Compliance · 14 August 2026
Since 2 August 2026, an SME that places a chatbot on its site is a deployer within the meaning of the AI Act. It must inform users that they are talking to AI, unless that is obvious. That sentence, simple as it is, cuts through a stubborn misunderstanding: “the model vendor is the one who is liable”. No. Provider and deployer have distinct obligations. Confusing them is signing an integration contract in the belief that you are transferring a risk the regulation leaves with you.
The two roles, as the text sets them out
The provider places an AI system on the market or into service under their name. In outline, that is the vendor of the model or of the packaged solution. The AI Office may investigate providers of general-purpose models since 2 August 2026. About 190 organisations have signed a voluntary transparency code (list of 31 July), among them Anthropic, Google, Meta, Microsoft, Mistral and OpenAI on the provider side. That code does not redefine your role.
The deployer uses an AI system under their authority. A VSE that activates an agent on its site, in internal messaging or on a reception kiosk is a deployer, even if it has not written a line of model code. Article 4 on AI literacy has applied to both since 2 February 2025: providers and deployers. You cannot say “we only plugged in the API” to escape the duty of a minimum of competence in your teams.
There are edge cases. If you take a model, fine-tune it, brand it in your name and resell it to other businesses, you may tip into provider. If you are only a user of a SaaS, you remain a deployer. The commercial contract does not decide it on its own: the actual operation is what counts.
What this changes the day you install an agent “at home”
Install, here, means: a widget on the site, an agent in messaging, a box on the shop floor, a copilot in the ERP. In all these cases, your customers or your staff talk to a system you have chosen, configured, connected to your data. Article 50 requires you to inform them about the nature of the counterpart. Synthetic content you publish under your brand is also on you, including machine-readable marking (with a deadline of 2 December 2026 for systems already on the market before 2 August) and the visible labelling of professional deepfakes.
The provider, for its part, may embed a watermark (Anthropic has announced an invisible text watermark in Claude models from 2 August; the detector is not yet public) or image and audio marking (SynthID at OpenAI, C2PA). These building blocks help. They do not write your welcome banner, do not choose your document bases, do not decide whether a quote goes out without review.
Fines on the transparency strand go up to €15 million or 3% of worldwide turnover. Prohibited practices, already sanctionable, go up to €35 million or 7%. A VSE deployer is not the first target of an AI Office investigation into a foundation model. It is the first target of its customer, its employee and its insurer.
Five questions to settle before go-live
- Who displays what, where. The “you are talking to AI” banner is a deployer obligation. Require the integrator to make it non-disableable by a rushed intern.
- Who is responsible for the data that is connected. An agent wired to the customer file, emails, site plans: you remain responsible for the perimeter. A GDPR compliance audit clarifies purpose, legal basis and transfer, including if the provider is outside the EU.
- Where the system runs. Provider cloud or local Synapse box: the deployer role does not disappear. On-prem, you gain control of the flows; you take on more of the operations. In the cloud, you remain a deployer and you add a processor.
- Who trains internal users. Article 4 does not stop at the vendor. The person who validates replies, who feeds the base, who turns off a filter, must know what they are doing.
- Who speaks in an incident. A pricing hallucination, a leaked document, a deepfake in your brand: plan who answers the customer. The provider may perhaps fix the model. It is your number the customer will call.
Integrator, vendor, client: three contracts, one regulation
Many SMEs buy an agent through a local integrator. The integrator does not erase your status as deployer. It can, contractually, commit to configuring the disclosure, the conversation log, the ring-fencing of data. Have that written. Do not settle for a slide that says “AI Act compliant”.
If you are yourself an integrator (you put agents in at your clients), you can wear several hats: deployer on your own site, and, depending on the set-up, provider or authorised representative for the client. That is precisely the case where a serious framing avoids signing commitments you cannot keep.
What we set out with VSEs and SMEs
Cybernecs designs AI agent solutions by naming each party’s role: what the model does, what the box or the cloud does, what the director does, what staff do. Patrick Dajan Mouelle, director of the firm, rejects formulas of the “AI takes care of compliance” type. AI is not the deployer. You are.
For a role review (contract, disclosure, data, training) before or after installation, go through the contact page. The aim is a readable sharing of responsibilities, not a magic clause.
Sources: Artificial Intelligence Regulation (AI Act), Touteleurope, L’Express.