Authorized Representative
An EU-based person or entity mandated in writing by a non‑EU AI provider to carry out specified AI Act compliance duties on the provider’s behalf.
Definition
Official/legal definition: An authorised representative under the EU Artificial Intelligence Act is "a natural or legal person located or established in the Union who has received and accepted a written mandate from a provider of an AI system or a general‑purpose AI model to, respectively, perform and carry out on its behalf the obligations and procedures established by this Regulation." (EU AI Act, Article 3(5); detailed obligations and minimum mandate tasks are set out in Articles 22 and 54). ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/reg/2024/1689/oj))
Context and scope: The authorised representative is a legal construct used by the EU AI Act to give market access and enforcement channels for AI providers that are established outside the European Union. The role is mandatory for providers established in third countries that place high‑risk AI systems or general‑purpose AI models on the Union market: the non‑EU provider must, prior to market placement, appoint an authorised representative established in the Union by written mandate. That mandate must empower the representative to be addressed by competent authorities and to keep and provide technical documentation, declarations of conformity, access logs and to cooperate with authorities for periods (for example, 10 years for certain documentation). See Articles 22 (high‑risk AI systems) and 54 (general‑purpose AI models) for the scope and list of minimum mandate powers. ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/reg/2024/1689/oj))
Jurisdictional Variations
European Union (EU): The EU AI Act provides an explicit statutory definition and prescribes minimum mandatory tasks for authorised representatives when providers are established outside the Union (Article 3(5); Articles 22 and 54). The representative must: verify that the EU declaration of conformity and technical documentation have been prepared; keep contact details and documentation available to competent authorities (often for 10 years); provide information and logs on request; cooperate with market surveillance and the AI Office; and may be addressed instead of the provider. The mandate must be written and the representative may be required to terminate the mandate and notify authorities where the provider acts contrary to the Regulation. ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/reg/2024/1689/oj))
United States: U.S. federal AI guidance and frameworks (for example, the NIST AI Risk Management Framework and the Executive Order on Safe, Secure, and Trustworthy AI) focus on organizational roles, risk governance, and voluntary risk‑management practices and do not create an EU‑style legal obligation to appoint an EU‑based authorised representative for market access. Instead, U.S. frameworks emphasize internal governance, mapping of AI actors, and voluntary compliance tools; enforcement‑style representative requirements are a feature of EU product/market access law rather than of the primary U.S. AI guidance documents. Businesses selling into the EU therefore must bridge this regulatory difference by complying with the EU requirement even where their domestic governance frameworks do not recognize the specific legal role. ([nist.gov](https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10?utm_source=openai))
International / standards and principles: Global instruments such as the OECD AI Principles, ISO/IEC standards (e.g. ISO/IEC 22989 on AI terminology) and UNESCO’s Recommendation on the Ethics of AI articulate principles, actor categories, technical definitions and governance guidance but do not define an EU‑style legally binding "authorised representative" role. Those instruments emphasise accountability and identifiable actors in the AI lifecycle, but the concrete requirement to appoint an EU‑established authorised representative is specific to EU market access legislation. International standards and principles are nevertheless useful references when drafting mandates and organisational processes for representatives because they provide interoperable definitions and governance expectations. ([oecd.ai](https://oecd.ai/en/ai-principles))
Practical implications for businesses:
- Non‑EU providers that intend to place high‑risk AI systems or general‑purpose AI models on the EU market must contractually appoint an authorised representative in the EU before market placement and must ensure the mandate grants the minimum powers required by the AI Act (verification, documentation custody, cooperation with authorities, registry/registration support, access to logs, etc.). ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/reg/2024/1689/oj))
- Providers should select representatives with the capacity to: receive and hold technical documentation in an EU language chosen by the competent authority; respond to reasoned requests from national competent authorities or the AI Office; and to make representations on the provider’s behalf—including, where necessary, terminating the mandate and notifying authorities if regulatory non‑compliance is suspected. ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/reg/2024/1689/oj))
- Commercial agreements must allocate liability, indemnities, confidentiality and practical access to logs and systems (many compliance tasks require contractual access to operational logs or documentation held by the provider or a deployer). The EU text contemplates the authorised representative having access to logs to the extent they are under the provider’s control by contract or law. ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/reg/2024/1689/oj))
- Because other jurisdictions’ frameworks (e.g., NIST AI RMF) do not create this requirement, multinational businesses must run parallel compliance programs: meet voluntary US/NIST governance best practices while also meeting mandatory EU market‑access obligations such as appointing an authorised representative. ([nist.gov](https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10?utm_source=openai))
Key requirements / criteria (EU AI Act minimum mandate elements):
- Written mandate from provider to representative (mandate must be accepted in writing). ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/reg/2024/1689/oj))
- Power to verify EU declaration of conformity and technical documentation and to keep copies available to competent authorities (10‑year retention for certain AI artefacts). ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/reg/2024/1689/oj))
- Obligation to provide, on reasoned request, all information and documentation to demonstrate conformity, including access to automatically generated logs where under the provider’s control. ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/reg/2024/1689/oj))
- Duty to cooperate with competent authorities and the AI Office in actions to reduce or mitigate risks; ability to be addressed by authorities in place of the provider. ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/reg/2024/1689/oj))
- Requirement to terminate the mandate and inform authorities if the representative considers the provider to be acting contrary to the Regulation. ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/reg/2024/1689/oj))
Examples: A Chinese company that offers a high‑risk medical diagnostic AI service and wants to market it in the EU must sign a written mandate appointing an EU‑based authorised representative (for example, an EU‑established legal entity or consultancy) who will hold the EU declaration of conformity and technical documentation, provide inspection copies to national competent authorities on request, and cooperate with any conformity or incident investigations. By contrast, a U.S. provider operating only in the U.S. without EU market presence would not itself be bound by the EU mechanism unless it places systems on the EU market, in which case the same EU obligations would apply. ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/reg/2024/1689/oj))
Cross‑references: Related EU AI Act roles and concepts: provider (actor who develops/places AI on market), importer, distributor, AI Office, market surveillance authorities, EU declaration of conformity, technical documentation, and registration obligations (Article 49, Article 71). For governance alignment and voluntary risk management in non‑EU jurisdictions see NIST AI RMF and relevant OECD/ISO/UNESCO guidance. ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/reg/2024/1689/oj))
Sources
- •EU AI Act Article 3(5)
- •EU AI Act Article 22
Related Terms
Provider
An entity (natural or legal person, public authority or body) that develops or commissions an AI system or general-purpose AI model and places it on the market or puts it into service under its name or trademark....
Importer
An entity in the EU that places on the Union market an AI system bearing the name or trademark of a person established outside the EU....
Market Surveillance Authority
A national authority designated to carry out market surveillance activities and measures under Regulation (EU) 2019/1020 to enforce the EU AI Act....
Technical Documentation
Detailed records demonstrating AI system compliance with regulatory requirements....