All questions

Does the EU AI Act apply if my company is outside the EU?

EU AI ActLegislation verified on Ook in het Nederlands

Short answer

Yes, in many cases. Regulation (EU) 2024/1689 (the "EU AI Act" or "AI-verordening") applies to providers and deployers of AI systems that are established outside the European Union when their AI systems or their outputs reach the EU market or users in the EU. The Act is explicitly extraterritorial, similar in structure to the GDPR.

When the AI Act applies to a non-EU company

The scope is set out in Article 2 of Regulation (EU) 2024/1689. The Act applies to:

SituationCovered by the AI Act?Basis
Provider established outside the EU, but places an AI system on the EU market or puts it into service in the EUYesArt. 2(1)(a)
Provider/deployer established outside the EU, where the AI system's output is used in the EUYesArt. 2(1)(c)
Provider/deployer established inside the EUYesArt. 2(1)(a)–(b)
Importer or distributor of an AI system on the EU marketYesArt. 2(1), read with Art. 3
Provider outside the EU that only serves users outside the EU, with no placing on the EU market and no EU-located output useGenerally NoArt. 2(1)

The two triggers most relevant to non-EU companies are:

  1. Placing on the market / putting into service in the Union (Art. 2(1)(a)). "Placing on the market" is defined in Article 3(9) as the first making available of an AI system on the EU market. "Putting into service" (Art. 3(11)) means first use of an AI system in the EU for its intended purpose. A non-EU provider triggers this the moment it makes its system available to EU-based customers, distributors, or deployers, or deploys it itself inside the EU.

  2. Use of the output in the Union (Art. 2(1)(c)). Even if a non-EU provider never formally places the system on the EU market, the Act still applies where the output produced by that AI system is used in the EU. This captures, for example, a foreign provider whose AI generates decisions, content, or predictions that are then relied on by an EU-based business or person.

The definitions of "provider" (Art. 3(3)) and "deployer" (Art. 3(4)) are deliberately substance-over-form: who developed the system or who uses it in a professional capacity matters, regardless of where the entity is headquartered. "Importer" (Art. 3(6)) and "distributor" (Art. 3(7)) are separately defined and bring additional non-EU actors within scope.

Main exceptions and limits

A non-EU company is not caught by the AI Act merely because its AI system could theoretically be accessed from the EU. The following carve-outs and qualifications are relevant:

  • Outputs not used in the EU. If neither the system nor any of its outputs are put on the EU market or used in the Union, Art. 2 does not reach the activity. The territorial link — placing on the EU market, putting into service in the EU, or output used in the EU — is the gateway.
  • National security, defence and military purposes. Art. 2(3) and Art. 2(4) exclude AI systems developed or used exclusively for military, defence or national security purposes, regardless of the type of entity carrying out that activity.
  • Scientific research and development. Art. 2(8) carves out research and development activity concerning AI systems before they are placed on the market or put into service. This is narrower than it sounds: it does not cover a non-EU company that releases research-stage systems to EU users.
  • Free and open-source models. Some obligations are modulated for certain open-source general-purpose AI models under Art. 53, but this is a substantive obligation carve-out, not a territorial one — it does not remove a non-EU open-source provider from scope where Art. 2 otherwise applies.
  • Law enforcement cooperation. Specific provisions in Art. 2(5)–(7) and Chapter IX govern law-enforcement use; these affect who the regulator is, not whether the Act applies.

A further practical point: even where the Act does not formally apply to a non-EU provider, that provider's EU-based customers may themselves become "deployers" or "importers" and owe their own obligations under the Act. Many non-EU providers therefore face commercial pressure to align with the regulation via contract, technical measures, or representation, regardless of strict legal coverage.

What to do if you are a non-EU company

  1. Map your exposure. Identify whether you (a) place an AI system on the EU market or put it into service in the EU, or (b) produce outputs that are used in the EU. If either is yes, the AI Act applies.
  2. Identify your role. Under Art. 3, decide whether you act as provider, deployer, importer, distributor, or — for general-purpose AI models — provider of a GPAI model. This determines your specific obligations.
  3. Allocate obligations to the relevant party. Many obligations under the Act attach to the provider (Art. 16 ff.) and to the deployer (Art. 26 ff.). A non-EU provider is typically the "provider" and bears the bulk of the conformity assessment, documentation, and post-market monitoring duties, even where distribution is handled by an EU partner.
  4. Appoint an authorised representative where required. For certain providers of high-risk or general-purpose AI systems established outside the EU, Art. 22 requires designation of an EU-based authorised representative.
  5. Watch the timeline. The Act entered into force on 1 August 2024 and applies in stages: prohibitions and AI-literacy obligations since 2 February 2025; GPAI rules and most other obligations from 2 August 2025; and the bulk of the high-risk-system obligations from 2 August 2026 (with a longer transition for some legacy systems under Art. 113).

Sources

This article is general information, not legal advice. Whether the EU AI Act applies to a specific non-EU company depends on the factual pattern, in particular where the system is made available and where its outputs are used.