EU AI Act

AI Act Authorised Representative for Non-EU Providers

If your business is established outside the EU and you place a high-risk AI system or a general-purpose AI model on the EU market, the AI Act requires you to appoint an EU authorised representative by written mandate before that system or model is made available. DataShield acts as your appointed representative on EU soil: we hold your documentation at the disposal of the authorities, serve as their point of contact, and support your registration obligations. Our service is overseen by a CNIL-designated DPO, so the same team can align your AI Act, GDPR and Article 27 representation under one mandate.

🛡 Overseen by a Data Protection Officer designated with the CNIL

What an AI Act authorised representative is

Under the AI Act, an authorised representative is a natural or legal person established in the EU who, by written mandate, agrees to perform a defined set of compliance tasks on behalf of a provider established outside the Union. The representative is not the provider and does not assume the provider's design or engineering duties.

The mandate is the legal instrument that empowers the representative. For high-risk systems it is governed by Article 22; for general-purpose AI models, by Article 54. In both cases the representative becomes a fixed, locally established point of accountability so that EU authorities can reach a responsible party without acting through a third country.

  • Appointed by written mandate
  • Established inside the EU
  • Acts for, but is distinct from, the provider

Who needs an authorised representative

The obligation applies to providers established outside the EU (including US and Canadian businesses) who place certain AI on the Union market. Two groups are concerned:

  • High-risk AI systems under Article 22: providers in a third country must appoint a representative before the system is made available on the EU market. These obligations phase in notably from 2 August 2026.
  • General-purpose AI models (GPAI) under Article 54: non-EU providers must appoint a representative before placing the model on the market. These obligations have applied since 2 August 2025.

A narrow exemption exists for certain free and open-source GPAI models, unless the model presents systemic risk. If you are unsure which category applies, we can help you assess it.

What DataShield does as your representative

Acting under your written mandate, DataShield performs the representative tasks the AI Act assigns:

  • Keep your technical documentation and EU declaration of conformity available to competent authorities for the retention period set by the Regulation (ten years for high-risk systems).
  • Cooperate with, and serve as the named contact point for, market-surveillance and competent authorities, providing information and documentation on reasoned request.
  • Support your registration in the relevant EU database for high-risk AI systems.
  • Verify that the declaration of conformity and documentation have been drawn up.

If we have reason to believe you are acting contrary to your AI Act obligations, we must terminate the mandate and inform the relevant authority. This safeguard is part of every appointment.

FAQ

AI Act Authorised Representative for Non-EU Providers

Is an AI Act authorised representative the same as a GDPR Article 27 representative?

No. They are separate legal roles under different regulations. A GDPR Article 27 representative covers personal data processing for organisations without an EU establishment, while an AI Act authorised representative covers obligations for high-risk AI systems and general-purpose AI models. Because DataShield is overseen by a CNIL-designated DPO, we can act in both capacities and coordinate them under one engagement, but each role rests on its own written mandate and its own statutory tasks.

When must we appoint an authorised representative?

Before the relevant AI is made available on the EU market. For general-purpose AI models, the obligation under Article 54 has applied since 2 August 2025. For high-risk AI systems under Article 22, the obligations phase in notably from 2 August 2026. Because the mandate must be in place beforehand, non-EU providers should appoint a representative well ahead of any EU launch rather than after authorities make contact. We can put the mandate in place quickly once your classification is confirmed.

Does appointing DataShield transfer our provider obligations to you?

No. You remain the provider and keep full responsibility for designing, documenting and assessing the conformity of your AI system or model. The authorised representative performs the specific tasks set out in the written mandate, such as holding documentation available, acting as the authorities' contact and supporting EU-database registration. We do not draw up your technical documentation or perform your conformity assessment, though we verify that they exist and we flag any concern, terminating the mandate where the law requires.

Work with a real DPO

Appoint an EU representative backed by genuine, verifiable expertise.

Get my quote →