Does the EU AI Act Apply to My Company

Does the EU AI Act Apply to My Company If I’m Not Based in Europe?

Does the EU AI Act apply to Non-EU Companies

Quick Answer Yes — in most cases. The EU AI Act applies to your company even if you have no office, employee, or server in Europe, as long as your AI system’s output is used by people in the EU, or an EU customer deploys your AI system inside the Union. Location does not determine liability. Usage does.

The Email That Changes Everything

A founder in Bengaluru runs a 40-person SaaS company. The product is a hiring-screening tool that scores résumés and ranks candidates for recruiters. The company has never had an EU office, never registered a single euro of EU revenue directly, and every engineer sits in India.

Then, on a Tuesday afternoon, an email arrives from a mid-sized HR agency in Munich that has been quietly using the tool through a reseller. The subject line reads: “AI Act compliance documentation — required before contract renewal.”

The founder’s first instinct is relief: “We’re not established in Europe, so this doesn’t apply to us.” That instinct is wrong, and it is one of the most expensive misconceptions circulating among Indian and other non-EU SaaS founders today.

The EU AI Act, formally Regulation (EU) 2024/1689, was built with a specific goal in mind: to prevent companies from escaping regulation simply by locating their servers and staff outside the Union (European Union, 2024, Recital 7). If your AI system’s output reaches someone in the EU — a hiring decision, a credit score, a generated recommendation, a piece of content — the Regulation can reach you too.

This article gives you a precise, article-by-article answer to the question every non-EU founder eventually has to ask: does this law actually apply to me?

Why This Question Matters More Than Founders Realise

Most non-EU companies discover their AI Act exposure the way the Bengaluru founder did — reactively, through a customer’s procurement or legal team, often with a contract renewal deadline attached. By that point, the company has lost the two things that make compliance manageable: time and choice.

If you ignore the question and you are in scope, the consequences are not abstract. The Regulation gives national market surveillance authorities the power to order an AI system withdrawn from the EU market, and penalties for non-compliance can reach up to €35 million or 7% of total worldwide annual turnover for prohibited AI practices, and up to €15 million or 3% of worldwide turnover for most other violations, whichever is higher (European Union, 2024, Art. 99). “Worldwide turnover” is the detail founders miss — the fine is not calculated on EU revenue alone.

Beyond fines, there is a quieter but more immediate risk: loss of the EU customer relationship itself. EU-based deployers are legally required to verify that the AI systems they use are compliant (European Union, 2024, Art. 26). An enterprise buyer that cannot get compliance documentation from a vendor will simply not renew — no fine required.

Who Is Actually Affected? The Territorial Scope, simple Explained

Article 2 of the Regulation sets out exactly who falls within scope. Strip away the legal phrasing, and it comes down to five categories of company, regardless of where they are headquartered:

Your RoleWhere You’re LocatedAre You in Scope?
Provider (you build/develop the AI system)Anywhere in the worldYes, if the system is placed on the EU market — location is irrelevant (Art. 2(1)(a))
Deployer (you use an AI system in your own operations)Established in the EUYes (Art. 2(1)(b))
Deployer (you use an AI system in your own operations)Established outside the EUYes, if the output is used in the EU (Art. 2(1)(c))
Importer / DistributorAnywhere, but placing the system on the EU marketYes (Art. 2(1)(d))
Authorised Representative of a non-EU providerMust be established in the EUYes — a mandatory role, not optional (Art. 2(1)(f))

The Regulation’s own explanatory recitals confirm this is intentional, not an accidental side effect: the Act is designed “to prevent the circumvention of this Regulation” by companies that might otherwise relocate operations to avoid it (European Union, 2024, Recital 22). Legal commentary published in International Legal Materials describes this as an extraterritorial reach “similar to the GDPR” — the Act follows the output, not the entity (Meszaros & Minssen, 2025).

The critical, most-overlooked term here is “output.” Article 3(1) defines output broadly as predictions, content, recommendations, or decisions that can influence physical or virtual environments (European Union, 2024, Art. 3(1)). There is no requirement that you intended your product for the EU market. If an EU-based user can receive a decision, a generated image, a chatbot reply, or a ranked list from your system, the output has reached the Union — and that alone can be enough to trigger scope.

How to Check Is Your AI System High-Risk Under the EU AI Act (2026)

Does the EU AI Act apply to non-EU Companies

The Original AspirixWriters Extraterritorial Exposure Test

Because Article 2 is written as legal scope language rather than a decision tool, we built a four-question screen specifically for non-EU founders. This is an Original AspirixWriters Framework — use it as your first-pass triage, not a substitute for legal advice.

Question 1 — Does any output from your AI system reach a person physically located in the EU? This includes B2B resale, white-labelling, and API access by an EU-based customer, even if your contract is signed with a non-EU parent company.

