Generated output has to be marked
Providers of systems that generate synthetic audio, image, video or text must mark the output in a machine-readable format and detectable as artificially generated or manipulated. A system placed on the market before 2 August 2026 has until 2 December 2026. That deadline is Article 111(4) of Regulation (EU) 2024/1689, and Article 111(4) is not in the 2024 text as published: it was added by Regulation (EU) 2026/1744, the Digital Omnibus on AI, at Article 1, point (39)(b), OJ L, 2026/1744, 24 July 2026.
Read the role carefully, and read it off the statute. Article 3(3) makes you a provider if you place the AI system on the market or put it into service under your own name or trademark. It does not turn on who built the model. So if you assemble a chat system, put it in front of users under your own name or brand, and run it on a third-party API, you are arguably the provider of that system and the deployer of the model inside it at the same time, and Article 50(2) is on the table. You are a deployer alone only where the assistant reaches your users under somebody else's name; then your obligations are 50(1) and, if you publish deepfakes or AI-written text on matters of public interest, 50(4).
It is a judgement call, not a settled one. We put the determination in writing as part of the install, with the clause quoted and the reasoning recorded, because getting it wrong in either direction costs money and the expensive direction is the one where you are told you are clear and do nothing.