Governance

Importer

An entity in the EU that places on the Union market an AI system bearing the name or trademark of a person established outside the EU.

Definition

Official/legal definition: Under the EU Artificial Intelligence Act, an importer is "a natural or legal person located or established in the Union that places on the market an AI system that bears the name or trademark of a natural or legal person established in a third country.". ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng?utm_source=openai))

Context and scope: The term is used in the EU AI Act to allocate compliance responsibilities within the cross‑border supply chain for AI systems placed into the EU market. An importer is distinct from the provider (the developer or brand owner) and the distributor; the importer is the Union‑based natural or legal person who is responsible for making available on the Union market an AI system that carries a third‑country name or trademark. Obligations placed on importers are particularly detailed for high‑risk AI systems (e.g., verification of conformity, preservation of documentation, contact details on the product/packaging, cooperation with market surveillance). See the Act’s obligations for importers of high‑risk AI systems (notably the pre‑placement checks, record keeping and cooperation duties). ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng?utm_source=openai))

Jurisdictional variations:

  • European Union: The EU AI Act (Regulation (EU) 2024/1689) provides an explicit, role‑based definition and allocates specific pre‑market and post‑market duties to importers (Article 3(6); see Articles setting importer obligations for high‑risk systems). This is the primary legal source for the term in AI regulation. ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng?utm_source=openai))
  • United States (federal/state frameworks): U.S. federal guidance and frameworks (for example NIST’s AI RMF) and executive direction concentrate on roles such as developers, deployers, users, and broader actor responsibilities rather than using the EU concept of an "importer" in AI‑specific law; U.S. policy instruments focus on risk management, safety, accountability and enforcement through consumer protection and sectoral statutes rather than an EU‑style importer construct. Executive Order 14110 and NIST AI RMF emphasize developer/deployer responsibilities and risk management practices rather than a formal importer role. Some U.S. state laws (for example Colorado’s consumer protection AI law) define developers/deployers and assign obligations to those roles rather than to an "importer" as defined by the EU AI Act. Practically, companies selling AI into the U.S. market typically encounter enforcement through consumer‑protection and anti‑discrimination regimes (FTC, EEOC, state AGs) rather than an EU‑style importer regime. ([nist.gov](https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10?utm_source=openai))
  • International / standards bodies: International instruments and standards (OECD AI Principles, ISO/IEC 22989, UNESCO Recommendation on AI ethics) supply common terminology for AI systems and actors (developers, deployers, users, AI actors) and high‑level governance principles but generally do not create a role that mirrors the EU legal concept of an "importer" with statutory market‑surveillance duties. These instruments are normative or standards‑based (in the OECD/UNESCO/ISO sense) and therefore do not allocate the same compliance liabilities as the EU Regulation. Organizations should therefore treat the EU "importer" role as a jurisdiction‑specific legal designation while using international standards to inform controls and governance. ([dig.watch](https://dig.watch/resource/oecdlegal0449-recommendation-council-artificial-intelligence?utm_source=openai))

Practical implications for businesses operating across jurisdictions: If a non‑EU provider (brand owner) places AI systems on the EU market under its own name or trademark, an EU‑established business that introduces or places that product in the EU will typically be the importer under the AI Act and therefore assumes legal duties (verification before placement, storage/transport safeguards, ten‑year document retention for high‑risk systems, cooperation with authorities). Cross‑border operators and supply‑chain partners must map roles contractually (provider vs authorised representative vs importer vs distributor) and ensure responsibilities (documentation, conformity evidence, EU declaration of conformity, CE marking where applicable) are contractually allocated and operationalized. Where U.S. or other international frameworks apply, the same entity may instead face obligations framed in developer/deployer language or consumer‑protection enforcement; businesses must therefore align product labeling, contractual allocation of duties, technical documentation practices and post‑market monitoring to satisfy the strictest applicable regime (often the EU). ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng?utm_source=openai))

Key requirements / criteria (EU‑specific):

  • Entity location: the importer must be "located or established in the Union" (EU AI Act Article 3(6)). ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng?utm_source=openai))
  • Trigger: the AI system bears the name or trademark of a person established in a third country and is placed on the Union market by the importer. ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng?utm_source=openai))
  • Obligations for high‑risk AI systems: verify provider’s conformity assessment; ensure technical documentation and EU declaration accompany the system; indicate importer contact details on the system or its packaging; retain specified documents for 10 years; cooperate with competent authorities and provide documentation on request. ([resolve.cambridge.org](https://resolve.cambridge.org/core/journals/international-legal-materials/article/regulation-20241689-of-the-eur-parl-council-of-june-13-2024-eu-artificial-intelligence-act/64F1F6734F8C66CA3EEA149C9759194E?utm_source=openai))
  • Liability and market surveillance: importers must act when they have reason to suspect non‑conformity (do not place on the market until conformity is ensured) and must cooperate with market surveillance authorities. ([resolve.cambridge.org](https://resolve.cambridge.org/core/journals/international-legal-materials/article/regulation-20241689-of-the-eur-parl-council-of-june-13-2024-eu-artificial-intelligence-act/64F1F6734F8C66CA3EEA149C9759194E?utm_source=openai))

Examples and cross‑references: Examples: (a) An EU distributor that physically brings into the Union and markets a third‑country facial‑recognition system under the non‑EU brand would be an importer and must verify conformity and keep documentation if the system is high‑risk; (b) An EU reseller that rebrands a third‑country chatbot under its own trademark may instead be a provider under the Act (different duties). Cross‑references: see provider, deployer, distributor, authorised representative, and the definitions of placing on the market and high‑risk AI system in the EU AI Act for role allocation and obligations. For international governance and terminology that inform internal controls (but do not substitute for EU legal duties), consult OECD AI Principles, ISO/IEC 22989 and the UNESCO Recommendation. ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng?utm_source=openai))

Sources

  • EU AI Act Article 3(6)
  • EU AI Act Article 23