Providers outside the EU that put a high-risk AI system on the Union market must appoint an authorised representative established in the EU under Article 22 of the EU AI Act. Engage Compliance takes that role from its EU establishment. The date it bites has moved, and most vendor pages still have it wrong.
The short answer: if you are established in a third country and you make a high-risk AI system available on the Union market, Article 22(1) requires you to appoint an authorised representative established in the EU, by written mandate, before the system goes on the market. Engage Compliance provides that role directly from its EU establishment, holds the documents the law puts in the representative’s hands, and is the point of contact for the market surveillance authorities.
The important thing to get right is timing. Under the Digital Omnibus, the high-risk representative duty no longer starts on 2 August 2026, the date almost every page on this topic still cites; it now applies from 2 December 2027 or 2 August 2028. The dates are further out than most pages say, so there is room to do this once and do it well.
Key takeaways
- Article 22 of the EU AI Act makes a third-country provider appoint an authorised representative in the EU before its high-risk AI system is made available on the Union market.
- Engage Compliance acts as that authorised representative directly from its EU establishment. Article 22 requires only that the representative be established in the Union and names no particular Member State.
- The date has moved. Regulation (EU) 2026/1744 postponed the obligation to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I product-embedded systems. It is not 2 August 2026.
- High-risk means Article 6(1) safety components of products under the Annex I harmonised legislation, or Article 6(2) Annex III use cases. Article 25 can move provider status, and the duty with it, onto a distributor, importer or deployer.
- The representative carries a ten-year document custody duty and a duty to terminate the mandate and report the provider to the market surveillance authority if it considers the provider non-compliant.
- The GPAI representative duty under Article 54 is a separate obligation and is already live. If that is what you need, start with our AI Act representative page.
Who needs one
Article 22(1) is direct: “Prior to making their high-risk AI systems available on the Union market, providers established in third countries shall, by written mandate, appoint an authorised representative which is established in the Union.”
So you are in scope when you are a provider established outside the EU and the system you are placing on the Union market is high-risk. A system counts as high-risk in one of two ways:
- Article 6(1), where the AI system is a safety component of a product, or is itself a product, covered by the Union harmonised legislation listed in Annex I.
- Article 6(2), where the system falls within one of the use cases in Annex III.
One point that catches people. Under Article 25, provider status can transfer. A distributor, importer or deployer that puts its own name on a high-risk system, or substantially modifies it, can become the provider, and the Article 22 duty travels with that status. If you take someone else’s high-risk model and ship it as your own, check whether the representative obligation has landed on you.
Who is exempt
There is no exemption written into Article 22. If you are a third-country provider of a high-risk system, the duty applies. The only real question is whether your system is high-risk at all, which is a classification question rather than an exemption, and our high-risk classification guide walks through how Annex III and the Article 6(1) product route actually work.
When it applies from
This is the part that is wrong on most pages, so it is worth being precise.
Article 113 of the AI Act originally applied Article 22 from 2 August 2026. Then Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and came into force on 27 July 2026. It postponed the application of Chapter III, Sections 1 to 3 of the AI Act.
Article 22 sits in Chapter III, Section 3. So it is inside the postponed sections, which the Digital Omnibus moved out to 2 December 2027 and 2 August 2028, and the high-risk authorised representative obligation does not bite on 2 August 2026. It applies from:
- 2 December 2027 for AI systems classified as high-risk under Article 6(2) and Annex III, the standalone systems.
- 2 August 2028 for AI systems classified as high-risk under Article 6(1) and Annex I, the ones embedded in regulated products.
If you have seen 2 August 2026 quoted as the deadline, that predates the Digital Omnibus. One thing the postponement does not touch: the GPAI representative duty under Article 54 is unaffected and has been live since 2 August 2025. That is a different obligation for a different kind of provider, and if you make a general-purpose AI model our AI Act representative page covers it.
Where the representative must be established
In the Union. Article 22 requires an authorised representative “which is established in the Union” and does not name a Member State, so a single EU establishment can hold the role for any high-risk provider. Engage Compliance provides it from its own EU establishment, with no need for a partner or a separate entity. That is unlike the UK and Swiss representative roles, where the law requires an entity in that specific country.
What the penalty is
Stated factually, and it is not the reason to act. Non-compliance with the obligations of authorised representatives under Article 22 attracts administrative fines up to €15 million or up to 3% of total worldwide annual turnover for the preceding financial year, whichever is higher, under Article 99(4)(b). For SMEs and start-ups, Article 99(6) provides that the cap is whichever of the percentage or the amount is lower, rather than higher.
The better reason to sort this out is simpler. It is a legal precondition to putting the system on the market, the market surveillance authorities can ask for the mandate and the documents at any point, and enterprise buyers and partners increasingly ask whether the appointment is real before a regulator ever does.
What we do
Engage Compliance acts as your Article 22 authorised representative and carries the duties the Regulation puts on the representative, not a nameplate version of them:
- Written mandate. The appointment Article 22(1) requires, with a copy provided to market surveillance authorities on request under Article 22(3).
- Ten-year document custody. We keep, at the disposal of the competent authorities, your contact details, a copy of the EU declaration of conformity under Article 47, the technical documentation and, where a notified body was involved, its certificate, for ten years after the system is placed on the market or put into service. This is the Article 22(3)(b) duty, and it survives the end of the commercial relationship.
- Registration. We handle the registration obligations under Article 22(3)(e), or, where you register the system yourself, make sure the Annex VIII information is correct.
- A single point of contact for the market surveillance authorities, with correspondence passed to your named internal owner and a recommended response.
- The termination duty, handled honestly. Article 22(4) requires the representative to end the mandate and tell the market surveillance authority, and any notified body, with reasons, if it considers you to be acting contrary to your obligations. We put how that works in the engagement terms at the start, because a representative that could report you is not something to discover later.
What it costs
Pricing is scoped to the mandate, because a single high-risk system and a portfolio of them are not the same job. Tell us what you are placing on the market and we will give you a quote. Talk to us on the contact page.
Sources and references
- EU AI Act, Article 22, European Commission AI Act Service Desk
- Regulation (EU) 2024/1689 (the EU AI Act), EUR-Lex
Representative mandates
These mandates stack rather than replace each other. One company selling into Europe can be caught by several at once, each is a separate appointment with its own published contact point, and an EU representative does not cover the UK. Engage Compliance holds them together so you have one point of contact across the set.
- EU GDPR Article 27 representative
- UK GDPR Article 27 representative
- Swiss FADP Article 14 representative
- DSA Article 13 legal representative
- EU AI Act GPAI authorised representative
- EU AI Act high-risk authorised representative
- NIS2 representative
- Data Act legal representative
- Data Governance Act representative
- e-Evidence legal representative
- Terrorist Content Online representative
- GPSR responsible person
- CE-marking authorised representative
- Non-EU regimes (Swiss, China, Korea, Turkey)