The integration of general-purpose AI models, such as GPT, Claude or Gemini, into a company’s own products and services is becoming increasingly common. From the perspective of the AI Act, the company carrying out the integration is not always simply a user of the model.

Depending on how it develops and provides the resulting system, it may be regarded as a downstream provider and may be liable for the compliance of the final system.

Who is the downstream provider?

The AI Act defines a downstream provider, in Article 3(68), as the provider of an AI system, including a general-purpose AI system, which incorporates an AI model. The model may be developed by the provider itself and integrated vertically, or it may originate from another entity on the basis of a contractual relationship.

For example, a company may integrate a GPT model into its own recruitment platform, a contract analysis application or a medical chatbot, and offer the resulting system under its own brand. Although the underlying model belongs to another entity, the company determines the purpose and functions of the final product, as well as how it is offered to customers. In this situation, the company may be regarded as a downstream provider.

By contrast, the mere internal use of a tool such as ChatGPT does not automatically confer this status. The entity must provide an AI system that integrates the model.

Obligations are determined according to the end system

The downstream supplier does not operate under a completely separate regime. It is the supplier of the resulting system and must determine the applicable obligations based on the system’s purpose, functionality and classification.

The analysis must establish whether the system:

- involves a prohibited practice under Article 5;

- is a high-risk system under Article 6 and Annexes I or III;

- falls within the scope of the transparency obligations set out in Article 50.

For example, a chatbot designed to interact with the public must, in principle, inform users that they are interacting with an AI system, in accordance with Article 50(1). A platform that uses AI for candidate selection may fall within the category of high-risk systems set out in Annex III.

If the system is classified as high-risk, the downstream provider must comply with the requirements set out in Articles 8–15 concerning risk management, data governance, technical documentation, logs, transparency, human oversight, accuracy, robustness and cybersecurity. Article 16 also imposes obligations regarding quality management, conformity assessment, system registration, corrective measures and demonstration of conformity.

According to the timetable set out in Article 113 of the consolidated version, these requirements will apply from 2 December 2027 to high-risk systems listed in Annex III and from 2 August 2028 to systems associated with regulated products listed in Annex I.

Access to information about the model

The downstream provider cannot assess and document the end system without sufficient information about the integrated model. Article 53(1)(b) requires the provider of the general-purpose AI model to provide the information necessary to understand the model’s capabilities and limitations and to comply with the AI Act.

According to Annex XII, the information must cover, amongst other things, the relevant versions, architecture, input and output data formats, usage policies, the technical means required for integration, and the origin of the data used for training, testing and validation.

For high-risk systems, Article 25(4) also requires a written agreement to be concluded between the provider of the end system and the third parties supplying the integrated models, components or services. The agreement must set out the information, technical access and support necessary for compliance.

Where the provider of the general-purpose AI model fails to fulfil its obligations, Article 89(2) allows the downstream provider to lodge a substantiated complaint with the AI Office.

The integration of an external model does not, therefore, transfer all responsibility to the model’s creator. Compliance must be assessed separately for the end system, taking into account its purpose, the manner of integration and the specific context in which it is placed on the market or put into service.