Importers, distributors, and the obligation matrix

Lesson 3 of 5 in The Value Chain: Providers, Deployers, Importers, Distributors.

Importers and distributors write no code and choose no use case — so the Act makes them paperwork gatekeepers. Their duties are verification duties, and their power is the power to refuse to pass the product along.

An importer (Art 23) must, before placing a high-risk system on the market, verify that the provider carried out the conformity assessment, drew up the technical documentation, affixed the CE marking, issued the declaration of conformity and instructions for use, and appointed an authorised representative. Where the importer has sufficient reason to consider the system non-conforming, falsified or accompanied by falsified documentation, it must not place it on the market until conformity is achieved — and where the system presents an Art 79(1) risk, it must inform the provider, the authorised representative and the market surveillance authorities. Importers also add their own name and address to the system or packaging, ensure storage and transport do not jeopardise compliance, and keep a copy of the certificate, instructions and declaration for 10 years.

A distributor (Art 24) runs a lighter check: CE marking present, declaration of conformity and instructions for use included, provider and importer identity-marking duties met. Same withhold-and-inform logic; plus a duty to take or trigger corrective action for systems it has already made available, and to hand authorities information on request.

Obligation-by-role matrix for high-risk AI systems (● = primary duty holder, ○ = verification or supporting duty)
ObligationProviderAuth. rep.ImporterDistributorDeployer

Arts 8–15 substantive compliance

● Art 16(a)

Quality management system

● Art 17

Conformity assessment

● Art 43

○ verify done (Art 22)

○ verify done (Art 23)

Technical documentation

● draw up, keep 10y (Arts 11, 18)

○ keep available 10y

○ verify drawn up; keep copy 10y

CE marking + declaration

● affix + issue (Arts 47–48)

○ verify affixed

○ verify present

Identity marking

● name + address (Art 16(b))

● add own name (Art 23(3))

○ verify both

EU database registration

● Art 49(1)

● public bodies register use; verify system registered (Art 26, Art 49(3))

Withhold non-conforming system

○ terminate mandate (Art 22(4))

● Art 23(2)

● Art 24(2)

○ suspend use on risk (Art 26(5))

Use per instructions + oversight

○ design for it (Arts 13–14)

● Art 26(1)–(2)

Input-data relevance

● Art 26(4)

Logs

● keep those under its control (Art 19)

● keep ≥6 months (Art 26(6))

Monitor + report risk / incidents

● Arts 20, 72–73

○ cooperate

○ inform on risk

○ inform on risk

● monitor, inform provider + authority (Art 26(5))

Inform workers before workplace use

● Art 26(7)

FRIA

● Art 27 (qualifying deployers)

Cooperate with authorities

● Art 21

● Art 22(3)

● Art 23(7)

● Art 24(6)

● Art 26(12)

Read the matrix column-wise and the Act’s logic surfaces. The provider column is dense at the top: design-time duties. The deployer column is dense at the bottom: use-time duties. The middle columns are almost entirely ○ marks — verification, withholding, informing. And notice the row where every column has an entry: cooperation with authorities. No role, however passive, is invisible to enforcement.

One more pattern worth memorising: the duties that protect people rather than paperwork — worker information, FRIA, informing persons subject to decisions, suspension on risk — cluster in the deployer column. The provider knows the system; only the deployer knows the people in front of it.

Interactive checkpoint quiz (1 questions) — open this page in a browser to take it.