COMPLIPATHPAGE complipath.io/guides/eu-ai-act-outside-the-euBUILT 2026-08-27CLASSIFIER 2026-08-09.1LAW VERSION 2024/1689 + 2026/1744 + Commission guidelines
Guides/Roles ·By Yobel Tzegai ·Updated 27 August 2026

Does the EU AI Act apply to me if my company is outside the EU?

Written 27 August 2026 against Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744.

It applies to you if you place an AI system on the market or put it into service in the Union — wherever you are established — and it applies to you if you are established in a third country and the output your system produces is used in the Union (Article 2(1), points (a) and (c)). Where your company sits is not one of the tests.

Quick answer

Which limb of Article 2(1) catches you?

Article 2(1) is a list of seven kinds of person, and three of them decide almost every question a company outside the Union asks.

Point (a) attaches to the act of supply: placing an AI system on the market or putting it into service in the Union, or placing a general-purpose AI model on the Union market. The article says in terms that it does not matter where the provider is. A US company selling into the Union is inside the Regulation for that system on the same terms as a company in Dublin.

Point (c) attaches to the effect. It reaches "providers and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union". This is the limb with no supply step in it at all: nothing has to be sold, licensed or shipped into the Union. If the thing your system produces ends up being used here, the Regulation reaches you.

Point (b) is the ordinary case for a European buyer: deployers established or located in the Union. A company in Berlin using a bought AI tool is a deployer under the Act whoever built the tool — which role you are in is decided by what you do with the system, not by who wrote it.

What does point (c) mean by output used in the Union?

The Regulation does not define it, and this guide does not pretend otherwise. What can be said is what the words do and do not require. They do not require a contract with anyone in the Union. They do not require the system to run here. They do require that the output — the prediction, the content, the recommendation, the decision — is used in the Union, which is an act by somebody, not a location where a server sits.

The practical consequence is that a company with no European customers can still be inside the Regulation if its output is used here by someone else. A screening model run in a third country, whose scores are used by a European subsidiary to shortlist candidates, is the archetype: the provider is caught by point (c) even though the system never entered the Union market. Where the line falls in less obvious cases is not answerable from the Regulation's text, and anyone telling you it is has read something into it that is not there.

Do we need an authorised representative?

Only for high-risk systems, and only if you are a provider established in a third country. Article 22(1) requires the appointment by written mandate, established in the Union, prior to making the system available on the Union market — so it is a step before supply, not a remediation after it. What the authorised representative actually owes is a separate set of duties from yours, and appointing one does not move your obligations onto them.

If your system is not high-risk, no representative is required by Article 22. The rest of the Regulation still reaches you through Article 2(1): the Article 5 prohibitions bind whoever places a system on the market or uses it, and the Article 50 transparency duties attach to providers and deployers by role, not by address.

What this means for you

If you're a provider outside the Union: the question to answer first is not whether you are established in the EU but whether anything you make reaches the Union, by supply or by output. Then classify: which tier the system lands in decides whether Article 22 applies at all, and the high-risk requirements arrive on 2 December 2027 for Annex III systems and 2 August 2028 for Annex I ones. Record the reasoning per system, because the answer differs system by system and a company-level answer is not one.

If you're a deployer outside the Union: point (c) reaches you too — the limb names deployers as well as providers. If your teams in the Union act on what a system produces, the deployer obligations for that system's tier attach to you, and the Article 4 AI-literacy duty attaches with no risk qualifier at all.

What this check can and cannot decide sets out where our own classification stops — it reads the tier from your answers and does not decide territorial scope for you.

Which of your systems reaches the Union?

Classify your first system — 5 questions on every run, plus follow-ups where they apply, no account, and the classification runs in your browser: answers stay there unless you choose to keep the result.

FAQ

Does the EU AI Act apply to a US company with no EU office?

Yes, if either limb is met: you place an AI system on the Union market under Article 2(1), point (a), whatever your establishment, or you are in a third country and the output your system produces is used in the Union under point (c). No European entity or office is required for either.

Does hosting our servers outside the EU keep us out of scope?

No. Article 2(1) is written around supply and output, not infrastructure. Point (a) turns on placing the system on the Union market, point (c) on the output being used in the Union. Where the model runs appears in neither test.

Do we need an authorised representative for a non-high-risk system?

No. Article 22(1) attaches only to providers established in third countries making high-risk AI systems available on the Union market. Systems in other tiers carry no representative requirement, though the rest of the Regulation still reaches you through Article 2(1).

Is the output limb in point (c) defined anywhere?

Not in the Regulation. Article 2(1), point (c) reaches a third-country provider or deployer "where the output produced by the AI system is used in the Union", and defines none of those words. Nothing in our source corpus as of 27 August 2026 settles it — verify before relying — so any answer at the edge is a judgement about your own facts.

Sources: Regulation (EU) 2024/1689 (EUR-Lex), Article 2(1), points (a), (b) and (c), Article 3, points (3) and (4), Article 22(1), Article 50 and Article 113; as amended by Regulation (EU) 2026/1744 (EUR-Lex), which replaced Article 2(2) and (7) and moved the high-risk application dates. Article 2(1) itself was not amended.

← All guides
Complipath

Complipath is EU AI Act compliance software for AI-heavy software companies without a compliance team — an AI system register, deterministic risk classification, the obligations that follow, and the evidence behind every decision.

Complipath is built by Yobel Tzegai in Gothenburg, Sweden.

Complipath provides legal information, not legal advice. Every guide cites its source on EUR-Lex — Regulation (EU) 2024/1689, and Regulation (EU) 2026/1744 where that has amended it; where the law is still settling, the guide says so.

We measure page views with Vercel Web Analytics. It uses no third-party cookies. Visitors are identified by a hash derived from the incoming request, which is discarded after 24 hours, and no identifier is stored that could follow a visitor to another site. What is collected: the time of the visit, the URL, the referring page, filtered query parameters, city-level location, operating system, browser and device type.