GPSR: in force since December 2024
GPSR Compliance for AI Products and Consumer Technology
The General Product Safety Regulation applies to every consumer AI product on the EU market — including the ones the EU AI Act does not cover. It has been in force since December 2024 and most AI teams have not mapped it.

AMLD6 — transposition deadline October 2021
The General Product Safety Regulation — Regulation (EU) 2023/988 — entered into effect on 13 December 2024, replacing the General Product Safety Directive of 2001. It applies directly in all EU member states without national transposition and introduces significantly expanded obligations for every economic operator placing consumer products on the EU market — manufacturers, importers, distributors, fulfilment service providers, and online marketplaces.
The GPSR is the EU’s catch-all product safety framework for the digital age. Where the EU AI Act governs high-risk AI systems, and the Cyber Resilience Act governs software security, the GPSR applies to every consumer product — including AI-enabled products — that does not fall under sector-specific safety legislation. It is not an alternative to those frameworks. It operates alongside them, filling the gaps they leave and applying its own distinct obligations on top.
For AI and digital product companies, the GPSR is an immediate compliance obligation if your product touches any of the following:
- Consumer-facing AI products — hardware or software used by members of the public
- Connected devices with AI components — smart home, wearables, consumer electronics
- AI-enabled products classified as low-risk or minimal-risk under the EU AI Act — the GPSR applies to these regardless of AI Act classification
- Online marketplaces and platforms facilitating the sale of AI-enabled consumer products
- Products with software updates that change safety-relevant behaviour after market placement
- Any consumer product where AI affects the safety characteristics of the physical product
If any of these apply, the GPSR reached your product in December 2024. The obligation is not upcoming — it is already in force and being enforced.
GPSR Compliance Assessment for Your AI System
A lawyer-built assessment of your product’s GPSR obligations — economic operator role determination, consumer product scope confirmation, risk assessment requirements, technical documentation obligations, responsible person appointment, incident reporting and recall obligations, and a documented compliance record your legal team, enterprise buyers, distributors, and market surveillance authorities can rely on.
How GPSR works for AI products
Five obligation areas. One regulation. Direct requirements for every consumer AI product on the EU market.

The GPSR organises its requirements across five core areas. Each creates specific obligations for economic operators placing AI-enabled consumer products on the EU market — obligations that apply regardless of how the same product is classified under the EU AI Act or the Cyber Resilience Act.
General safety requirement
Every consumer product placed on the EU market must be safe. Under the GPSR, safe means that a product — under normal or reasonably foreseeable conditions of use, including misuse — does not present any risk or presents only minimal risks compatible with its use and considered acceptable. For AI-enabled products, this is not a static assessment. An AI product’s safety characteristics can change with software updates, model retraining, and changes in how the system makes decisions. The GPSR requires safety to be assessed and maintained across the product’s entire lifecycle — not just at the point of first market placement.
Risk assessment and technical documentation
Manufacturers must conduct a comprehensive risk assessment before placing a product on the market and maintain technical documentation for ten years. For AI products, the risk assessment must address not only traditional physical safety risks but also cybersecurity risks, risks to mental health and social wellbeing where relevant, and the specific risks that arise from AI decision-making — including risks to vulnerable users, risks from algorithmic bias, and risks from software updates that change the product’s behaviour. The European Commission’s guidance published in November 2025 confirms that a holistic approach to risk assessment is required, including consideration of vulnerable individuals and the product’s behaviour across a wide range of users.
Responsible person appointment
Non-EU manufacturers placing products on the EU market must appoint an EU-established responsible person before doing so. The responsible person — a manufacturer established in the EU, an importer, or an authorised representative — holds the technical documentation, verifies that the product meets the GPSR’s safety requirements, ensures labelling and instructions comply, and acts as the point of contact for market surveillance authorities. This obligation mirrors the EU AI Act’s Authorised Representative requirement in structure but is a separate appointment under a separate regulation — a non-EU AI product manufacturer may need both.
