EU AI ACT AUTHORISED REPRESENTATIVE

EU AI Act Authorised Representative for High-Risk AI Systems

Article 22 representation for providers established outside the European Union that make high-risk AI systems available on the Union market, subject to the applicable Article 6 classification route and application date.

AI ACT
ARTICLE
22HIGH-RISK AI REPRESENTATION

OSTRAI supports eligible third-country providers in preparing and establishing Article 22 authorised-representative structures for high-risk AI systems.

Our service combines high-risk classification and scope assessment, representation readiness, written mandate, conformity-documentation interface, competent-authority communications, registration coordination where applicable, regulatory cooperation and continuing representation once the relevant Article 22 requirements apply.

Not sure whether your system is high-risk, which Article 6 route applies or when Article 22 becomes applicable? Start with the scope and classification assessment.

CURRENT APPLICATION

Two high-risk routes.
Two application dates.

ARTICLE 6(2) / ANNEX III

Chapter III Sections 1–3, including Article 22, apply from this date to high-risk AI systems classified under Article 6(2) and Annex III.

ARTICLE 6(1) / ANNEX I SECTION A

Chapter III Sections 1–3, including Article 22, apply from this date to Article 6(1) high-risk AI systems linked to Annex I Section A.

ANNEX I SECTION B

Under the current Article 2(2), systems related to products covered by Annex I Section B are subject only to the AI Act provisions specified there. Article 22 is not among those provisions.

Therefore the Article 22 representative analysis must distinguish Annex I Section A from Annex I Section B.

OSTRAI can support classification, readiness and mandate structuring in advance of the applicable date.

Review your Article 22 timeline

ARTICLE 22 / SCOPE

The route to an EU
authorised representative.

  1. Is the entity the provider of the AI system?

    The provider is the entity that develops, or has developed, the AI system and places it on the market or puts it into service under its own name or trademark.

    If yes

    If no

    Article 22 does not arise for that entity on this basis.

  2. Is the provider established in a third country?

    If yes

    If no

    Article 22 does not arise on the basis of absence of EU establishment.

  3. Is the AI system classified as high-risk under an Article 22-relevant route?

    ROUTE AArticle 6(2) / Annex III

    OR

    ROUTE BArticle 6(1) / Annex I Section A

    If yes

    If neither route applies

    No Article 22 representative requirement on this basis.

  4. If the system falls within Annex III, does the Article 6(3) filter remove the high-risk classification?

    An Annex III system that performs profiling of natural persons remains high-risk notwithstanding the Article 6(3) filter.

    If no / Annex I Section A route

    If yes

    No Article 22 requirement on the basis of that Annex III classification.

  5. Is the provider making the high-risk AI system available on the Union market?

    If yes

    If no

    No Article 22 representative trigger on this basis.

  6. Has the relevant Article 113 application date been reached?

    ANNEX III / ARTICLE 6(2)2 December 2027

    ANNEX I SECTION A / ARTICLE 6(1)2 August 2028

    If yes

    If no

    Prepare Article 22 representation and compliance readiness before the applicable date.

EU AI Act Authorised Representative required

The provider must appoint an authorised representative established in the Union by written mandate before making the high-risk AI system available on the Union market.

ARTICLE 6

High-risk classification
follows two different routes.

ARTICLE 6(1)

Regulated product route

An AI system can be high-risk where:

  • It is intended to be used as a safety component of a product, or is itself a product, covered by relevant Union harmonisation legislation in Annex I; and
  • The relevant product or system is required to undergo third-party conformity assessment under that legislation.

For Article 22 representation, distinguish Annex I Section A from Section B because of the current Article 2(2) rule.

ARTICLE 6(2)

Annex III use-case route

AI systems falling within the high-risk use cases listed in Annex III can be classified as high-risk, subject to the Article 6(3) filter.

The classification assessment is system-specific, intended-purpose-specific, provider-specific and route-specific.

Assess high-risk classification

ANNEX III

High-risk use cases extend
across sensitive areas.

