European Union
EU AI Act Extraterritorial Scope: Do Non-EU Companies Need to Comply?
Article 2 reaches companies with zero EU presence if their AI system's output is used in the Union. Here's exactly when non-EU companies are in scope — and when they aren't.
"We don't have an office in the EU, so this doesn't apply to us." That's the sentence that ends most non-EU companies' analysis of the EU AI Act — and it's the wrong test. Article 2 of the Act never asks where a company is incorporated or headquartered. It asks two much narrower questions: where is the AI system placed on the market or put into service, and, separately, where is its output actually used. Get the second question wrong and a company with zero EU presence can still find itself squarely inside the Regulation's scope.
That second trigger is the one that catches people off guard, because almost nothing else in EU regulatory practice works this way. A US company that has never signed an EU contract, never marketed in the EU, and has no EU subsidiary can still be a "provider" or "deployer" in scope — purely because someone in the Union is using what the system produces.
Trigger one: placing on the market or putting into service in the Union
The trigger most non-EU providers already half-understand is Article 2(1)(a): the Regulation applies to providers placing an AI system, or a general-purpose AI model, on the market or putting it into service in the Union — "irrespective of whether those providers are established or located within the Union or in a third country." Sell an AI system into the EU, license it to an EU customer, or make it available for EU users to sign up for, and this trigger is satisfied regardless of where the company selling it is based. This part isn't unusual; it's the same logic GDPR and plenty of other EU regulation already applies to non-EU sellers. A Delaware-incorporated SaaS company with no EU staff is still "placing on the market in the Union" the moment an EU customer can buy and use its product.
Trigger two: output used in the Union, even with zero EU presence
The trigger that actually surprises people is Article 2(1)(c). It reaches providers and deployers "established or located in a third country, where the output produced by the AI system is used in the Union" — full stop. No EU sale. No EU contract. No EU market placement decision by the company itself. If the results the system produces end up being used by someone in the Union, the third-country operator producing them is in scope.
Recital 22 explains why the Act reaches this far, and gives its own concrete illustration: an operator established in the Union contracts services to an operator established in a third country, in connection with an activity to be performed by an AI system that would qualify as high-risk. That third-country AI system processes data lawfully collected in and transferred from the Union, and sends its output back to the EU-based contracting operator. Without Article 2(1)(c), a company could route its AI processing offshore, keep the compliant-looking EU business relationship on paper, and never fall under the Act at all. The provision exists specifically to close that gap — the Act's own drafters call this out as an anti-circumvention measure, not an accidental overreach.
Consider Meridian HR Analytics, a fictional AI resume-screening vendor based in Austin, Texas. Meridian has no EU office, no EU sales team, and no EU-facing marketing. Its only customer relationship is with a US-headquartered manufacturing company. But that manufacturing company has a wholly-owned subsidiary in Poland, and the Poland-based hiring managers use Meridian's tool — through their US parent's enterprise license — to screen candidates applying to Polish roles. The rankings and shortlist decisions Meridian's system produces are the "output," and that output is being used in the Union by the hiring managers who rely on it to decide who advances. Meridian never sold anything directly into the EU. It's still a provider whose AI system's output is used in the Union, which is exactly the fact pattern Article 2(1)(c) is written to capture.
This is also why "we don't sell to EU customers" is not, by itself, a safe scoping conclusion. The right question is narrower and less comfortable: does anyone in the Union rely on what this system produces, through any path — a US parent's EU subsidiary, an EU-based end user of a US customer's product, a contractor relationship several steps removed from the original sale.
What actually takes a company out of scope
Article 2 does carve out real exclusions — they're just narrower than most companies assume, and it's worth knowing them precisely rather than assuming a use case is exempt because it feels adjacent to one.
Article 2(3) excludes AI systems placed on the market, put into service, or used "exclusively" for military, defense, or national security purposes, regardless of what type of entity is carrying out the activity. The word doing the real work here is "exclusively." A dual-use system built for defense applications but also deployed for civilian, humanitarian, or law-enforcement functions doesn't get the exclusion for those civilian uses — only the genuinely military-only deployment is out of scope.
