Article 22 EU AI Act: The Plain-English Guide to Authorised Representatives for Non-EU Providers

If your company builds high-risk AI outside the EU and wants to place it on the EU market, there is one obligation that must be in place before anything else: you need an EU-based authorised representative, appointed in writing, before your system goes live. That is the core rule of Article 22 of the EU AI Act (Regulation (EU) 2024/1689), and it applies to every non-EU (third-country) provider of a high-risk AI system - regardless of size, sector, or country of origin.
This guide explains what Article 22 requires, what the mandate must cover, how the representative differs from an importer or distributor, and what the revised compliance timeline means for your planning.
Who Does Article 22 Apply To?
The rule is straightforward in scope. Prior to making their high-risk AI systems available on the Union market, providers established in third countries shall, by written mandate, appoint an authorised representative which is established in the Union. That covers any company - US, UK, Canadian, Indian, or anywhere else - that builds a system falling under the AI Act's high-risk categories (Annex I or Annex III) and intends to sell or deploy it in the EU.
The AI Act defines an authorised representative precisely. An "authorised representative" is a natural or legal person located or established in the Union who has received and accepted a written mandate from a provider of an AI system established in a third country to perform and carry out on its behalf the obligations and procedures established by the Regulation. In plain terms: a person or company inside the EU who formally agrees, in writing, to act as your compliance point of contact with EU authorities.
The appointment must happen prior to making the system available on the EU market — not after launch, not concurrently. If you go live without a mandated representative in place, you are already non-compliant.
What the Mandate Must Empower the Representative to Do
The written mandate is not a formality. Article 22 specifies exactly what the representative must be empowered to carry out. The provider must enable the representative to perform these tasks - meaning you cannot appoint someone and then deny them access to the documents and information they need.
(a) Verify that conformity documentation has been drawn up
The representative must be able to verify that the EU declaration of conformity (Article 47) and the technical documentation (Article 11) have been drawn up, and that an appropriate conformity assessment procedure has been carried out by the provider. This is a verification role, not a drafting role - the provider remains responsible for producing the documentation. But the representative needs genuine access to confirm it exists and is complete.
(b) Keep records available for 10 years
The representative must keep at the disposal of competent authorities, for a period of 10 years after the high-risk AI system has been placed on the market or put into service: the contact details of the provider, a copy of the EU declaration of conformity, the technical documentation, and, if applicable, the certificate issued by the notified body. This is a long-term custodial obligation. The representative needs a reliable, accessible document repository - not a shared folder that might disappear when staff turn over.
(c) Provide information and documentation to authorities on request
Upon a reasoned request from a competent authority, the representative must provide all information and documentation necessary to demonstrate conformity - including access to the logs automatically generated by the high-risk AI system, to the extent those logs are under the provider's control. This means the provider must give the representative a clear path to retrieve logs when needed, not just promise to do so later.
(d) Cooperate with competent authorities on corrective actions
The representative must cooperate with competent authorities on any action taken in relation to the high-risk AI system - including corrective actions, recalls, or investigations. This is an active duty, not a passive one.
(e) Handle or verify registration obligations
Where applicable, the representative must comply with the registration obligations under Article 49(1), or - if the provider registers directly - verify that the information submitted in the EU database is correct.
Mandate scope matters. The mandate must cover all five tasks above. A narrowly drafted mandate that only covers document-keeping, for example, will not satisfy Article 22. Have legal counsel review the mandate text against the full list in Article 22(3) before signing.
The Representative's Liability Exposure
This is the part that surprises many non-EU providers. The mandate shall empower the authorised representative to be addressed, in addition to or instead of the provider, by the competent authorities, on all issues related to ensuring compliance with the Regulation. "In addition to or instead of" is significant: the representative becomes a legal target for EU enforcement authorities, not just a mailbox.
That means a competent authority can come directly to your representative with requests, investigations, or enforcement actions - without needing to reach you in a third country first. The representative shares legal exposure. This is why any serious representative will conduct due diligence on your compliance posture before accepting the mandate, and why you should expect them to ask hard questions about your technical documentation, conformity assessment, and quality management system.
The representative's liability does not replace yours. Your obligations as provider under Articles 8-21 remain fully intact. The representative is an additional point of accountability within EU jurisdiction, not a shield.
The Termination Right - and Why It Matters
Article 22(4) gives the representative a meaningful exit right, with teeth. The authorised representative shall terminate the mandate if it considers or has reason to consider the provider to be acting contrary to its obligations under the Regulation, and shall immediately inform the relevant market surveillance authority - and, where applicable, the relevant notified body - about the termination and the reasons therefor.
