EU AI Act guide: AI Act representative, CE marking and fines2026-07-24T12:11:16+00:00

EU AI Act guide: AI Act representative, CE marking and fines

Last Updated: July 24, 2026

The EU AI Act (Regulation (EU) 2024/1689) requires non-EU providers of high-risk AI systems and general-purpose AI models to appoint an EU-based authorised representative where required. Failing to meet this requirement can lead to fines of up to €15 million or 3% of worldwide annual turnover. This guide explains who needs a representative, what they do, and what to prepare.

This guide is specifically designed for you if:

  • You provide an AI system or a general-purpose AI model, and your company is not established in the EU.
  • You are not sure whether your AI system counts as high-risk under the AI Act.
  • Your product is sold through an EU distributor or reseller, and you are not sure who is legally responsible.
  • You want to understand what an AI Act representative actually does before you appoint one.
Does the EU AI Act apply to the UK?
The UK has not adopted the EU AI Act and follows its own, more principle-based approach to AI regulation. However, the EU AI Act still applies directly to any UK company that places an AI system on the EU market or puts one into service there, regardless of where the company is based.

Answers for fast readers

Do I need an AI Act representative if I’m not based in the EU?
Yes, if you provide a high-risk AI system or a general-purpose AI model to the EU market. The obligation applies regardless of your company’s size, with a narrow exemption for free and open-source GPAI models that do not present systemic risk (models the Commission has designated as capable of large-scale impact).

What happens if I don’t appoint one?
You risk administrative fines of up to €15 million or 3% of global turnover. Beyond the fine, authorities can block your AI system from the EU market or order it withdrawn, and marketplaces can suspend your listings.

Does this only affect high-risk AI, or do chatbots count too?
General-purpose AI models are covered separately from high-risk AI systems, and the representative obligation for non-EU GPAI model providers has applied since 2 August 2025. Chatbots and generative AI tools are often built on GPAI models, but the company offering the tool is not automatically the provider of the underlying model. Its obligations depend on its role and the system’s intended use.

How do I find out if my AI system is high-risk?
Check it against the Annex III use cases (biometrics, employment, education, critical infrastructure and similar) or whether it is a safety component of a regulated product under Annex I. Both are covered further down this guide.

What is the EU AI Act?

The EU AI Act, officially Regulation (EU) 2024/1689, regulates artificial intelligence using a risk-based approach. Stricter obligations apply to AI systems that create higher risks for health, safety or fundamental rights.

 

What does the AI Act mean for my company?
If you are a non-EU provider placing a high-risk AI system on the EU market, you must appoint an EU-based authorised representative and meet the applicable requirements for technical documentation, conformity assessment, an EU declaration of conformity and CE marking by the relevant deadline. Non-EU providers of general-purpose AI models must also appoint an EU-based authorised representative, unless the applicable open-source exemption applies, but follow separate documentation and GPAI obligations.

The Act divides AI into four categories:

  • Unacceptable risk (prohibited practices, banned outright)
  • High-risk (systems used in areas such as employment, education, credit scoring, critical infrastructure and biometric identification)
  • Transparency risk (where users must be told they are dealing with AI, such as chatbots)
  • and Minimal risk (most other AI systems, with no extra obligations under the Act)
AI Act risk categories

High-risk AI systems face the heaviest obligations before they reach the market:

  • Risk assessment
  • High-quality datasets
  • Logging
  • Documentation
  • Information for deployers
  • Human oversight
  • Robustness
  • Cybersecurity
  • Accuracy
What is the risk-based approach?
The AI Act does not regulate AI technology as such, it regulates what the technology is used for. The same general-purpose AI model can be low-risk in one application and high-risk in another, depending on the use case. Classifying your specific system correctly matters more than knowing the underlying technology.

What counts as a high-risk AI system under the EU AI Act?

Under the EU AI Act, an AI system is considered high-risk if it can significantly impact people’s safety, health, or fundamental rights. This includes AI built into regulated products like toys, cars, or medical devices. It also covers AI used in sensitive areas like hiring, grading students, approving loans, or law enforcement.

