One seat outside the Union, three appointments inside it
fictional demo profile
DeepHelm AI ships general-purpose models from outside the EU. The compute threshold decides which duty set applies — and the missing EU establishment triggers appointment duties in three regimes that look alike and are not.
- AI Act · GPAI + systemic risk
- Art. 54 · Art. 27 · Art. 13
- no Annex III track
Model case study. This scenario is built on a fictional demo persona that ships with the Regingada Compliance Suite — not a real client, not a real company. Any similarity to existing companies is coincidental. It shows how the suite maps a profile of this shape to EU digital law. No legal advice.
A model provider that never set foot in the Union
DeepHelm AI (fictional demo profile) develops general-purpose AI models and offers them to developers who build products on top. The reader in this persona is a Chief AI Safety Officer — someone who already knows the vocabulary and is looking for the exact cut of the duty set, not an introduction. The company has no establishment in the Union, but its models reach European deployers and, through them, European users. That is enough for EU digital law to take an interest.
The portfolio has two tiers. A general-purpose model, and a larger one whose training compute crosses the threshold at which the AI Act presumes systemic risk. Those two tiers are not a marketing distinction; they carry different obligations, and the larger model adds an entire second layer on top of the first. On the data-protection side the company processes personal data of people in the Union without being established there. The demo profile therefore answers: provider, seat outside the EU, general-purpose model plus a model above the compute threshold, personal data yes, EU representative under the GDPR yes. No intermediary service, so the DSA profile stays empty.
The GPAI track, plus what a missing seat costs
The suite opens the general-purpose chapter of the AI Act with its systemic-risk layer, and the GDPR with the third-country representative. It does not open the Annex III high-risk track: a foundation model is not a listed high-risk use case, and pushing that cockpit at a model provider is precisely the mis-sale this profile is designed to expose. The DSA appears only as context in the cross-regulation view, because the appointment logic runs parallel there — not as an obligation set, since the company runs no intermediary service.
Central articles for this profile
| Article | Duty in short | Why for this profile |
|---|---|---|
| AI Act · Art. 51 | Classification of general-purpose models with systemic risk | The fork in the road: one model stays on the base track, the other picks up the systemic-risk layer. |
| AI Act · Art. 52 | Notification to the Commission when a model meets the classification condition | A procedural duty with a short fuse — it attaches to a training run, not to a launch date. |
| AI Act · Art. 53 | Base duties for GPAI providers: technical documentation, information to downstream providers, copyright policy, public summary of training content | Applies to both models. The downstream-information duty is what the persona's customers will ask for first. |
| AI Act · Art. 54 | Authorised representative for GPAI providers established in a third country | The core consequence of the non-EU seat, and the duty most often discovered late. |
| AI Act · Art. 55 | Additional duties for systemic-risk models: evaluation, adversarial testing, risk mitigation, serious-incident reporting, cybersecurity protection | The second layer for the larger model — evaluation and incident reporting become recurring operations. |
| AI Act · Art. 56 | Codes of practice as a route to demonstrating compliance | Signing or not signing is a strategic decision with documentation consequences either way. |
| AI Act · Annex XI | Content of the technical documentation for GPAI providers | Turns the Art. 53 documentation duty into a concrete list of items. |
| AI Act · Annex XIII | Criteria for designating a model as carrying systemic risk | Compute is not the only route in — the criteria are worth reading before assuming the base track. |
| AI Act · Art. 22 | Authorised representatives of third-country providers of high-risk systems | Sits next to Art. 54 and is constantly confused with Art. 22 GDPR — see the collision points. |
| GDPR · Art. 3(2) | Territorial scope for controllers without an establishment in the Union | The reason the GDPR reaches this company at all, and the precondition for Art. 27. |
| GDPR · Art. 27 | Designation of a representative in the Union, in writing | A separate appointment with a separate scope — it is not covered by the AI Act representative. |
| DSA · Art. 13 | Legal representative for intermediary providers without an EU establishment | Shown as context only: the same fact pattern, a different trigger — and not activated for this profile. |
Articles are shown because a profile of this shape reaches them, not because a lawyer has found that they apply to you. Which of them actually bite in a concrete company is an assessment — and that is a mandate.
