AI Assurance Logo
AI Assurance aiassurance.co.za
Get In Touch

The Need for an Authorised AI Representative:
A Compliance Imperative for Non-EU
Companies Entering the European Market

The European Union's Artificial Intelligence Act (EU AI Act), the world's first comprehensive horizontal regulation on AI, entered into force in 2024 and is phasing in through 2027. For companies established outside the EU, whether in South Africa, US, Asia, UK, or elsewhere, this regulation introduces extraterritorial obligations that directly impact market access. One of the most critical requirements for many non-EU providers is the mandatory appointment of an Authorised Representative (AR) established within the Union.

This article explores why non-EU companies need an Authorised AI Representative, the legal basis, responsibilities involved, timelines, practical implications, and strategic considerations.

Understanding the EU AI Act's Extraterritorial Reach

The EU AI Act applies not only to entities based in the EU but also to providers outside the Union in several scenarios:

  • Placing AI systems or general-purpose AI (GPAI) models on the EU market.
  • Putting AI systems into service in the EU.
  • Where the output of the AI system is used in the EU.

A "provider" is broadly defined as any person or entity that develops an AI system or GPAI model and places it on the market or puts it into service under its own name or trademark (including cases where a third party develops it on their behalf).

This scope means that a US-based startup offering an AI-powered hiring tool via API to European clients, or a Singaporean company distributing a large language model downloadable in the EU, falls under the regulation-even without a physical EU presence.

Who Must Appoint an Authorised Representative?

Non-EU providers must appoint an authorised representative in two main categories:

  1. Providers of High-Risk AI Systems (Article 22): These include AI used in areas like employment, education, critical infrastructure, law enforcement, migration, justice, and certain products regulated under existing EU laws (e.g., medical devices, machinery).
  2. Providers of General-Purpose AI (GPAI) Models (Article 54): These are models trained with large amounts of data via self-supervision, displaying significant generality and capable of performing a wide range of tasks (e.g., large language models like those powering ChatGPT-style services). Exemptions may apply for certain open-source releases, but many commercial GPAI providers are covered.

Exceptions and Nuances: Purely internal use without market placement or service in the EU may not trigger this, but once EU users or outputs are involved, obligations often kick in. Importers, distributors, or deployers may have separate duties, but the primary onus for non-EU developers rests on providers.

Legal Basis and Appointment Process

Under Articles 22 and 54, providers established in third countries must, by written mandate, appoint an authorised representative established in the Union prior to making their high-risk AI systems available or placing GPAI models on the Union market.

  • The authorised representative must be a natural or legal person (e.g., a company or individual) located or established in the EU.
  • The mandate must explicitly enable the authorised representative to perform all specified tasks and allow them to be addressed directly by the European AI Office or national authorities.
  • The provider must enable the authorised representative to fulfil these duties and cannot restrict necessary cooperation.

This mirrors mechanisms in other EU regulations like the Medical Devices Regulation or GDPR (where non-EU controllers/processors appoint representatives), creating a familiar "local point of contact" model.

Responsibilities of the Authorised Representative

The authorised representative acts as a bridge between the non-EU provider and EU regulators. Key tasks include:

  • Quality Management System: Maintaining an effective quality management system, the mandatory path to compliance, with real-time protection mechanisms, record management and operational control that can be demonstrated to regulatory authorities on demand.
  • Documentation and Records: Verifying and holding technical documentation, EU declarations of conformity, and records for at least 10 years. Providing these to authorities upon request.
  • Compliance Verification: Assisting with conformity assessments and ensuring the provider meets obligations.
  • Cooperation with Authorities: Serving as the primary contact for the AI Office, market surveillance authorities, and others. Cooperating on risk management, investigations, or corrective actions.
  • Information Provision: Supplying necessary details on the AI system/model and provider.
  • Termination Rights: The authorised representative can (and in some cases must) terminate the mandate and inform authorities if the provider fails to comply, protecting the representative from liability while enforcing accountability.

The authorised representative does not assume full liability for the AI system itself-that remains with the provider-but non-compliance by the provider can lead to the authorised representative ending the relationship and potential market restrictions.

Timelines for Compliance

  • GPAI Models: Obligations (including authorised representative appointment) apply from 2 August 2025.
  • High-Risk AI Systems: From 2 August 2026.
  • Full AI Act application for most provisions by 2 August 2027, with phased enforcement.

Non-EU companies planning EU market entry must act early, as appointing an authorised representative is a prerequisite for lawful placement.

Why Non-EU Companies Need an Authorised Representative: Key Drivers

  1. Regulatory Access and Market Entry Without an authorised representative, non-EU providers cannot legally place covered AI on the EU market. The EU represents a massive economic bloc (over 450 million consumers), and exclusion means lost revenue, competitive disadvantage against EU-based rivals, and barriers to innovation scaling.
  2. Enforcement and Accountability The AI Act empowers authorities with significant tools: fines up to €35 million or 7% of global annual turnover (whichever is higher), bans on non-compliant systems, and mandatory cooperation. An authorised representative ensures regulators have a local entity to engage, facilitating swift enforcement and reducing the practical challenges of pursuing offshore companies.
  3. Risk Management and Trust AI systems carry risks to health, safety, and fundamental rights. The authorised representative mechanism promotes transparency, documentation, and post-market monitoring, building user and regulator trust. It also helps providers demonstrate proactive compliance, mitigating reputational and legal risks.
  4. Alignment with Broader EU Strategy The AI Act fits into the EU's digital single market and "Brussels Effect," where EU standards influence global practices. Appointing an authorised representative signals commitment to high standards, potentially easing compliance in other jurisdictions adopting similar rules.
  5. Operational Efficiency A professional authorised representative can handle authority interactions, documentation storage, and monitoring, allowing the non-EU company to focus on development while outsourcing localized compliance expertise.

Practical Considerations and Challenges

  • Costs: Appointing an authorised representative involves fees for services (legal entities specializing in this exist), plus ongoing compliance costs. However, these are typically lower than establishing a full EU subsidiary.
  • Selection: Choose a reputable, experienced authorised representative with AI/regulatory knowledge. Multiple authorised representatives are not permitted; it must be a single representative.
  • Integration with Other Regulations: Coordinate with data protection officers (if applicable), as data protection often intersects with AI (e.g., training data).
  • Edge Cases: Open-source GPAI providers may have exemptions, but commercial fine-tuning or deployment often removes them. Pure research or non-market uses differ.
  • Penalties for Non-Compliance: Operating without an authorised representative risks fines, product withdrawal, and reputational damage.

Non-EU companies should conduct a gap analysis: classify their AI (prohibited, high-risk, limited-risk, minimal-risk), map obligations, and engage legal/compliance experts early.

Strategic Implications and Recommendations

Appointing an Authorised AI Representative is more than a checkbox-it is a gateway to responsible innovation in the EU. For non-EU companies, it underscores the need for global compliance strategies in an increasingly regulated AI landscape.

Recommendations:

  • Assess applicability now based on your AI offerings and EU exposure.
  • Budget for authorised representative services and integrate into go-to-market plans.
  • Leverage specialized providers offering AI Act authorised representative services alongside quality management systems.
  • Monitor European AI Office guidelines for updates.
  • View compliance as a competitive advantage: trustworthy AI attracts EU partners and customers.

In summary, the Authorised Representative requirement ensures that powerful AI technologies developed anywhere in the world meet Europe's high standards for safety, transparency, and rights protection. For non-EU companies, proactive appointment is essential-not optional-for sustainable access to one of the world's largest and most influential markets. As AI evolves, those who embrace structured compliance will be best positioned to thrive globally.