Regulation Tracker / EU AI Act / Chapter III · Section 3
Article 25
Responsibilities along the AI value chain
Chapter III — Classification rules for high-risk AI systems, Section 3 — Obligations of providers of high-risk AI systems. 7 distinct duties, powers or definitions are coded from this article, applying from 2027-12-02. 5 reach legal practice directly.
Amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI), in force 2026-07-27 — about 176 words changed. The text below is the consolidated version of 27 July 2026; the 2024 text and the amending regulation are on EUR-Lex. 7 of the duties below now apply later than Article 113 originally provided; each shows both dates.
official text: EUR-Lex (consolidated 27 Jul 2026) · text © European Union (Decision 2011/833/EU) · coding CC BY 4.0 · data: obligations.json · Hugging Face · GitHub
The text
1. Any distributor, importer, deployer or other third-party shall be considered to be a provider of a high-risk AI system for the purposes of this Regulation and shall be subject to the obligations of the provider under Article 16, in any of the following circumstances:
- (a)they put their name or trademark on a high-risk AI system already placed on the market or put into service, without prejudice to contractual arrangements stipulating that the obligations are otherwise allocated;
- (b)they make a substantial modification to a high-risk AI system that has already been placed on the market or has already been put into service in such a way that it remains a high-risk AI system pursuant to Article 6;
- (c)they modify the intended purpose of an AI system, including a general-purpose AI system, which has not been classified as high-risk and has already been placed on the market or put into service in such a way that the AI system concerned becomes a high-risk AI system in accordance with Article 6.
2. Where the circumstances referred to in paragraph 1 occur, the provider that initially placed the AI system on the market or put it into service shall no longer be considered to be a provider of that specific AI system for the purposes of this Regulation.
3. In the case of high-risk AI systems that are safety components of products covered by the Union harmonisation legislation listed in Section A of Annex I, the product manufacturer shall be considered to be the provider of the high-risk AI system, and shall be subject to the obligations under Article 16 under either of the following circumstances:
- (a)the high-risk AI system is placed on the market together with the product under the name or trademark of the product manufacturer;
- (b)the high-risk AI system is put into service under the name or trademark of the product manufacturer after the product has been placed on the market.
4. The provider of a high-risk AI system and the third party that supplies an AI system, AI model, tools, services, components, or processes that are used or integrated in a high-risk AI system shall, by written agreement, specify the necessary information, capabilities, technical access and other assistance based on the generally acknowledged state of the art, in order to enable the provider of the high-risk AI system to fully comply with the obligations set out in this Regulation. This paragraph shall not apply to third parties making accessible to the public tools, services, processes, or components, other than general-purpose AI models, under a free and open-source licence.
5. Paragraphs 2 and 3 are without prejudice to the need to observe and protect intellectual property rights, confidential business information and trade secrets in accordance with Union and national law.
What it requires, coded
SafeLegalAI's reading of each duty in this article: who, what, from when, under which fine tier, and whether it reaches a firm, chambers, court or legal-AI vendor. Descriptive, not advice; the quoted words are the Regulation's.
Art. 25(1) (a)Scope or definitionHigh-risklegal practice
A distributor, importer, deployer or other third party becomes the provider of a high-risk AI system if it puts its name or trademark on an already marketed or used high-risk AI system, subject to contractual allocation.
"they put their name or trademark on a high-risk AI system already placed on the market or put into service, without prejudice to contractual arrangements stipulating that the obligations are otherwise allocated;"
- Who
- Distributor, Importer, Deployer, Downstream provider, Any operator
- From
- (Art. 113(c)(i) as amended by Reg. (EU) 2026/1744)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).For Art. 6(1)/Annex I high-risk systems, Art. 113(c)(ii) as amended applies the corresponding obligation from 2028-08-02; Art. 111(2) gives public-authority high-risk systems until 2030-08-02.
- Fine tier
- Art. 99(4)
- Legal practice
- Reaches legal practice directly — Legal-AI resellers, integrators or deployers can become providers by white-labelling a high-risk legal-AI system.
- See
- Art. 16 · Annex III point 8
Art. 25(1) (b)Scope or definitionHigh-risklegal practice
A distributor, importer, deployer or other third party becomes provider if it substantially modifies an already marketed or used high-risk AI system so it remains high-risk under Article 6.
"they make a substantial modification to a high-risk AI system that has already been placed on the market or has already been put into service in such a way that it remains a high-risk AI system pursuant to Article 6;"
- Who
- Distributor, Importer, Deployer, Downstream provider, Any operator
- From
- (Art. 113(c)(i) as amended by Reg. (EU) 2026/1744)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).For Art. 6(1)/Annex I high-risk systems, Art. 113(c)(ii) as amended applies the corresponding obligation from 2028-08-02; Art. 111(2) gives public-authority high-risk systems until 2030-08-02.
- Fine tier
- Art. 99(4)
- Legal practice
- Reaches legal practice directly — Legal-AI integrators or law firms materially modifying high-risk legal tools may take on provider status.
- See
- Art. 6 · Art. 16 · Annex III point 8
Art. 25(1) (c)Scope or definitionHigh-risklegal practice
A distributor, importer, deployer or other third party becomes provider if it changes the intended purpose of a non-high-risk system or general-purpose AI system so it becomes high-risk under Article 6.
