GovCompass

Art. 54 EU AI Act: authorized representatives of GPAI providers

By GovCompass.ai· Last updated August 2026· Aligned with the consolidated EU AI Act, including the 2026 Omnibus amendments.

Art. 54 requires a provider of a general-purpose AI model established outside the EU to appoint, by written mandate, an authorized representative located in the Union before placing the model on the EU market. The representative is the Union-based point of contact that the AI Office and national authorities can address, and it holds the documentation and cooperates with supervision on the provider's behalf. It is the mechanism that keeps a non-EU model provider reachable under the Act.

Part of the wider governance context. This article explains one provision of the EU AI Act. How that provision fits into AI governance as a whole, from the seven pillars of responsible AI to the controls that keep systems inside agreed boundaries, starts at What is AI governance.

Why a representative is required

A large share of the most significant general-purpose AI modelsgeneral-purpose AI modelEU AI Act term for a model displaying significant generality and capable of many distinct tasks, typically integrated into downstream systems; carries its own obligation set, with extra duties for models posing systemic risk.Open full entry → are developed by providersproviderThe actor who develops an AI system (or has it developed) and places it on the market or into service under its own name. It carries manufacturer-style duties: design controls, documentation, conformity.Open full entry → established outside the EU. Art. 54 ensures that placing such a model on the Union market does not put it beyond the reach of EU supervision. A provider established in a third country must, prior to making its model available in the Union, appoint by written mandate an authorized representativeauthorized representativeA person established in the EU, appointed in writing by a non-EU provider to carry out the provider's obligations under the AI Act.Open full entry → established in the Union. This mirrors the authorized-representative mechanism that exists elsewhere in EU product and digital regulation.

What the representative does

The authorized representative is not a formality. Under its mandate it performs a defined set of tasks on behalf of the provider. It verifies that the technical documentationtechnical documentationRecords a provider must compile and keep for a high-risk AI system to demonstrate conformity, covering its design, data, testing, risk management and monitoring.Open full entry → required under Art. 53 has been drawn up and that the provider has met its obligations. It keeps a copy of that documentation available for the AI OfficeAI OfficeThe European Commission body that coordinates implementation of the EU AI Act and supervises general-purpose AI models. National market surveillance authorities enforce the Act for most AI systems; the AI Office is the central point for the general-purpose AI layer. See general-purpose AI, EU AI Act.Open full entry → and national competent authorities for the required period. It serves as the point of contact for the authorities on all matters relating to the model's compliance, and it cooperates with them on any action they take. The mandate must empower the representative to be addressed, alongside or instead of the provider, on compliance matters.

The representative also has a duty to act where the provider does not. If the representative considers that the provider is acting contrary to its obligations under the Act, it must terminate the mandate and inform the AI Office, which prevents the representative role from being used as a shield.

Why it matters

For a downstream organization in the EU integrating a model from a non-EU provider, Art. 54 is the reason there is an accountable, reachable party inside the Union. The authorized representative is who EU authorities engage when a question arises about the model, which means the regulatory line does not stop at the EU border even when the model was built outside it.

In the seven pillars of responsible AI

Art. 54 is an accountabilityaccountabilityThe principle that a named human or organization answers for an AI system's outcomes, through ownership, documentation, audit trails and redress; never the system itself. The EU AI Act attaches obligations to the role rather than the technology, with provider duties in Article 16 and deployer duties in Article 26, supported by technical documentation (Article 11) and record-keeping (Article 12). See provider, deployer, record-keeping, responsible AI.Open full entry → provision. It guarantees that for every general-purpose AIgeneral-purpose AIA model trained on broad data that can be adapted to many downstream tasks; the AI Act sets specific obligations for it, with extra duties when it poses systemic risk.Open full entry → model on the EU market there is an identifiable, reachable party within the Union who is answerable for the model's documentation and cooperates with supervision.

Continue reading

Legal referencesArt. 54
Share Share on LinkedIn

More on Accountability

Agentic AI and governance: why autonomy sharpens the control question

Analysis

Agentic AI does not need a new kind of governance. Autonomy widens the gap between what a system does and who is accountable for it, which makes the existing governance chain, control tracing to risk and forward to evidence, more important, not less. The actions are real and sometimes irreversible, so the stakes on each control rise.

Agentic AI risk assessment: from architecture decisions to control objectives

Analysis

Assessing the risk of an AI agent does not need a separate method. The steps stay the same: recognize the risk, assess how likely and how severe it is for your system, and control it. What changes is the input. An agent runs the process through recorded architecture decisions, about the model, the instruction, retrieved knowledge, tools, orchestration, memory, and autonomy, and each of those decisions, alone or in combination, creates the possibility of harm. The output of the assessment is a set of risk scenarios with a control objective for each.

AI certification: what exists and what it proves

Analysis

AI certification is not one category. Three different objects are assessed, each by a different kind of assessor: a person, an organization's AI management system, and an AI system placed on the EU market. The first two can be certified. The third is subject to a legal conformity assessment, which produces a certificate on one of its two routes and none on the other. Identifying which object a credential covers is the first step to judging what it is worth.

AI governance and enterprise risk management: where they meet

Analysis

AI governance is not a parallel structure that sits beside enterprise risk management. It belongs inside it. The seven pillars of responsible AI are the control structure the organization uses to govern each AI system; enterprise risk management is the machine that carries the residual risk those controls leave behind into the board's risk appetite, the risk register, and the assurance plan. The practical question is not whether to build AI governance or ERM, but how to slot the first into the second so that one accountable structure, not two competing ones, owns AI risk.