  1. Biometrics

  2. Critical infrastructure

  3. Education and vocational training

  4. Employment, workers’ management and access to self-employment

  5. Access to and enjoyment of essential private services and essential public services and benefits

  6. Law enforcement

  7. Migration, asylum and border control management

  8. Administration of justice and democratic processes

Not every AI system used in one of these sectors is automatically high-risk. The specific Annex III use case, intended purpose and Article 6(3) filter must be assessed.

Review your Annex III position

ANNEX III / ARTICLE 6(3)

An Annex III listing does not always end the classification analysis.

An Annex III AI system may not be considered high-risk where it does not pose a significant risk of harm to health, safety or fundamental rights, including by not materially influencing the outcome of decision-making, where the statutory conditions are met.

Narrow procedural task

Improves the result of a previously completed human activity

Detects decision-making patterns or deviations without replacing or influencing the completed human assessment without proper human review

Preparatory task to an Annex III assessment

PROFILING

An Annex III AI system that performs profiling of natural persons is always considered high-risk for this purpose.

A provider relying on Article 6(3) must document its assessment before placing the system on the market or putting it into service and is subject to the relevant registration requirement.

Assess the Article 6(3) filter

PRODUCT-RELATED HIGH RISK

Not every Annex I route
leads to Article 22.

ANNEX I / SECTION A

New Legislative Framework
product legislation.

Where the Article 6(1) conditions are satisfied and the relevant Chapter III provisions apply, Article 22 can form part of the provider’s AI Act compliance architecture from the applicable date.

ANNEX I / SECTION B

Other Union
harmonisation legislation.

Under the current Article 2(2), high-risk AI systems related to products covered by Section B are subject only to the AI Act provisions identified in Article 2(2).

Article 22 is not included in that list.

Product-related high-risk classification and Article 22 representation therefore require a sector-specific assessment of the underlying Annex I legislation.

Assess the product-regulation route

TWO REPRESENTATIVE REGIMES

High-risk system representation
is not GPAI model representation.

ARTICLE 22

High-Risk
AI System

  • Provider established outside the Union
  • High-risk system made available on the Union market
  • Article 11 technical documentation / Annex IV
  • Conformity assessment
  • EU declaration of conformity
  • Registration where applicable
  • Competent-authority interface

ARTICLE 54

General-Purpose
AI Model

  • Provider established outside the Union
  • GPAI model placed on the Union market
  • Annex XI technical documentation
  • Article 53 obligations
  • Article 55 obligations where applicable
  • AI Office / competent-authority interface

The two roles concern different regulated objects and different statutory mandates. A provider may require separate analysis under Articles 22 and 54.

See GPAI Model Representation

HIGH-RISK AI REQUIREMENTS

Article 22 sits within
a broader conformity framework.

Article 9

Risk management

Article 10

Data and data governance

Article 11 / Annex IV

Technical documentation

Article 12

Record-keeping

Article 13

Transparency and information to deployers

Article 14

Human oversight

Article 15

Accuracy, robustness & cybersecurity

These are underlying provider compliance requirements. The authorised representative does not replace the provider’s responsibility for satisfying them.

Explore AI Act Advisory

FROM DOCUMENTATION TO MARKET ACCESS

Article 22 connects to the system’s conformity structure.

The precise conformity route depends on the type of high-risk system, the Article 6 classification route and, where relevant, applicable Union harmonisation legislation and notified-body involvement.

  1. ARTICLE 11Technical documentation / Annex IV
  2. ARTICLE 43Applicable conformity assessment
  3. ARTICLE 47EU declaration of conformity
  4. ARTICLE 48CE marking
  5. PRE-MARKET / PRE-AVAILABILITY REQUIREMENTS

    ARTICLE 22EU authorised representative
    where required
    AND, WHERE APPLICABLE
    ARTICLE 49Registration
  6. UNION MARKET / PUTTING INTO SERVICE

ARTICLE 22 MANDATE

The authorised representative is part of the high-risk AI conformity architecture.

Article 22 does not establish a passive address service. The written mandate must empower the representative to verify specified conformity steps, maintain required documentation, respond to authority requests, cooperate in regulatory action and carry out registration tasks where applicable.

