WHAT THE ARTICLE IS ABOUT
The compliance gatekeeper role of EU importers
Article 23 establishes the obligations of importers of high-risk AI systems. An importer is any EU-established entity that places on the EU market an AI system bearing the name or trademark of a non-EU provider. The article makes importers active compliance participants — they must verify, disclose, and in some cases halt the market placement of non-compliant systems.
WHAT IT SAYS
Verify before placing, disclose your identity, retain records
- Before placing a high-risk AI system on the market, importers must verify that the provider has carried out the relevant conformity assessment, that technical documentation has been drawn up, that the system bears the CE marking, and that the provider has appointed an authorised representative
- Where an importer has reason to believe a system is not in conformity, or that its documentation is falsified, they must not place it on the market until it is brought into compliance
- Where the system presents a risk, the importer must inform the provider, the authorised representative, and market surveillance authorities
- Importers must indicate their name, trade name or trademark, and contact address on the system or its packaging
- Importers must ensure that storage and transport conditions do not jeopardise the system’s compliance with the requirements
- Importers must keep a copy of the EU declaration of conformity for ten years and make the technical documentation available to authorities on request
- Importers must cooperate with competent authorities in any action taken regarding a system they have placed on the market
WHO IS AFFECTED
EU businesses that act as the market entry point for non-EU AI
- Any EU-established company that imports high-risk AI systems developed and produced outside the EU
- EU subsidiaries of non-EU AI companies that place the parent company’s systems on the EU market
- Distributors who also act as importers in their supply chain role
- Companies that sometimes serve as both authorised representative and importer for a non-EU provider
WHAT IT MEANS FOR SMES
Due diligence before you import — not after
- If you import and resell AI systems from non-EU providers, you are not just a reseller — you are a regulated importer with legal obligations under the AI Act
- Your primary protection is due diligence before importing: request and verify the CE marking, the EU declaration of conformity, and the technical documentation from the provider before placing any system on the market
- If a provider cannot supply these documents, do not import the system — placing a non-compliant system on the market creates direct liability for you
- The ten-year documentation retention obligation mirrors the provider’s obligation — budget for secure long-term document storage from the start of any import relationship
- Contractually: ensure your import agreements with non-EU providers clearly allocate responsibility for compliance documentation, CE marking, and corrective actions — do not assume the provider will handle everything
Related Articles
- Article 22 — Authorised representatives (importers and representatives often overlap in role)
- Article 24 — Obligations of distributors (the next link in the supply chain)
- Article 25 — Responsibilities along the AI value chain (when importers become providers)
- Article 47 — EU declaration of conformity (the document importers must verify and retain)