Question 2 — Is your product a “general-purpose AI model” (e.g., a foundation model or LLM) that could be placed on the EU market by you or a downstream reseller? General-purpose AI model providers face obligations under Articles 53–55 regardless of where they are established, once the model is placed on the EU market (European Union, 2024, Art. 53–55).

Question 3 — Could your system’s output influence a decision about an EU-based individual — hiring, credit, insurance, education access, law enforcement, or biometric identification? These use cases sit closer to the Act’s high-risk categories and demand more careful review, since high-risk classification changes your entire obligation set (European Union, 2024, Art. 6).

Question 4 — Does your product fall under one of the Article 2(8) or 2(6) exclusions — for example, is it used exclusively for scientific R&D prior to market placement, or is it a pure research tool never placed on the market? If yes, you may be temporarily outside scope, but only until the system is placed on the market or put into service (European Union, 2024, Art. 2(6), 2(8)).

If you answered “yes” to Question 1 or 2, and “no” to Question 4, you are very likely in scope of the EU AI Act — regardless of where your company is headquartered.

EU AI ACT

If You’re In Scope: What the Law Actually Requires of You

Being in scope does not mean identical obligations for everyone — your obligations depend on your role.

If you are a provider established outside the EU (Article 2(1)(a)): You must, prior to making your high-risk AI system available on the EU market, appoint by written mandate an authorised representative established in the Union (European Union, 2024, Art. 22(1)). This representative is not a formality — the mandate must empower them to hold your technical documentation and EU declaration of conformity for ten years, respond to regulator requests, and cooperate with market surveillance authorities on your behalf (European Union, 2024, Art. 22(3)). If you provide a general-purpose AI model rather than a high-risk system, the equivalent obligation sits in Article 54.

If you are a deployer outside the EU whose output is used in the EU (Article 2(1)(c)): You must meet deployer obligations under Article 26, including ensuring human oversight, monitoring the system’s operation, and — for high-risk systems — conducting a fundamental rights impact assessment in specific circumstances (European Union, 2024, Art. 26, Art. 27).

If you sell through an EU-based importer or distributor: That importer must verify your conformity documentation before placing your product on the market (European Union, 2024, Art. 23). Distributors carry a lighter, but still real, verification duty (European Union, 2024, Art. 24).

EU AI Act

Common Mistakes Non-EU Founders Make

  1. Assuming “no EU office” means “no EU exposure.” Article 2 was written specifically to close this loophole (European Union, 2024, Recital 22).
  2. Believing indirect resale through an EU partner removes responsibility. Distributors and importers have their own duties, but yours as the provider do not disappear (European Union, 2024, Art. 23–24).
  3. Treating “authorised representative” as optional or symbolic. It is a written-mandate legal requirement before market placement, not a nice-to-have (European Union, 2024, Art. 22(1)).
  4. Confusing GDPR compliance with AI Act compliance. They are separate regimes that apply concurrently — GDPR compliance does not satisfy AI Act obligations, and vice versa (European Union, 2024, Art. 2(7)).
  5. Waiting for a customer’s legal team to raise the issue. By then, you are negotiating from a position of weakness, not readiness.

The Regulatory Timeline You Need to Track

The AI Act entered into force on 1 August 2024, with a staged implementation timeline (European Union, 2024, Art. 113). Prohibited AI practices under Article 5 became enforceable first, followed by obligations for general-purpose AI models, with the bulk of high-risk system obligations originally scheduled around August 2026.

Important regulatory update: In May 2026, EU co-legislators reached political agreement on a “Digital Omnibus” package that would shift the main Annex III high-risk system compliance deadline from August 2026 to December 2027, and the Annex I high-risk deadline to August 2028. This development is significant, moves quickly, and postdates much of the publicly available legal commentary. Founders should verify the current, legally binding deadline directly on EUR-Lex or the European Commission’s AI Act page before making compliance timing decisions, since political agreements can be adjusted before formal adoption.

EU AI Act

A Worked Example: The Bengaluru HR-Tech Startup

Returning to our opening scenario: the hiring-screening SaaS company has no EU entity. But its output — candidate rankings — is received and acted upon by a recruiter physically located in Munich. Under Article 2(1)(c), that is sufficient for the Regulation to apply to the company as a provider whose system’s output is used in the Union.

Because the system screens and ranks candidates for employment decisions, it also falls into a category the Act treats with particular seriousness: AI systems used in recruitment sit among the higher-scrutiny use cases under Annex III, meaning the company should immediately investigate whether its system meets the Article 6 high-risk classification criteria rather than assuming otherwise. (Note on this section: the precise, exhaustive Annex III text and its interaction with Article 6(3) exemption criteria should be independently verified against the official EUR-Lex text before being relied upon for a specific product; this article provides orientation, not a final legal classification.)

