White-label and the EU AI Act: who is the provider and who is the deployer

White-labeling does not settle responsibility by itself: the provider and deployer roles depend on what each party does and whose authority governs the system. A separate transparency question can arise when an AI system is intended to interact directly with people, so the applicable facts and rules still need to be checked. Assign each role from the deployment facts and document the resulting responsibility instead of treating every branded assistant as the same legal case.

Two pairs of people exchange a glowing cube, layered panels and documents on display pedestals against a dark background.

By Reynier RiveroSoftware engineer

Why this question has no comfortable answer yet

At 9:00 on launch day, an agency's new assistant answers under the agency's brand. The studio built it; the client operates it. Then someone asks the question nobody wrote into the contract: who owns the disclosure telling customers they are speaking to AI?

This is a hypothetical scenario, not a reported incident. It captures the awkward middle ground in white-label delivery: the studio builds, the agency brands and sells, and the end client deploys.

By 9:20, the launch is paused: the disclosure is missing from the WhatsApp welcome message, and nobody can say who has authority to approve the fix or where the final configuration should be recorded. The system is technically ready but cannot move operationally.

The immediate problem is an ownership gap. A contract can describe the build, brand and deployment work without assigning anyone the final decision when those layers meet.

That is the same ownership problem that appears when an agency evaluates white-label platforms: the product may be shared, but responsibility cannot be left to implication.

Where this bites in practice

This is not an abstract concern. It bites at three specific moments, and all three are cheap to handle in advance and expensive afterwards.

  • First, if Article 50(1) applies to the system, somebody has to decide the exact disclosure wording, where it appears, and what happens in voice and in WhatsApp where there is no interface to imply it. If nobody owns that decision, it does not get made.
  • Second, a client may need a practical point of contact. The agency may be the client's first contractual point of contact, but that is not a universal legal conclusion about responsibility.
  • Third, there is a change of studio. If the disclosure, the logs and the evaluation set live with the supplier, changing supplier may mean rebuilding the evidence needed to operate the system.

An assistant that calls APIs, searches a knowledge base or writes to a CRM is a real AI agent or chatbot product, not just a branded conversation window. Its tools, data access and handoff records belong in the same ownership map as its disclosure.

The definition does the work

The consolidated Article 3 text defines a provider through two independent paths: a person may develop an AI system, or may have it developed and place it on the market or put it into service under its own name or trademark. The second path matters in white-label delivery, but the facts of the deployment still determine which party fits the definition.

The AI Act's territorial scope is set out in Article 2. It applies to providers placing AI systems on the Union market or putting them into service there regardless of whether they are established in the Union or a third country; it also applies to deployers established or located in the Union and to certain third-country providers or deployers where the output is used in the Union. For a US studio or agency, being established outside the EU is not, by itself, an exemption when the system is placed on the Union market, put into service there, or its output is used in the Union.

The same consolidated Article 3 text defines a deployer as the entity using an AI system under its authority. In a white-label arrangement, the end client may be the deployer if it uses the system under its authority, but that role is not automatic and another party may fit the definition on the facts.

There is a second filter before anyone writes chatbot copy. The consolidated Article 50 text states that providers must ensure AI systems intended to interact directly with natural persons are designed and developed so those people are informed they are interacting with AI, subject to the stated exception. Article 50(1) is therefore not a universal chatbot rule.

What timing does — and does not — answer

The Commission's official transparency guidance published on July 20, 2026 says the Article 50 transparency obligations apply from August 2, 2026. That answers when the scheduled obligation enters the calendar; it does not answer which entity is the provider in a three-party arrangement.

The timing also needs to be read alongside the Commission's July 27, 2026 notice that the Digital Omnibus entered into force. The current consolidated text contains the Article 3 text and Article 50 text alongside the July 27, 2026 amendment; use that consolidated version for the current wording and do not turn an earlier calendar into a complete post-Omnibus schedule. In particular, do not assume a blanket December transition or that every high-risk adjustment changes Article 50(1).

The annex for agency arrangements

The annex exists because the alternative is a very expensive conversation later. It is not clever; it is just written down. It can assign operational tasks, but on its own it does not determine which party is the legal provider or remove applicable obligations.

  • Name the provider and deployer for each deployment, stated per client rather than once in general.
  • Agree the exact disclosure wording and its placement before launch, and version it so it can be shown later.
  • Define who deploys a change to that wording, and within how long, when the interpretation moves.
  • Record where the logs live, who can read them, and how long they are kept.
  • Specify what the studio hands over if the agency changes supplier: prompts, evaluation set, index and disclosure configuration.
  • Set out mutual non-solicitation and the rule governing contact with the end client.

What remains fact-dependent

Provider and deployer assignment remains fact-dependent in a white-label arrangement: it depends on what each party does and whose authority governs the system. The practical risk is that nobody owns the disclosure by default in a white-label arrangement. Writing down whose job it is is a small task. Discovering that nobody owns it costs a client.

The white-label AI development guidance for agencies is a useful companion for turning those decisions into a small, auditable architecture across provider/deployer ownership, disclosure placement, logging and supplier handover. Prontavel can help build that layer around the systems you already use.

This is informational and not legal advice. Check your arrangement with a lawyer qualified in your jurisdiction.

Check your assistant against Article 50

Twelve checks against the transparency duty that has applied since 2 August 2026. It is not a verdict: it is the list we run over our own deployments, and every "no" names the gap.

  1. Opening the conversation shows a notice that this is an AI, without having to look for it.
  2. The notice is in the thread itself, not only in the terms of use or a tooltip.
  3. In voice, the notice is in the first few words of the first turn.
  4. On WhatsApp or SMS, the notice is in the first message, because no interface implies it.
  5. The name and avatar do not impersonate a specific person on your team.
  6. The assistant answers "are you human?" correctly, and that answer is tested.
  7. Text published without human review on matters of public interest is labelled.
  8. Generated image, audio or video resembling real people is labelled as generated.
  9. Who is provider and who is deployer is decided and written down, especially with an agency in the middle.
  10. There is a record of which version of the notice was deployed and since when.
  11. The notice exists in every language the assistant replies in.
  12. Someone is explicitly responsible for revisiting this when the interpretation moves.

The service this article is about: Your brand. Our build. Your client never meets us.

Kickoff in 1-2 weeks

Tell us what you need

We reply with a plan and a range, not a sales pitch. Book a call or send a message.