AI Governance Study

Roles across the AI value chain: developer, provider, deployer and user

AI law assigns obligations by role. Which duties an organization has depends on whether it built the system, put it on the market, runs it, or interacts with it. The same four roles return in Domain II to decide legal obligations, and in Domain IV to decide

Domain I · Establish and communicate organizational expectations for AI governance · about 10 min

Why this matters for the exam

AI law assigns obligations by role. Which duties an organization has depends on whether it built the system, put it on the market, runs it, or interacts with it. The same four roles return in Domain II to decide legal obligations, and in Domain IV to decide who is liable when something goes wrong.

What you need to know

The last competency covered what AI is and how it fails. This one turns to the people and organizations around a system, starting with the four roles the course uses as its baseline:

RoleWho it isExample
DeveloperThe technical creator: designs, builds and tests the system.A startup building a generative AI chatbot.
ProviderPuts the system on the market or into service under its own name or trademark.A company that develops and sells an AI recruitment system.
DeployerUses the system under its own authority, in a professional context.A bank using AI to help decide loan applications.
UserAnyone who interacts with the system or is directly affected by it.A customer talking to a company's AI chatbot.

Different laws use different labels for functionally similar roles. The Colorado AI Act says "developer" where the EU AI Act says "provider." A single organization can hold more than one role across a system's life, and a developer can also become a deployer.

Two things move along the chain, in opposite directions. Documentation moves from the builders toward the people affected. Feedback moves back the other way.

Developer / Provider Deployer User Documentation flows downstream → ← Feedback flows upstream

Documentation moves from the developer and provider to the deployer and the user. Feedback moves back the other way. Developer and provider share a box because both sit upstream of the deployer; they remain two distinct roles.

Developer

The developer is the technical creator. A developer:

Provider

Under the EU AI Act, a provider is a person, public authority, agency or other body that develops an AI system or general-purpose AI model (or has one developed) and puts it on the market or into service under its own name or trademark. An organization becomes a provider by placing the system on the market under its own name. It does not have to have built the system itself. A provider:

Deployer

A deployer is an individual or entity that uses an AI system under its own authority, generally in a professional context. Purely personal, non-professional use is excluded. A deployer:

Providers and deployers are held to different data standards. Article 10 puts the heavier one on the provider: training, validation and testing data must be relevant, sufficiently representative and, to the best extent possible, free of errors and complete. The deployer's Article 26(4) duty is narrower. Input data under its control must be relevant and sufficiently representative for the intended purpose.

The training duty reaches further than teaching people what the tool is and what they may use it for. An effective training program teaches escalation paths: a defined route by which any employee can report a suspected AI harm, malfunction or concern, and certainty about who to tell. Internal escalation is the first link in the deployer's external reporting chain — staff report to the deployer, and the deployer reports identified risks and serious incidents onward to the provider.

User

A user is anyone who interacts with or is directly affected by an AI system. A user has three parts to play. The first is knowing that an AI system is involved, which is not always obvious. The second is giving feedback where a channel exists. The third is using the rights that attach to AI-driven decisions, such as a right to notice or to human review of a consequential decision.

The roles applied to an example

A software firm builds a résumé-screening model and sells it under its own brand: it is the developer and, by putting it on the market under its own name, also the provider. A logistics company licenses the system and uses it to screen its own job applicants. It is the deployer. The applicants being screened are the users.

The deployer role is not permanent. A deployer can become a provider, and it then carries the fuller provider obligations. That happens when it does any of these:

Obligations and needs along the chain

RoleObligationsNeeds
DevelopersFully understand the algorithm's purpose; use appropriate data; document decisions, data source and training use.A clear purpose definition; resources for governance; understanding of applicable legal restrictions; a feedback channel from deployers/users.
ProvidersEnsure safety, transparency and accountability standards before market; manage life-cycle risk; report serious incidents.Clear information about the algorithm's purpose and construction; governance resources; understanding of legal restrictions; a feedback channel.
DeployersEnsure responsible use; provide documentation and training; update acceptable-use policies as needed.Clear information on how the algorithm was built; guidance on appropriate-use parameters; a feedback channel from users.
UsersUnderstand the algorithm's limits and appropriate uses; provide performance feedback.Clear usage guidance and applicable governance documentation; knowledge of how to give feedback.

Responsibility along this chain is shared, and it shifts. Developers carry primary responsibility for ethical design, and joint responsibility for documentation and technical performance. They do not remain solely liable for regulatory compliance once someone else deploys the system. Deployers own ongoing monitoring and auditing of a system in use, while independent bias assessments before release belong to the developer and provider, pre-market.

Responsibility versus accountability

ResponsibilityAccountability
What it meansPerforming a task.Answering for the outcome.
Who holds itWhoever does the work — e.g., the data scientist implementing bias mitigation on a hiring model.The designated system owner or organizational leadership (per frameworks such as the NIST AI RMF).
Can it be transferred?Yes — tasks can be assigned or delegated.No — delegating the work, or sourcing the model from a vendor, does not transfer accountability for what the system does.

When a deployed system causes harm, the accountable owner answers for it. That holds whoever performed the technical work, and whichever function was monitoring the system in operation.

Next up: how governance is organized inside the organization — the three structural models, and the people a real program pulls in.

Remember

  • Developer builds it. Provider puts it on the market under its own name. Deployer uses it professionally under its own authority. User is anyone who interacts with or is affected by it.
  • Documentation flows downstream (developer and provider → deployer → user); feedback flows upstream.
  • Pre-market bias testing belongs to the developer and provider; ongoing monitoring in use belongs to the deployer.
  • A deployer becomes a provider by rebranding a system under its own name, substantially modifying a high-risk system, or modifying a system into high-risk status.
  • Responsibility is doing the task. Accountability is answering for the outcome, and it stays with the system owner or leadership no matter who did the work.

Practise this topic

Domain I is free in the app, including its practice questions and flashcards, with progress tracking and no card details.

Start studying free

Previous: How AI fails and who gets hurt: failure modes and the five levels of harm
Next: Governance structures, models and stakeholder roles
Back to the AIGP study guide.

AI Governance Study is an independent study aid. It does not represent a government entity: it is not affiliated with, endorsed by or authorised by any government, government agency or regulatory authority, and it does not provide government services or legal advice. Laws and frameworks are described in our own words — the official texts are listed at official sources. It is also not affiliated with, endorsed by, or sponsored by the IAPP. The AIGP name is used only to identify the exam this material helps you prepare for.