"they modify the intended purpose of an AI system, including a general-purpose AI system, which has not been classified as high-risk and has already been placed on the market or put into service in such a way that the AI system concerned becomes a high-risk AI system in accordance with Article 6."
- Who
- Distributor, Importer, Deployer, Downstream provider, Any operator
- From
- (Art. 113(c)(i) as amended by Reg. (EU) 2026/1744)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).For Art. 6(1)/Annex I high-risk systems, Art. 113(c)(ii) as amended applies the corresponding obligation from 2028-08-02; Art. 111(2) gives public-authority high-risk systems until 2030-08-02.
- Fine tier
- Art. 99(4)
- Legal practice
- Reaches legal practice directly — A legal organisation adapting a general-purpose system for judicial, ADR or other Annex III high-risk use may become the provider.
- See
- Art. 6 · Art. 16 · Annex III point 8
Art. 25(2)Scope or definitionHigh-risklegal practice
Where Article 25(1) circumstances occur, the provider that initially placed the AI system on the market or put it into service is no longer considered provider of that specific system.
"Where the circumstances referred to in paragraph 1 occur, the provider that initially placed the AI system on the market or put it into service shall no longer be considered to be a provider of that specific AI system for the purposes of this Regulation."
- Who
- Provider, Downstream provider
- From
- (Art. 113(c)(i) as amended by Reg. (EU) 2026/1744)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).For Art. 6(1)/Annex I high-risk systems, Art. 113(c)(ii) as amended applies the corresponding obligation from 2028-08-02; Art. 111(2) gives public-authority high-risk systems until 2030-08-02.
- Fine tier
- Art. 99(4)
- Legal practice
- Reaches legal practice directly — Clarifies responsibility shifts in legal-AI supply chains after white-labelling, substantial modification or purpose changes.
- See
- Art. 25(1) · Art. 99(4)(da)
Art. 25(3)Scope or definitionHigh-risk
For high-risk AI safety components of Annex I Section A products, the product manufacturer is considered the provider and subject to Article 16 when the system is marketed or put into service under its name or trademark.
"In the case of high-risk AI systems that are safety components of products covered by the Union harmonisation legislation listed in Section A of Annex I, the product manufacturer shall be considered to be the provider of the high-risk AI system, and shall be subject to the obligations under Article 16 under either of the following circumstances:"
- Who
- Product manufacturer, Provider
- From
- (Art. 113(c)(i) as amended by Reg. (EU) 2026/1744)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).For Art. 6(1)/Annex I high-risk systems, Art. 113(c)(ii) as amended applies the corresponding obligation from 2028-08-02; Art. 111(2) gives public-authority high-risk systems until 2030-08-02.
- Fine tier
- Art. 99(4)
- Legal practice
- Institutional — Mostly concerns product-regulated manufacturers and legal advice on responsibility allocation rather than ordinary legal-AI deployments.
- See
- Annex I Section A · Art. 16
Art. 25(4)RequirementHigh-risklegal practice
The high-risk AI provider and third-party suppliers of integrated AI systems, AI models, tools, services, components or processes must specify necessary information, capabilities, technical access and assistance by written agreement.
"The provider of a high-risk AI system and the third party that supplies an AI system, AI model, tools, services, components, or processes that are used or integrated in a high-risk AI system shall, by written agreement, specify the necessary information, capabilities, technical access and other assistance based on the generally acknowledged state of the art, in order to enable"
- Who
- Provider, Downstream provider, Any operator, GPAI model provider
- From
- (Art. 113(c)(i) as amended by Reg. (EU) 2026/1744)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).For Art. 6(1)/Annex I high-risk systems, Art. 113(c)(ii) as amended applies the corresponding obligation from 2028-08-02; Art. 111(2) gives public-authority high-risk systems until 2030-08-02.
- Fine tier
- Art. 99(4)
- Legal practice
- Reaches legal practice directly — High-risk legal-AI vendors often rely on models, tools or services from third parties and need written value-chain support allocation.
- See
- Art. 99(4)(da) · Annex III point 8
Art. 25(5)Scope or definitionHigh-risk
Article 25(2) and (3) do not prejudice the need to observe and protect intellectual property rights, confidential business information and trade secrets under Union and national law.
"Paragraphs 2 and 3 are without prejudice to the need to observe and protect intellectual property rights, confidential business information and trade secrets in accordance with Union and national law."
- Who
- Provider, Product manufacturer, Downstream provider, Any operator
- From
- (Art. 113(c)(i) as amended by Reg. (EU) 2026/1744)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).For Art. 6(1)/Annex I high-risk systems, Art. 113(c)(ii) as amended applies the corresponding obligation from 2028-08-02; Art. 111(2) gives public-authority high-risk systems until 2030-08-02.
- Legal practice
- Reaches legal-AI vendors or public bodies — Relevant to contracts and disputes in legal-AI supply chains involving models, data, technical documentation and trade secrets.
- See
- Art. 25(2) · Art. 25(3)
Cite
Regulation (EU) 2024/1689, Article 25 (Responsibilities along the AI value chain), as amended by Regulation (EU) 2026/1744, consolidated text of 27 July 2026, https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_25 — text © European Union; only the Official Journal is authentic. Coding: SafeLegalAI (published by Cognesio LLP), "EU AI Act, structured", safelegalai.com/regulation/eu-ai-act/article-25, accessed 2026-09-08, CC BY 4.0.