A Compliance Imperative for Non-EU Companies Entering the European Market
The European Union's Artificial Intelligence Act (EU AI Act), the world's first comprehensive horizontal regulation on AI, entered into force in 2024 and is phasing in through 2027. For companies established outside the EU-whether in the US, Asia, the UK, or elsewhere-this regulation introduces extraterritorial obligations that directly impact market access. One of the most critical requirements for many non-EU providers is the mandatory appointment of an Authorised Representative (AR) established within the Union.
The EU AI Act applies not only to entities based in the EU but also to providers outside the Union in several scenarios:
A "provider" is broadly defined as any person or entity that develops an AI system or GPAI model and places it on the market or puts it into service under its own name or trademark (including cases where a third party develops it on their behalf).
This scope means that a US-based startup offering an AI-powered hiring tool via API to European clients, or a Singaporean company distributing a large language model downloadable in the EU, falls under the regulation-even without a physical EU presence.
Non-EU providers must appoint an authorised representative in two main categories:
These include AI used in areas like employment, education, critical infrastructure, law enforcement, migration, justice, and certain products regulated under existing EU laws (e.g., medical devices, machinery).
These are models trained with large amounts of data via self-supervision, displaying significant generality and capable of performing a wide range of tasks (e.g., large language models like those powering ChatGPT-style services). Exemptions may apply for certain open-source releases, but many commercial GPAI providers are covered.
Under Articles 22 and 54, providers established in third countries must, by written mandate, appoint an authorised representative established in the Union prior to making their high-risk AI systems available or placing GPAI models on the Union market.
This mirrors mechanisms in other EU regulations like the Medical Devices Regulation or GDPR (where non-EU controllers/processors appoint representatives), creating a familiar "local point of contact" model.
The authorised representative acts as a bridge between the non-EU provider and EU regulators. Key tasks include:
The authorised representative does not assume full liability for the AI system itself - that remains with the provider. However, non-compliance by the provider can lead to the authorised representative ending the relationship and potential market restrictions.
Non-EU companies planning EU market entry must act early, as appointing an authorised representative and establishing an effective quality management system are prerequisites for lawful placement.
Without an authorised representative, non-EU providers cannot legally place covered AI on the EU market. The EU represents a massive economic bloc (over 450 million consumers), and exclusion means lost revenue, competitive disadvantage against EU-based rivals, and barriers to innovation scaling.
The AI Act empowers authorities with significant tools: fines up to €35 million or 7% of global annual turnover (whichever is higher), bans on non-compliant systems, and mandatory cooperation. An authorised representative ensures regulators have a local entity to engage, facilitating swift enforcement and reducing the practical challenges of pursuing offshore companies.
AI systems carry risks to health, safety, and fundamental rights. The authorised representative mechanism promotes transparency, documentation, and post-market monitoring, building user and regulator trust. It also helps providers demonstrate proactive compliance, mitigating reputational and legal risks.
The AI Act fits into the EU's digital single market and "Brussels Effect," where EU standards influence global practices. Appointing an authorised representative signals commitment to high standards, potentially easing compliance in other jurisdictions adopting similar rules.
A professional authorised representative can handle authority interactions, documentation storage, and monitoring, allowing the non-EU company to focus on development while outsourcing localized compliance expertise.
Non-EU companies should conduct a gap analysis: classify their AI (prohibited, high-risk, limited-risk, minimal-risk), map obligations, and engage legal/compliance experts early.
Appointing an Authorised AI Representative is more than a checkbox - it is a gateway to responsible innovation in the EU. For non-EU companies, it underscores the need for global compliance strategies in an increasingly regulated AI landscape.
In summary, the Authorised Representative requirement ensures that powerful AI technologies developed anywhere in the world meet Europe's high standards for safety, transparency, and rights protection. For non-EU companies, proactive appointment is essential, not optional, for sustainable access to one of the world's largest and most influential markets. As AI evolves, those who embrace structured compliance will be best positioned to thrive globally.