Verify

Verify that:

  • The EU declaration of conformity referred to in Article 47 has been drawn up;
  • The technical documentation referred to in Article 11 has been drawn up; and
  • An appropriate conformity assessment procedure has been carried out by the provider.

Retain

Keep at the disposal of the relevant authorities for 10 years after the high-risk AI system has been placed on the market or put into service:

  • Provider contact details;
  • Copy of the EU declaration of conformity;
  • Article 11 technical documentation; and
  • Notified-body certificate where applicable.

Respond

Provide a competent authority, upon reasoned request, with information and documentation necessary to demonstrate conformity with Chapter III Section 2, including access to automatically generated logs where those logs are under the provider’s control.

Cooperate

Cooperate with competent authorities, upon reasoned request, in actions concerning the high-risk AI system, particularly measures to reduce and mitigate risks.

Register

Where applicable, comply with Article 49(1) registration obligations or, where registration is performed by the provider, ensure that the specified information is correct.

DIFFERENT FUNCTIONS

Verification is not certification.

Provider

  • Responsible for underlying high-risk AI compliance.
  • Draws up technical documentation.
  • Ensures appropriate conformity assessment.
  • Draws up EU declaration of conformity.
  • Affixes CE marking as applicable.
  • Complies with registration and other provider obligations.

Authorised representative

OSTRAI

  • Verifies that specified documentation and conformity steps have been completed.
  • Maintains the required representative documentation.
  • Provides the EU regulatory interface.
  • Coordinates authority requests.
  • Cooperates with competent authorities.

Notified body

WHERE APPLICABLE

  • Performs third-party conformity-assessment activities within its notified scope.
  • May issue relevant certificates where required by the applicable conformity route.

OSTRAI’s Article 22 representative role is not a notified-body function and does not constitute independent certification of the high-risk AI system.

REGULATORY INTERFACE

Authorities, representative
and provider.

Market surveillance / competent authorities

OSTRAI

EU AI ACT AUTHORISED REPRESENTATIVE

  • Regulatory contact
  • Mandate interface
  • Documentation availability
  • Information requests
  • Registration coordination
  • Risk-mitigation cooperation
  • Escalation
  • Mandate coordination

Represented provider

  • System development
  • Risk management
  • Data governance
  • Technical documentation
  • Conformity assessment
  • EU declaration of conformity
  • CE marking
  • Post-market responsibilities
  • Technical implementation

The Article 22 mandate must empower the authorised representative to be addressed, in addition to or instead of the provider, by competent authorities on issues concerning compliance with the AI Act.

YOUR REPRESENTATION SERVICE

A functioning Article 22
representation structure.

Article 22 readiness and appointment

Pre-appointment readiness followed, when applicable, by written appointment of OSTRAI Limited as EU AI Act Authorised Representative within the agreed mandate.

Conformity-verification structure

A structured process for verifying that the EU declaration of conformity and Article 11 technical documentation have been drawn up and that the appropriate conformity assessment has been carried out.

Documentation arrangements

Secure arrangements for maintaining the documentation required under Article 22 for the statutory period.

Designated regulatory channel

A monitored OSTRAI channel for communications connected with the representative mandate.

Designated lead

A defined OSTRAI contact coordinating the representative relationship and material regulatory escalations.

Competent-authority communications

Receipt and coordination of communications directed to OSTRAI in its Article 22 capacity.

Information-request coordination

Coordination of reasoned requests for conformity information, documentation and logs where relevant.

Risk-mitigation cooperation

Coordination with the provider where competent authorities take action to reduce or mitigate risks associated with the high-risk AI system.

Registration coordination

Article 49(1) registration support within the representative mandate where applicable.

Escalation protocol

Defined provider contacts and procedures for urgent, material or time-sensitive regulatory matters.

Representative disclosure support

Support for correctly identifying OSTRAI as authorised representative and including the relevant representative contact details in the system’s instructions for use where required under Article 13.

Mandate maintenance

Review of material changes affecting the provider, system, classification, conformity route and representative mandate.

Discuss the Article 22 mandate

ARTICLE 11 / ARTICLE 22

The representative must remain connected to the conformity evidence.

