The hidden trap in your AI stack
Many startups are building products on top of general-purpose models via APIs from providers like OpenAI, Google, or Anthropic. In practice, they tend to see themselves as power users of advanced technology, not as developers of their own AI systems. The EU Artificial Intelligence Act (AI Act), however, introduces a critical twist: under certain conditions, a company that integrates and extends the behavior of a model can be treated as a “provider” of an AI system. And that shift comes with a far more demanding legal regime than most product and engineering teams expect.
The AI Act draws a clear line between a “deployer” and a “provider.” A deployer uses an AI system under its own authority, while a provider places an AI system on the market under its own name or brand. That boundary holds as long as the company uses the system as originally intended. The problem arises when the regulation deems the company to fall into the provider category: if a business substantially modifies a high-risk system, or changes its purpose so that it becomes subject to stricter obligations, it is automatically considered a provider.
The recruitment example
Take a startup that uses a general-purpose model to generate job descriptions for roles such as Android or iOS mobile developers. In that scenario, it acts as a deployer. But if the service evolves into a system that automatically pre-screens candidates and whose recommendations significantly influence hiring decisions, it enters the high-risk domain. From that point on, the system is classified accordingly, and the startup may be considered a provider—even if the underlying model has not been technically modified. What matters is the purpose for which the final system is placed on the market.
What it means to be a provider of a high-risk AI system
Taking on the role of provider triggers a set of formal obligations. These include implementing a quality management system, preparing detailed technical documentation, maintaining automatic logs, and carrying out a conformity assessment that, in many cases, results in CE marking. When a high-risk system relies on a general-purpose model, the model provider must supply enough information to enable compliance. The AI Act does not require the sharing of training data or trade secrets, but it does demand documentation that allows for responsible and compliant integration.
How startups should respond
Before expanding functionality, companies should take a close look at how their system is used and whether that use falls into any of the categories subject to heightened regulatory scrutiny. It is also important to assess whether a “substantial modification” is taking place (particularly when retraining, redesigning, or making changes that affect the system’s overall behavior). Finally, startups should review the documentation provided by the model vendor and determine whether it is sufficient to support compliance with their own obligations. While this kind of review does not eliminate regulatory burden in high-risk scenarios, it does allow teams to anticipate requirements, make informed choices, and build compliant products without taking unnecessary risks.
In another post, we discuss how a Proof of Concept (PoC) can help startups navigate this process.
Legal and economic consequences of non-compliance
Failing to meet the obligations of a high-risk AI system provider can lead to significant administrative penalties. For serious infringements—such as missing technical documentation, lack of a conformity assessment, or the absence of an adequate quality management system—fines can reach up to €15 million or 3% of a company’s total worldwide annual turnover. Providing incorrect or misleading information to competent authorities may result in additional penalties of up to €7.5 million or 1.5% of global revenue. Combined with the potential withdrawal of the system from the market, remediation costs, and reputational damage, these sanctions can seriously threaten a company’s financial viability—especially for startups and fast-growing businesses.
I'd love some
advice for my app