EU AI Act Distributor Obligations: What Article 24 Requires Before, During, and After You Make a High-Risk System Available
EU AI Act Article 24 distributor duties: verify CE marking, the declaration of conformity and instructions, preserve conformity, act on non-conformity.
You resell a high-risk AI system you neither built nor imported — and you assume the provider's paperwork is somebody else's problem. It is not. The moment your firm makes that system available on the Union market, Article 24 of Regulation (EU) 2024/1689 puts five concrete duties on you, spanning the moment before you ship, the time the system sits under your control, and the day a customer reports it misbehaving. This page walks Article 24 clause by clause.
Who counts as a distributor, and why Article 24 applies to you
A distributor is any natural or legal person in the supply chain, other than the provider or the importer, that makes an AI system available on the Union market (Article 3(7)). The trigger is commercial availability, not technical contact: you can be a distributor without ever touching the system's code.
Two defined terms set the boundary. Making available means supplying an AI system for distribution or use on the EU market in the course of a commercial activity, whether for payment or free of charge (Article 3(10)); placing on the market is the first such supply (Article 3(9)). The provider or importer places it; everyone further down the chain who supplies it again is making it available — and is a distributor.
Resellers, value-added resellers, channel partners and B2B marketplaces that neither developed nor imported the system typically sit here. Distributor duties bite specifically on high-risk AI systems — the stand-alone Annex III use cases and the Annex I safety components — so the checklist below presupposes a product already conformity-assessed and CE-marked upstream.
The page is organised around three phases: what you check before making a system available, the conditions you preserve while it is under your control, and what you do when something is wrong.
Article 24 clause by clause: the five distributor duties
Pre-availability verification (Article 24(1))
Before making a high-risk AI system available, you must verify four things: that the CE marking is affixed (Article 48); that the system is accompanied by the EU declaration of conformity (Article 47) and the instructions for use (Article 13); that the provider has complied with Article 16; and, where a non-EU provider is involved, that the importer has complied with Article 23. You inspect evidence, not re-run anything.
Do not make a non-conforming system available (Article 24(2))
If you consider, or have reason to consider, that the system is not in conformity, you must not make it available until conformity has been restored (Article 24(2)). A missing declaration, an absent CE marking, or instructions your deployers cannot read each stop the shipment.
Preserve conformity in storage and transport (Article 24(1), final subparagraph)
While the system is under your responsibility, storage and transport conditions must not jeopardise its compliance with the high-risk requirements of Section 2 — for software-delivered systems, that reads onto configuration, versioning and deployment-package integrity.
Corrective action and authority notification (Article 24(3) and (4))
If you have reason to believe an already-distributed system is non-conforming, you must take corrective action — bring it into conformity, withdraw it, or recall it — and immediately inform the provider or importer and the competent authorities (Article 24(4)). Where it presents a risk, also inform the relevant national authorities (Article 24(3)).
Cooperation and information on request (Article 24(6))
On a reasoned request from a competent authority, you must provide all the information and documentation needed to demonstrate conformity, and cooperate on any action taken (Article 24(6)).
Distributor duties are deliberately lighter than provider duties. You verify and you preserve; you do not run the conformity assessment, draw up the Annex IV technical documentation, or affix the CE marking yourself.
The distributor verification checklist
Every pre-availability check maps to a governing Article and the artefact that evidences it. The distributor reviews that evidence; it does not re-perform the conformity assessment under Article 43, which stays with the provider.
| Check | Article | Artefact to obtain or inspect | If it fails |
|---|---|---|---|
| CE marking is affixed | Article 48 | CE mark on the system, packaging or documentation | Do not make available (Article 24(2)) |
| EU declaration of conformity accompanies the system | Article 47 | Signed written declaration | Do not make available (Article 24(2)) |
| Instructions for use are present and intelligible | Article 13 | Instructions in a language deployers understand | Do not make available (Article 24(2)) |
| Provider met its obligations | Article 16 | Evidence of conformity assessment, documentation, registration | Do not make available (Article 24(2)) |
| Importer met its obligations (non-EU provider) | Article 23 | Importer name/address on system; retained records | Do not make available (Article 24(2)) |
| Storage and transport preserve conformity | Article 24(1) | Package integrity, configuration, version control | Remediate before supply |
This table is distributor-scoped. It omits the importer-only steps — marking your own name and address on the system, ten-year retention of the declaration of conformity, and confirming an authorised representative under Article 22 — which are not distributor duties.
