5 Comments
User's avatar
Andrea Politano's avatar

Excellent post, Silvia! One question: what is the status of agentic systems for internal usage? Meaning, a company develops an agent for internal usage, leveraging off-the-shelf LLMs (e.g. GPT without fine-tuning). Does the company falls within the "provider" category is such case?

Silvia Stepitova's avatar

Great question, Andrea. Let me add a bit of context. We need to distinguish two roles here: provider of the model versus provider of the system. If there’s no fine-tuning, it generally means you're not a provider of the GPAI model. That's the compute-threshold test, and you've stayed under it. But the agent you built on top is its own AI system, and you developed it. That likely makes you the provider of that system, fine-tuning or not.

"Internal usage" doesn't get you out either. Putting into service is defined to include putting a system into service for your own use.

What actually moves the needle isn't provider versus deployer. It's whether the agent is high-risk. That's where the obligations get real. An internal agent that isn't high-risk: your obligations as a deployer or provider are different but light. If it’s high-risk, then it’s a different story.

Andrea Politano's avatar

Very clear, thanks a lot!

State of Play's avatar

Thanks for this. Your "the deployer role can change without you noticing" is the sharpest observation in an already sharp piece, and it's more structurally true than the legal framing alone captures. The system-by-system role classification you prescribe runs directly into the fact that most organizations can't enumerate the systems they'd need to classify: surveys across enterprise deployments show more than 50% lack any systematic AI inventory, and roughly 60% of AI systems run outside IT visibility. The silent deployer-to-provider transition isn't an edge case to watch for; it's the modal enterprise situation, and it's structurally invisible precisely because the AI inventory that would surface it is the single most common governance gap. Your decision tree is well-designed; the problem is that step one is failing before step two begins.

Silvia Stepitova's avatar

You're right that the inventory gap sits underneath all of it. The classification only works if you know what you're classifying, and the systems running outside IT visibility are often the ones that shifted the role in the first place.