High-risk areas include:

  • Biometric identification and categorisation
  • Critical infrastructure
  • Education and vocational training
  • Employment and worker management
  • Access to essential services
  • Law enforcement
  • Migration and border control
  • Administration of justice
  • AI used as a safety component in regulated products

For high-risk systems, appointing an AI Act Authorised Representative is only one part of compliance. Providers also need technical documentation, a risk management system, human oversight measures, post-market monitoring, an EU declaration of conformity, conformity assessment and CE marking where required.

Which are the roles and definitions under the EU AI Act?

Role What it means
Provider The company that develops an AI system, or has one developed, and places it on the market under its own name or trademark.
Deployer A company using an AI system as part of its own operations, not the end consumer it is used on.
Importer A company established in the EU that brings an AI system from a non-EU provider into the EU market.
Distributor A company in the supply chain, other than the provider or importer, that makes the system available on the EU market.
Authorised representative An EU-based person or company appointed by written mandate to carry out specific compliance tasks for a non-EU provider.
General-purpose AI (GPAI) model An AI model trained on broad data that can competently perform a wide range of distinct tasks. The kind of technology behind tools like AI chatbots or writing assistants.
High-risk AI system A system used in a sensitive area the Act lists (Annex III, things like hiring or biometric identification), or a safety-critical part of a regulated product (Annex I, things like machinery or toys), unless a specific exception applies.

Does the AI Act affect my business?

If your business develops, sells, or puts into service an AI system, a general-purpose AI model, a chatbot, or a product with embedded AI that reaches the EU market, this regulation can apply to you, regardless of where your company is based. The scope is broad by design: a US software company, a Korean electronics manufacturer and a UK reseller can all be equally in scope, depending on their role.

What am I responsible for under the AI Act?

Responsibility follows control, not just creation. The provider that builds an AI system usually holds the primary obligations, but a distributor, importer or deployer can become the provider under Article 25, and inherit every obligation that comes with it, including appointing a representative.
As a provider, you are responsible for:

  • Classifying your AI system correctly
  • Building a risk management system
  • Keeping high-quality datasets and technical documentation
  • Giving deployers the information they need
  • Ensuring human oversight
  • Completing the correct conformity assessment before your system reaches the market
Important: If you are established outside the EU and your system is high-risk or a general-purpose AI model, you are also responsible for appointing an EU-based representative to support these obligations.
The provider principle: If you put your own brand on a high-risk AI system, substantially modify one, or repurpose an AI system so it becomes high-risk, you become the provider under Article 25, whether or not you built the underlying system.

What if I’m not the original developer of the high-risk AI system?

The AI Act does not only look at who built the system. A distributor, importer, deployer or other third party becomes the provider of a high-risk AI system in specific situations, and takes on that provider’s obligations, including the representative requirement.
This happens when a company:

  • Puts its own name or trademark on a high-risk AI system
  • Makes a substantial modification to one
  • Changes an AI system’s intended purpose so that it becomes high-risk

Who needs an AI Act representative?

Under the EU AI Act, providers located outside the European Union must appoint an authorised representative if they want to offer high-risk AI systems or general-purpose AI models in the EU. Providers of free and open-source GPAI models are exempt, unless the model is classified as presenting systemic risk.
You must appoint an AI Act representative if your company is established outside the EU, and you:

  • Provide a high-risk AI system to the EU market
  • Provide a general-purpose AI model to the EU market and the open-source exemption does not apply
  • Put your name or trademark on a high-risk AI system already placed on the EU market
  • Substantially modify a high-risk AI system and it remains high-risk
  • Change the intended purpose of a system so that it becomes high-risk

What is an AI Act Authorised Representative?

An AI Act Authorised Representative is a natural or legal person established in the EU, appointed by written mandate from a non-EU provider. The provider remains legally responsible for the AI system. The representative carries out specific mandated tasks and acts as the official EU contact point for authorities.

What does an AI Act representative do?

They must verify that your technical documentation and EU declaration of conformity are correctly prepared, keep a copy of your documentation and contact details available for authorities for ten years after your system is placed on the market, provide authorities with the information needed to prove your system’s compliance, and cooperate with any action authorities take regarding your AI system.