Distributor vs importer: parallel duties, different positions in the chain
Both roles verify much the same artefacts but sit at different points in the chain. An importer (Article 23) is the first EU-established party for a system whose provider sits outside the Union; a distributor (Article 24) is everyone further down the chain who makes that system available.
Importers carry the heavier load: they must indicate their own name and address on the system, retain the declaration of conformity and the certificate for ten years, and confirm the non-EU provider appointed an authorised representative under Article 22. Distributors carry neither obligation.
The same company can be both for different products. If a non-EU developer's system enters the EU through your firm under your name, you are the importer; if you resell a system already placed on the EU market, you are the distributor.
When a distributor becomes a provider: the Article 25 flip
This is the trap. Article 25(1) reclassifies a distributor (or an importer, or a deployer) as the provider of a high-risk system in three situations: putting its name or trademark on the system; making a substantial modification (Article 3(23)) that keeps it high-risk; or modifying the intended purpose of a non-high-risk system so that it becomes high-risk.
A substantial modification under Article 3(23) is a change not foreseen in the initial conformity assessment that affects compliance with Section 2 or alters the intended purpose — white-labelling, retraining, or repurposing all qualify.
Once reclassified, the original provider's Article 16 obligations no longer apply to it for that system, though it must still cooperate and supply the information needed (Article 25(2)). The new provider inherits the whole stack: risk management (Article 9), data governance (Article 10), Annex IV technical documentation (Article 11), conformity assessment (Article 43), CE marking (Article 48), the declaration of conformity (Article 47), and database registration (Article 49).
The bright line: if the system you sell is the same one the provider declared conformity on, and it carries the provider's name, you are distributing — not providing.
Worked example: a regional reseller of a high-risk credit-scoring system
Iberia Risk Solutions is a 60-person, Madrid-based fintech reseller. It distributes a creditworthiness-scoring AI system — high-risk under Annex III point 5(b) — built by an EU provider, to Spanish credit unions. It built nothing and imports nothing: it is a distributor.
Phase 1 — before making available. Iberia Risk inspects the CE marking (Article 48), files the declaration of conformity (Article 47), confirms Spanish-language instructions for use (Article 13), and satisfies itself the provider met Article 16. All checks pass, so it distributes lawfully.
Phase 2 — preserving conformity. It stores the deployment package and configuration so storage conditions do not degrade the documented conformity (Article 24(1)).
Phase 3 — non-conformity. A credit union reports the scoring model behaving outside its documented limitations. Iberia Risk takes corrective action, notifies the provider and the relevant Spanish competent authority, and supplies documentation on request (Article 24(4) and (6)).
The counterfactual. Had Iberia Risk rebranded the tool under its own name, or retrained it for a new use, Article 25 would flip it into the provider role — triggering a fresh conformity assessment (Article 43) and database registration (Article 49).
Penalties, deadlines, and how Confir helps
Breach of Article 24 falls under Article 99(4): fines up to €15 million or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher. For SMEs and start-ups, Article 99(6) caps the fine at the lower of the two figures. Trigger Article 25 and then fail the provider stack, and you face the same Article 99(4) tier.
On timing: the statute originally set high-risk obligations for stand-alone Annex III systems (Article 6(2)) at 2 August 2026. The Digital Omnibus, which reached provisional agreement on 6–7 May 2026 (COREPER around 13 May), is now adopted — the European Parliament passed it on 16 June 2026 and the Council on 29 June 2026 — deferring stand-alone Annex III to 2 December 2027 and Annex I product-embedded systems to 2 August 2028. It enters into force on publication in the Official Journal (Article 113), expected before 2 August 2026, a formality that does not change the dates: plan against 2 December 2027. Not everything is delayed: the Article 5 prohibitions have applied since 2 February 2025 and are unaffected.