This is not a quiet resignation. The representative must notify the regulator and explain why. For the provider, this means:
- A terminated mandate leaves you without an EU representative - and therefore unable to legally continue making your system available on the EU market.
- The notification to the market surveillance authority will trigger scrutiny of your system.
- Finding and onboarding a replacement representative takes time, during which you may need to suspend EU market access.
The termination right is also why a well-run representative will monitor your ongoing compliance, not just file documents. They have skin in the game.
How the Authorised Representative Differs from the Importer and Distributor
These three roles are often confused. They are legally distinct.
| Role | Who they are | Core function | Appointed by | Legal basis |
|---|---|---|---|---|
| Authorised Representative (Art. 22) | EU-based person/entity mandated by the non-EU provider | Compliance point of contact with EU authorities; holds documentation; cooperates on enforcement | Non-EU provider (written mandate) | Article 22 |
| Importer (Art. 23) | EU-based entity that places the system on the EU market under the non-EU provider's name/trademark | Verifies conformity before placing on market; keeps records; informs authorities of risks | Not appointed — role attaches to whoever performs the act of placing on market | Article 23 |
| Distributor (Art. 24) | Any supply-chain entity (other than provider or importer) that makes the system available in the EU | Verifies CE marking, declaration of conformity, and that provider/importer have met their obligations before further distribution | Not appointed — role attaches to the supply-chain position | Article 24 |
A key practical point: the authorised representative is not the importer or the distributor - it is a separate role that the provider designates, and the importer must verify that an authorised representative has been appointed before placing the system on the market. One entity can hold multiple roles (for example, an EU subsidiary could be both importer and authorised representative), but the contractual arrangements must be clear, and the obligations of each role remain separate.
Importers, under Article 23, must check - before placing the system on the market - that the provider has appointed an authorised representative in accordance with Article 22(1). So the representative appointment is a prerequisite that the importer will look for.
The GPAI Parallel: Article 54
If your company provides a general-purpose AI (GPAI) model - rather than (or in addition to) a high-risk system - a parallel obligation applies. Article 54 of the AI Act requires providers of GPAI models established in third countries to appoint an authorised representative in the EU, with responsibilities including verifying technical documentation, providing information to demonstrate compliance, and cooperating with authorities on actions related to the GPAI model. The underlying principle is the same: ensuring accountability within EU jurisdiction regardless of where the model originates. A single EU entity can hold both an Article 22 and an Article 54 mandate, but the two mandates and their duty sets are legally separate.
The Revised Timeline: What the Digital Omnibus Changes
The original AI Act set 2 August 2026 as the date from which high-risk AI obligations - including the Article 22 representative requirement - would apply to Annex III stand-alone systems. That date has now moved.
On 29 June 2026, the Council of the EU gave final approval to the "Digital Omnibus" simplification package, formally pushing back the compliance deadline for stand-alone high-risk AI systems under Annex III from 2 August 2026 to 2 December 2027 - a 16-month extension. High-risk AI systems embedded in regulated products under Annex I receive a parallel 12-month extension, moving their deadline from 2 August 2027 to 2 August 2028.
The legislative act was published in the EU's Official Journal shortly after the Council's 29 June adoption and entered into force three days after publication.
What this means in practice:
| System type | Previous deadline | New deadline |
|---|---|---|
| Stand-alone Annex III (e.g. recruitment, credit scoring, law enforcement AI) | 2 August 2026 | 2 December 2027 |
| Annex I product-embedded (e.g. medical devices, machinery) | 2 August 2027 | 2 August 2028 |
| Article 50 transparency obligations | 2 August 2026 | Unchanged - 2 August 2026 |
The extra runway is real. But it does not mean you should wait. Finding a competent representative, negotiating the mandate, building the document repository, and completing your conformity assessment all take months. The delay reflects standards-readiness gaps at the EU level, not a reduction in the Act's substantive requirements.
2 August 2026 is still a live date. Article 50 transparency obligations — including disclosure when users interact with AI systems and labelling of AI-generated content — apply from 2 August 2026 and were not moved by the Digital Omnibus. If your system has a user-facing component, those duties apply now.
Practical Guidance for Non-EU Providers
Choose a representative with genuine AI Act competence
The representative will be your legal face to EU regulators. A law firm, compliance consultancy, or specialist EU representative service that understands the AI Act's technical documentation requirements, conformity assessment procedures, and market surveillance framework is worth the investment. A nominee director service that handles paperwork but cannot engage substantively with a regulator is not adequate.
