Art.23
EU AI Act Guide › Chapter III — High-Risk AI Systems › Article 23

Article 23 — Obligations of Importers of High-Risk AI Systems

Governance SME Relevant ~3 min read · 516 words

Article 23 defines the compliance obligations of importers — companies that bring high-risk AI systems developed outside the EU into the European market. Importers are not passive intermediaries under the AI Act. They carry significant verification, disclosure, and corrective action responsibilities of their own.

! High compliance impact for SMEs

WHAT THE ARTICLE IS ABOUT

The compliance gatekeeper role of EU importers

Article 23 establishes the obligations of importers of high-risk AI systems. An importer is any EU-established entity that places on the EU market an AI system bearing the name or trademark of a non-EU provider. The article makes importers active compliance participants — they must verify, disclose, and in some cases halt the market placement of non-compliant systems.

WHAT IT SAYS

Verify before placing, disclose your identity, retain records

WHO IS AFFECTED

EU businesses that act as the market entry point for non-EU AI

  • Any EU-established company that imports high-risk AI systems developed and produced outside the EU
  • EU subsidiaries of non-EU AI companies that place the parent company’s systems on the EU market
  • Distributors who also act as importers in their supply chain role
  • Companies that sometimes serve as both authorised representative and importer for a non-EU provider

WHAT IT MEANS FOR SMES

Due diligence before you import — not after

  • If you import and resell AI systems from non-EU providers, you are not just a reseller — you are a regulated importer with legal obligations under the AI Act
  • Your primary protection is due diligence before importing: request and verify the CE marking, the EU declaration of conformity, and the technical documentation from the provider before placing any system on the market
  • If a provider cannot supply these documents, do not import the system — placing a non-compliant system on the market creates direct liability for you
  • The ten-year documentation retention obligation mirrors the provider’s obligation — budget for secure long-term document storage from the start of any import relationship
  • Contractually: ensure your import agreements with non-EU providers clearly allocate responsibility for compliance documentation, CE marking, and corrective actions — do not assume the provider will handle everything

Related Articles

← Previous Art. 22 — Authorised Representatives of Providers of High-Risk AI Systems Next → Art. 24 — Obligations of Distributors