Navigating EU AI Act Compliance: Core Obligations and Authorised Representative Requirements
Introducing the EU AI Act – Effective August 2026
As the EU’s Artificial Intelligence Act comes into force in August 2026, providers of certain AI systems—both inside and outside the Union—must adhere to a tiered, risk-based regulatory framework. Understanding these compliance obligations is the first step toward lawful market entry.
Compliance Obligations for AI Providers
High-Risk AI Systems (Annex III)
Systems whose failure or bias could threaten health, safety or fundamental rights—for example, biometric identification, critical-infrastructure control or recruitment screening tools—are classified as high-risk. Such providers must:
- Conformity Assessment: Complete either internal quality-management checks or a third-party audit by a notified body.
- Technical Documentation: Maintain comprehensive files detailing system design, data sources, validation results, performance metrics and risk-mitigation strategies for at least ten years.
- Post-Market Monitoring: Implement ongoing surveillance to detect performance drift, emerging biases or new hazards, with periodic reviews and corrective actions.
General-Purpose AI Models (Article 54)
Broadly capable models (e.g., large language or vision systems) that can have systemic impact even when unbranded must also meet specific transparency and risk-control rules:
- Public Summary: Publish a concise overview of training data, development methodology and implemented risk-mitigation measures.
- Transparency & User Guidance: Provide clear instructions on system capabilities, known limitations and safe operation practices.
Core Compliance Elements
- Technical Documentation: Detailed records on architecture, datasets, testing protocols, performance evaluation and safeguards.
- Transparency Obligations: User-facing materials that include contact details (provider or Representative), system functions, limitations and guidance for correct use.
- Conformity Assessments: Selected based on risk level—internal checks for lower-end high-risk systems; notified-body audits for others.
- Post-Market Surveillance: Continuous monitoring, periodic impact assessments and documented corrective workflows.
- Standards & Codes of Practice: Alignment with harmonised EU standards and sector-specific codes to benefit from a presumption of conformity.
Authorised Representative: When and Why
Non-EU providers of high-risk systems or general-purpose models must appoint an Authorised Representative established in the EU. This mandated partner:
- Archives Documentation: Holds a full copy of the system’s technical files for at least ten years.
- Liaises with Regulators: Acts as the official contact for the EU AI Office and national surveillance authorities, supplying records upon request.
- Supports Compliance Procedures: Assists in audits, investigations and corrective-action processes.
- Terminates Mandate if Needed: Withdraws representation and notifies authorities if the provider falls out of compliance.
Implementation Timeline
- 1 August 2024: Act enters into force.
- 2 August 2026: Major risk-based obligations become applicable.
- 2 August 2027: Sector-and component-specific rules apply.
- 2 August 2028: Extended deadline for AI systems already on the market.
- 31 December 2030: Compliance deadline for Annex X IT system components.
By prioritising these compliance steps—documentation, assessment, transparency, monitoring and adherence to standards—and securing an EU Authorised Representative where required, AI developers can meet the EU AI Act’s mandates and prepare for market access starting August 2026.