Incident reporting and market surveillance cooperation
Manufacturers and distributors must notify market surveillance authorities and consumers of safety issues without undue delay. Where a product presents a serious risk, notification to authorities must occur immediately — and a recall or withdrawal may be required. For AI products, incidents include not only physical safety events but software-related safety failures, unexpected AI behaviour that creates consumer risk, and cybersecurity incidents affecting the product’s safety characteristics. The GPSR’s incident reporting obligations interact with the CRA’s 24-hour ENISA vulnerability reporting requirement for connected products — where both apply, both timelines must be met.
Online marketplace obligations
Online platforms facilitating the sale of consumer products bear specific GPSR obligations — traceability requirements, cooperation with market surveillance authorities, and product removal where safety issues are identified. AI-powered recommendation systems and marketplace algorithms that facilitate consumer product sales must be assessed against these obligations. A platform whose AI directs consumers toward non-compliant products faces GPSR exposure alongside the product manufacturer.
Who GPSR applies to
The GPSR applies to every economic operator in the supply chain for consumer products — not only the manufacturer. AI companies whose products reach EU consumers directly or through distribution chains face obligations at multiple points in that chain.
| Entity type | In scope of GPSR? | Key obligation |
|---|---|---|
| EU manufacturer of consumer AI product | Yes — directly | General safety requirement, risk assessment, technical documentation, incident reporting |
| Non-EU manufacturer placing consumer AI on EU market | Yes — directly | Same obligations as EU manufacturer plus responsible person appointment |
| Importer of AI-enabled consumer products | Yes — directly | Verify manufacturer compliance, hold contact details, cooperate with authorities |
| Distributor of AI-enabled consumer products | Yes — directly | Verify product compliance, cooperate with recalls, incident notification |
| Online marketplace facilitating AI product sales | Yes — directly | Traceability, authority cooperation, product removal where safety issues identified |
| Manufacturer of low-risk AI product under EU AI Act | Yes — GPSR applies regardless | Full GPSR obligations — EU AI Act low-risk classification does not exempt from GPSR |
| Developer of AI software update changing safety behaviour | Yes — update triggers re-assessment | Safety re-assessment required before software update deployment |
| Manufacturer of AI-embedded connected device | Yes — CRA and GPSR simultaneously | GPSR safety obligations plus CRA security by design requirements |
| Non-EU company with EU consumer users | Yes — extraterritorial | Full GPSR obligations where consumer products reach EU market |
| B2B-only AI product with no consumer exposure | Likely no | Document this determination — scope depends on whether end users qualify as consumers |
The GPSR obligation AI systems most commonly fail
The GPSR’s application to software updates is the provision creating the most immediate compliance gaps for AI product teams — and the one almost no compliance function has built into its product development process.
AI products whose safety characteristics change after market placement — through model retraining, algorithm updates, or software patches that affect how the system makes decisions — trigger a fresh safety assessment obligation under the GPSR. Three things AI product teams consistently misunderstand:
A software update that changes an AI system’s decision-making logic is not a minor patch. Under the GPSR, any update that affects the safety characteristics of a consumer product requires assessment against the general safety requirement before deployment. An AI product that was compliant at launch may become non-compliant after a model update — and the manufacturer is responsible for ensuring it does not. Most AI development cycles do not include this assessment as a standard gate before update release.
The GPSR applies to low-risk AI products that the EU AI Act does not reach. This is the compliance gap most AI teams have missed entirely. A product classified as minimal risk or limited risk under the EU AI Act — and therefore facing minimal AI Act obligations — is still fully subject to the GPSR as a consumer product. The two regulations address different risks: the AI Act addresses the AI system’s decision-making risk, the GPSR addresses the product’s consumer safety risk. Both can apply simultaneously and independently.
