AI Act: The Risk of Being Reclassified as a Provider of a High‑Risk AI System
The AI Act distinguishes between the various actors involved in the AI supply chain, between providers and deployers of AI systems. In principle, an organisation that uses an AI system in the context of its professional activities is classified as a deployer and is subject to a more limited set of obligations than those applicable to providers.
This classification is, however, neither automatic nor definitive. The AI Act expressly provides for several situations in which a deployer may be reclassified as a provider of a high‑risk AI system, triggering the full set of obligations applicable to providers.
Deployer or Provider: A Boundary Defined by Use
Determining your organisation’s exact role is essential, as it directly determines the applicable obligations and your level of compliance with the AI Act. Particular attention must be paid to the actual use made of the AI system, irrespective of your organisation’s initial classification as a deployer.
Article 25 of the AI Act provides that a deployer (or any other third party) is to be considered a provider of a high‑risk AI system where it falls under one of the following situations:
- it places on the market or puts into service, under its own name or trademark, a high‑risk AI system that has already been placed on the market or put into service;
- it makes a substantial modification to a high‑risk AI system that has already been placed on the market or put into service;
- it changes the intended purpose of an AI system that is not high‑risk, and which becomes high‑risk as a result of that change.
Chatbots and Human Resources: A Frequent Reclassification Scenario
Many organisations currently use chatbots classified as limited‑risk AI systems under Article 50 of the AI Act. For such uses, they are, in principle, considered deployers.
However, this role may evolve depending on the chatbot’s specific use. This is notably the case where a chatbot is used to pre‑screen job applicants based on their CVs or to assist in decision‑making relating to employee promotions.
Such use cases are considered high‑risk under the AI Act (subject to limited exceptions). By changing the original intended purpose of the AI system, the organisation using it may therefore be reclassified as a provider of a high‑risk AI system, even if it did not develop or commission the development of that system itself.
Significant Legal Consequences for the Organisation
Reclassification as a provider of a high‑risk AI system is far from trivial. It results in the application of extensive obligations, including: the implementation of risk management and quality management systems, the preparation of comprehensive technical documentation, compliance with stringent data quality requirements, conformity assessments.
Compliance with these obligations may prove particularly complex where the initial provider has expressly excluded any transformation of the system into a high‑risk AI system. In such cases, the initial provider is not legally required to cooperate with the downstream provider.
Our advice:
As part of your compliance efforts under the AI Act, it is essential to anticipate reclassification risks linked to the use of AI tools, particularly where such tools are deployed in sensitive areas such as human resources.
This notably requires:
- an in‑depth legal analysis of the envisaged use cases;
- strict internal policies governing the use of chatbots and other AI tools (AI policy, AI governance and training);
- carefully drafted contracts with AI tool providers and with external service providers using AI on behalf of your organisation.
Our team of experts supports you at each of these stages, through advantageous service packages such as our AI Act Compliance Pack and our AI Policy Workshop Pack.
