Skip to content
Call, +49 511 47 55 58 10
lexICT GmbH, Home

Point of law

Whom the transparency duties bind

Art. 50 AI Act allocates four duties to two addressees. Paragraphs 1 and 2 bind the provider, paragraphs 3 and 4 the deployer. Which role applies follows from Art. 3(3) AI Act, from placing on the market or from putting into service under one's own name, and that is how an organisation can become a provider without ever having developed a model.

Your own name over someone else’s model

A business unit has built an assistant. Underneath sits a third party language model, above it an interface of its own with a name of its own. Legal asks which transparency duties this triggers, and the answer turns on a prior question.

Four duties, two addressees

Whom each duty binds is set out in Art. 50 AI Act more plainly than the provision tends to be read. Four duties are allocated there to two roles, and the wrong role leads to the wrong duty.

The four paragraphs and their addressees

ProviderMerkmalDeployer
Paragraph 1The system has to be designed and developed so that the person is informed, unless that is obvious.Interaction with peopleNot addressed
Paragraph 2Machine-readable and detectable as artificially generated. The duty attaches to the system and thus to its provider.Marking synthetic contentNot addressed
Not addressedEmotion recognition and biometric categorisationParagraph 3The persons exposed have to be informed of the operation of the system.
Not addressedDeepfakes and certain textsParagraph 4Disclosure that the content has been artificially generated or manipulated, with exceptions for artistic works and for texts under editorial responsibility.

Paragraph 5 applies to all four. The information has to be provided clearly and distinguishably at the latest at the time of the first interaction, and it has to meet the applicable accessibility requirements.

An organisation using a third party tool owes nothing under paragraphs 1 and 2. As soon as it is a provider itself, it owes both, and for a system it did not program.

Provider status also arises without development

How an organisation becomes a provider itself follows from Art. 3(3) AI Act. The second form of conduct named there tends to be read past, because a provider is also whoever puts an AI system into service under their own name.

Three routes into provider status

  1. Putting into service under your own name

    Art. 3(3) AI Act together with its point 11. Supply for first use, including for your own use, suffices. Development of your own is not required.

  2. Putting your name on a high-risk system

    Art. 25(1)(a) AI Act. Contractual arrangements allocating duties differently are unaffected.

  3. Substantial modification or a new intended purpose

    Art. 25(1)(b) and (c) AI Act. The second case also covers a system that becomes high-risk only through the change.

3 von 3

For the assistant in the situation above, that means an assessment in two steps, and the first is the harder one.

Four features by which provider status becomes visible

Liste zu erledigender Punkte

  • The assistant has a name of its own that is not the model provider’s
  • It is supplied to a group of users, whether internal or external
  • The supply is the first of its kind for that purpose
  • The interface gives users the impression of a product of your own

Where those are present, provider status is settled first. Only then does the question arise which paragraphs of Art. 50 AI Act apply, and that question is the easier one.

How we support you with the transparency obligations

The role can be recorded per system in a single line, and that line belongs in the register in which the systems already appear. It names the name under which the system is supplied, the body supplying it, and from those the role. Where the role is provider, the list of duties follows from Art. 50 AI Act. Where it is deployer, the list is shorter, and the rest is a question for the supplier.

Frequently asked questions

Since when does Art. 50 AI Act apply?

Since 2 August 2026, the general date of application under Art. 113 AI Act. Art. 111 AI Act provides no transitional rule for these duties in respect of systems already in use. The periods set out there concern large-scale IT systems, high-risk systems and general purpose models.

We use a third party model inside our own application. What are we?

That turns on the name and on the supply. Where the application is supplied for first use under your own name, including for your own use, there is a putting into service under Art. 3(11) AI Act, and provider status under Art. 3(3) AI Act comes into consideration. Where the provider's own tool is merely used, deployer status remains.

Does the original provider remain responsible alongside?

In the cases covered by Art. 25(1) AI Act, no. Under paragraph 2 the initial provider is no longer considered the provider of that specific system, but it has to cooperate closely with the new provider and supply the necessary information.

Does provider status coincide with being a controller?

No. The AI Act attaches to placing on the market and to use, the GDPR to the decision on purposes and means. The same body can be a deployer and at the same time a controller, and the model provider can be a provider and at the same time a processor.

Get in touch!

Have we sparked your interest? Do you have questions? Would you like a quote without obligation? We look forward to hearing from you!

Contact us

Alternatively you can request a call back.