See how Trussed maps to EU AI Act in minutes

    No generic demo, just the controls relevant to your program.

    Book a session
    Compliance Guide

    Authorized Representative Under the EU AI Act

    A factual guide to Article 22 obligations, appointment triggers, and documentation readiness for non-EU AI providers.

    At a glance. Under Article 22 of the EU AI Act (Regulation (EU) 2024/1689), providers of high-risk AI systems not established in the EU must appoint, by written mandate, an EU-based Authorized Representative before the system is placed on the EU market. The representative verifies that conformity documentation exists, keeps required records available to market surveillance authorities for ten years, and acts as the authorities' point of contact. Providers of general-purpose AI models face a parallel requirement under Article 54. The role is distinct from the GDPR Article 27 representative and requires its own written mandate and documentation pipeline.

    Article 22 at a glance

    The Authorized Representative mechanism gives EU market surveillance authorities a reachable counterpart when the provider sits outside the Union. The core elements are fixed in the Act and drive how enterprises structure mandates, evidence packs, and retention.

    Key dimensions of the appointment
    Trigger A non-EU provider places a high-risk AI system on the EU market.
    Instrument A written mandate establishing the representative's authority.
    Retention Ten years of conformity records available to authorities.
    Parallel rule Article 54 applies the same logic to general-purpose AI models.

    What the Authorized Representative role covers

    Under Article 22, the Authorized Representative is an EU-based natural or legal person appointed by a non-EU provider of a high-risk AI system. Appointment is by written mandate and must be in place before the system is placed on the EU market.

    In practical terms, the role covers three primary duties:

    • Verify that the conformity documentation the provider is required to draw up actually exists and is complete enough to support market access.
    • Keep the required records available to market surveillance authorities for ten years.
    • Serve as the authorities' point of contact for the provider in relation to the system under mandate.

    The mandate defines the representative's authority. Enterprises should treat that instrument as an operational control as much as a legal formality: it should name the systems in scope, the documentation the representative will hold or be able to obtain, and how reasoned requests from authorities will be handled within statutory timelines.

    When the requirement applies

    The Article 22 duty applies when a provider of a high-risk AI system is not established in the European Union and places that system on the EU market. The appointment must precede placing on the market; late designation does not cure a gap at the moment of access.

    Providers of general-purpose AI models face a parallel requirement under Article 54. The logic is the same: where the provider is outside the Union, an EU-based representative stands as the formal counterpart for documentation and authority contact, under a written mandate suited to that article's scope.

    Documentation readiness before appointment

    Before a mandate is signed, compliance teams should confirm that conformity documentation for each in-scope system or model can be produced, versioned, and retained for the ten-year window the representative must support.

    Obligations and liabilities the representative carries

    The representative's obligations follow from the written mandate and from Article 22. They include confirming that conformity documentation exists, retaining required records for ten years so they remain available to market surveillance authorities, and acting as the point of contact when those authorities make requests.

    Enterprises should align internal evidence practices with what the representative must be able to produce. That typically means:

    • A clear inventory of systems (or models) covered by each mandate.
    • Controlled storage of conformity files, with ownership and retrieval paths the representative can rely on.
    • Retention schedules that meet the ten-year availability expectation.
    • A process for responding to reasoned requests within the timelines the mandate and applicable law require.

    Compliance teams preparing for Article 22 appointments need documentation and evidence practices that can withstand statutory retention and reasoned-request timelines. Gaps in versioning, ownership, or retrieval become the representative's problem only after they have already become the provider's regulatory exposure.

    AI Act Article 22 representative vs. GDPR Article 27 representative

    The EU AI Act Authorized Representative is distinct from the representative required under GDPR Article 27. Organizations that already have a GDPR representative should not assume that appointment satisfies Article 22 or Article 54.

    Dimension AI Act Art. 22 / 54 GDPR Art. 27
    Legal basis EU AI Act (Regulation (EU) 2024/1689) General Data Protection Regulation
    Primary focus High-risk AI systems (Art. 22) and general-purpose AI models (Art. 54) Processing of personal data by controllers or processors not established in the Union
    Core duties Verify conformity documentation, retain records for ten years, act as market surveillance contact Serve as contact point for supervisory authorities and data subjects on GDPR matters
    Mandate Own written mandate for AI Act purposes Separate written mandate for GDPR purposes
    Documentation pipeline Conformity and AI Act evidence packs Records of processing and GDPR compliance materials

    Each regime requires its own written mandate and its own documentation pipeline. Shared vendors or corporate affiliates may perform both roles only where the legal instruments, scopes, and evidence sets are kept separate and complete for each regulation.

    Where documentation governance and runtime governance intersect

    Article 22 is centered on appointment, documentation, and availability of records. In practice, those static obligations depend on live governance of the systems under mandate. Conformity files only remain trustworthy if design decisions, risk controls, and operating constraints stay aligned with what was declared when the system was placed on the market.

    Documentation governance covers the creation, approval, versioning, and retention of the materials the representative must verify and hold available. Runtime governance covers how the system behaves in production relative to those materials. When the two drift, the representative may still hold a file for ten years, but that file no longer describes the system authorities will examine.

    Enterprises preparing non-EU high-risk systems (or in-scope general-purpose models under Article 54) for the EU market should therefore treat the Authorized Representative mandate as one control in a wider chain: accurate conformity documentation, a durable evidence store, a written EU mandate, and ongoing operational controls that keep the running system consistent with what the documentation claims.

    Align Internal Documentation With Representative Obligations

    Compliance teams preparing for Article 22 appointments need documentation and evidence practices that can withstand statutory retention and reasoned-request timelines.

    Talk to an Expert