Confir's deterministic, rule-based engine derives your role — provider, deployer, importer or distributor — from a plain-English supply-chain intake, maps the Article 24 checklist onto the systems you handle, and flags the Article 25 triggers that would reclassify you. The same answers always produce the same finding, with the firing rule shown in plain language — rule-based, not model inference. No hallucination, no AI in the product.
Frequently asked questions
What exactly must a distributor verify before making a high-risk AI system available?
Under Article 24(1) of Regulation (EU) 2024/1689, a distributor must verify four things before making a high-risk AI system available: the system bears the CE marking (Article 48); it is accompanied by the EU declaration of conformity (Article 47) and instructions for use (Article 13); the provider has fulfilled its Article 16 obligations; and, where a non-EU provider is involved, the importer has met its Article 23 obligations. The distributor reviews this evidence — it does not re-run the conformity assessment, which remains the provider's job.
Does a distributor have to keep records or register the system in the EU database?
No. Database registration under Article 49 and the drawing-up of technical documentation under Article 11 are provider obligations, and the ten-year retention of the declaration of conformity is specifically an importer duty under Article 23. A pure distributor under Article 24 verifies conformity artefacts, preserves conformity during storage and transport, and cooperates with authorities on request. Those database and record-keeping duties only attach if the distributor crosses into provider status under Article 25 by rebranding or substantially modifying the system.
What must a distributor do if it discovers a system it already sold is non-conforming?
Article 24(4) requires the distributor to take immediate corrective action — bringing the system into conformity, withdrawing it, or recalling it — and to inform the provider, the importer if one exists, and the competent authorities. Where the system presents a risk, Article 24(3) requires the distributor to inform the relevant national authorities of the member state concerned, giving details of the non-conformity and of any corrective measures taken. Acting promptly limits both legal exposure under Article 99(4) and the harm a non-conforming system can cause in the field.
How is a distributor different from an importer under the EU AI Act?
An importer (Article 23) is the first EU-established party that places on the market an AI system from a provider based outside the Union; a distributor (Article 24) is any later actor in the domestic supply chain that makes the system available. Both verify the same conformity artefacts, but importers carry heavier duties: marking their own name and address on the system, retaining the declaration of conformity and certificate for ten years, and confirming a non-EU provider appointed an authorised representative under Article 22. Distributors do not carry those extra obligations.
When does a distributor become a provider under Article 25?
Article 25(1) treats a distributor as a provider — with the full Article 16 obligation stack — in three cases: it puts its own name or trademark on a high-risk AI system; it makes a substantial modification (Article 3(23)) that keeps the system high-risk; or it modifies the intended purpose of a non-high-risk system so that it becomes high-risk. Once reclassified, the distributor must complete the conformity assessment (Article 43), draw up technical documentation, affix CE marking (Article 48), sign the declaration of conformity (Article 47), and register the system (Article 49).
What penalty does a distributor face for breaching Article 24?
Non-compliance with Article 24 falls under Article 99(4): fines up to €15 million or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher. For SMEs and start-ups, Article 99(6) caps the fine at the lower of those two figures rather than the higher. If a distributor triggers Article 25 and then fails the provider obligations, it is exposed to the same Article 99(4) tier, because breaches of Article 16 are governed by the same provision.
Have the distributor deadlines been extended to 2027?
Yes. The statute originally set high-risk obligations for stand-alone Annex III systems at 2 August 2026. The Digital Omnibus, provisionally agreed on 6–7 May 2026, is now adopted — the European Parliament passed it on 16 June 2026 and the Council on 29 June 2026 — deferring that to 2 December 2027 (and Annex I product-embedded systems to 2 August 2028). It enters into force on publication in the Official Journal, expected before 2 August 2026, a formality that does not change the dates. Plan against 2 December 2027. The Article 5 prohibitions, in force since 2 February 2025, are unaffected by any of this.
Related guides
- Importer obligations under Article 23
- Distributor (EU AI Act glossary)
- Article 25: responsibilities along the AI value chain
- Article 16: provider obligations
- Provider vs deployer roles explained
Manage your EU AI Act compliance in one place
Confir automates risk classification, technical documentation, and audit trails for any company. No consultants. No 6-month projects. 14-day free trial.
Start free trial →