Article 22 requires the authorised representative to keep specified conformity documentation available for 10 years after the high-risk AI system has been placed on the market or put into service.

Effective documentation arrangements depend on current and accurate information being supplied by the provider.

  1. Provider develops / updates Article 11 technical documentation
  2. Appropriate conformity assessment completed
  3. EU declaration of conformity drawn up
  4. OSTRAI verification
  5. Required Article 22 documentation held
  6. 10-year availability
  7. Competent-authority request
  8. Information and evidence coordination

ANNEX IV

High-risk AI documentation
is system-specific.

Article 11 requires technical documentation to be drawn up before the high-risk AI system is placed on the market or put into service and kept up to date.

The documentation must demonstrate conformity with the applicable Chapter III Section 2 requirements and contain, at minimum, the elements required by Annex IV.

  • System description
  • Intended purpose
  • System architecture
  • Development methods
  • Data requirements
  • Testing and validation
  • Performance
  • Risk-management information
  • Human oversight
  • Cybersecurity
  • Changes / versions
  • Standards and specifications where relevant
Discuss conformity readiness

ARTICLE 49

Registration is part of some Article 22 mandates, not all of them.

Article 22(3)(e) specifically connects the authorised representative’s registration role to Article 49(1). Article 49(1) concerns relevant Annex III high-risk AI systems and contains its own exclusions and registration architecture.

Where Article 49(1) applies, the authorised representative may perform the registration. If the provider performs the registration itself, Article 22 requires the authorised representative to ensure that the representative information specified in Section A, point 3 of Annex VIII is correct.

Registration should therefore be assessed separately for the particular system.

Assess registration requirements
  1. System classification
  2. Article 49 applicability
  3. Provider registrationORAuthorised representative registration where applicable
  4. Information verification
    ANNEX VIII · SECTION A, POINT 3

    Authorised representative:
    Name · Address · Contact details

  5. Mandate maintenance

REGULATORY COOPERATION

Article 22 reaches
beyond document custody.

Following a reasoned request, the authorised representative must provide the competent authority with the information and documentation necessary to demonstrate conformity of the high-risk AI system with Chapter III Section 2.

This includes access to automatically generated logs referred to in Article 12(1), to the extent those logs are under the provider’s control.

  1. Authority request
  2. OSTRAI receives / triages
  3. Identify legal and technical scope
  4. Request provider information / logs
  5. Coordinate legal / technical / compliance teams
  6. Provide or facilitate response
  7. Record & follow up

RESPONSIBILITY

The provider remains responsible for the high-risk AI system.

Representation and substantive high-risk AI compliance are distinct.

Represented provider

  • High-risk classification
  • Risk management
  • Data governance
  • Technical documentation
  • Quality management
  • Conformity assessment
  • EU declaration of conformity
  • CE marking
  • Registration
  • Corrective actions
  • Post-market monitoring
  • Incident reporting
  • Technical implementation

OSTRAI

ARTICLE 22 AUTHORISED REPRESENTATIVE

  • Verification
  • Documentation availability
  • Regulatory interface
  • Information-request coordination
  • Registration role where applicable
  • Authority cooperation
  • Risk-mitigation cooperation
  • Escalation
  • Mandate maintenance

ARTICLE 22(4)

The mandate cannot continue regardless of provider conduct.

Where the authorised representative considers, or has reason to consider, that the provider is acting contrary to its obligations under the AI Act, Article 22 requires the representative to terminate the mandate.

In that case, the representative must immediately inform the relevant market surveillance authority and, where applicable, the relevant notified body about the termination and the reasons for it.

This statutory duty is one reason OSTRAI applies controlled acceptance, compliance-readiness review and ongoing mandate monitoring.

  1. Potential compliance concern identified
  2. Obtain information / clarification
  3. Assess Article 22(4) position
  4. IF ARTICLE 22(4) THRESHOLD IS MET
  5. Terminate mandate
  6. Immediately inform relevant market surveillance authority
  7. Inform relevant notified body where applicable

CONTROLLED ACCEPTANCE

We assess the mandate
before appointment.

