in the supply chain

Story phase: whose fault. The obligations from chapters 3–4 have to be distributed across roles.

The situation at Kompas

Working through the obligations of chapters 3–4, the Kompas team runs into something uncomfortable: half the requirements (data governance under Art. 10, accuracy metrics, robustness) partly relate to something Kompas didn't make — the foundation model under the hood. The distribution question arises: who in this chain is responsible for what? The model provider? Kompas? The recruiters who deploy the product on their side?

The AI Act's answer is not "some one party," but the role determines the set of duties, and a single company can carry several roles at once. Kompas turns out to wear two hats at once — and that changes both its obligations and its contracts up and down the chain.

What the rule says

Four roles, different sets of duties.

Change of roles — the Art. 25 trap. A deployer (or distributor, importer) becomes a provider of a high-risk system with the full liability if it puts its own name on it, substantially modifies it, or changes its intended purpose such that the system becomes high-risk. This is a direct trap for integrators and "wrappers": you took someone else's model, built on top, sold it under your own brand — you became a provider.

The value chain for GPAI. The foundation-model provider must pass documentation and information down the chain so downstream developers can meet their obligations (details in ch. 7). This is the legal bridge between "someone else's model" and your Annex IV.

Informing the affected. On the deployer's side lies the duty to tell the people caught by a high-risk system that it is being applied to them (Art. 26). For hiring this means: the candidate must learn that a system is evaluating them.

How it lands on the product

Kompas wears two hats at once: it is the provider of its own high-risk system (scoring) — and the deployer of someone else's GPAI model on which it is built. Hence two different sets of duties that must not be mixed.

The recruiter clients are Kompas's deployers. Part of the requirements is physically performed on their side: human oversight in their workflow, informing candidates. So Kompas as the provider must supply them with instructions for use (Art. 13) and tools so they can perform their part — otherwise the gap in the chain closes on the Kompas brand.

The chapter's artifact is a map of roles and duties across the whole chain: model provider → Kompas → recruiter → candidate, with each duty explicitly tied to its bearer and to the confirming contract.

Where it breaks

"Substantial modification" — a blurred boundary. Art. 25 gives no clear threshold for when building on top of someone else's model or fine-tuning it makes you the provider of the model itself. The integrator lives in this gray zone, and the interpretation can turn against them.

The liability gap. The GPAI provider may not disclose all the needed documentation, while Kompas's provider is formally responsible for the data quality and metrics of a system it didn't build from scratch. There is liability, but no control over the source.

Clients don't do their part. A recruiter-deployer may ignore oversight and informing candidates. Legally that's their violation — but the reputational, and often contractual, blow also lands on Kompas.

What to do as engineer/product

Explicitly define your roles per component (provider of scoring, deployer of the model) and lock the distribution of duties with contracts — up with the model provider (what it must disclose and warrant), down with the client-deployers (what they must do on their side).

Supply clients with instructions for use and built-in tools for their part of the obligations (an oversight interface, a candidate-notification template). A duty the client can't physically perform through your product will come back to you.

Provocation

"We're only an integrator" is the second most expensive phrase after "we're just a wrapper." The AI Act is built so that as soon as you put your name on a high-risk system or substantially modify it, the law makes you a provider with the full weight of liability — entirely regardless of whose model you run under the hood and how much it was trained before you.

Read next

Shipping an AI product under regulatory risk?

A read of your product against the EU AI Act: risk class, role in the value chain, obligations and dossier — as a design constraint on the way in, not a lawyer's check at the end.

Email me

The transition engine

Next Move Engine — the system that takes a team to an autonomous delivery loop.

Next Move Engine →