GovCompass
AI governance

The provider and deployer line breaks under autonomy

By GovCompass.ai· Last updated August 2026· The Commission has stated its position on AI agents is preliminary; more specific guidance is expected.

The EU AI Act assigns obligations on the assumption that the provider who builds a system and the deployer who uses it are distinct, stable roles. Agentic AI destabilises that assumption. A deployer who configures an agent with broad tool-calling rights, autonomous decision scope, or the ability to spawn sub-agents may be making changes substantial enough to carry provider-level obligations. Under autonomy, the question of who is answerable cannot be read off the contract. It has to be assessed against what the deployer actually configured the agent to do.

This is part of our work on agentic AI, the condition that changes how all seven pillarspillarA responsible-AI principle as something an organization actively holds rather than merely endorses: one of the seven pillars of responsible AI, one per principle. A pillar is held, not implemented, by naming the harms that would breach the principle, assessing their risk, and placing controls that reduce it. Distinct from agentic AI, which is not one of the seven but a condition that changes how all of them are governed. See principle, harm, risk, agentic AI.Open full entry → of responsible AIresponsible AIThe set of principles an AI system should live up to: fairness, safety and reliability, privacy, security and robustness, transparency and explainability, accountability, and human oversight. Widely shared and sitting under the EU AI Act and the major frameworks. On their own the principles are statements of intent; the law turns them into duties that cannot be met unless they are carried inside the organization's governance, which is how responsible AI lands in governance rather than beside it. The seven principles are organized into seven pillars, one pillar per principle. See principle, pillar, governance. The seventh principle carries two names in practice: human oversight in the seven-pillar model, and human-centricity in the IAPP AIGP body of knowledge; the substance overlaps.Open full entry → are governed.

How the Act allocates responsibility

The EU AI ActEU AI ActRegulation (EU) 2024/1689, the European Union's law on artificial intelligence. It takes a risk-based approach: prohibited practices, requirements for high-risk AI systems, transparency obligations for specific uses, and a separate regime for general-purpose AI models. Obligations are divided between providers and deployers. See general-purpose AI, conformity assessment.Open full entry → builds its obligations on a role distinction. The providerproviderThe actor who develops an AI system (or has it developed) and places it on the market or into service under its own name. It carries manufacturer-style duties: design controls, documentation, conformity.Open full entry → develops an AI systemAI systemA machine-based system that, for explicit or implicit objectives, infers from input how to generate outputs (predictions, content, recommendations or decisions) that can influence physical or virtual environments. The OECD-style definition followed by the EU AI Act.Open full entry → or has it developed and places it on the market under its own name. The deployerdeployerAn organization using an AI system under its own authority in its activities. It carries the operator duties: use per instructions, oversight, input relevance, monitoring, notices.Open full entry → uses an AI system under its authority. Providers carry the heavier obligations: conformity assessmentconformity assessmentThe pre-market process demonstrating a high-risk AI system meets the EU AI Act's requirements, leading to CE marking and registration.Open full entry →, technical documentationtechnical documentationRecords a provider must compile and keep for a high-risk AI system to demonstrate conformity, covering its design, data, testing, risk management and monitoring.Open full entry →, the quality management system. Deployers carry a lighter but real set: ensuring human oversighthuman oversightDesigned-in human ability to monitor, intervene in, override or shut down an AI system. It is meaningful only when the human has authority, information and time to act. One of the seven pillars of responsible AI, and under the EU AI Act a requirement for high-risk AI systems: Article 14 requires that those systems are designed so natural persons can effectively oversee them. Oversight that exists on paper but amounts to confirming in practice does not meet that bar. See override rate, automation bias, high-risk AI system, fairness, safety and reliability, privacy, security and robustness, transparency and explainability, accountability, responsible AI. In the IAPP AIGP body of knowledge, this principle appears as human-centricity, with human oversight as one of its elements.Open full entry →, monitoring operation, using the system in accordance with instructions.

The Act also has a rule for when a deployer becomes a provider. A deployer that makes a substantial modificationsubstantial modificationA change to a deployed AI system that materially alters its function or purpose, capable of shifting provider obligations onto the modifier.Open full entry → to a high-riskriskIn the EU AI Act's terms, the combination of the likelihood that a harm occurs and the severity of it if it does. The link between a principle (via the harm that would breach it) and a control (the measure that reduces it). Naming the harm and assessing its risk is required by Art. 9 before any mitigation measure is chosen. See harm, control, residual risk.Open full entry → system, or that puts its name on the system, or that changes the intended purpose, takes on provider obligations. In classic deployments this rule is rarely triggered, because deployers use systems roughly as delivered.

Why agentic configuration changes this

Agentic systems are configured, not just used. The deployer of an agent platform decides which tools the agent can call, how much autonomy it has, what decision scope it operates within, whether it can spawn sub-agentssub-agentAn agent invoked by another agent or an orchestrator to carry out part of a task. Its actions still inherit the obligations of the stack it belongs to.Open full entry →, and what actions it can take without human approval. These are not peripheral settings. They are the choices that determine what the system does in the world.

