← HomeREP27All categories

AI systems and general-purpose AI models

Digital and connected products

In short
Authorised representative in the Union for high-risk AI systems, and for providers of general-purpose AI models established outside the Union

Who has to appoint one

Providers established outside the Union that place high-risk AI systems on the EU market or put them into service there must appoint an authorised representative in the Union by written mandate before doing so. The same applies under Article 54 to providers of general-purpose AI models placed on the Union market. Deployers established in the Union have their own, lighter duties. A deployer becomes a provider — with the full obligations — if it puts its name on a high-risk system, substantially modifies it, or changes its intended purpose so that it becomes high-risk.

Thresholds and exemptions

The prohibited practices in Article 5 apply to everyone with no threshold. The representative obligation attaches to high-risk systems, which are those falling under Annex I product legislation or listed in Annex III: biometrics, critical infrastructure, education, employment and worker management, access to essential services including credit scoring, law enforcement, migration and border control, and administration of justice. General-purpose models have their own regime, with additional obligations for models presenting systemic risk above the compute threshold.

What must appear on the label

Not a physical label for most systems. The provider's name, trade name or trade mark and address, and those of the authorised representative, must appear on the system, its packaging or its accompanying documentation, and in the instructions for use. High-risk systems that are products under Annex I carry CE marking. Systems interacting with people must disclose that they are AI, and synthetic content must be marked in a machine-readable format.

Marketplace fields

No marketplace field yet, but EU procurement questionnaires already ask who the Article 22 representative is, whether the system is classified as high-risk, and how the transparency obligations are met. Enterprise buyers increasingly require this before contracting, ahead of the August 2026 deadline.

Documentation you must hold

Technical documentation under Annex IV, kept for ten years. A risk management system running across the lifecycle. Data governance documentation covering training, validation and testing datasets. Automatically generated logs. Instructions for use enabling deployers to comply with their own obligations. A quality management system. The EU declaration of conformity and registration in the EU database for Annex III systems. For general-purpose models, technical documentation for the AI Office and for downstream providers, a copyright policy, and a sufficiently detailed public summary of the training content.

Standards and testing

Conformity assessment based on internal control for most Annex III systems, or through a notified body for biometric systems where harmonised standards are not applied. Systems embedded in Annex I products follow that product's assessment route. Accuracy, robustness and cybersecurity must be tested and the levels declared. Post-market monitoring continues after placing on the market.

Language requirements

Instructions for use in a language easily understood by deployers in the member state concerned, as that state determines. Transparency disclosures to individuals in the language they would reasonably understand.

When it applies

Prohibitions and AI literacy obligations since 2 February 2025. General-purpose model obligations since 2 August 2025, with models already on the market before that date having until August 2027. High-risk obligations under Annex III from 2 August 2026. High-risk systems embedded in Annex I regulated products from 2 August 2027.

How long records are kept

Technical documentation, the declaration of conformity and the quality management documentation for ten years after the system is placed on the market. Logs for at least six months unless other law requires longer. The authorised representative keeps a copy of the mandate and the documentation for the same ten years and must produce it on request.

What happens if you do not comply

Up to €35 million or 7% of total worldwide annual turnover for prohibited practices. Up to €15 million or 3% for breaches of most other obligations, including those of providers and authorised representatives. Up to €7.5 million or 1% for supplying incorrect, incomplete or misleading information. Market surveillance authorities can also require withdrawal or recall of a system.

Who enforces it

National market surveillance authorities designated by each member state, the AI Office for general-purpose models, the European Artificial Intelligence Board, and notified bodies where third-party assessment applies.

Where the boundary lies

Most business software is not high-risk, and the classification depends on the use rather than the technology: the same model can be low-risk in one deployment and Annex III high-risk in another. A chatbot has transparency duties only. But an AI used to screen job applicants, score creditworthiness or allocate access to public services is high-risk regardless of how simple the model is. The authorised representative can terminate the mandate if it believes the provider is acting contrary to the Regulation, and must then inform the authority — a duty with no equivalent in Article 27 GDPR.

Questions we are asked

We use AI but do not build it — are we a provider?
Normally you are a deployer, with lighter duties. You become a provider if you put your name on a high-risk system, modify it substantially, or change its intended purpose so that it becomes high-risk.
Does the AI Act apply to a model we host outside the EU?
Yes if the output is used in the Union, or if the system or model is placed on the Union market. Physical location of the servers is not the test.
Is an Article 27 GDPR representative enough?
No. They are separate appointments under separate regulations, with different duties and different documentation, even where one provider holds both.
AI Act authorised representative · on request

Who signs for you
EU representative Europe Services, SE — Na Čečeličce 425/4, Smíchov, 150 00 Praha 5, Czech Republic
UK representative REP27 LTD — Unit 82a James Carter Road, Mildenhall, Suffolk IP28 7DE, United Kingdom

Talk to usCheck your category