The EU AI Act's Authorised Representative Requirement for Non-EU Providers
9 min read · updated August 11, 2026
A non-EU provider of a high-risk AI system cannot simply nominate a European contact. Article 22 requires a written mandate with a defined minimum content, and the representative it appoints acquires duties of its own, including a duty to terminate the mandate and tell a regulator why.
When the obligation is triggered
Article 22(1) of Regulation (EU) 2024/1689 provides that, prior to making their high-risk AI systems available on the Union market, providers established in third countries shall, by written mandate, appoint an authorised representative established in the Union; the provision is at EUR-Lex. The trigger is making available on the Union market, and it is prior to, not concurrent with. Appointing a representative is a step before launch, not a step in the launch.
Whether you are a third-country provider making a high-risk system available in the Union is a question answered by Article 2, and it reaches further than establishment. The Regulation applies to providers placing systems on the market or putting them into service in the Union irrespective of where they are established, and also to providers and deployers established outside the Union where the output produced by the AI system is used in the Union. That output limb is the one that catches companies who believed they had no European exposure. See the extraterritorial scope page for the analysis; this page assumes you have already concluded you are in scope.
The obligations for Annex III high-risk systems apply from 2 August 2026 under Article 113, and those on the Article 6(1) product route from 2 August 2027. The representative has to be in place before the system is made available, which for a system already on the Union market on the applicable date means before that date, not after it.
What the mandate must empower
Article 22(3) is the operative provision, and it is written as a minimum: the mandate must empower the representative to carry out the following tasks, and the representative performs the tasks specified in the mandate it receives. It must provide a copy of the mandate to market surveillance authorities on request, in an official language of the Union institutions indicated by the authority.
- Verify the paperwork exists. Verify that the EU declaration of conformity under Article 47 and the technical documentation under Article 11 have been drawn up, and that an appropriate conformity assessment procedure has been carried out by the provider. This is a verification duty on the representative, not a recital: a representative that never looked has not performed its mandate.
- Keep the file for ten years. Keep at the disposal of competent authorities and the national authorities or bodies referred to in Article 74(10), for ten years after the system has been placed on the market or put into service, the contact details of the appointing provider, a copy of the EU declaration of conformity, the technical documentation and, where applicable, the certificate issued by the notified body.
- Answer reasoned requests. Provide a competent authority, on a reasoned request, with all the information and documentation necessary to demonstrate conformity with the Chapter III Section 2 requirements — including access to the logs automatically generated by the system under Article 12(1), to the extent those logs are under the provider’s control. That last clause requires the representative to have a route to the provider’s generated logs, which is a technical arrangement, not a contractual formula.
- Cooperate on risk. Cooperate with competent authorities, on a reasoned request, in any action they take in relation to the high-risk system, in particular to reduce and mitigate the risks it poses.
- Handle registration. Where applicable, comply with the registration obligations in Article 49(1), or, where the provider registers the system itself, ensure that the information in Annex VIII Section A point 3 is correct.
Article 22(3) closes by requiring the mandate to empower the representative to be addressed, in addition to or instead of the provider, by the competent authorities on all issues relating to compliance with the Regulation. That is the sentence that makes the role substantive rather than a mailbox. An authority may address the representative instead of the provider, and the representative must be in a position to respond. Article 22(2) requires the provider to enable its representative to perform the tasks in the mandate, which means access, documents and cooperation as a matter of obligation rather than of goodwill.
The duty to walk away
Article 22(4) is the provision that makes this a role a firm should think hard before accepting. Where the representative considers, or has reason to consider, that the provider is acting contrary to its obligations under the Regulation, it must terminate the mandate; and having done so, it must immediately inform the relevant market surveillance authority and, where applicable, the relevant notified body, of the termination and the reasons for it.
The threshold is “has reason to consider”, not “knows”. The consequence is not merely resignation but notified resignation, with reasons, to the regulator. In substance, Article 22(4) turns the representative into a party with an obligation adverse to its own client, and no contractual term between provider and representative can displace it. Any provider planning to appoint an affiliate or a small local service firm as its representative should read this paragraph before the commercial terms, and any firm offering the service commercially should price it accordingly.
Article 54: a second, different representative
Article 22 is about high-risk AI systems. Providers of general-purpose AI models have their own, separate provision in Article 54, and a company doing both needs both. Article 54(1) requires third-country providers, prior to placing a general-purpose AI model on the Union market, to appoint by written mandate an authorised representative established in the Union. The task list is parallel but keyed to Chapter V rather than to Chapter III: verify that the technical documentation specified in Annex XI has been drawn up and that all obligations under Article 53, and where applicable Article 55, have been fulfilled; keep a copy of the Annex XI documentation at the disposal of the AI Office and national competent authorities for ten years after the model was placed on the market, along with the provider’s contact details; provide the AI Office on reasoned request with all information and documentation necessary to demonstrate compliance; and cooperate with the AI Office and competent authorities in any action they take.
Two differences from Article 22 matter for planning. The dates: Chapter V, including Article 54, has applied since 2 August 2025, a year ahead of the Annex III high-risk obligations. And there is an exemption: Article 54 does not apply to providers of general-purpose AI models released under a free and open-source licence allowing access, use, modification and distribution, where the parameters including weights, information on model architecture and information on model usage are made publicly available — unless the model presents systemic risk. That mirrors the wider open-source exemption and, like it, falls away entirely once the systemic risk threshold is met.
What this role is not
Three adjacent roles are routinely conflated with this one, and the conflation causes real problems in contracts.
It is not the GDPR Article 27 representative. That role exists for controllers and processors without a Union establishment that process Union residents’ personal data, its task is to be a point of contact for supervisory authorities and data subjects and to maintain the record of processing, and it has no verification duty and no termination-with-reasons duty. The same firm can hold both mandates but they are separate appointments under separate instruments with different content, and one appointment letter cannot do both jobs without saying so explicitly.
It is not an importer. Article 23 places its own obligations on importers — including verifying that the conformity assessment was carried out, that the technical documentation exists, that the CE marking and declaration of conformity are present, and that the provider has appointed an authorised representative. An importer that finds no representative has been appointed has, by that fact, found a system it should not place on the market. See importer and distributor obligations.
And it is not a way to become the provider, nor a way to stop being one. The provider remains the provider with the full Article 16 obligation set; the representative holds a defined mandate on top. The route by which somebody else does become the provider is Article 25, and it runs through branding and substantial modification, not through representation.