Law / European Union

AI Act, Article 22(3), points (b) and (c) (authorised representative: documents held for 10 years and access to logs)

Regulation (EU) 2024/1689, Article 22(3), points (b) and (c)

An AI governance rule binding public and private bodies.

How the hook was established
express
What makes it apply
Market targeting, Operator establishment
Obligation class
Governance, Retention
Audit expectation
on_request
Who audits it
Regulator

As of .

What it requires

  • This duty takes effect on (Article 113, as amended by Regulation (EU) 2026/1744) for a high-risk AI system classified under Article 6(2) and Annex III, and on for one classified under Article 6(1) and Annex I, other than a system related to a product covered by the Union harmonisation legislation listed in Section B of Annex I, to which, under Article 2(2), only Article 6(1), Article 60a and Articles 102 to 112 apply, and Articles 57, 58 and 59 apply only in so far as the requirements for high-risk AI systems under this Regulation have been integrated in that Union harmonisation legislation; a system already placed on the market or put into service before its date is reached only once its design changes significantly, or by if it is intended for use by public authorities.
  • It reaches you if you are the authorised representative of a provider of a high-risk AI system: you are established in the Union and have received and accepted a written mandate from a provider established in a third country, which Article 22(1) requires that provider to appoint before it makes the system available on the Union market.
  • Perform the tasks specified in the mandate, which Article 22(3) says must empower you to carry out the tasks in points (b) and (c) below.
  • Keep at the disposal of the competent authorities and the national authorities or bodies referred to in Article 74(10), for 10 years after the high-risk AI system has been placed on the market or put into service, the contact details of the provider that appointed you, a copy of the EU declaration of conformity, the technical documentation and, if applicable, the certificate issued by the notified body (Article 22(3), point (b)).
  • When a competent authority makes a reasoned request, provide it with all the information and documentation, including the items listed in the point above, necessary to demonstrate the conformity of the high-risk AI system with the requirements of Section 2, including access to the logs automatically generated by the system, as referred to in Article 12(1), to the extent those logs are under the control of the provider (Article 22(3), point (c)).

If you get it wrong

Private right of actionNo

Penalty structure

Article 99(4)(b): non-compliance with the obligations of authorised representatives under Article 22 is fined up to EUR 15,000,000 or 3% of worldwide annual turnover, whichever is higher. Article 99(6) requires the lower of the two amounts for an SME, including a start-up; Article 99(6a), inserted by Regulation (EU) 2026/1744, gives the same lower-of treatment to a small mid-cap enterprise, since both apply to paragraph 4 fines.

Rule
Lower of for SME
As of
Currency
EUR
Fixed cap
15,000,000
Turnover percentage cap
3

What it makes you log

Who may demand the log

Regulator

Log retention

Ten years after the high-risk AI system has been placed on the market or put into service, for the provider's contact details, the EU declaration of conformity, the technical documentation and the notified body's certificate that the authorised representative keeps at the competent authorities' disposal; the period is for those documents, not for the logs, whose minimum period is Article 19's.

Unit
Years
As of
Basis
Fixed
Maximum value
10
Minimum value
10

Logging duty

Point (c) names access to the logs, as referred to in Article 12(1), that the system automatically generates, to the extent they are under the control of the provider, and point (b) names the documents the authorised representative keeps for 10 years. The article does not itself create the logging capability (Article 12), the provider's own keeping of the logs and their minimum period (Article 19) or the provider's own duty to give a competent authority access (Article 21(2)); it adds the authorised representative as a second route to the same logs.

Kind
Explicit
As of
Provision
Article 22(3), points (b) and (c)
Trigger
high_risk_systems

What this law does

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

Research summary

Legal information, not legal advice. This is LexLint's own research summary of a public legal source, and it creates no attorney-client relationship. For decisions that matter, consult qualified counsel in the relevant jurisdiction. About LexLint

Providers established in third countries must, by written mandate, appoint an authorised representative established in the Union prior to making their high-risk AI systems available on the Union market.

An authorised representative is a natural or legal person located or established in the Union who has received and accepted a written mandate from a provider of an AI system or a general-purpose AI model to perform and carry out on its behalf the obligations and procedures established by the Regulation. For the purposes of the Regulation, the mandate empowers the authorised representative to carry out the tasks listed in Article 22(3).

Under Article 22(3), point (b), the authorised representative keeps at the disposal of the competent authorities and the national authorities or bodies referred to in Article 74(10), for a period of 10 years after the high-risk AI system has been placed on the market or put into service, the contact details of the provider that appointed it, a copy of the EU declaration of conformity, the technical documentation and, if applicable, the certificate issued by the notified body.

Under Article 22(3), point (c), the authorised representative provides a competent authority, upon a reasoned request, with all the information and documentation, including that referred to in point (b), necessary to demonstrate the conformity of a high-risk AI system with the requirements set out in Section 2, including access to the logs, as referred to in Article 12(1), automatically generated by the system, to the extent such logs are under the control of the provider.

Article 21(2) separately requires the provider itself, upon a reasoned request by a competent authority, to give that authority access to the automatically generated logs of the high-risk AI system referred to in Article 12(1), to the extent such logs are under its control. The authorised representative performs the tasks specified in the mandate it receives from the provider.

Article 22 sits in Chapter III, Section 3, so it takes effect on the schedule the Digital Omnibus on AI (Regulation (EU) 2026/1744) wrote into Article 113: for a system classified as high-risk under Article 6(2) and Annex III, and for a system classified as high-risk under Article 6(1) and Annex I, rather than the Regulation's general application date.

Under Article 111(2), as the Digital Omnibus on AI rewrote it, the Regulation reaches the operators of a high-risk AI system placed on the market or put into service before the date Chapter III applies only if, from that date, the system's design changes significantly; in any case, the providers and deployers of a high-risk AI system intended to be used by public authorities must take the necessary steps to comply with the Regulation's requirements and obligations by .

Article 22 does not apply to a high-risk AI system related to a product covered by the Union harmonisation legislation listed in Section B of Annex I, to which, under Article 2(2), only Article 6(1), Article 60a and Articles 102 to 112 apply, and Articles 57, 58 and 59 apply only in so far as the requirements for high-risk AI systems under this Regulation have been integrated in that Union harmonisation legislation.

When LexLint raises it

When your app profile says your app makes high-risk automated decisions.

Back to the example  ·  Lint your app