The short answer, that the AI Act has extraterritorial reach, is true and useless. The Regulation does not apply to non-EU companies generally; it applies through four specific connecting factors in Article 2(1), and which one catches you decides which obligations you have.
The connecting factors in Article 2(1)
Article 2(1) of Regulation (EU) 2024/1689 lists the categories of actor it applies to. The four that matter for this question:
- Providers placing on the Union market. Providers that place AI systems on the market or put them into service in the Union, or that place general-purpose AI models on the Union market — expressly “irrespective of whether those providers are established or located within the Union or in a third country”. This is the main hook and it is about the market, not about you.
- Deployers located in the Union. Deployers that have their place of establishment or are located within the Union.
- The output test. Providers and deployers established or located in a third country, where the output produced by the AI system is used in the Union.
- The supply chain. Importers and distributors; product manufacturers placing a system on the market together with their product under their own name or trademark; authorised representatives of non-EU providers; and affected persons located in the Union.
Scope is the determination on which everything else rests and it is fact-sensitive. This page explains the tests; it is not legal advice on whether your company meets them, and a scope opinion is one of the few places where paying for one is straightforwardly worth it.
The output test, and what it does not say
The output limb is the provision that unsettles people, and it is worth reading precisely. It catches a third-country provider or deployer where the output produced by the system is used in the Union. It does not say the system is accessible from the Union, that EU residents’ data was in the training set, or that a European once used the product. It is about where the output is put to use.
Recital 22 explains the purpose: to stop circumvention of the Regulation by arrangements in which an operator established in the Union has services performed by an operator outside it, in respect of an activity intended to be carried out in the Union, with the output used in the Union. Recitals are interpretive aids rather than binding rules, but they are the best available guide to how the limb is meant to bite, and it is plainly aimed at outsourcing patterns rather than at incidental exposure.
What counts as “used in the Union” at the margins is not yet settled. The Regulation does not define it, no Commission guidelines resolve it, and there is no case law. Reasonable practitioners disagree about, for example, a US company whose model scores a document for a US client whose EU branch later relies on the score. It would take a Commission guideline under Article 96, a national authority decision, or ultimately a ruling of the Court of Justice to settle it. Treat a confident answer at the margin — in either direction — with suspicion.
Five scenarios
- A US SaaS company selling to EU businesses. Making the AI system available on the Union market in the course of a commercial activity is placing it on the market, so the first limb catches you directly, without needing the output test at all. If the system is high-risk, the whole provider regime applies and Article 22 requires you to appoint an authorised representative established in the Union by written mandate before making it available.
- A US company with an EU subsidiary that resells. The subsidiary is likely a distributor or importer with its own duties under Articles 23 and 24, and the parent remains the provider. Putting a corporate entity in between changes who checks the paperwork, not who is responsible for the conformity of the system.
- A third-country company doing back-office processing for an EU client. This is the paradigm case for the output limb: the processing happens outside, the result is used inside. The client is a deployer established in the Union; you may be a provider or a deployer depending on whose system it is and whose name is on it.
- A model published on a hosting platform. Making a general-purpose model available on the Union market is squarely within the first limb. The free and open-source position is narrow: Article 2(12) disapplies the Regulation to systems released under free and open-source licences unless they are placed on the market or put into service as high-risk systems or as systems falling under Article 5 or Article 50, and Chapter V contains its own separate and partial open-source exemption for models.
- A purely domestic third-country product with EU visitors. A consumer app operated outside the Union, not marketed there, whose output is used by the individual wherever they are, is the weakest case for the output limb. It is also the scenario least addressed by any authoritative source, which is a reason to document your reasoning rather than to assume the answer.
The exclusions that actually help
Article 2 carries several exclusions, and a few of them do real work for non-EU organisations:
- Research and development before market. The Regulation does not apply to research, testing or development activity on AI systems or models prior to their being placed on the market or put into service. Testing in real-world conditions is expressly not covered by that exclusion.
- Scientific research and development as sole purpose. Systems and models developed and put into service for the sole purpose of scientific research and development are outside scope.
- Military, defence and national security. Systems placed on the market, put into service or used exclusively for military, defence or national security purposes are excluded, whatever the type of entity carrying out those activities.
- Purely personal non-professional use. The deployer obligations do not apply to natural persons using AI systems in the course of a purely personal non-professional activity.
Note what is not on that list: there is no small-company exemption and no revenue threshold. Article 99(6) reduces the ceiling on fines for SMEs and start-ups by taking whichever of the fixed amount or the percentage is lower, and there are procedural accommodations elsewhere in the Regulation, but scope itself does not turn on size.
What being in scope costs you
Being in scope is not one obligation set. The Regulation is layered, and the layer you land in is what matters:
- Article 5 prohibitions apply to everyone in scope and have done since 2 February 2025. There is no risk classification step to reach them.
- Article 50 transparency duties — telling people they are interacting with an AI system, marking synthetic content, labelling deepfakes — apply from 2 August 2026 regardless of risk tier.
- The high-risk regime applies only if the system meets Article 6, and brings the full Chapter III load: requirements, documentation, conformity assessment, CE marking, registration, monitoring and incident reporting. Its start date moved by more than a year in July 2026 — to 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for AI embedded in Annex I products, by Regulation (EU) 2026/1744, in force since 27 July 2026. Scope is unchanged by that; only the calendar is. Nothing in it narrows the Article 2 connecting factors, so a non-EU provider that is in scope today is in scope on the new dates too.
- Chapter V applies if you place a general-purpose model on the Union market, and has done since 2 August 2025.
The single most under-appreciated consequence for a non-EU provider is the authorised representative requirement. It is not a mailbox: the representative holds the technical documentation, cooperates with authorities, and can terminate the mandate — with reasons — if it considers the provider is acting contrary to its obligations, notifying the authority and the Commission when it does.
Top comments (0)