EUMandat by TAC Digital
01 — EU AUTHORISED REPRESENTATIVE / CONNECTED & AI DEVICES

Your connected product is entering Europe.
Five laws are waiting for it.

RED cybersecurity, the AI Act, the Cyber Resilience Act, GDPR and the new Toy Regulation: five separate deadlines, one liability — yours. We build the complete file, and we hold it at the disposal of the authorities in your name.

See where your product stands Reply within 48 h · 15 minutes on the phone
02 — THE STAIRCASE OF DEADLINES

It isn't a wall. It's a staircase, and every step has a date.

Two steps are already behind us. The next one is close.

1 Aug 2025
RED cybersecurity — Art. 3.3 d/e/f, EN 18031
Anything with Wi-Fi or Bluetooth: children's watches, baby monitors, connected toys, speakers.
IN FORCE
2 Aug 2026
AI Act — Article 50
A product that talks must say it is an AI. Emotion recognition triggers a duty to inform.
IN FORCE
11 Dec 2027
Cyber Resilience Act — full application
Essential requirements, technical documentation, SBOM, security support, cyber CE marking. Fines up to €15M or 2.5% of worldwide turnover.
AHEAD
2 Aug 2028
High-risk AI — third-party assessed toys
Postponed by the digital omnibus, Regulation (EU) 2026/1744.
AHEAD
1 Aug 2030
New Toy Regulation — (EU) 2025/2509
Digital hazards, privacy, digital product passport.
AHEAD
03 — LIABILITY

The factory is not liable.
You are.

If your brand is on the product, you are the manufacturer under EU law — even when the device ships from a factory in Shenzhen and the model runs on an Asian cloud.

The market surveillance authority calls you. Amazon or your distributor chases you. And your company carries the fine.

CRA — ANNEX III, CLASS I

An internet-connected toy that talks, films or locates a child is class I. Self-assessment is only possible where harmonised standards cover the whole product. Otherwise a third party assesses it.

THE AUTHORISED REPRESENTATIVE — CRA ART. 18 · RED ART. 11 · REG. 2019/1020 ART. 4

Every text provides for one role: the authorised representative established in the Union, appointed by written mandate, who keeps the declaration and the technical file at the disposal of the authorities for ten years and answers them. Its name goes on the product. That is the role we hold — with the file we built.

04 — THE GAP

What your factory certificates don't cover.

Factories supply EN 71, EN 62115, CE, RoHS, REACH, sometimes ASTM. Those documents cover the toy and its materials: mechanical safety, chemistry, flammability.

EN 71 · EN 62115 · CE · RoHS · REACHSUPPLIED
RED cybersecurity — EN 18031NOT COVERED
AI Act — Article 50NOT COVERED
Cyber Resilience ActNOT COVERED
GDPR — children's dataNOT COVERED

The gap is invisible when you place the order. It shows up the day a distributor, a marketplace or an authority asks for the Declaration of Conformity.

05 — WHAT WE DO

Three tiers, in the order you need them.

TIER 01

Diagnostic

Where your product stands, law by law.

DONE WHEN

You have a written list of what's missing, sorted by deadline, with what each gap costs if left untreated.

TIER 02

Compliance file

The complete technical file: product and firmware analysis, factory documentation read including in Chinese, EN 18031 assessment, AI Act transparency, children's data, CRA readiness, EU Declaration of Conformity.

DONE WHEN

The file is complete and holds up — ready for a request from Amazon, a distributor or an authority.

WHAT WE DON'T DO

Laboratory testing. We scope it, order it from a notified body, and fold the results into the file.

TIER 03

Mandate and monitoring

We become your EU authorised representative: your file kept at the disposal of the authorities for ten years, our name on your product, and CRA monitoring — from September 2026, an actively exploited vulnerability must be reported within 24 hours.

ONGOING

Surveillance of your product's components, a reporting procedure ready before you need it, answers to the authorities in your name, and a file kept current as your product and the texts evolve.

06 — WHO IT'S FOR
European brandslaunching a connected or AI device without an in-house compliance team.
Importers and sellerscarrying EU liability for a product designed elsewhere.
Manufacturers outside the EUwho must appoint a representative established in Europe, and want that representative to have built the file it holds.
07 — WHO

Jérémy Tripoli — TAC Digital

I build product compliance files for European sellers: general product safety, extended producer responsibility, marketplace account compliance. I read factory technical documentation in Chinese.

Not a law firm, not a test lab. The person who assembles the file, makes both ends of the chain talk to each other — the factory and the European text — and hands you a document that holds up under a request. Then holds it in your name, as your authorised representative.

08 — LET'S TALK

One question to start: who built your RED cybersecurity file after August 2025?

If the answer is "nobody" or "I don't know", let's spend fifteen minutes on it.