Non-EU providers of GPAI models must appoint an EU authorised representative
Context fileUnder EU AI Act, Article 54
What does it require?
Before placing a general-purpose AI model on the Union market, a provider established in a third country must appoint, by written mandate, an authorised representative established in the Union. The representative checks that the Annex XI documentation exists and the Article 53 duties are met, keeps a copy of the documentation and the provider's contact details for ten years after market placement, provides information to the AI Office on request, cooperates with authorities, and must end the mandate if the provider breaches the Regulation. Open-source models without systemic risk are exempt.
Practical action
Appoint an EU representative under a written mandate covering document retention and AI Office liaison before the model reaches EU users.
Who does it apply to?
Providers of general-purpose AI models established outside the EU, unless the model is free and open-source and not of systemic risk.
- Sectors
- Cross-sector / all sectors
- Use cases
- Generative AI and foundation models
Applies from:
Which controls meet this duty?
Satisfies: the control, operated properly, does the work the duty asks for. Supports: it contributes but the duty needs more. Each control page lists every other duty it serves, so work done once can be counted once.
-
satisfiesContractual termLegal counsel · once per ai systemContractual allocation of AI duties across the supply chain
Serves 8 recorded duties · evidence: AI supplier clause set, AI customer or deployer clause set, Contract clause index against the AI register
The mandate and its task list.
-
supportsProcessProduct or model owner · at launch and on material changeTechnical documentation, model cards and instructions for use
Serves 13 recorded duties · evidence: Technical documentation file, Model card or deployer information pack, Instructions for use
The documentation the representative holds.
What evidence would a reviewer expect?
| Evidence | Type | Notes |
|---|---|---|
| Written mandate of authorised representative for GPAI | document | |
| Representative's verification of Annex XI documentation | record |
Framework mappings
Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.
See every European Union duty mapped this way →
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| ISO/IEC 42001:2023 | Clause 5.3; Annex A.10.2 | Responsibilities allocated to an external party. | medium |
| NIST AI RMF 1.0 | GOVERN 2.1, GOVERN 6.1 | Roles and third-party arrangements. | low |
Cite this record
AIPolicyTracker (2026). “Non-EU providers of GPAI models must appoint an EU authorised representative (EU AI Act)”. https://aipolicytracker.org/obligations/eu-ai-act-art-54-gpai-authorised-representative (accessed 24 September 2026). Data licensed CC BY 4.0.
Cite the official text alongside it: Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence, Official Journal of the European Union, https://eur-lex.europa.eu/eli/reg/2024/1689/oj.
Similar obligations in other instruments
- Providers of GPAI models must notify the Commission within two weeks of meeting the systemic-risk threshold — EU AI Act, European Union
- Providers must meet the full set of provider duties for high-risk AI — EU AI Act, European Union
- Use high-risk AI as instructed, monitor it and inform affected people — EU AI Act, European Union
- Providers must supply conformity evidence and log access to authorities on request — EU AI Act, European Union
- Non-EU providers must appoint an EU authorised representative for high-risk AI — EU AI Act, European Union
- Deployers, distributors and importers must assume provider duties when they rebrand or substantially modify high-risk AI — EU AI Act, European Union
- Law-enforcement deployers must obtain authorisation for post-remote biometric identification and report annually — EU AI Act, European Union
- Operators of high-impact AI must prepare user-protection measures and keep records of their safety and trust measures — Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust, South Korea
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.