COMPLIPATHDOC complipath.io/guides/ai-act-authorised-representativeRENDERED 2026-08-23ENGINE 2026-08-09.1CORPUS 2024/1689 + 2026/1744 + Commission guidelines
Guides/Roles ·By Yobel Tzegai ·Updated 22 August 2026

What are the authorised representative obligations under the EU AI Act?

A provider established outside the EU must appoint an EU-established authorised representative, by written mandate, before making a high-risk AI system available on the Union market (Article 22(1)). The mandate has to empower five named tasks, and the representative must terminate it if the provider stops complying.

Quick answer

Who has to appoint an authorised representative?

Article 22(1), in full: "Prior to making their high-risk AI systems available on the Union market, providers established in third countries shall, by written mandate, appoint an authorised representative which is established in the Union."

Three things decide it. You are the provider — the one that develops the system and places it on the market or puts it into service under its own name or trademark (Article 3, point (3)). You are established in a third country. And the system is high-risk, so the prior question is which of your systems the Act puts in that tier. A third-country provider whose systems are none of those owes nothing under this article.

The duty is the provider's, and Article 22(2) adds one on top of appointing: "The provider shall enable its authorised representative to perform the tasks specified in the mandate received from the provider." A mandate the representative cannot act on does not discharge it.

What must the mandate empower the representative to do?

Article 22(3) lists five tasks, and the word is "shall empower" — the mandate is the instrument, so a task left out of it is a task the representative cannot perform:

Then a closing subparagraph that is easy to read past and changes who the authority talks to: "The mandate shall empower the authorised representative to be addressed, in addition to or instead of the provider, by the competent authorities, on all issues related to ensuring compliance with this Regulation." In addition to or instead of — that is the phrase that moves who answers.

When does the duty bite?

Article 22 sits in Chapter III, Section 3 — the same section as the provider, importer, distributor and deployer obligations. That section was moved by Regulation (EU) 2026/1744: it applies from 2 December 2027 for systems classified as high-risk under Article 6(2) and Annex III, and from 2 August 2028 for Article 6(1) and Annex I systems (Article 113, third paragraph, point (c), as amended). The full timeline is here.

The amending act did not touch Article 22. Its enumeration names no operation on it, so the 2024 wording quoted above is the wording in force.

What happens if the provider stops complying?

Article 22(4) is the provision people miss, and it points the wrong way for anyone treating the role as a mailbox: "The authorised representative shall terminate the mandate if it considers or has reason to consider the provider to be acting contrary to its obligations pursuant to this Regulation. In such a case, it shall immediately inform the relevant market surveillance authority, as well as, where applicable, the relevant notified body, about the termination of the mandate and the reasons therefor."

That is a duty to resign and report, not a discretion. It is why the role is not administrative: the representative has to form a view about the provider's compliance and act on it.

Non-compliance with Article 22 carries administrative fines of up to EUR 15 000 000 or, if the offender is an undertaking, up to 3 % of total worldwide annual turnover for the preceding financial year, whichever is higher (Article 99(4), point (b)) — with one change since 2026: for small mid-cap enterprises the same fines are capped the other way: each fine "shall be up to the percentages or amount referred therein, whichever is lower" (Article 99(6a), inserted by Regulation (EU) 2026/1744). What the tiers cost is set out here.

Is a general-purpose AI model different?

Yes, and it is a different article with a different addressee. Article 54 requires a third-country provider of a general-purpose AI model to appoint an EU authorised representative before placing the model on the Union market. Four differences matter:

Article 54 sits in Chapter V, which is not deferred: it has applied since 2 August 2025 (Article 113, third paragraph, point (b)). So a third-country GPAI provider's representative duty is live now, while a third-country high-risk provider's is not. The GPAI regime is covered here.

What this means for you

(Split by the two parties a mandate has — the third-country provider, and the EU company being asked to act.)

If you are the provider, established outside the Union: the mandate is a document rather than an intention, and it must name the five tasks. Before you can write it you need the two things point (a) makes the representative verify — the EU declaration of conformity and the Article 11 technical documentation — so the mandate is downstream of the conformity work, not a substitute for it. Classify the systems first: the duty attaches per high-risk system, not per company.

If you are the EU company being asked to act as representative: read Article 22(4) before you sign. You take on a ten-year retention duty, a duty to answer authorities directly, and a duty to terminate and report if you come to think the provider is not complying — and Article 99(4), point (b) fines the representative's obligations, not only the provider's. Complipath keeps every system's classification, the obligations that follow and the evidence behind them in one register with a named owner, which is the file Article 22(3), point (c) assumes you can produce on request.

Which of the systems you built outside the Union reach it?

Classify your system now — 7 questions on the main line, plus follow-ups where they apply, no account, and the classification runs in your browser: answers stay there unless you choose to keep the result.

FAQ

Does an EU company selling a US vendor's AI tool need to be its authorised representative? No — those are different roles. Reselling a third-country system under the vendor's brand makes you the importer (Article 3, point (6)) — and Article 23(1), point (d) makes you verify the provider appointed a representative. The importer and distributor duties are here.

Can the authorised representative be the same company as the importer? The Regulation does not forbid it, and it does not address the combination. What it does fix is that both sets of duties attach in full: Article 22 for the representative, Article 23 for the importer, each fined separately under Article 99(4), points (b) and (c).

Is the mandate needed before the system reaches the Union, or before it is sold? Before it is made available: Article 22(1) says "prior to making their high-risk AI systems available on the Union market". "Making available" is any supply for distribution or use in the course of a commercial activity, paid or free (Article 3, point (10)).

What does the representative have to keep, and for how long? Ten years after the system was placed on the market or put into service: the provider's contact details, a copy of the EU declaration of conformity, the technical documentation and the notified-body certificate where there is one (Article 22(3), point (b)).


Sources: Regulation (EU) 2024/1689 (EUR-Lex), Articles 3, 11, 12, 22, 23, 47, 49, 54, 74, 99 and 113, and Annexes VIII and XI, as amended by Regulation (EU) 2026/1744 (EUR-Lex), Article 1, points (38)(c) and (40). Article 22 and Article 54 were not amended: the act's enumeration names no operation on either, so the 2024 wording is the wording in force. What the Regulation does not settle, and this guide will not invent: whether one company may hold mandates for several third-country providers, what a representative must do between forming a suspicion under Article 22(4) and terminating, and whether Article 99(4) reaches an Article 54 representative — that paragraph lists Article 22 and does not list Article 54.

← All guides
Complipath

Complipath is EU AI Act compliance software for AI-heavy software companies without a compliance team — an AI system register, deterministic risk classification, the obligations that follow, and the evidence behind every decision.

Complipath is built by Yobel Tzegai in Gothenburg, Sweden.

Complipath provides legal information, not legal advice. Every guide cites its source on EUR-Lex — Regulation (EU) 2024/1689, and Regulation (EU) 2026/1744 where that has amended it; where the law is still settling, the guide says so.

We measure page views with Vercel Web Analytics. It uses no third-party cookies. Visitors are identified by a hash derived from the incoming request, which is discarded after 24 hours, and no identifier is stored that could follow a visitor to another site. What is collected: the time of the visit, the URL, the referring page, filtered query parameters, city-level location, operating system, browser and device type.