Source: OJ L, 2024/1689, 12.7.2024 · Consolidated textCurrent language: EN
- Artificial intelligence act
Basic legislative acts
- AI act regulation
Article 25 Responsibilities along the AI value chain
Summary What does Article 25 of the AI act regulation say?
This article addresses the shifting of provider status and responsibility within the AI supply chain.
It establishes the circumstances under which a distributor, importer, deployer, or other third party can become reclassified as a provider of a high-risk AI system, thereby inheriting the full obligations that come with that role under Article 16.
Crucially, it also governs what happens to the original provider once that shift occurs, including their duty to cooperate with and support the new provider.
The article further addresses contractual obligations between providers and third-party suppliers of components integrated into high-risk AI systems.
Important points:
- Distributors, importers, deployers, or other third parties become subject to all provider obligations under Article 16 if they rebrand, substantially modify, or repurpose a system into a high-risk AI system.
- The original provider loses provider status when one of these triggering circumstances occurs, but must still cooperate with the new provider by sharing technical documentation, known limitations and failure modes, and technical access for testing and validation.
- Providers of high-risk AI systems must establish written agreements with third-party suppliers of components or tools integrated into those systems, specifying the information, capabilities, and technical access needed for regulatory compliance — with an exception for publicly available free and open-source tools, services, processes, or components other than general-purpose AI models.
Springlex's summary of the article is a reading aid, not a substitute for the legal text.
Any distributor, importer, deployer or other third-party shall be considered to be a provider of a high-risk AI system for the purposes of this Regulation and shall be subject to the obligations of the provider under Article 16, in any of the following circumstances:
they put their name or trademark on a high-risk AI system already placed on the market or put into service, without prejudice to contractual arrangements stipulating that the obligations are otherwise allocated;
they make a substantial modification to a high-risk AI system that has already been placed on the market or has already been put into service in such a way that it remains a high-risk AI system pursuant to Article 6;
they modify the intended purpose of an AI system, including a general-purpose AI system, which has not been classified as high-risk and has already been placed on the market or put into service in such a way that the AI system concerned becomes a high-risk AI system in accordance with Article 6.
- ▼M1ModificationReplacedParagraph 2 replaced by Regulation (EU) 2026/1744, Article 1(12)(a). Published in the Official Journal 24 July 2026.
Where the circumstances referred to in paragraph 1 occur, the provider that initially placed the AI system on the market or put it into service shall no longer be considered to be a provider of that specific AI system for the purposes of this Regulation.
That initial provider shall closely cooperate with new providers and shall make available the necessary information and provide the reasonably expected technical access and other assistance that are required for the fulfilment of the obligations set out in this Regulation, in particular with regard to compliance with the conformity assessment of high-risk AI systems.
In particular, the obligation laid down in the second subparagraph shall include, where relevant for the purposes specified therein, the following:
making available of technical documentation sufficient to assess compliance with the requirements laid down in Article 16;
informing the new providers about known limitations and failure modes; and
providing the new providers with targeted technical access, including for testing and validation.
This paragraph shall not apply in cases where the initial provider has clearly specified that its AI system is not to be changed into a high-risk AI system and therefore does not fall under the obligation to cooperate with the new providers and hand over the documentation.
In the case of high-risk AI systems that are safety components of products covered by the Union harmonisation legislation listed in Section A of Annex I, the product manufacturer shall be considered to be the provider of the high-risk AI system, and shall be subject to the obligations under Article 16 under either of the following circumstances:
the high-risk AI system is placed on the market together with the product under the name or trademark of the product manufacturer;
the high-risk AI system is put into service under the name or trademark of the product manufacturer after the product has been placed on the market.
- ▼M1ModificationReplacedSubparagraph of paragraph 4 replaced by Regulation (EU) 2026/1744, Article 1(12)(b). Published in the Official Journal 24 July 2026.
The provider of a high-risk AI system and the third party that supplies an AI system, AI model, tools, services, components, or processes that are used or integrated in a high-risk AI system shall, by written agreement, specify the necessary information, capabilities, technical access and other assistance based on the generally acknowledged state of the art, in order to enable the provider of the high-risk AI system to fully comply with the obligations set out in this Regulation. This paragraph shall not apply to third parties making accessible to the public tools, services, processes, or components, other than general-purpose AI models, under a free and open-source licence.
The AI Office may develop and recommend voluntary model terms for contracts between providers of high-risk AI systems and third parties that supply tools, services, components or processes that are used for or integrated into high-risk AI systems. When developing those voluntary model terms, the AI Office shall take into account possible contractual requirements applicable in specific sectors or business cases. The voluntary model terms shall be published and be available free of charge in an easily usable electronic format.
Paragraphs 2 and 3 are without prejudice to the need to observe and protect intellectual property rights, confidential business information and trade secrets in accordance with Union and national law.
Relevant recitals
Recital 83 Operators acting in more than one role
In light of the nature and complexity of the value chain for AI systems and in line with the New Legislative Framework, it is essential to ensure legal certainty and facilitate the compliance with this Regulation. Therefore, it is necessary to clarify the role and the specific obligations of relevant operators along that value chain, such as importers and distributors who may contribute to the development of AI systems. In certain situations those operators could act in more than one role at the same time and should therefore fulfil cumulatively all relevant obligations associated with those roles. For example, an operator could act as a distributor and an importer at the same time.
