COMPLIPATHDOC complipath.io/guides/ai-act-importer-distributorRENDERED 2026-08-23ENGINE 2026-08-09.1CORPUS 2024/1689 + 2026/1744 + Commission guidelines
Guides/Roles ·By Yobel Tzegai ·Updated 13 August 2026

What are the importer and distributor obligations under the EU AI Act?

Updated 9 August 2026 for Regulation (EU) 2026/1744.

An importer is an EU-established company placing on the market an AI system that bears a third-country company's name or trademark (Article 3, point (6)). A distributor is anyone else in the supply chain making the system available (Article 3, point (7)). Both must verify a high-risk system's paperwork before letting it circulate — duties that apply from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems (Article 113, third paragraph, point (c), as amended by Regulation (EU) 2026/1744).

Quick answer

Who counts as an importer?

Article 3, point (6): an importer is "a natural or legal person located or established in the Union that places on the market an AI system that bears the name or trademark of a natural or legal person established in a third country."

The plain-language test has three parts: you are in the EU, you are the one first putting the system on the Union market ("placing on the market" is "the first making available", Article 3, point (9)), and the system carries someone else's third-country brand. An EU SaaS company that resells a US vendor's AI tool to EU customers under the vendor's brand is an importer, whether or not anyone calls it that.

Carrying your name instead makes you the provider — directly under Article 3, point (3), or through the re-badging trigger in Article 25(1), point (a).

Who counts as a distributor?

Article 3, point (7): a distributor is "a natural or legal person in the supply chain, other than the provider or the importer, that makes an AI system available on the Union market." "Making available" means supply "for distribution or use on the Union market in the course of a commercial activity, whether in return for payment or free of charge" (Article 3, point (10)).

Distributor is the residual supply-chain role: everyone downstream who passes the system on commercially. An EU reseller buying from an EU importer, or an integrator bundling a vendor's AI module into client installations — both distributors. Free supply counts.

What must an importer verify before placing a high-risk system on the market?

Article 23(1): before placing a high-risk AI system on the market, importers "shall ensure that the system is in conformity with this Regulation by verifying that":

Article 23(2) is the stop duty: an importer with "sufficient reason to consider" that the system is not in conformity, "or is falsified, or accompanied by falsified documentation", must not place it on the market until it has been brought into conformity. Where the system presents a risk within the meaning of Article 79(1) — to health, safety or fundamental rights — the importer must inform the provider, the authorised representative and the market surveillance authorities.

What are the importer's ongoing duties?

Five more paragraphs follow:

What must a distributor verify — and do afterwards?

The distributor's checklist is shorter — two parties upstream already checked. Article 24(1): before making a high-risk AI system available, verify that it bears the required CE marking, that it is accompanied by a copy of the EU declaration of conformity referred to in Article 47 and instructions for use, and that the provider and the importer, as applicable, have complied with Article 16, points (b) and (c) — the provider's own name-and-address labelling and quality management system — and Article 23(3), the importer's labelling.

The rest mirrors the importer's duties with one addition:

Neither role owes a conformity assessment, its own technical documentation, or registration — those belong to the provider, as long as you stay in your lane.

When does an importer or distributor become the provider?

Article 25(1) names both roles: a "distributor, importer, deployer or other third-party" becomes the provider of a high-risk AI system — with the full Article 16 obligations — through three triggers, all concerning systems already placed on the market or put into service: putting its name or trademark on a high-risk system (with the contractual caveat in point (a)), making a substantial modification such that it remains high-risk pursuant to Article 6, or modifying the intended purpose of a non-high-risk system so that it becomes high-risk in accordance with Article 6. White-labelling a third-country AI tool is the classic trap: the moment your brand goes on it, you are no longer an importer with a checklist but a provider with a conformity assessment. The mechanics are in when a deployer becomes a provider; they apply to importers and distributors identically.

What this means for you

(Split by importer and distributor — the two roles this guide covers.)

If you're an importer: These duties apply from 2 December 2027 for Annex III systems — see the high-risk deadline guide. Collect the four Article 23(1) items from your third-country vendor as documents, not assurances. Then set up the 10-year retention under Article 23(5) and put your own name and address on what ships. Whether the tools you resell are high-risk at all is the prior question — classify them first.

If you're a distributor: Your Article 24(1) verification is narrower but personal — "on the basis of the information in its possession" cuts both ways: a reseller who never asked for the declaration of conformity has a thin file when an authority asks under Article 24(5). Record what you checked, when, and for which system version. Complipath keeps every system's classification, obligations and evidence in one register with a named owner — the record Articles 23(6) and 24(5) assume you have.

Is the system you're placing on the market high-risk?

Classify your system now — 7 questions on the main line, plus follow-ups where they apply, no account, and the classification runs in your browser: answers stay there unless you choose to keep the result.

FAQ

We resell a US vendor's AI tool in the EU. Which role are we? If you are the first to place it on the Union market under the vendor's brand, you are the importer (Article 3, point (6)). If an EU importer already placed it and you sell downstream, you are a distributor (Article 3, point (7)). Rebrand it as yours, and Article 25(1), point (a) makes you the provider.

Do these duties apply to AI systems that are not high-risk? No. Articles 23 and 24 attach to high-risk AI systems only. But the definitions in Article 3, points (6) and (7) cover AI systems generally, and Article 2(1), point (d) puts "importers and distributors of AI systems" in scope — so classify each system before assuming the checklist is empty.

Can we rely on the vendor's word that the paperwork exists? Article 23(1) says importers verify — the conformity assessment, the technical documentation, the CE marking with declaration and instructions, the authorised representative. A contractual assurance is not verification. Distributors verify a narrower list under Article 24(1), but "has reason to consider" in Article 24(2) still presumes you looked.

When do Articles 23 and 24 apply? Not yet. Both sit in Chapter III, Section 3, which applies from 2 December 2027 for Annex III systems and from 2 August 2028 for Annex I systems (Article 113, third paragraph, point (c), as amended by Regulation (EU) 2026/1744). Chapter III Section 4, the notified-body section, has applied since 2 August 2025. See the full timeline.


Sources: Regulation (EU) 2024/1689 (EUR-Lex), Articles 2, 3, 16, 22, 23, 24, 25, 79 and 113, as amended by Regulation (EU) 2026/1744 (EUR-Lex), which replaced Article 113, third paragraph, point (c) and amended Article 25. Article 79(1) defines "presenting a risk" by reference to Regulation (EU) 2019/1020; how market surveillance authorities will apply the falsified-documentation limb of Article 23(2) in practice has no track record yet — no enforcement decisions existed at the time of writing.

← All guides
Complipath

Complipath is EU AI Act compliance software for AI-heavy software companies without a compliance team — an AI system register, deterministic risk classification, the obligations that follow, and the evidence behind every decision.

Complipath is built by Yobel Tzegai in Gothenburg, Sweden.

Complipath provides legal information, not legal advice. Every guide cites its source on EUR-Lex — Regulation (EU) 2024/1689, and Regulation (EU) 2026/1744 where that has amended it; where the law is still settling, the guide says so.

We measure page views with Vercel Web Analytics. It uses no third-party cookies. Visitors are identified by a hash derived from the incoming request, which is discarded after 24 hours, and no identifier is stored that could follow a visitor to another site. What is collected: the time of the visit, the URL, the referring page, filtered query parameters, city-level location, operating system, browser and device type.