Get the mandate scope right
The mandate must cover all five tasks in Article 22(3). It must be in writing. The representative must be able to provide a copy to market surveillance authorities on request, in one of the official languages of the EU institutions. Work with legal counsel in both your jurisdiction and the EU to draft it correctly.
Build an accessible document repository
The representative needs to be able to produce your declaration of conformity, technical documentation, and notified body certificate (if applicable) within a reasonable timeframe when a competent authority asks. That means a shared, version-controlled repository - not a promise to email files when needed. The 10-year retention clock starts from the date the system is placed on the market or put into service.
Give the representative access to logs
Article 22(3)(c) requires the representative to provide access to automatically generated logs to the extent they are under the provider's control. Build a clear process for log retrieval and transfer before the mandate goes live.
Remember: the representative is not a shield
Your obligations as provider under Articles 8-21 - risk management system, technical documentation, data governance, human oversight, post-market monitoring, incident reporting - remain entirely yours. The representative is an additional accountability layer within the EU, not a substitute for your own compliance programme.
Pre-Appointment Checklist for Non-EU Providers
Ready to Appoint? Talk to Our Team First.
Appointing an EU AI Act authorised representative is a legal and operational commitment - for both you and the representative. Getting the mandate scope right, building the document infrastructure, and choosing a representative with genuine regulatory competence all take careful preparation.
Frequently Asked Questions
Does every non-EU AI provider need an authorised representative?
Only providers of high-risk AI systems (Annex I or Annex III) that want to make their system available on the EU market. If your system is not high-risk under the AI Act's classification rules, Article 22 does not apply — though other obligations (such as Article 50 transparency duties) may still apply.
Can our EU subsidiary act as our authorised representative?
Yes, in principle. An EU subsidiary can hold the Article 22 mandate. However, the mandate must be properly documented, the subsidiary must be genuinely empowered to perform all five tasks, and the arrangement must be structured so the subsidiary is not also acting as the importer (which carries separate obligations). Get legal advice on the structure before proceeding.
What happens if we go live on the EU market without an authorised representative?
You are non-compliant from day one. Importers are required to verify that an authorised representative has been appointed before placing your system on the market — so the absence of a representative can block your supply chain. Market surveillance authorities can also take enforcement action directly.
Does the Digital Omnibus delay mean we can wait until late 2027 to appoint a representative?
Technically, the obligation for Annex III stand-alone systems now applies from 2 December 2027. But finding a competent representative, negotiating the mandate, and building the document infrastructure takes months. Starting in 2027 leaves very little margin. Most compliance advisers recommend beginning the process at least 12 months before the applicable deadline.
What is the difference between the Article 22 representative and the Article 54 representative for GPAI models?
They are parallel obligations for different product types. Article 22 applies to providers of high-risk AI systems; Article 54 applies to providers of general-purpose AI (GPAI) models. A single EU entity can hold both mandates, but the two mandates are legally separate and carry different task sets.
Can the representative terminate the mandate without notice?
Article 22(4) requires the representative to terminate if it considers the provider is acting contrary to its obligations — and to immediately notify the relevant market surveillance authority and (where applicable) the notified body, giving reasons. The termination right exists to protect the representative from being complicit in a non-compliant provider's conduct. It is not a casual exit clause.
This post is for informational purposes only and does not constitute legal advice. Consult qualified legal counsel for advice specific to your organisation's situation. Article 22 text is drawn from the official version of Regulation (EU) 2024/1689 of 13 June 2024, as available via artificialintelligenceact.eu/article/22 and the EU AI Act Service Desk. Timeline information reflects the Digital Omnibus formally adopted by the Council of the EU on 29 June 2026.
Related reading

Harmonised Standards and Presumption of Conformity Under the EU AI Act: A Plain-English Guide to Articles 40 and 41
What "presumption of conformity" actually buys you under Articles 40 and 41, why the CEN-CENELEC standards are delayed, and what high-risk AI providers must do right now.

EU AI Act Article 9: A Plain-English Guide to the Risk Management System for High-Risk AI
Article 9 of the EU AI Act requires a continuous, lifecycle-wide risk management system for every high-risk AI system. Here's exactly what that means and how to build one.

Article 11 and Annex IV EU AI Act: Your Plain-English Guide to Technical Documentation for High-Risk AI
Every provider of a high-risk AI system must build a technical file before market launch. This plain-English guide walks through Article 11, all nine Annex IV sections, the Digital Omnibus deadline changes, and practical steps to start now.