EU AI Act guide: AI Act representative, CE marking and fines
The EU AI Act (Regulation (EU) 2024/1689) requires non-EU providers of high-risk AI systems and general-purpose AI models to appoint an EU-based authorised representative where required. Failing to meet this requirement can lead to fines of up to €15 million or 3% of worldwide annual turnover. This guide explains who needs a representative, what they do, and what to prepare.
This guide is specifically designed for you if:
Answers for fast readers
Do I need an AI Act representative if I’m not based in the EU?
Yes, if you provide a high-risk AI system or a general-purpose AI model to the EU market. The obligation applies regardless of your company’s size, with a narrow exemption for free and open-source GPAI models that do not present systemic risk (models the Commission has designated as capable of large-scale impact).
What happens if I don’t appoint one?
You risk administrative fines of up to €15 million or 3% of global turnover. Beyond the fine, authorities can block your AI system from the EU market or order it withdrawn, and marketplaces can suspend your listings.
Does this only affect high-risk AI, or do chatbots count too?
General-purpose AI models are covered separately from high-risk AI systems, and the representative obligation for non-EU GPAI model providers has applied since 2 August 2025. Chatbots and generative AI tools are often built on GPAI models, but the company offering the tool is not automatically the provider of the underlying model. Its obligations depend on its role and the system’s intended use.
How do I find out if my AI system is high-risk?
Check it against the Annex III use cases (biometrics, employment, education, critical infrastructure and similar) or whether it is a safety component of a regulated product under Annex I. Both are covered further down this guide.
What is the EU AI Act?
The EU AI Act, officially Regulation (EU) 2024/1689, regulates artificial intelligence using a risk-based approach. Stricter obligations apply to AI systems that create higher risks for health, safety or fundamental rights.
The Act divides AI into four categories:

High-risk AI systems face the heaviest obligations before they reach the market:
- Risk assessment
- High-quality datasets
- Logging
- Documentation
- Information for deployers
- Human oversight
- Robustness
- Cybersecurity
- Accuracy
What counts as a high-risk AI system under the EU AI Act?
Under the EU AI Act, an AI system is considered high-risk if it can significantly impact people’s safety, health, or fundamental rights. This includes AI built into regulated products like toys, cars, or medical devices. It also covers AI used in sensitive areas like hiring, grading students, approving loans, or law enforcement.
High-risk areas include:
For high-risk systems, appointing an AI Act Authorised Representative is only one part of compliance. Providers also need technical documentation, a risk management system, human oversight measures, post-market monitoring, an EU declaration of conformity, conformity assessment and CE marking where required.
Which are the roles and definitions under the EU AI Act?
| Role | What it means |
|---|---|
| Provider | The company that develops an AI system, or has one developed, and places it on the market under its own name or trademark. |
| Deployer | A company using an AI system as part of its own operations, not the end consumer it is used on. |
| Importer | A company established in the EU that brings an AI system from a non-EU provider into the EU market. |
| Distributor | A company in the supply chain, other than the provider or importer, that makes the system available on the EU market. |
| Authorised representative | An EU-based person or company appointed by written mandate to carry out specific compliance tasks for a non-EU provider. |
| General-purpose AI (GPAI) model | An AI model trained on broad data that can competently perform a wide range of distinct tasks. The kind of technology behind tools like AI chatbots or writing assistants. |
| High-risk AI system | A system used in a sensitive area the Act lists (Annex III, things like hiring or biometric identification), or a safety-critical part of a regulated product (Annex I, things like machinery or toys), unless a specific exception applies. |
Does the AI Act affect my business?
If your business develops, sells, or puts into service an AI system, a general-purpose AI model, a chatbot, or a product with embedded AI that reaches the EU market, this regulation can apply to you, regardless of where your company is based. The scope is broad by design: a US software company, a Korean electronics manufacturer and a UK reseller can all be equally in scope, depending on their role.
What am I responsible for under the AI Act?
Responsibility follows control, not just creation. The provider that builds an AI system usually holds the primary obligations, but a distributor, importer or deployer can become the provider under Article 25, and inherit every obligation that comes with it, including appointing a representative.
As a provider, you are responsible for:
- Classifying your AI system correctly
- Building a risk management system
- Keeping high-quality datasets and technical documentation
- Giving deployers the information they need
- Ensuring human oversight
- Completing the correct conformity assessment before your system reaches the market
What if I’m not the original developer of the high-risk AI system?
The AI Act does not only look at who built the system. A distributor, importer, deployer or other third party becomes the provider of a high-risk AI system in specific situations, and takes on that provider’s obligations, including the representative requirement.
This happens when a company:
- Puts its own name or trademark on a high-risk AI system
- Makes a substantial modification to one
- Changes an AI system’s intended purpose so that it becomes high-risk
Who needs an AI Act representative?
Under the EU AI Act, providers located outside the European Union must appoint an authorised representative if they want to offer high-risk AI systems or general-purpose AI models in the EU. Providers of free and open-source GPAI models are exempt, unless the model is classified as presenting systemic risk.
You must appoint an AI Act representative if your company is established outside the EU, and you:
What is an AI Act Authorised Representative?
An AI Act Authorised Representative is a natural or legal person established in the EU, appointed by written mandate from a non-EU provider. The provider remains legally responsible for the AI system. The representative carries out specific mandated tasks and acts as the official EU contact point for authorities.
What does an AI Act representative do?
They must verify that your technical documentation and EU declaration of conformity are correctly prepared, keep a copy of your documentation and contact details available for authorities for ten years after your system is placed on the market, provide authorities with the information needed to prove your system’s compliance, and cooperate with any action authorities take regarding your AI system.