The responsible person obligation for non-EU manufacturers is a market access precondition, not a post-launch administrative step. A non-EU manufacturer that places a consumer AI product on the EU market without an EU-established responsible person in place is in breach of the GPSR from the first sale. The responsible person must be appointed and must hold the technical documentation before the product reaches the EU consumer — the same timing logic as the EU AI Act’s Authorised Representative requirement, under a different regulation, requiring a separate appointment.
What GPSR compliance requires for AI products
These are the GPSR requirements that apply most directly to AI-enabled consumer products and the economic operators that place them on the EU market.
Cross-framework mapping — identification of where GPSR safety obligations interact with EU AI Act technical robustness and post-market monitoring requirements, CRA security-by-design obligations for connected AI products, and the revised Product Liability Directive’s strict liability provisions where a defective AI product causes consumer harm.
Economic operator role determination — confirmation of whether your organisation operates as a manufacturer, importer, distributor, fulfilment service provider, or online marketplace under the GPSR — the role that determines your specific obligations and the starting point for every subsequent compliance step.
Consumer product scope confirmation — assessment of whether your AI product qualifies as a consumer product under the GPSR, whether any sector-specific safety legislation takes precedence, and whether the GPSR applies as the primary safety framework or as a supplementary catch-all alongside sector regulation.
Risk assessment — a structured safety risk assessment covering traditional physical risks, cybersecurity risks, mental health and social wellbeing risks where relevant, and AI-specific risks including algorithmic bias, unexpected decision-making behaviour, and risks to vulnerable user groups — conducted against the GPSR’s holistic assessment standard.
Technical documentation — assessment of your technical documentation against GPSR requirements — product description, risk assessment, conformity evidence, and the information required to support market surveillance authority review — structured for the ten-year retention obligation.
Responsible person determination — confirmation of whether your organisation requires an EU-established responsible person, identification of the appropriate responsible person entity, and verification that the appointment satisfies the GPSR’s formal requirements before market placement.
Software update safety assessment process — assessment of whether your product development process includes a GPSR safety re-assessment gate before AI model updates, algorithm changes, or software patches that affect the product’s safety characteristics are deployed to EU consumers.
Incident reporting and recall readiness — assessment of your incident classification framework and notification process against the GPSR’s immediate notification obligation for serious risks, and your recall readiness for rapid product withdrawal where required.
Living Compliance File™ — audit-ready compliance record structured by economic operator role and product type, formatted so a market surveillance authority, distributor, online marketplace, or enterprise buyer can open it and find what they need.
One engagement. Every GPSR obligation mapped for your AI system.
A lawyer-built GPSR assessment covering economic operator role determination, consumer product scope confirmation, risk assessment requirements, technical documentation obligations, responsible person appointment, software update safety assessment process, incident reporting and recall readiness, and cross-framework mapping against your EU AI Act, CRA, and revised Product Liability Directive position where all apply.
Frequently Asked Questions About GPSR Compliance
What is the GPSR and when did it come into force?
The General Product Safety Regulation — Regulation (EU) 2023/988 — entered into effect on 13 December 2024, replacing the General Product Safety Directive of 2001. It applies directly in all EU member states without national transposition. It is the EU’s updated catch-all product safety framework, expanded to address digital products, AI-enabled consumer goods, connected devices, and online marketplace obligations that the 2001 directive did not anticipate.
Does the GPSR apply to AI products specifically?
Yes. The GPSR applies to all consumer products, including those with AI or digital components. It is specifically designed as a safety net for products that may not be covered by sector-specific legislation — including AI products classified as low-risk or minimal-risk under the EU AI Act. The EU AI Act and the GPSR address different risks and both can apply to the same product simultaneously. A low-risk AI consumer product faces minimal EU AI Act obligations but full GPSR obligations.
Does the GPSR apply to non-EU companies placing products on the EU market?
