Providers outside the EU that put a high-risk AI system on the Union market must appoint an authorised representative established in the EU under Article 22 of the EU AI Act. Engage Compliance takes that role from its EU establishment. The date it bites has moved, and most vendor pages still have it wrong.
The short answer: if you are established in a third country and you make a high-risk AI system available on the Union market, Article 22(1) requires you to appoint an authorised representative established in the EU, by written mandate, before the system goes on the market. Engage Compliance provides that role directly from its EU establishment, holds the documents the law puts in the representative’s hands, and is the point of contact for the market surveillance authorities.
The important thing to get right is timing. Required from 2 December 2027 if your system is high-risk, and from 2 August 2028 if it is a high-risk system embedded in a product under Annex I. Most pages on this topic still cite 2 August 2026, which the Digital Omnibus moved. Appoint now, because your customers and partners will start asking before the law does, and because there is room to do this once and do it well.
Key takeaways
- Article 22 of the EU AI Act makes a third-country provider appoint an authorised representative in the EU before its high-risk AI system is made available on the Union market.
- Engage Compliance acts as that authorised representative directly from its EU establishment. Article 22 requires only that the representative be established in the Union and names no particular Member State.
- Required from 2 December 2027 if your system is high-risk under Annex III, and from 2 August 2028 if it is high-risk under Annex I and embedded in a regulated product. Regulation (EU) 2026/1744 moved both dates from 2 August 2026. Appoint now, because your customers and partners will start asking before the law does.
- High-risk means Article 6(1) safety components of products under the Annex I harmonised legislation, or Article 6(2) Annex III use cases. Article 25 can move provider status, and the duty with it, onto a distributor or deployer established outside the EU.
- The representative carries a ten-year document custody duty and a duty to terminate the mandate and report the provider to the market surveillance authority if it considers the provider non-compliant.
- The GPAI representative duty under Article 54 is a separate obligation and is already live. If that is what you need, start with our AI Act representative page.
Who needs one
Article 22(1) is direct: “Prior to making their high-risk AI systems available on the Union market, providers established in third countries shall, by written mandate, appoint an authorised representative which is established in the Union.”
So you are in scope when you are a provider established outside the EU and the system you are placing on the Union market is high-risk. A system counts as high-risk in one of two ways:
- Article 6(1), where the AI system is a safety component of a product, or is itself a product, covered by the Union harmonised legislation listed in Annex I.
- Article 6(2), where the system falls within one of the use cases in Annex III.
Provider status can transfer, and people miss that. Article 25(1) makes a distributor, importer, deployer or other third party the provider of a high-risk AI system in three cases: where they put their own name or trademark on a system already placed on the market or put into service; where they make a substantial modification to a high-risk system that has already been placed on the market or put into service, in a way that keeps it high-risk under Article 6; or where they modify the intended purpose of a system that was not classified as high-risk, including a general-purpose AI system, so that it becomes high-risk under Article 6.
Article 25 moves the status. It does not decide whether Article 22 then applies. That question is answered by Article 22(1) on its own terms, and it has two conditions: the provider must be established in a third country, and it must be making the high-risk system available on the Union market. Both have to be met.
Distributors and deployers are where this bites in practice, because neither definition carries an establishment requirement. Article 3(7) defines a distributor as a person in the supply chain, other than the provider or the importer, that makes an AI system available on the Union market, and Article 3(4) defines a deployer as a person using an AI system under its authority. Neither says where they have to be. So a distributor or deployer established outside the EU that triggers one of the three Article 25 cases becomes a third-country provider, and Article 22 applies to it.
Importers are the conditional case. Article 3(6) defines an importer as a person “located or established in the Union”, and those are two different things: being located here does not by itself establish you here. Where an importer that becomes the provider under Article 25 is genuinely established in the Union, Article 22 does not apply to it, because Article 22(1) reaches only providers established in third countries. Where it is located here without being established here, the Article 22 conditions can still be met and the duty can still land. If you take someone else’s high-risk system and ship it under your own name, the question to answer is not which label you wear but whether you are established in a third country and making the system available on the Union market.
Who is exempt
There is no exemption written into Article 22. If you are a third-country provider of a high-risk system, the duty applies. The only real question is whether your system is high-risk at all, which is a classification question rather than an exemption, and our high-risk classification guide walks through how Annex III and the Article 6(1) product route actually work.
When it applies from
Most pages get this wrong, so here it is precisely.
Article 113 of the AI Act originally applied Article 22 from 2 August 2026. Then Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and came into force on 27 July 2026. It postponed the application of Chapter III, Sections 1 to 3 of the AI Act.
Article 22 sits in Chapter III, Section 3, which is inside the postponed sections. So:
- Required from 2 December 2027 if your system is high-risk under Article 6(2) and Annex III, the standalone systems.
- Required from 2 August 2028 if your system is high-risk under Article 6(1) and Annex I, the ones embedded in regulated products.
Appoint now, because your customers and partners will start asking before the law does. If you have seen 2 August 2026 quoted as the deadline, that predates the Digital Omnibus. One thing the postponement does not touch: the GPAI representative duty under Article 54 is unaffected and has been live since 2 August 2025. That is a different obligation for a different kind of provider, and if you make a general-purpose AI model our AI Act representative page covers it.