The company’s realistic next steps: appoint an EU-based authorised representative, prepare technical documentation, and open a direct compliance conversation with its Munich customer — rather than waiting for the next renewal-deadline email.

Checklist: Am I Ready to Answer the “Do You Apply to Us?” Question?

  • [ ] I have identified every instance where my AI system’s output reaches an EU-based user, customer, or reseller
  • [ ] I know whether I am a provider, deployer, importer, or distributor under Article 2
  • [ ] I have checked whether my product could fall under a high-risk Annex III use case
  • [ ] I have appointed (or am preparing to appoint) an EU-based authorised representative, if required
  • [ ] I have documentation ready to answer an EU customer’s compliance request within days, not months
  • [ ] I am tracking the Digital Omnibus deadline changes via EUR-Lex, not secondary sources
  • [ ] I understand that GDPR compliance does not substitute for AI Act compliance

Does the EU AI Act Apply to Indian Companies? A Complete Compliance Guide (2026)

EU AI Act

Frequently Asked Questions

Does the EU AI Act apply if I only have a handful of EU users?

Yes. The Regulation does not set a minimum user count or revenue threshold for scope under Article 2(1)(c) — a single EU-based user receiving output can be enough to trigger relevance, though enforcement priorities in practice tend to follow risk and scale.

I’m a deployer, not a developer — does that mean I’m safe?

No. Deployers established in the EU are in scope automatically (Art. 2(1)(b)), and deployers outside the EU are in scope if the AI system’s output is used in the Union (Art. 2(1)(c)).

What if my AI product is open-source?

Open-source AI systems and models are generally exempt from certain obligations, but this exemption does not apply to models classified as high-risk, or to general-purpose AI models with systemic risk (European Union, 2024, Art. 2(12), Art. 53(2)).

Do I need an EU entity, or just an authorised representative?

For high-risk systems and general-purpose AI models, a written-mandate authorised representative established in the EU is required — this is distinct from needing a full EU legal entity or subsidiary (European Union, 2024, Art. 22, Art. 54).

Is my research-stage AI product covered?

Generally not, while it remains purely a research, testing, or development activity prior to being placed on the market — but this exclusion ends the moment the system is placed on the market or put into service, and does not cover real-world testing (European Union, 2024, Art. 2(6), Art. 2(8)).

Key Takeaways

  • The EU AI Act’s scope is based on where your AI system’s output is used, not where your company is headquartered.
  • Providers anywhere in the world are in scope once they place an AI system on the EU market; deployers outside the EU are in scope if their system’s output is used in the Union.
  • Non-EU providers of high-risk systems and general-purpose AI models must appoint an authorised representative established in the EU before market placement.
  • Penalties are calculated on worldwide turnover, not just EU revenue — up to €35 million or 7% of global turnover for the most serious violations.
  • The Annex III and Annex I high-risk deadlines are shifting under the 2026 Digital Omnibus agreement — always verify the current binding date on EUR-Lex before finalising compliance timelines.

Conclusion

The most dangerous assumption a non-EU founder can make is treating geography as a shield. The EU AI Act was deliberately written to close that gap. If your product’s output reaches someone in the Union — through direct sales, resale, or API access — the question is no longer whether the Regulation applies to you, but how well prepared you are when an EU customer, regulator, or partner asks.

The founders who handle this well are not the ones with the biggest legal budgets. They are the ones who ran the exposure test early, documented their answer, and treated the authorised representative requirement as a real operational task rather than paperwork to defer.

My Startup Uses ChatGPT. Do I Really Need an AI Policy? (2026 Guide)

About the Author

Dr. Rekha Khandelwal is the Founder of AspirixWriters and a legal researcher and writer specialising in AI Governance, AI Regulation, AI Compliance, AI Ethics, and Responsible AI. Her work is grounded in academic and policy research on emerging technology law, with a focus on translating complex legal and technical topics into practical guidance for businesses, professionals, researchers, and students navigating the evolving global AI regulatory landscape.

Explore more AspirixWriters resources on EU AI Act compliance, including our complete guide and downloadable compliance tools.

  • EU AI Act: The Complete Guide
  • How Can an Indian SaaS Startup Comply with the EU AI Act Without Hiring a Full-Time Compliance Team?
  • How Do I Classify My AI System Under the EU AI Act (Step-by-Step)?
  • What Documents Do I Need to Prove EU AI Act Compliance?

References

European Union. (2024). Regulation (EU) 2024/1689 of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Official Journal of the European Union.

https://commission.europa.eu/topics/artificial-intelligence_en

Meszaros, J., & Minssen, T. (2025). Navigating the European Union Artificial Intelligence Act for healthcare.

Scroll to Top