Real-world scenarios
When must I comply with the AI Act?
The Act entered into force on 1 August 2024, and applies in stages. Prohibited practices and AI literacy obligations have applied since 2 February 2025. Governance rules and GPAI obligations have applied since 2 August 2025, with the Commission’s enforcement powers over GPAI starting 2 August 2026.
High-risk systems now follow a revised timeline agreed under the AI Omnibus simplification package on 7 May 2026.
| Date | What applies |
|---|---|
| 2 Feb 2025 | Prohibited AI practices and AI literacy obligations |
| 2 Aug 2025 | Governance rules and GPAI obligations, including the representative requirement for GPAI providers |
| 2 Aug 2026 | Commission enforcement powers over GPAI obligations |
| 2 Dec 2027 | High-risk systems in sensitive areas (biometrics, employment, education, critical infrastructure and similar), a 16-month extension on the original date |
| 2 Aug 2028 | High-risk systems embedded in regulated products (machinery, lifts, toys and similar), a 12-month extension on the original date |
What conformity assessment does the EU AI Act require?
Providers of high-risk AI systems must complete the correct conformity assessment before the system reaches the market or is put into service. Some systems follow an internal control procedure. Others require a notified body. Where a high-risk AI system is already covered by existing EU harmonisation legislation, the assessment under that legislation applies, and the AI Act requirements are folded into it.
This matters for manufacturers of products that already need CE marking, such as machinery, toys or connected devices. When AI is built into the product as a safety component, the AI Act adds requirements to the existing CE marking process rather than creating a separate one.
Does the EU AI Act require CE marking?
Yes, for high-risk AI systems. Article 16 requires providers to affix the CE marking to the system, or to its packaging or documentation where that is not possible. Article 48 sets out the detail. For digitally provided systems, a digital CE marking must be used when it is easily accessible through the interface or a machine-readable code.
Where a high-risk AI system is also subject to other EU legislation requiring CE marking, the marking indicates compliance with those rules too. If a notified body is involved, its identification number appears alongside the marking.
What documentation do I need to prove compliance?
Providers of high-risk AI systems need a technical file and an EU Declaration of Conformity, covering the system’s design, its risk management measures and the conformity assessment carried out. Providers of general-purpose AI models need technical documentation covering training and testing. Both must be kept available for ten years and produced to authorities on request.
Am I liable if my AI system causes harm?
The AI Act sets safety and compliance requirements. It does not, by itself, decide who pays compensation when an AI system causes harm.
The revised Product Liability Directive (EU) 2024/2853 already treats software and AI systems as products. If a defective AI system causes death, personal injury, property damage or data loss, you can be held strictly liable as the manufacturer, without the claimant needing to prove fault. Courts can also presume a defect or a causal link where the technical complexity of an AI system would otherwise make this too difficult for a claimant to prove.
What are the penalties for non-compliance?
Fines are tiered by severity. Prohibited AI practices carry fines of up to €35 million or 7% of global turnover, whichever is higher. Non-compliance with most other obligations, including the representative requirement under Article 22, can lead to fines of up to €15 million or 3% of turnover. Supplying incorrect, incomplete or misleading information to authorities can lead to fines of up to €7.5 million or 1% of turnover. SMEs and start-ups face the lower of the two thresholds at every tier.
Fines are not the only risk. Non-compliance also brings:
- Authority requests
- Launch delays
- Withdrawal from the EU market
- Reputational damage with customers and partners

How do I choose the right AI Act representative?
Look for technical and regulatory competence, the ability to verify complex technical documentation and conformity assessment procedures, not just a registered address. Look for operational capacity for the full ten-year retention period. And look for a proven liaison record with EU authorities, including experience supporting product recalls where needed.
Given the complexity of the AI Act, confirm your representative has this specific expertise, rather than offering only generalised compliance services.
How 24hour-AR can help
24hour-AR helps non-EU businesses work out what EU market access actually requires for regulated AI and traditional products. For AI Act questions, we help clarify whether you need a representative, whether your system is high-risk, whether CE marking applies, which conformity assessment route fits, and how your AI Act obligations sit alongside any existing CE marking or authorised representative arrangements you already have.
Send us your AI system’s details and we will help you identify the next step:
Conclusion
The requirement to appoint an AI Act representative is already live for providers of general-purpose AI models, and the timeline for high-risk systems now runs to December 2027 and August 2028. Waiting for your specific deadline is not the same as being ready for it. The documentation, risk classification and representative appointment all take time to get right.
If your AI system is already on the EU market without a representative, or you are planning a launch, contact our team of specialists to secure your EU market access.
Author Inma Antequera is Content Manager at 24hour-AR, responsible for producing the guides, articles and resources that help businesses understand and meet EU and UK regulatory obligations. She combines a sharp editorial instinct with a thorough understanding of the compliance landscape to make complex requirements accessible to a global audience.




