The classic trap
Recital 82 clarifies the obligation for non-EU providers to appoint an authorised representative established in the Union before placing any high-risk AI system on the market. In practice, many US, UK or Asian vendors distribute their solutions through Luxembourg integrators as white-label products, without a compliant written mandate. The EU AI Office and the future Luxembourg AI market surveillance authority can request this mandate during an inspection, and absent it, liability falls back to the Luxembourg importer or deployer. The CNPD remains competent on the personal data side whenever the AI system processes personal data.
What the written mandate must contain under Article 22
- Verification that technical documentation (Annex IV) and the EU declaration of conformity have been drawn up by the non-EU provider.
- Retention of the mandate, technical documentation and declaration of conformity at the disposal of authorities for 10 years.
- Cooperation with national competent authorities on any action aimed at reducing or mitigating risks.
- Provision, upon reasoned request, of all information and documents necessary to demonstrate compliance, in an official language of the Member State.
- Termination of the mandate if the provider acts contrary to the Regulation, with immediate notification to the surveillance authority and the AI Office.
- Clear identification of the authorised representative in the documentation accompanying the high-risk AI system.
The Luxembourg-specific trap
The Luxembourg market is heavily supplied by non-European AI vendors (US, UK, Israel, Switzerland). Many SMEs and financial players buy these solutions via a local reseller or directly as SaaS, without checking whether an EU authorised representative exists. The result: during an inspection, the Luxembourg deployer is left alone facing the authority, with no European point of contact for the provider. Mandate verification must therefore become a blocking checkpoint in your AI procurement due diligence.
How Luxgap automates this risk
Our Luxgap AI Vendor Origin Tracer eliminates the blind spot of non-EU AI providers by automatically mapping the actual legal origin of every AI system deployed in your IT estate, and by verifying the existence and validity of the Article 22 EU authorised representative. The tool cross-references your Odoo contracts, your SaaS subscriptions via Microsoft Cloud App Security, your payment flows and public registries (Companies House, EU commercial registers, OpenCorporates) to reconstruct the real supplier chain behind white labels and local resellers.
- Automatically detects every new AI system introduced into your IT estate through M365, Azure, AWS, Google Workspace connectors and your ERP APIs.
- Identifies the actual legal entity of the provider (registered office, country of incorporation) beyond Luxembourg resellers and integrators.
- Verifies the existence of the EU authorised representative, its address, the validity of its written mandate and its alignment with AI Act Article 22 requirements.
- Alerts via Teams or email as soon as a non-EU provider is detected without a valid authorised representative, with recommended action (purchase suspension, mandate request, DPO escalation).
- Generates an enforceable register of the EU authorised representatives of your AI providers, timestamped and cryptographically signed, ready to be produced during an inspection.
- Produces a consolidated non-EU exposure score, updated in real time, to steer your AI committee and procurement committee.
Available as a complement to a Luxgap DPO or CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your real AI providers, with a free scan within 48h to materialise your non-EU exposure before any engagement.