Before accepting an Article 22 mandate, OSTRAI reviews the provider, relevant high-risk AI system, provider status, Article 6 classification route, Annex I or Annex III position, applicable Article 6(3) analysis, Union market activity, relevant application date, technical documentation, conformity assessment, EU declaration of conformity, registration position, notified-body involvement where applicable, regulatory history and operational readiness.

Where classification, conformity, documentation or wider AI Act obligations require substantive legal, regulatory or technical work, that work can be separately scoped before appointment.

The provider’s regulatory position and readiness determine whether OSTRAI can accept the mandate.

Discuss whether OSTRAI can accept the mandate

ONBOARDING

The information behind
an effective Article 22 appointment.

Entity
Correct legal entity to be represented.
Provider status
Basis on which the entity is the provider.
EU establishment
Whether the provider has an establishment in the Union.
AI system
Relevant high-risk AI system or systems.
Intended purpose
Purpose and relevant deployment context.
High-risk route
Article 6(1) / Annex I Section A or Article 6(2) / Annex III
Annex III filter
Article 6(3) analysis where relevant.
Application date
2 December 2027 or 2 August 2028, depending on route.
Union market activity
How and where the system is or will be made available.
Technical documentation
Article 11 / Annex IV status and version.
Instructions for use
Current instructions for use and the location of provider / authorised-representative contact information.
Conformity assessment
Applicable Article 43 or sectoral conformity route.
EU declaration of conformity
Article 47 status.
CE marking
Article 48 position where applicable.
Notified body
Identity, scope and certificate where applicable.
Registration
Article 49 position where applicable.
Logs
Article 12 availability and control arrangements.
Quality management
Article 17 compliance structure.
Post-market arrangements
Relevant monitoring, corrective-action and incident processes.
Regulatory history
Existing authority or notified-body communications.
Internal contacts
Legal · regulatory · product · AI / engineering · quality · security · compliance.
Escalation
Named contacts for urgent or material authority matters.
Start Article 22 onboarding

OPERATIONAL READINESS

The representative needs access to the organisation behind the mandate.

Effective Article 22 representation depends on prompt access to accurate information, conformity evidence and responsible internal teams when competent-authority communications arise.

  • Legal / regulatory
  • AI governance
  • Product
  • Engineering
  • Quality / conformity
  • Risk management
  • Cybersecurity
  • Post-market monitoring
  • Incident response
  • Executive escalation
  • External conformity / technical advisers where relevant
  • Notified-body contact where applicable

OSTRAIARTICLE 22 AUTHORISED REPRESENTATIVE

SCOPE

Representation and high-risk
AI implementation are distinct.

Standard representative mandate

  • Article 22 readiness / written appointment
  • Representative regulatory channel
  • Conformity-document verification
  • Required documentation availability
  • Competent-authority communications
  • Information-request coordination
  • Registration role where applicable
  • Routine authority cooperation
  • Risk-mitigation cooperation
  • Escalation
  • Mandate maintenance

Separately scoped support

  • AI-system definition analysis
  • Article 6 high-risk classification
  • Annex I / Annex III analysis
  • Article 6(3) assessment
  • Provider-status analysis
  • Article 9 risk-management system
  • Article 10 data governance
  • Article 11 / Annex IV technical documentation
  • Article 12 logging
  • Article 13 transparency
  • Article 14 human oversight
  • Article 15 accuracy, robustness & cybersecurity
  • Article 17 quality-management system
  • Conformity-assessment readiness
  • EU declaration of conformity
  • CE-marking support
  • Article 49 registration analysis
  • Post-market monitoring
  • Serious-incident processes
  • Standards / common-specification analysis
  • Contractual allocation across the AI value chain
  • Regulatory-response work

TRANSITIONAL POSITION

Existing systems require
a separate timing analysis.

The current AI Act contains transitional provisions for high-risk AI systems placed on the market or put into service before the relevant Chapter III application date.

Whether and when the Chapter III obligations apply to an existing system can depend on matters including the relevant application date and subsequent significant changes to the system’s design.

