Article 22 & Article 54 EU AI Act

EU Authorised Representative

The representative your product needs in the EU — across every framework that requires one.

When you place a high-risk AI system or a general-purpose AI model on the EU market from outside the EU, Article 22 and Article 54 require you to appoint an authorised representative — by written mandate, before market placement, as a precondition to registration.

But the AI Act is rarely the only framework that reaches you. The same product usually triggers a GDPR representative, and often a CRA, NIS2, or DSA one too.

Most providers appoint each separately, from different vendors, and discover the overlaps too late.

We hold the role across every framework that applies to your product — coordinated, from one appointment, by someone who has read these regulations at drafting level.

✓ Written mandate, market-access ready
✓ Every applicable framework, one appointment
✓ Held by a qualified EU regulatory legal expert

Yuliia Habriiel

Do I need a EU Authorised Representative?

You need an EU authorised representative if all of these are true, for any applicable framework:

  • You are established outside the EU
  • You place a covered product on the EU market (a high-risk AI system, a GPAI model, a product with digital elements, or personal-data processing reaching EU residents)
  • You have no legal establishment inside the EU

If that is you, the appointment is not optional and, for the AI Act, it is a precondition to market access. The only real question is how many representatives you need and whether they should be coordinated — which the scoping call answers.

An authorised representative is a regulatory gatekeeper (not a mailbox)

Most AR services sell you a forwarding address. Articles 22 and 54 of the AI Act do not permit that — the role carries real statutory duties, and a representative who cannot perform them is exposure, not protection.

They must verify your documentation, not just hold it.

Before your system reaches the market, your representative has to verify that your technical documentation exists and holds up, then keep it at the disposal of authorities for ten years. A signature on a mandate the representative cannot actually stand behind is a liability, not a safeguard.

They must understand your system.

Verification means reading your validation datasets, bias-mitigation records, and performance and robustness evidence. A representative who cannot technically assess your system cannot lawfully verify it — which is why the role belongs with someone who can read the documentation, not an agent holding a nameplate.

They are legally required to report you if you breach.

Written into the Act: your representative must terminate the mandate and inform authorities if it has reason to believe you are non-compliant. That makes who you appoint decisive — a representative who understands your system flags problems early; one who doesn’t discovers them at the point they are obliged to report you.

The EU Authorised Representative requirement is not one duty. It is many.

FrameworkThe roleWhat triggers it
EU AI Act — Art 22Authorised representative (high-risk AI)Placing a high-risk AI system on the EU market from outside the EU
EU AI Act — Art 54Authorised representative (GPAI)Placing a general-purpose AI model on the EU market from outside the EU
GDPR — Art 27EU representativeOffering goods/services to, or monitoring, EU residents with no EU establishment
Cyber Resilience ActAuthorised representativePlacing a product with digital elements on the EU market from outside the EU
GPSRResponsible personPlacing a consumer product on the EU market with no EU-established economic operator
Medical Device RegulationAuthorised representativeNon-EU manufacturer of a medical device or IVD
NIS2EU representativeNon-EU operator of essential or important services
DSA — Art 13Legal representativeIntermediary service with no EU establishment

You are probably appointing the wrong number of Authorised Representatives

One provider, several duties.

A non-EU company shipping an AI-enabled connected product into the EU can simultaneously need an AI Act AR (the system), a GDPR representative (the personal data), and a CRA AR (the product’s digital elements). Most appoint one, or appoint three from three vendors who never speak to each other.

The gatekeeper duty is real, and it runs against you.

Your AI Act representative is legally required to report you to regulators and terminate the mandate if you breach. That is not a reason to avoid an AR — it is a reason to appoint one who will help you stay compliant rather than one who discovers your breach at the worst moment. The relationship is only safe if the representative understands your system well enough to flag problems early.

No representative, no market.

Under Article 22, appointing the AR is a precondition to Article 71 database registration. Without it, you cannot register, and without registration you cannot lawfully place the system on the EU market. The AR is not paperwork you do after launch. It is the gate you pass through to launch.

What holding the role actually involves

Written mandate, correctly scoped.

We draw up the Article 22 / 54 mandate — or the multi-framework mandate — specifying exactly the duties the representative assumes, so the appointment is valid and market-access ready.

Technical documentation verification.

Before your system reaches the market, we verify that your technical documentation exists and holds up — because that is the AR’s statutory duty, and because we authored what that documentation has to contain.

Ten-year custody and authority liaison.

