AI Act, Article 22(3), points (b) and (c) (authorised representative: documents held for 10 years and access to logs)
Regulation (EU) 2024/1689, Article 22(3), points (b) and (c)
An AI governance rule binding public and private bodies.
- How the hook was established
- express
- What makes it apply
- Market targeting, Operator establishment
- Obligation class
- Governance, Retention
- Audit expectation
- on_request
- Who audits it
- Regulator
As of .
What it requires
- This duty takes effect on (Article 113, as amended by Regulation (EU) 2026/1744) for a high-risk AI system classified under Article 6(2) and Annex III, and on for one classified under Article 6(1) and Annex I, other than a system related to a product covered by the Union harmonisation legislation listed in Section B of Annex I, to which, under Article 2(2), only Article 6(1), Article 60a and Articles 102 to 112 apply, and Articles 57, 58 and 59 apply only in so far as the requirements for high-risk AI systems under this Regulation have been integrated in that Union harmonisation legislation; a system already placed on the market or put into service before its date is reached only once its design changes significantly, or by if it is intended for use by public authorities.
- It reaches you if you are the authorised representative of a provider of a high-risk AI system: you are established in the Union and have received and accepted a written mandate from a provider established in a third country, which Article 22(1) requires that provider to appoint before it makes the system available on the Union market.
- Perform the tasks specified in the mandate, which Article 22(3) says must empower you to carry out the tasks in points (b) and (c) below.
- Keep at the disposal of the competent authorities and the national authorities or bodies referred to in Article 74(10), for 10 years after the high-risk AI system has been placed on the market or put into service, the contact details of the provider that appointed you, a copy of the EU declaration of conformity, the technical documentation and, if applicable, the certificate issued by the notified body (Article 22(3), point (b)).
- When a competent authority makes a reasoned request, provide it with all the information and documentation, including the items listed in the point above, necessary to demonstrate the conformity of the high-risk AI system with the requirements of Section 2, including access to the logs automatically generated by the system, as referred to in Article 12(1), to the extent those logs are under the control of the provider (Article 22(3), point (c)).
If you get it wrong
Private right of actionNo
Penalty structure
Article 99(4)(b): non-compliance with the obligations of authorised representatives under Article 22 is fined up to EUR 15,000,000 or 3% of worldwide annual turnover, whichever is higher. Article 99(6) requires the lower of the two amounts for an SME, including a start-up; Article 99(6a), inserted by Regulation (EU) 2026/1744, gives the same lower-of treatment to a small mid-cap enterprise, since both apply to paragraph 4 fines.
- Rule
- Lower of for SME
- As of
- Currency
- EUR
- Fixed cap
- 15,000,000
- Turnover percentage cap
- 3
What it makes you log
Who may demand the log
Regulator
Log retention
Ten years after the high-risk AI system has been placed on the market or put into service, for the provider's contact details, the EU declaration of conformity, the technical documentation and the notified body's certificate that the authorised representative keeps at the competent authorities' disposal; the period is for those documents, not for the logs, whose minimum period is Article 19's.
- Unit
- Years
- As of
- Basis
- Fixed
- Maximum value
- 10
- Minimum value
- 10
Logging duty
Point (c) names access to the logs, as referred to in Article 12(1), that the system automatically generates, to the extent they are under the control of the provider, and point (b) names the documents the authorised representative keeps for 10 years. The article does not itself create the logging capability (Article 12), the provider's own keeping of the logs and their minimum period (Article 19) or the provider's own duty to give a competent authority access (Article 21(2)); it adds the authorised representative as a second route to the same logs.
- Kind
- Explicit
- As of
- Provision
- Article 22(3), points (b) and (c)
- Trigger
- high_risk_systems
What this law does
Providers established in third countries must, by written mandate, appoint an authorised representative established in the Union prior to making their high-risk AI systems available on the Union market.
An authorised representative is a natural or legal person located or established in the Union who has received and accepted a written mandate from a provider of an AI system or a general-purpose AI model to perform and carry out on its behalf the obligations and procedures established by the Regulation. For the purposes of the Regulation, the mandate empowers the authorised representative to carry out the tasks listed in Article 22(3).
Under Article 22(3), point (b), the authorised representative keeps at the disposal of the competent authorities and the national authorities or bodies referred to in Article 74(10), for a period of 10 years after the high-risk AI system has been placed on the market or put into service, the contact details of the provider that appointed it, a copy of the EU declaration of conformity, the technical documentation and, if applicable, the certificate issued by the notified body.
Under Article 22(3), point (c), the authorised representative provides a competent authority, upon a reasoned request, with all the information and documentation, including that referred to in point (b), necessary to demonstrate the conformity of a high-risk AI system with the requirements set out in Section 2, including access to the logs, as referred to in Article 12(1), automatically generated by the system, to the extent such logs are under the control of the provider.
Article 21(2) separately requires the provider itself, upon a reasoned request by a competent authority, to give that authority access to the automatically generated logs of the high-risk AI system referred to in Article 12(1), to the extent such logs are under its control. The authorised representative performs the tasks specified in the mandate it receives from the provider.
Article 22 sits in Chapter III, Section 3, so it takes effect on the schedule the Digital Omnibus on AI (Regulation (EU) 2026/1744) wrote into Article 113: for a system classified as high-risk under Article 6(2) and Annex III, and for a system classified as high-risk under Article 6(1) and Annex I, rather than the Regulation's general application date.
Under Article 111(2), as the Digital Omnibus on AI rewrote it, the Regulation reaches the operators of a high-risk AI system placed on the market or put into service before the date Chapter III applies only if, from that date, the system's design changes significantly; in any case, the providers and deployers of a high-risk AI system intended to be used by public authorities must take the necessary steps to comply with the Regulation's requirements and obligations by .
Article 22 does not apply to a high-risk AI system related to a product covered by the Union harmonisation legislation listed in Section B of Annex I, to which, under Article 2(2), only Article 6(1), Article 60a and Articles 102 to 112 apply, and Articles 57, 58 and 59 apply only in so far as the requirements for high-risk AI systems under this Regulation have been integrated in that Union harmonisation legislation.
When LexLint raises it
When your app profile says your app makes high-risk automated decisions.