Where the regimes rub against each other
-
Three representatives, one company
Art. 54 AI Act, Art. 27 GDPR and Art. 13 DSA all answer the same practical question — who can be reached inside the Union — with three different appointments. Different triggers, different scopes, different addressees, and no substitution: appointing one does not discharge the others. The map connects them because the fact pattern is one, not because the duties are. For a non-EU provider this is the single most useful cross-regulation view on the whole board.
-
Which Article 22 is being discussed?
Art. 22 AI Act concerns authorised representatives of third-country providers of high-risk systems. Art. 22 GDPR concerns automated individual decisions and has nothing to do with representation. Both come up in a non-EU conversation, and the second one is usually the one people mean when they should mean the first. The map keeps them as separate anchors with no edge between them — same number, different norm.
-
A general-purpose model is not an Annex III system
The high-risk track and the GPAI track are separate regimes inside the same regulation, and a model provider does not inherit Annex III duties by shipping a capable model. The picture changes downstream: a customer who builds the model into a listed high-risk use case takes on the provider role for that system. Where responsibility passes along the value chain is a genuine question — but it is a different one, with different addressees, and the twin does not answer it by opening the wrong cockpit.
-
The code-of-practice fork
Adhering to a code of practice is a route to demonstrating compliance with the GPAI duties; a provider that does not adhere has to show that it meets them by other, equivalent means. That is a strategy decision, not a formality, and it changes what has to be documented and how. The twin makes the fork visible instead of assuming one branch.
What the map does not claim
The corpus carries Annex XI and Annex XIII as mapped nodes. Annex XII is named at the level of the obligation, where the regulation names it, but it is not modelled with the same depth. That gap is stated rather than papered over — a map that pretends to depth it does not have is worse than one that marks its edges.
Two tiers, one appointment map
GPAI cockpit
The two tiers side by side: the base duties under Art. 53 for every general-purpose model, and the additional systemic-risk layer under Art. 55 for the model above the threshold. Documentation, downstream information, copyright policy and training-content summary on one side; evaluation, adversarial testing, mitigation, incident reporting and cybersecurity on the other. The code-of-practice route is shown as what it is — a route, with consequences.
Appointment view
The three representative duties in one picture, with their separate triggers: Art. 54 AI Act for the model provider, Art. 27 GDPR for the controller without an EU establishment, Art. 13 DSA for intermediary services. Which ones a profile reaches, which stay out, and where the scopes differ rather than overlap.
Cross-regulation view
The representative triple is one of the curated walk-throughs; the Art. 22 numbering trap is another. Real connections are drawn as edges, false friends are drawn as separations — the difference is the point.
Radar watch
Change entries tagged to this profile: the designation criteria for systemic risk, the code-of-practice process, and movement in the application dates. The radar reports the state of the watchlist with its date; it does not claim to be a live feed.
Deliverables — and the DRAFT rule
The suite can generate a tier classification memo, a GPAI documentation outline, an appointment map across the three regimes and a gap report. Everything it produces is marked DRAFT. A DRAFT carries no signature, no assessment and no liability; it is a structured starting point. It becomes an assessment only when the law firm Theo Funk takes it into a mandate and signs it off. The appointed representative function itself is a service of Regingada UG (haftungsbeschränkt) under a separate representation contract, not a by-product of the software. Package details and prices are listed separately under pricing.
Where the software stops
Everything above is orientation: a map of what a profile of this shape reaches in EU digital law, drawn from a public corpus and readable back to its sources. It is structured self-assessment and decision support — it is not an evaluation of a specific company, and it is not legal advice.
The assessment is the second step, and it belongs to the law firm Theo Funk under a separate mandate: whether a model crosses into systemic risk, how far the training-content summary has to go, what a downstream information package must contain, how the three appointments are structured. Regingada UG (haftungsbeschränkt) builds the software and can act as the appointed EU representative; the firm does the legal work. The two are strictly separated, and that separation is the reason the tool can be as blunt as it is.
Other profiles: all five model cases. Packages: pricing.
Orientation, not legal advice
This model case and the suite provide orientation and information only. They are not legal advice. Individual-case advice is provided exclusively by the law firm Theo Funk under a separate mandate. Regingada UG (haftungsbeschränkt) — the software company and appointed EU representative — and the law firm are strictly separated.