Where the representative must be established
In the Union. Article 22 requires an authorised representative “which is established in the Union” and does not name a Member State, so a single EU establishment can hold the role for any high-risk provider. Engage Compliance provides it from its own EU establishment, with no need for a partner or a separate entity. That is unlike the UK and Swiss representative roles, where the law requires an entity in that specific country.
What the penalty is
Stated factually, and it is not the reason to act. Non-compliance with the obligations of authorised representatives under Article 22 attracts administrative fines up to €15 million or up to 3% of total worldwide annual turnover for the preceding financial year, whichever is higher, under Article 99(4)(b). For SMEs and start-ups, Article 99(6) provides that the cap is whichever of the percentage or the amount is lower, rather than higher.
The better reason to sort this out is simpler. It is a legal precondition to putting the system on the market, the market surveillance authorities can ask for the mandate and the documents at any point, and enterprise buyers and partners increasingly ask whether the appointment is real before a regulator ever does.
What we do
Engage Compliance acts as your Article 22 authorised representative and carries the duties the Regulation puts on the representative, not a nameplate version of them:
- Written mandate. The appointment Article 22(1) requires, with a copy provided to market surveillance authorities on request under Article 22(3).
- Ten-year document custody. We keep, at the disposal of the competent authorities, your contact details, a copy of the EU declaration of conformity under Article 47, the technical documentation and, where a notified body was involved, its certificate, for ten years after the system is placed on the market or put into service. This is the Article 22(3)(b) duty, and it survives the end of the commercial relationship.
- Registration. We handle the registration obligations under Article 22(3)(e), or, where you register the system yourself, make sure the Annex VIII information is correct.
- A single point of contact for the market surveillance authorities, with correspondence passed to your named internal owner within one business day.
- The termination duty, handled honestly. Article 22(4) requires the representative to end the mandate and tell the market surveillance authority, and any notified body, with reasons, if it considers you to be acting contrary to your obligations. We put how that works in the engagement terms at the start, because a representative that could report you is not something to discover later.
What it costs
The appointment is €690 a year at the smallest band, for a company with 1 to 10 people, under €2m revenue, and under 5,000 people in the EU and UK whose data you hold, charged once, up front, with no setup fee. Whichever of headcount, revenue or the number of people whose data you hold puts you highest sets the band.
| Company size | AI Act Representative for high-risk systems |
|---|---|
| 1 to 10 people, under €2m revenue, and under 5,000 people in the EU and UK whose data you hold | €690 |
| 11 to 50 people, or €2m to €10m revenue, or 5,000 or more people in the EU and UK whose data you hold | €990 |
| 51 to 250 people, or €10m to €50m revenue | €2,290 |
| 251 or more people, or over €50m revenue | From €4,490 |
The smallest band is for very small organizations only: 1 to 10 people, under €2m in global annual revenue, and under 5,000 people in the EU and UK whose personal data you hold. All three must be true. If any one of them is not, the next band up applies.
Commercial pricing bands based on familiar market-size and market-pricing thresholds. They are not a statutory size test.
Every appointment you hold is a separate mandate, and only the highest-priced one in the basket is charged in full. Every other appointment is charged at a share of its own price, and for this one that share is half its own price. So adding this to an appointment you already hold costs €345 at band 0, €495 at band 1, €1,145 at band 2, €2,245 at band 3, rather than a second full price.
Two extras are optional, and each is charged once per order rather than once per appointment. Higher-risk processing, which covers special category data and criminal offense data, is €250 at band 0, €500 at band 1, €750 at band 2, €1,000 at band 3. Same-business-day response is a service level on authority and data subject correspondence rather than substantive advice, and is €1,200 a year.
Every band is published and buyable, so you can see your price and appoint online without talking to anyone first. The full table for every mandate is on representative services.
The appointment issues in seconds. After payment you answer a short form about your company and who we should send correspondence to, about three minutes of typing, and the appointment document, the certificate, the public verification link and the wording you need all issue automatically at that moment. Nobody at Engage has to approve anything.
Sources and references
- EU AI Act, Article 22, European Commission AI Act Service Desk
- Regulation (EU) 2024/1689 (the EU AI Act), EUR-Lex
Representative verification register
Representative mandates
These mandates stack rather than replace each other. One company selling into Europe can be caught by several at once, each is a separate appointment with its own published contact point, and an EU representative does not cover the UK. Engage Compliance holds them together so you have one point of contact across the set.
- EU GDPR Article 27 representative
- UK GDPR Article 27 representative
- Swiss FADP Article 14 representative
- DSA Article 13 legal representative
- EU AI Act GPAI authorised representative
- EU AI Act high-risk authorised representative
- NIS2 representative
- Data Act legal representative
- Data Governance Act representative
- e-Evidence legal representative
- Terrorist Content Online representative
- GPSR responsible person
- CE-marking authorised representative
- Non-EU regimes (Swiss, China, Korea, Turkey)