Recital 84 Identification of the provider
To ensure legal certainty, it is necessary to clarify that, under certain specific conditions, any distributor, importer, deployer or other third-party should be considered to be a provider of a high-risk AI system and therefore assume all the relevant obligations. This would be the case if that party puts its name or trademark on a high-risk AI system already placed on the market or put into service, without prejudice to contractual arrangements stipulating that the obligations are allocated otherwise. This would also be the case if that party makes a substantial modification to a high-risk AI system that has already been placed on the market or has already been put into service in a way that it remains a high-risk AI system in accordance with this Regulation, or if it modifies the intended purpose of an AI system, including a general-purpose AI system, which has not been classified as high-risk and has already been placed on the market or put into service, in a way that the AI system becomes a high-risk AI system in accordance with this Regulation. Those provisions should apply without prejudice to more specific provisions established in certain Union harmonisation legislation based on the New Legislative Framework, together with which this Regulation should apply. For example, Article 16(2) of Regulation (EU) 2017/745, establishing that certain changes should not be considered to be modifications of a device that could affect its compliance with the applicable requirements, should continue to apply to high-risk AI systems that are medical devices within the meaning of that Regulation.
Recital 85 Providers of general-purpose AI systems used for high-risk applications
General-purpose AI systems may be used as high-risk AI systems by themselves or be components of other high-risk AI systems. Therefore, due to their particular nature and in order to ensure a fair sharing of responsibilities along the AI value chain, the providers of such systems should, irrespective of whether they may be used as high-risk AI systems as such by other providers or as components of high-risk AI systems and unless provided otherwise under this Regulation, closely cooperate with the providers of the relevant high-risk AI systems to enable their compliance with the relevant obligations under this Regulation and with the competent authorities established under this Regulation.
Recital 86 Former providers of AI systems used for high-risk applications
Where, under the conditions laid down in this Regulation, the provider that initially placed the AI system on the market or put it into service should no longer be considered to be the provider for the purposes of this Regulation, and when that provider has not expressly excluded the change of the AI system into a high-risk AI system, the former provider should nonetheless closely cooperate and make available the necessary information and provide the reasonably expected technical access and other assistance that are required for the fulfilment of the obligations set out in this Regulation, in particular regarding the compliance with the conformity assessment of high-risk AI systems.
Recital 87 Product manufacturers using high-risk AI systems as safety components
In addition, where a high-risk AI system that is a safety component of a product which falls within the scope of Union harmonisation legislation based on the New Legislative Framework is not placed on the market or put into service independently from the product, the product manufacturer defined in that legislation should comply with the obligations of the provider established in this Regulation and should, in particular, ensure that the AI system embedded in the final product complies with the requirements of this Regulation.
Recital 88 Obligations of parties in the value chain
Along the AI value chain multiple parties often supply AI systems, tools and services but also components or processes that are incorporated by the provider into the AI system with various objectives, including the model training, model retraining, model testing and evaluation, integration into software, or other aspects of model development. Those parties have an important role to play in the value chain towards the provider of the high-risk AI system into which their AI systems, tools, services, components or processes are integrated, and should provide by written agreement this provider with the necessary information, capabilities, technical access and other assistance based on the generally acknowledged state of the art, in order to enable the provider to fully comply with the obligations set out in this Regulation, without compromising their own intellectual property rights or trade secrets.
Recital 89 AI components under a free and open-source license
Third parties making accessible to the public tools, services, processes, or AI components other than general-purpose AI models, should not be mandated to comply with requirements targeting the responsibilities along the AI value chain, in particular towards the provider that has used or integrated them, when those tools, services, processes, or AI components are made accessible under a free and open-source licence. Developers of free and open-source tools, services, processes, or AI components other than general-purpose AI models should be encouraged to implement widely adopted documentation practices, such as model cards and data sheets, as a way to accelerate information sharing along the AI value chain, allowing the promotion of trustworthy AI systems in the Union.
Recital 90 Voluntary model contractual terms to facilitate cooperation
The Commission could develop and recommend voluntary model contractual terms between providers of high-risk AI systems and third parties that supply tools, services, components or processes that are used or integrated in high-risk AI systems, to facilitate the cooperation along the value chain. When developing voluntary model contractual terms, the Commission should also take into account possible contractual requirements applicable in specific sectors or business cases.
Springlex and this text is meant purely as a documentation tool and has no legal effect. No liability is assumed for its content. The authentic version of this act is the one published in the Official Journal of the European Union.
Definition
conformity assessment
Definition
instructions for use
Definition
distributor
Definition
testing in real-world conditions
Definition
provider
Definition
authorised representative
Definition
substantial modification
Definition
general-purpose AI system
Definition
safety component
Definition
AI Office
Definition
subject
Definition
operator
Definition
deployer
Definition
importer
Definition
intended purpose
Definition
placing on the market
Definition
AI system
Definition
risk
Definition
putting into service
Definition
general-purpose AI model