# AI Act provider obligations

> A provider develops or has an AI system developed and places it on the market or puts it into service under its own name or trademark. Its obligations are often heavier, especially for high-risk systems.

## Summary

Compaia helps identify provider obligations, structure evidence and connect requirements to the relevant articles.

## Key points

- Providers often have to manage risks, data, documentation, logs, transparency and monitoring.
- High-risk systems trigger strong and documented requirements.
- Compliance must be integrated into the product lifecycle.

## Frequent requirements

Depending on the type of system, providers must document design, data, performance, limitations and monitoring measures.

- Risk management system.
- Data governance.
- Technical documentation.
- Instructions for use and transparency.
- Post-market monitoring.

## Frequently asked questions

### Can a SaaS startup be a provider under the AI Act?

Yes if it develops or has an AI system developed and places it on the market or puts it into service under its own name or trademark.

## Sources

- [AI Act - official text](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689)

## Related resources

- [AI Act obligations](https://compaia.eu/obligations)
- [AI Governance](https://compaia.eu/gouvernance-ia)