Checklist do you need an AI act authorised representative

Real-world scenarios

Case scenario 1:

A UK company’s EU distributor puts its own brand on an AI-powered recruitment screening tool the UK company built. Because the distributor has rebranded a high-risk system, Article 25 makes the distributor the provider, with the representative obligation that comes with it. The original UK developer is no longer the party responsible for this requirement in the EU.

Job interview

Case scenario 2:

A Korean manufacturer embeds a computer-vision AI system into industrial machinery sold in the EU. The system is a safety component of regulated machinery, so it falls under Annex I. The representative obligation for this category applies from 2 August 2028, but the manufacturer still needs its technical documentation and risk management system ready well before then.

Computer vision system in industrial robot

Case scenario 3:

A US company develops its own general-purpose AI model and integrates it into a customer service chatbot made available in the EU. As the provider of the underlying GPAI model, the company falls within the AI Act representative requirement and must appoint an EU-based authorised representative by the applicable deadline, unless the qualifying free and open-source exemption applies. A company that merely builds a chatbot using another provider’s GPAI model does not automatically become the provider of that underlying model, although it may have separate obligations as the provider of the chatbot AI system.

When must I comply with the AI Act?

The Act entered into force on 1 August 2024, and applies in stages. Prohibited practices and AI literacy obligations have applied since 2 February 2025. Governance rules and GPAI obligations have applied since 2 August 2025, with the Commission’s enforcement powers over GPAI starting 2 August 2026.
High-risk systems now follow a revised timeline agreed under the AI Omnibus simplification package on 7 May 2026.

Date What applies
2 Feb 2025 Prohibited AI practices and AI literacy obligations
2 Aug 2025 Governance rules and GPAI obligations, including the representative requirement for GPAI providers
2 Aug 2026 Commission enforcement powers over GPAI obligations
2 Dec 2027 High-risk systems in sensitive areas (biometrics, employment, education, critical infrastructure and similar), a 16-month extension on the original date
2 Aug 2028 High-risk systems embedded in regulated products (machinery, lifts, toys and similar), a 12-month extension on the original date

What conformity assessment does the EU AI Act require?

Providers of high-risk AI systems must complete the correct conformity assessment before the system reaches the market or is put into service. Some systems follow an internal control procedure. Others require a notified body. Where a high-risk AI system is already covered by existing EU harmonisation legislation, the assessment under that legislation applies, and the AI Act requirements are folded into it.
This matters for manufacturers of products that already need CE marking, such as machinery, toys or connected devices. When AI is built into the product as a safety component, the AI Act adds requirements to the existing CE marking process rather than creating a separate one.

Does the EU AI Act require CE marking?

Yes, for high-risk AI systems. Article 16 requires providers to affix the CE marking to the system, or to its packaging or documentation where that is not possible. Article 48 sets out the detail. For digitally provided systems, a digital CE marking must be used when it is easily accessible through the interface or a machine-readable code.
Where a high-risk AI system is also subject to other EU legislation requiring CE marking, the marking indicates compliance with those rules too. If a notified body is involved, its identification number appears alongside the marking.

What documentation do I need to prove compliance?

Providers of high-risk AI systems need a technical file and an EU Declaration of Conformity, covering the system’s design, its risk management measures and the conformity assessment carried out. Providers of general-purpose AI models need technical documentation covering training and testing. Both must be kept available for ten years and produced to authorities on request.

Am I liable if my AI system causes harm?

The AI Act sets safety and compliance requirements. It does not, by itself, decide who pays compensation when an AI system causes harm.
The revised Product Liability Directive (EU) 2024/2853 already treats software and AI systems as products. If a defective AI system causes death, personal injury, property damage or data loss, you can be held strictly liable as the manufacturer, without the claimant needing to prove fault. Courts can also presume a defect or a causal link where the technical complexity of an AI system would otherwise make this too difficult for a claimant to prove.

What are the penalties for non-compliance?

Fines are tiered by severity. Prohibited AI practices carry fines of up to €35 million or 7% of global turnover, whichever is higher. Non-compliance with most other obligations, including the representative requirement under Article 22, can lead to fines of up to €15 million or 3% of turnover. Supplying incorrect, incomplete or misleading information to authorities can lead to fines of up to €7.5 million or 1% of turnover. SMEs and start-ups face the lower of the two thresholds at every tier.