We keep your documentation at the disposal of authorities for the statutory retention period, and act as your point of contact for the AI Office and national market surveillance authorities across all 27 member states.

Ongoing, not one-off Authorised Representative.

The representative role runs for as long as your system is on the market. We hold it continuously — monitoring, custody, and liaison — not as a one-time filing.

Why this representative holds up when a nameplate doesn’t.

Generic AR agentBig FourThis service
Can verify your technical documentationNoSometimesYes — authored the obligations
Frameworks coveredOne, billed separatelyOne, billed separatelyEvery applicable framework, one appointment
BasisAdministrative agentGeneral regulatory knowledgeDrafting-level expertise + compliance engine
Understands the system technicallyNoRarelyYes
Cross-framework viewNoNoYes — sees how AI Act, GDPR, DSA, NIS2, GPSR, CRA interact
Held byNameplate in a member stateRotating account teamA named qualified legal specialist
PriceLow — low capabilityHighFixed, transparent

How it works

From scoping call to named representative — without the parts you’d expect to slow it down.

Step 1 — Scope.

A short form covering your product’s function, connectivity, data flows, intended market, and current documentation. Takes fifteen to twenty minutes and is the basis for everything that follows.

Step 2 — Mandate

We draw up the written mandate for each applicable framework, correctly scoped, and — for the AI Act — verify your technical documentation is ready.

Step 3 – Appointment and custody

We are named as your representative, take custody of the required documentation, and act as your authority contact for as long as your product is on the market.

Representative appointments

Most non-EU companies need at least one EU representative, and often more than one. We hold the two most common roles as fixed appointments and assess coordinated multi-framework mandates individually.

Your Article 27 contact point held by a specialist, not a mailbox.

GDPR Representative

From

€900*

If you process the personal data of people in the EU without an establishment there, GDPR Article 27 requires you to appoint an EU representative. Most services sell you a forwarding address and pass correspondence back for you to handle. When a supervisory authority or a data subject makes contact, it reaches a named regulatory legal specialist who understands what they’re asking and what your exposure is — not a mailbox that forwards the problem back to you.

What’s included:

☑️ Written Article 27 mandate
☑️ Named EU-established regulatory representative
☑️ Contact point for supervisory authorities and data subjects
☑️ Coordinated with your AI Act position, if you hold both with us
☑️ Held for as long as you process EU data

* Exact band established during scoping call

Best for US and other non-EU providers bringing an AI system to the EU market.

EU AI Act Authorised Representative

From

€2,400

Non-EU providers of a high-risk AI system (Article 22) or a general-purpose AI model (Article 54) must appoint an authorised representative before market placement — and it’s a precondition to database registration. Without it, you cannot lawfully place the system on the EU market. This is the most demanding representative role in EU law: it requires verifying your technical documentation, which a low-cost administrative agent cannot do because they cannot read what they’re signing off. We can, because the person holding your mandate authored the AI Act’s technical documentation obligations, control by control, into a bespoke compliance engine.

What’s included:

☑️ Article 22 or 54 written mandate
☑️ Technical documentation verified before appointment — not after
☑️ Ten-year statutory documentation custody
☑️ Contact point for the AI Office and 27 national market surveillance authorities
☑️ Annual review call and regulatory alerts as the Act develops
☑️ Held by the legal specialist who authored these obligations, not an agent holding a nameplate

Best for products facing several EU regimes at once, where separate appointments from separate vendors would leave gaps.

Multi-Framework Coordination

From

€6,000

An AI-enabled or connected product can need several representatives at once — the AI Act, GDPR, and often the CRA or GPSR — each with its own duties, authorities, and liability. We can hold them together, so nothing falls between frameworks. Because each added framework changes the duties and the exposure, coordinated appointments are assessed and priced individually, not bought off the page. We establish exactly what applies to your product, what holding each role involves, and what it costs — before anything is agreed.

What’s included:

☑️ Assessment of which frameworks require a representative for your product
☑️ A coordinated mandate across the frameworks that apply
☑️ One point of contact across every represented framework
☑️ Priced to the specific duties and liability involved

FAQ

Can’t I just use a low-cost AR agent?

You can appoint one — but under the AI Act the representative must verify your technical documentation, and an administrative agent holding a nameplate cannot read validation data or bias-mitigation records they don’t understand. EU Authorised Representative mandate signed by someone who cannot perform the verification is not protection. It is a signature waiting to fail under scrutiny. The price difference reflects a capability difference.

I already have a GDPR representative — am I covered?

