30 September 2026
Building AI Inside Your Company
Under the EU AI Act, organisations that build, adapt or repurpose AI systems for internal use may take on provider obligations—even when nothing is sold externally.

AI-provider duties can apply to organisations building systems for internal use—not only AI sellers.
A deployer uses an AI system under its authority. A provider develops or commissions one and places it on the market or puts it into service under its own name. Internal use can count.
Use a vendor’s system as supplied and you are generally a deployer. Build around a model with prompts, data and decision logic, put the resulting system into service under your own name, and you may be its provider.
Substantial modification of high-risk AI or repurposing AI for high-risk use can make deployers providers.
The Commission describes four risk levels:
—Prohibited: social scoring and certain harmful manipulation or exploitation.
—High risk: under Article 6(1)/Annex I, certain AI products or safety components subject to specified EU product rules and third-party conformity assessment; these duties apply from 2 August 2028. Under Article 6(2)/Annex III, uses including employment, education, creditworthiness, life/health insurance, essential services, and certain biometric, law-enforcement and migration contexts; these duties apply from 2 December 2027.
—Transparency: from 2 August 2026, chatbots, deepfakes and some AI content may need disclosure or labelling.
—Minimal or no risk: most other AI. A full AI Act technical file or registration is generally not required; GDPR and sector rules may still apply.
Risk depends mainly on intended purpose—not simply technology or personal data. Profiling within an Annex III use case is always high-risk.
Before market launch or internal use, the provider of a high-risk system must document its purpose and operation; components and data; risks and safeguards; human oversight; testing; and monitoring. It must also put in place a documented quality management system (QMS) covering compliance, design and testing controls, data and risk management, post-market monitoring, incident reporting, record-keeping and accountability. Implementation is proportionate to the provider’s size, but the required rigour and level of protection remain.
Deferred deadlines create preparation time, not retrospective evidence. Upstream documentation can describe the model, but not how the finished system was configured, tested, supervised or behaved on your data. That evidence must be generated and retained from the outset.
Article 25(2) cooperation can fall away if the initial provider excludes conversion to high-risk use, making Article 25(4)’s written agreement a procurement gate. If adequate documentation, technical access or support cannot be secured before building, change the agreement, vendor or design.
The provider must also complete conformity assessment, issue the declaration and apply CE marking. Most Annex III systems must also be registered in the EU database.
A high-risk deployer does not normally prepare the provider’s full technical file. It must follow instructions, assign human oversight, check input data it controls, monitor and report problems, retain logs and give required notices. GDPR and AI Act impact assessments may also be required.
A sandbox supports testing and evidence but does not replace documentation.
An Annex III system may be treated as not high-risk only if it poses no significant risk of harm and meets a narrow exemption. The provider must document the assessment and register the system. Profiling systems cannot use the exemption.
The question is not only what AI we buy or what we build around it. It is also whether that changes our legal role—and whether we could prove how the resulting system behaved if asked.
AI governance also extends beyond the EU: the US has the voluntary NIST AI RMF, China has binding AI rules, and ISO/IEC 42001 is an international AI-management standard.