Fines are not the only risk. Non-compliance also brings:

  • Authority requests
  • Launch delays
  • Withdrawal from the EU market
  • Reputational damage with customers and partners
AI Act fines the three tiers infographic

How do I choose the right AI Act representative?

Look for technical and regulatory competence, the ability to verify complex technical documentation and conformity assessment procedures, not just a registered address. Look for operational capacity for the full ten-year retention period. And look for a proven liaison record with EU authorities, including experience supporting product recalls where needed.
Given the complexity of the AI Act, confirm your representative has this specific expertise, rather than offering only generalised compliance services.

How 24hour-AR can help

24hour-AR helps non-EU businesses work out what EU market access actually requires for regulated AI and traditional products. For AI Act questions, we help clarify whether you need a representative, whether your system is high-risk, whether CE marking applies, which conformity assessment route fits, and how your AI Act obligations sit alongside any existing CE marking or authorised representative arrangements you already have.
Send us your AI system’s details and we will help you identify the next step:

Conclusion

The requirement to appoint an AI Act representative is already live for providers of general-purpose AI models, and the timeline for high-risk systems now runs to December 2027 and August 2028. Waiting for your specific deadline is not the same as being ready for it. The documentation, risk classification and representative appointment all take time to get right.
If your AI system is already on the EU market without a representative, or you are planning a launch, contact our team of specialists to secure your EU market access.

Inma Antequera Content Manager

Author Inma Antequera is Content Manager at 24hour-AR, responsible for producing the guides, articles and resources that help businesses understand and meet EU and UK regulatory obligations. She combines a sharp editorial instinct with a thorough understanding of the compliance landscape to make complex requirements accessible to a global audience.

Frequently asked questions

What is an AI Act representative?2026-07-23T14:00:28+00:00

An AI Act representative is an EU-based authorised representative appointed by a non-EU provider of a high-risk AI system or general-purpose AI model. The representative is the official EU contact point and keeps compliance documentation available for authorities for ten years.

Is an AI Act representative the same as a CE marking authorised representative?2026-07-23T14:00:46+00:00

No. They are separate roles with separate legal bases and mandates. One organisation can hold both only if formally appointed for both and competent to carry out both sets of tasks.

Does the EU AI Act require CE marking?2026-07-23T14:01:14+00:00

Yes, for high-risk AI systems. Providers must affix the CE marking to the system, or to its packaging or documentation where that is not possible. For digitally provided systems, a digital CE marking must be used when it is easily accessible.

What is the deadline for appointing an AI Act representative?2026-07-23T14:02:14+00:00

For general-purpose AI models, the obligation has applied since 2 August 2025. For high-risk systems in sensitive areas, the current timeline points to 2 December 2027. For high-risk systems embedded in regulated products, it points to 2 August 2028.

Can I still be liable for AI harm if I’ve appointed a representative?2026-07-23T14:02:33+00:00

Yes. Appointing a representative satisfies the AI Act’s compliance requirement. It does not remove liability for harm caused by a defective AI system under the Product Liability Directive, or under national fault-based liability rules.

Do US or UK companies need an AI Act representative?2026-07-23T14:02:51+00:00

Yes, when they are established outside the EU and provide a high-risk AI system or a general-purpose AI model to the EU market, unless the open-source GPAI exemption applies.

Does the EU AI Act apply to open-source AI models?2026-07-23T14:03:07+00:00

Free and open-source GPAI models are generally exempt from the representative requirement, unless the model is classified as presenting systemic risk, in which case the obligation applies as normal.

What are the EU AI Act fines?2026-07-23T14:03:24+00:00

Up to €35 million or 7% of global turnover for prohibited practices, up to €15 million or 3% for most other obligations including the representative requirement, and up to €7.5 million or 1% for supplying incorrect information to authorities.

Can 24hour-AR help with AI Act CE marking?2026-07-23T14:03:38+00:00

Yes. We help companies work out whether EU AI Act CE marking applies and how it interacts with any existing CE marking obligations, which matters most when an AI system is part of a regulated physical product.

Go to Top