No. A GDPR Article 27 representative and an AI Act authorised representative are different roles, under different laws, answering to different authorities — appointing one does nothing for the other. Most non-EU companies shipping an AI product need both, and often a CRA or GPSR representative on top. Holding them separately means no one sees where the frameworks interact; holding them together means one party does.

I don’t want a representative who’s legally required to report me.

That duty exists whoever you appoint — it is written into the Act, not a term we add. The only choice you have is u003cemu003ewhich kindu003c/emu003e of representative holds it: one who understands your system and flags problems early enough to fix them, or one who discovers your breach at the moment they are obliged to disclose it. The reporting duty is a reason to appoint someone who keeps you compliant, not a reason to avoid an AR.

What is an EU authorised representative?

An authorised representative is a person or company established inside the EU that a non-EU business formally appoints to act as its official point of contact for European regulators. u003cbru003eu003cbru003eThe role exists because EU law needs someone reachable u003cemu003einsideu003c/emu003e the Union when the company itself is not, someone authorities can address, hold accountable, and, depending on the framework, who verifies the company’s compliance. u003cbru003eu003cbru003eAuthorised representative service is a legal appointment made by written mandate, not an informal arrangement, and under some frameworks it is a precondition to selling in the EU at all.

Do I need an EU authorised representative?

You need an EU authorised representative if you are established outside the EU, you place a covered product or service on the EU market, and you have no legal establishment inside the Union. u0022Coveredu0022 depends on the framework: u003cbru003e- A high-risk AI system or GPAI model triggers the AI Act requirement; u003cbru003e- Processing EU residents’ personal data triggers GDPR; u003cbru003e- A connected product triggers the CRA. u003cbru003eu003cbru003eIf more than one of these describes what you ship, you need more than one representative — and appointing them separately from different vendors is where the interactions get missed. u003cbru003eu003cbru003eThe fastest way to know exactly how many you need is the scoping call, which rules each framework in or out for your specific product.u003cbru003e

What is an authorised representative of a company?

An authorised representative of a company is the EU-based party that company designates to represent it before European authorities under a specific regulation — for example, an AI Act representative that verifies the company’s technical documentation, or a GDPR representative that answers to data protection authorities on the company’s behalf. u003cbru003eu003cbru003eThe EU authorised representative is not an employee or a subsidiary; it is an independent appointment that carries defined legal duties toward regulators. For a non-EU company, it is often the only party inside the EU that authorities can lawfully address about the product.

Are EU authorised representatives mandatory?

Yes — where a framework’s conditions are met, appointing an EU authorised representative is a legal obligation, not a best practice. u003cbru003eu003cbru003eUnder the EU AI Act it is mandatory for non-EU providers of high-risk AI systems (Article 22) and GPAI models (Article 54), and it is a precondition to EU database registration, meaning without it you cannot lawfully place the system on the market. u003cbru003eu003cbru003eUnder GDPR (Article 27) it is mandatory for most non-EU organisations processing EU residents’ data without an EU establishment, and the underlying data-protection breaches carry exposure up to €20M or 4%u003cbru003eu003cbru003eThe only case where it is not mandatory is where you genuinely fall outside every framework’s scope — which the scoping call confirms rather than assumes.

What is the difference between regular authorised representative and the one to deal with AI Act or GDPR?

Regulatory EU authorised representative is appointed specifically to satisfy an EU regulatory requirement — most commonly under the EU AI Act (Articles 22 and 54), GDPR (Article 27), the Cyber Resilience Act, NIS2, or the Medical Device Regulation. Each of these frameworks requires certain non-EU companies to name an EU-established representative before or while they operate in the European market. u003cbru003eu003cbru003eThe duties differ by framework: an AI Act representative verifies technical documentation and gates market access, while a GDPR representative is the contact point for data protection authorities and individuals. u003cbru003eu003cbru003eMany companies need more than one EU authorised representative, which is why we hold the role across every framework that applies to a single product.

Is the authorised representative service legal advice?

The representative role is a statutory function — we perform the specific duties the AI Act assigns to your representative, including verifying your documentation and acting as your contact with EU authorities. The verification involves regulatory analysis by a qualified specialist. It is not the provision of legal advice as your counsel, and does not create a solicitor-client relationship. u003cbru003eu003cbru003eIf you need a full legal analysis of your regulatory position before appointing a representative, that is the u003ca href=u0022https://europeancompliancesuite.com/eu-compliance-assessment/u0022 data-type=u0022pageu0022 data-id=u00222395u0022u003eEU Compliance Assessmentu003c/au003e.