Identify provider, deployer, and other roles for each AI system, then connect applicable duties to the AI management system.
Map the AI value chain system by system
For each AI use, record who develops it, places it on the market, puts it into service, deploys it, supplies a general-purpose model, or integrates a third-party component. The same company may play different roles for different systems. A product team that buys a model and offers its own AI application should not assume it is only a purchaser.
Attach the role analysis to the AI inventory, with the product, purpose, users, markets, and supplier contracts. Reassess it when the intended use or commercial route changes.
Assess classification and obligations separately
The EU AI Act distinguishes prohibited practices, high-risk systems, transparency obligations, and general-purpose AI model rules. Identify which provisions might apply to a particular system and role using the legal text and current Commission guidance. Seek qualified legal interpretation for difficult cases, especially where sector rules or national law interact.
Do not describe ISO/IEC 42001 certification as proof of AI Act compliance. The standard addresses organizational AI management; the Act creates duties tied to regulated actors and systems.
Connect legal duties to operational records
Once a duty is identified, assign an owner, deadline, control, and evidence source. Some records may already exist in the AIMS: risk and impact assessment, technical documentation, testing, human oversight design, monitoring, incidents, supplier information, and management review. Mark the exact requirement supported by each record rather than claiming a broad crosswalk.
The Commission has published guidance on certain transparency obligations under Article 50. Its current guidance should be checked when a system interacts with people or generates content requiring disclosure.
Keep change and legal review linked
A new market, product role, model, autonomy level, or intended purpose can change both the AI risk and legal analysis. Put a role and obligation check into release and procurement workflows. Review the register as EU guidance and law develop, and preserve the version of the interpretation used for a decision.
Management should see open legal questions alongside operational risks, with named owners and a route to specialist advice.
Put it into practice
- Record provider and deployer roles for each material AI system.
- Assess classification and applicable duties separately from ISO/IEC 42001.
- Map each applicable duty to an owner, control, and evidence record.
- Reopen the analysis after product or market changes.
Primary sources
- European Union: AI Act text
- European Commission: AI Act Article 16 provider duties
- European Commission: AI Act Article 26 deployer duties
- ISO: ISO/IEC 42001 AI management systems
Normstone resources are general information, not legal advice or an independent assessment.