This is where the line breaks. A deployer who grants an agent broad tool-calling rights and autonomous scope over a high-risk decision may have changed the system's behavior and risk profile substantially enough that they are, in functional terms, shaping a new high-risk system. The Act's text was written for a world where the deployer received a finished product. Agentic configuration hands the deployer a set of dials that can alter the system's purpose and risk, and altering purpose and risk is precisely what tips a deployer into provider territory.

The Commission has been explicit that its position on AI agentsAI agentA system that perceives its environment, decides and takes actions toward a goal (calling tools, executing plans). Autonomy of action demands allowlists, approval gates, sandboxing, logging and a kill switch.Open full entry → is preliminary and that more specific guidance is likely. The structural problem it has identified is that the Act assumes roles are stable, and in agentic systems they are not. An entity that designs and operates a system in which AI systems direct, invoke, or constrain other AI systems does not fit cleanly into either the provider or the deployer box.

What an AI Officer should do now

The practical response is to treat agentic configuration as a governancegovernanceThe system through which an organization steers itself: corporate governance, risk management, compliance, lines of accountability, risk appetite, and the operating model. It exists across everything the organization does, before and beyond AI. AI governance is this same system extended for AI. See AI governance, governance design, execution level.Open full entry → decision with classification consequences, not as a technical setting. For each agent your organization deploys, document the configuration choices that bear on autonomy: tool access, decision scope, sub-agent spawning, and the actions permitted without human approval. Then assess, against the Act's substantial-modification and intended-purpose tests, whether those choices push your organization toward provider obligations.

Where the assessment is close, the conservative position is to assume provider-level responsibility and build the corresponding documentation, because the cost of being wrong is carrying provider obligations you have not met. Where you procure an agent platform from a vendor, the contract should make explicit which party bears provider obligations under which configurations, because the default allocation written for non-agentic systems will not map cleanly onto what you are actually deploying.

The deeper point

AccountabilityaccountabilityThe principle that a named human or organization answers for an AI system's outcomes, through ownership, documentation, audit trails and redress; never the system itself. The EU AI Act attaches obligations to the role rather than the technology, with provider duties in Article 16 and deployer duties in Article 26, supported by technical documentation (Article 11) and record-keeping (Article 12). See provider, deployer, record-keeping, responsible AI.Open full entry → is one of the seven pillars of responsible AI, and agentic AIagentic AISystems where a model takes actions (calling tools, executing multi-step plans), amplifying both capability and every failure mode; governed with action allowlists, approvals and full logging.Open full entry → is where it is most severely tested. The Act's role model is a proxy for a simpler question: when this system takes an action that harmsharmHarm is the concrete damage an AI system causes or can cause: to a person, a group, an organization, or society. A risk is that same damage seen in advance, weighed by likelihood and severity; a harm that has occurred is remedied rather than managed.Open full entry → someone, who is answerable? In a configured, autonomous, multi-agent systemmulti-agent systemA system in which several agents interact, delegate, and pass outputs to one another to reach a goal, with no human checkpoint between each step.Open full entry →, the honest answer cannot be deferred to a contract clause written for a different kind of technology. It has to be established deliberately, before deployment, by the organization that decided how much the agent is allowed to do.

Legal referencesArt. 25Art. 26
Continue withAccountability
Share Share on LinkedIn

More on Accountability

Agentic AI and governance: why autonomy sharpens the control question

Analysis

Agentic AI does not need a new kind of governance. Autonomy widens the gap between what a system does and who is accountable for it, which makes the existing governance chain, control tracing to risk and forward to evidence, more important, not less. The actions are real and sometimes irreversible, so the stakes on each control rise.

Agentic AI risk assessment: from architecture decisions to control objectives

Analysis

Assessing the risk of an AI agent does not need a separate method. The steps stay the same: recognize the risk, assess how likely and how severe it is for your system, and control it. What changes is the input. An agent runs the process through recorded architecture decisions, about the model, the instruction, retrieved knowledge, tools, orchestration, memory, and autonomy, and each of those decisions, alone or in combination, creates the possibility of harm. The output of the assessment is a set of risk scenarios with a control objective for each.

AI certification: what exists and what it proves

Analysis

AI certification is not one category. Three different objects are assessed, each by a different kind of assessor: a person, an organization's AI management system, and an AI system placed on the EU market. The first two can be certified. The third is subject to a legal conformity assessment, which produces a certificate on one of its two routes and none on the other. Identifying which object a credential covers is the first step to judging what it is worth.

AI governance and enterprise risk management: where they meet

Analysis

AI governance is not a parallel structure that sits beside enterprise risk management. It belongs inside it. The seven pillars of responsible AI are the control structure the organization uses to govern each AI system; enterprise risk management is the machine that carries the residual risk those controls leave behind into the board's risk appetite, the risk register, and the assurance plan. The practical question is not whether to build AI governance or ERM, but how to slot the first into the second so that one accountable structure, not two competing ones, owns AI risk.