Authorized Representative Under the EU AI Act
A factual guide to Article 22 obligations, appointment triggers, and documentation readiness for non-EU AI providers.
At a glance. Under Article 22 of the EU AI Act (Regulation (EU) 2024/1689), providers of high-risk AI systems not established in the EU must appoint, by written mandate, an EU-based Authorized Representative before the system is placed on the EU market. The representative verifies that conformity documentation exists, keeps required records available to market surveillance authorities for ten years, and acts as the authorities' point of contact. Providers of general-purpose AI models face a parallel requirement under Article 54. The role is distinct from the GDPR Article 27 representative and requires its own written mandate and documentation pipeline.
Article 22 at a glance
The Authorized Representative mechanism gives EU market surveillance authorities a reachable counterpart when the provider sits outside the Union. The core elements are fixed in the Act and drive how enterprises structure mandates, evidence packs, and retention.
| Trigger | A non-EU provider places a high-risk AI system on the EU market. |
|---|---|
| Instrument | A written mandate establishing the representative's authority. |
| Retention | Ten years of conformity records available to authorities. |
| Parallel rule | Article 54 applies the same logic to general-purpose AI models. |
What the Authorized Representative role covers
Under Article 22, the Authorized Representative is an EU-based natural or legal person appointed by a non-EU provider of a high-risk AI system. Appointment is by written mandate and must be in place before the system is placed on the EU market.
In practical terms, the role covers three primary duties:
- Verify that the conformity documentation the provider is required to draw up actually exists and is complete enough to support market access.
- Keep the required records available to market surveillance authorities for ten years.
- Serve as the authorities' point of contact for the provider in relation to the system under mandate.
The mandate defines the representative's authority. Enterprises should treat that instrument as an operational control as much as a legal formality: it should name the systems in scope, the documentation the representative will hold or be able to obtain, and how reasoned requests from authorities will be handled within statutory timelines.
When the requirement applies
The Article 22 duty applies when a provider of a high-risk AI system is not established in the European Union and places that system on the EU market. The appointment must precede placing on the market; late designation does not cure a gap at the moment of access.
Providers of general-purpose AI models face a parallel requirement under Article 54. The logic is the same: where the provider is outside the Union, an EU-based representative stands as the formal counterpart for documentation and authority contact, under a written mandate suited to that article's scope.
Documentation readiness before appointment
Before a mandate is signed, compliance teams should confirm that conformity documentation for each in-scope system or model can be produced, versioned, and retained for the ten-year window the representative must support.
Obligations and liabilities the representative carries
The representative's obligations follow from the written mandate and from Article 22. They include confirming that conformity documentation exists, retaining required records for ten years so they remain available to market surveillance authorities, and acting as the point of contact when those authorities make requests.
Enterprises should align internal evidence practices with what the representative must be able to produce. That typically means:
- A clear inventory of systems (or models) covered by each mandate.
- Controlled storage of conformity files, with ownership and retrieval paths the representative can rely on.
- Retention schedules that meet the ten-year availability expectation.
- A process for responding to reasoned requests within the timelines the mandate and applicable law require.
Compliance teams preparing for Article 22 appointments need documentation and evidence practices that can withstand statutory retention and reasoned-request timelines. Gaps in versioning, ownership, or retrieval become the representative's problem only after they have already become the provider's regulatory exposure.
AI Act Article 22 representative vs. GDPR Article 27 representative
The EU AI Act Authorized Representative is distinct from the representative required under GDPR Article 27. Organizations that already have a GDPR representative should not assume that appointment satisfies Article 22 or Article 54.
| Dimension | AI Act Art. 22 / 54 | GDPR Art. 27 |
|---|---|---|
| Legal basis | EU AI Act (Regulation (EU) 2024/1689) | General Data Protection Regulation |
| Primary focus | High-risk AI systems (Art. 22) and general-purpose AI models (Art. 54) | Processing of personal data by controllers or processors not established in the Union |
| Core duties | Verify conformity documentation, retain records for ten years, act as market surveillance contact | Serve as contact point for supervisory authorities and data subjects on GDPR matters |
| Mandate | Own written mandate for AI Act purposes | Separate written mandate for GDPR purposes |
| Documentation pipeline | Conformity and AI Act evidence packs | Records of processing and GDPR compliance materials |
Each regime requires its own written mandate and its own documentation pipeline. Shared vendors or corporate affiliates may perform both roles only where the legal instruments, scopes, and evidence sets are kept separate and complete for each regulation.
Where documentation governance and runtime governance intersect
Article 22 is centered on appointment, documentation, and availability of records. In practice, those static obligations depend on live governance of the systems under mandate. Conformity files only remain trustworthy if design decisions, risk controls, and operating constraints stay aligned with what was declared when the system was placed on the market.
Documentation governance covers the creation, approval, versioning, and retention of the materials the representative must verify and hold available. Runtime governance covers how the system behaves in production relative to those materials. When the two drift, the representative may still hold a file for ten years, but that file no longer describes the system authorities will examine.
Enterprises preparing non-EU high-risk systems (or in-scope general-purpose models under Article 54) for the EU market should therefore treat the Authorized Representative mandate as one control in a wider chain: accurate conformity documentation, a durable evidence store, a written EU mandate, and ongoing operational controls that keep the running system consistent with what the documentation claims.
Align Internal Documentation With Representative Obligations
Compliance teams preparing for Article 22 appointments need documentation and evidence practices that can withstand statutory retention and reasoned-request timelines.
Talk to an Expert