Assess an existing system

AI REGULATION PRACTICE

Representation backed by substantive high-risk AI capability.

OSTRAI’s Article 22 Authorised Representative service sits within a broader European AI, product and technology-regulation practice.

Where necessary, separately scoped work can address high-risk classification, product-regulation intersections, technical documentation, conformity architecture, risk management, data governance, human oversight, cybersecurity, registration, post-market obligations, contractual allocation, regulatory response and applicable standards.

This allows communications reaching the authorised representative to be understood within their wider legal, technical and conformity context.

WHY OSTRAI

Why OSTRAI for Article 22 representation

Article 22 focus

Representation structured around the statutory authorised-representative role.

Conformity architecture

A mandate model designed around the actual Article 22 verification and documentation obligations.

Controlled acceptance

Mandates assessed against classification, conformity documentation and operational readiness before appointment.

Defined escalation

Clear routes for market-surveillance and competent-authority communications.

Cross-regulatory capability

Ability to identify intersections with product regulation, cybersecurity, privacy, digital regulation and sector-specific Union law.

Standards perspective

Ability to identify where harmonised standards, common specifications and relevant technical standards interact with high-risk AI conformity.

QUESTIONS & ANSWERS

Before
appointment.

A provider established in a third country must appoint an EU-established authorised representative before making a high-risk AI system available on the Union market where Article 22 applies, subject to the relevant classification route, current Article 2 scope rules and application date.

Not generally as of September 2026. Chapter III Sections 1–3 apply from 2 December 2027 for Article 6(2) / Annex III high-risk systems; and from 2 August 2028 for Article 6(1) / Annex I high-risk systems, subject to the current Article 2(2) treatment of Annex I Section B.

No. The current Article 2(2) provides a special regime for high-risk AI systems related to products covered by Annex I Section B, and Article 22 is not one of the provisions identified as applicable to those systems. Annex I Section A and Section B must therefore be distinguished.

No. The specific Annex III use case must apply, and the Article 6(3) filter must be considered where relevant. An Annex III system performing profiling of natural persons remains high-risk notwithstanding that filter.

That the EU declaration of conformity and Article 11 technical documentation have been drawn up and that an appropriate conformity assessment procedure has been carried out by the provider.

No. The authorised-representative function is distinct from the provider’s conformity responsibilities and from notified-body conformity assessment where notified-body involvement is required.

Article 22 requires specified documentation to remain available for 10 years after the system has been placed on the market or put into service, including provider contact details, the EU declaration of conformity, technical documentation and any applicable notified-body certificate.

Yes. The mandate must empower the representative to be addressed in addition to or instead of the provider on issues concerning AI Act compliance.

Potentially. Following a reasoned request, Article 22 can require information and documentation necessary to demonstrate conformity, including access to Article 12(1) logs to the extent those logs are under the provider’s control.

Where Article 49(1) registration applies, Article 22 provides for a role for the authorised representative. The particular registration route must be assessed for the system.

Article 22(4) requires the representative to terminate the mandate if it considers or has reason to consider that the provider is acting contrary to its obligations. The representative must immediately inform the relevant market surveillance authority and, where applicable, the relevant notified body.

No. Article 22 concerns high-risk AI systems. Article 54 concerns general-purpose AI models. They are separate statutory representative regimes with different documentation, regulatory interfaces and obligations.

Potentially. Where the same third-country entity is the provider of a GPAI model and separately the provider of a high-risk AI system, each statutory role must be assessed separately.

Yes. Classification, technical documentation, conformity-readiness and wider high-risk AI implementation can be separately scoped from the standard Article 22 representative mandate.

The AI Act contains transitional rules, including Article 111. Existing systems should be assessed separately rather than assuming the same position as newly placed systems.

EU AI ACT AUTHORISED REPRESENTATIVE

Put the right Article 22
representation structure in place.

OSTRAI supports eligible third-country providers of high-risk AI systems from Article 6 classification and Article 22 scope assessment through representation readiness, onboarding, written mandate, conformity-documentation arrangements, competent-authority interface, registration coordination where applicable and continuing representation once the relevant requirements apply.