Newsletter Anmeldung

Bleiben Sie mit dem Newsletter immer up to date.

Request
arrow-to-top
HomeMandatesRepresentative positionsExternal representative for GPAI providers
Dimitri Korostylev
Head of Legal & Data Privacy Consulting
request

The external EU representative for General Purpose AI models (GPAI) under the AI Act

For the legally compliant provision of your GPAI modules in the EU – even without a local branch

Chapter V of the EU AI Act contains specific rules for General Purpose AI (GPAI) models, i.e. AI models that can be used for a wide variety of purposes in many downstream applications, such as large language models, foundation models or multimodal models.

Providers of such models must, among other things:

  • provide technical documentation and training information,
  • comply with certain transparency and information obligations,
  • take appropriate measures to manage risks and protect fundamental rights, health, safety and the environment; with additional requirements for GPAI models posing systemic risk.

For providers not established in the EU who make GPAI models available on the EU market, Article 54 of the AI Act stipulates that:

  • Before making the GPAI model available in the internal market, they must appoint in writing an authorised representative established in the EU,
  • who acts as the point of contact for the competent authorities and assists in monitoring compliance with the AI Act obligations,
  • certain open-source models are exempt only in exceptional cases, e.g. if they are provided freely and with open source code and do not pose a systemic risk.

Our role as your representative

We act as your authorised representative in accordance with Article 54 of the AI Act and ensure that requirements and enquiries from EU authorities regarding your GPAI models are handled centrally, in a coordinated manner and within the prescribed timeframes.

Our services include, among other things:

  • Acting as the official point of contact in the EU for the competent authorities and the AI Office – through our subsidiary Swiss Infosec (Deutschland) GmbH, based in Berlin, Germany.
  • Receiving, coordinating and forwarding requests for information, orders and measures relating to your GPAI models, including those involving systemic risk.
  • Support in providing technical documentation and transparency information in accordance with Article 53 of the AI Act (e.g. model description, training data overviews, evaluation and benchmark results).
  • Pragmatic recommendations for action to implement the obligations for GPAI providers, including risk management, governance structures, monitoring processes and handling of reports on systemic risks.
  • Support in coordinating with downstream users and integrators (downstream providers), e.g. regarding terms of use, information obligations and technical interfaces.
  • Alignment of AI Act requirements with existing security and compliance frameworks (ISO 27001, ISO 42001, GDPR, NIS-2, Data Act, etc.) to avoid duplication of effort and leverage synergies.

This allows you to maintain your focus on research, development and scaling of your GPAI models. We take care of the role of EU representative and interaction with the authorities.

Why choose Swiss Infosec as your representative under Article 54 of the AI Act?

  • A thorough understanding of GPAI models and their risk profiles (e.g. large language models, generative models, multimodal foundation models), as well as the relevant obligations under Chapter V of the AI Act.
  • Experience with European digital and data regulations (AI Act, GDPR, Data Act, Digital Services Act, etc.) and how they interact.
  • Practical, technically sound advice – we speak the language of both development teams and legal and compliance departments.
  • Structured process models for governance, documentation, risk management and reporting specifically for GPAI providers, including the handling of models with systemic risk.
  • Clear roles and short lines of communication throughout the entire lifecycle of your models.

Our goal: to enable you to position your GPAI models securely, reliably and in compliance with the AI Act in the EU market, without unnecessarily slowing down your innovation and speed.

Next steps

Contact us for a no-obligation initial consultation. Together, we will clarify:

  • Whether your models are to be classified as GPAI models (possibly with systemic risk) within the meaning of the AI Act,
  • what specific obligations you have as a provider, and
  • how we can efficiently integrate the role of authorised representative for your GPAI models into your existing governance, compliance and development processes.

Let us take care of the role of authorised representative for your GPAI models, so that you can scale your AI innovation in the EU market responsibly, transparently and in compliance with the law.

Dimitri Korostylev
Head of Legal & Data Privacy Consulting
request

Non-binding enquiry

© Swiss Infosec AG 2026