Yes. The GPSR applies extraterritorially to any manufacturer placing consumer products on the EU market regardless of where the manufacturer is established. Non-EU manufacturers face the same safety, documentation, and incident reporting obligations as EU-established manufacturers — plus the additional requirement to appoint an EU-established responsible person before placing the product on the market. US, UK, Canadian, Indian, and other non-EU manufacturers with EU consumer users are fully in scope.
What is the responsible person requirement under the GPSR?
Where a manufacturer is not established in the EU, it must appoint an EU-established responsible person before placing the product on the EU market. The responsible person holds the technical documentation, verifies GPSR compliance, ensures labelling and instructions are correct, and acts as the point of contact for market surveillance authorities. This is a separate appointment from the EU AI Act’s Authorised Representative — a non-EU manufacturer of a consumer AI product may need both, under separate mandates, satisfying separate regulatory requirements.
How does the GPSR interact with the EU AI Act?
The GPSR and the EU AI Act address different risks and apply independently. The EU AI Act governs the AI system’s decision-making risk — classification, prohibited practices, technical documentation, and human oversight. The GPSR governs the consumer product’s safety — physical risk, cybersecurity risk, and risks to mental health and social wellbeing. Where an AI product is high-risk under the EU AI Act, both regimes apply simultaneously. Where it is low-risk under the EU AI Act, it may still face full GPSR obligations as a consumer product. A cross-framework assessment maps where the two regimes overlap and where they impose distinct requirements.
How does the GPSR apply to software updates for AI products?
Any software update that changes the safety characteristics of a consumer AI product triggers a fresh safety assessment obligation under the GPSR before deployment. For AI products, this includes model retraining, algorithm updates, and software patches that affect how the system makes decisions or interacts with consumers. Most AI development cycles do not include this assessment as a standard pre-deployment gate. A product that was GPSR-compliant at launch may become non-compliant after a model update if the update has not been assessed against the general safety requirement.
What are the penalties for GPSR non-compliance?
Non-compliance with the GPSR carries fines of up to 4% of global annual turnover and mandatory product removal from the EU market. Market surveillance authorities across all EU member states have enforcement powers and can require immediate withdrawal of products presenting serious consumer safety risks.
The GPSR’s notification and recall requirements complement the revised Product Liability Directive — non-compliance with GPSR safety obligations increases exposure to strict liability claims under the PLD where a defective product causes consumer harm.
How does the GPSR interact with the Cyber Resilience Act for connected AI products?
The CRA governs the security of software products connecting to networks or devices — security by design, vulnerability handling, and incident reporting obligations. The GPSR governs the safety of consumer products — including connected devices with AI components. Both apply simultaneously to most consumer AI hardware products.
The CRA’s 24-hour ENISA vulnerability reporting obligation and the GPSR’s immediate incident notification requirement for serious safety risks may both be triggered by the same security incident — different timelines, different authorities, both must be met.
Does the GPSR apply to online platforms selling AI products?
Yes. Online marketplaces facilitating the sale of consumer products bear specific GPSR obligations — traceability requirements for products sold through the platform, cooperation with market surveillance authorities, and removal of non-compliant or unsafe products. AI-powered recommendation systems and marketplace algorithms that facilitate consumer product sales must be assessed against these obligations alongside the platform’s DSA obligations where applicable.
How do I start GPSR compliance for my AI product?
First, confirm that your product qualifies as a consumer product under the GPSR and that no sector-specific safety legislation takes full precedence.
Second, determine your economic operator role — manufacturer, importer, distributor, or marketplace — which determines your specific obligations.
Third, conduct a comprehensive risk assessment covering physical, cybersecurity, and AI-specific consumer safety risks, and compile the technical documentation required to support it.
Fourth, if you are a non-EU manufacturer, appoint an EU-established responsible person before any EU consumer sale. A lawyer-built assessment covers all four steps and delivers a documented compliance position specific to your product — mapped against your EU AI Act, CRA, and revised Product Liability Directive position where all apply.