Article 2(4) excludes research, testing, and development activity regarding AI systems or models prior to their being placed on the market or put into service. This is the exclusion companies most often over-apply. It covers genuine pre-market R&D — and explicitly does not cover testing in real-world conditions, which the Regulation carves back into scope even though it happens before a formal commercial launch. A company running a live pilot of its AI system with real EU users, even under an early-access or beta label, isn't automatically inside the R&D exclusion just because the product hasn't formally "launched" yet.
Neither exclusion turns on where the company is based. Both turn on what the system is actually doing and who is actually using it — the same orientation as the scope triggers themselves, and the same orientation behind the eight practices Article 5 prohibits outright, which apply to non-EU companies under this exact scope logic.
Once you're in scope: the authorised representative requirement
For a non-EU provider of a high-risk AI system, being in scope under Article 2 has an immediate practical consequence most companies don't discover until it comes up in a customer's procurement questionnaire or a regulator's inquiry: Article 22 requires the provider to appoint, by written mandate, an authorised representative established in the Union before placing the system on the EU market.
That representative isn't a rubber stamp. The mandate has to empower them to be addressed by competent authorities on compliance matters in place of or alongside the provider, to verify that the declaration of conformity and technical documentation have actually been drawn up, to supply authorities with the information and documentation needed to demonstrate conformity, and to cooperate with authorities on any corrective action. Critically, the representative also has an independent obligation to terminate the mandate — and notify the relevant market surveillance authority why — if they have reason to believe the provider is acting contrary to its obligations under the Regulation. A non-EU provider can't treat this appointment as paperwork; it's a standing compliance relationship with real termination consequences attached.
This is a downstream obligation of being in scope for a high-risk system specifically, not a universal requirement for every non-EU company caught by Article 2 — a company only in scope through the output-use trigger for a limited-risk or minimal-risk system faces a different, lighter set of obligations. But for the high-risk case, it's usually the first concrete "now what" a non-EU company runs into once the scope question is settled.
How to actually run this analysis for your own company
The self-check sequence is shorter than the anxiety around it usually suggests:
First, is your AI system, or a general-purpose AI model you provide, being placed on the market or put into service in the Union by anyone — including through a reseller, a licensing arrangement, or an EU-facing product tier? If yes, Article 2(1)(a) applies, and where you're incorporated doesn't change that.
Second, if the answer to the first question is no, is your system's output — as the third-country provider or deployer — being used by anyone located in the Union, through any path, even one your company didn't directly control? If yes, Article 2(1)(c) applies.
Third, if either trigger is satisfied, does a genuine exclusion apply — narrowly, not generously: exclusively military/defense/national-security use under Article 2(3), or pre-market R&D that stops short of real-world testing under Article 2(4)?
Fourth, if you're still in scope and your system is a provider's high-risk system, have you appointed an Article 22 authorised representative in the Union — and does your contract with them actually give them the powers Article 22 requires, not just a name on a compliance page?
That sequence won't resolve every edge case on its own — classifying a system as high-risk in the first place is a separate analysis worth working through carefully before assuming any of this applies, and a system that clears the scope test still has to go through conformity assessment before it can reach the EU market. But this sequence replaces the wrong question ("are we an EU company?") with the two questions that actually determine the answer.
Frequently asked questions
- If my company has no office, employees, or subsidiary in the EU, does the AI Act still apply to us?
- Yes, potentially — physical presence and incorporation location aren't the test. Article 2(1)(a) reaches providers placing an AI system on the EU market or putting it into service there regardless of where they're established, and Article 2(1)(c) separately reaches third-country providers and deployers whenever the AI system's output is used in the Union, with no EU sale or contract required at all.
- What does 'output used in the Union' actually mean in practice?
- It means a person or process in the EU is using the results the AI system produces — a score, a decision, a classification, a generated recommendation — even if the system runs entirely outside the EU and the company operating it has no EU presence. Recital 22 gives its own example: an EU-based company sends EU-sourced data to a third-country operator's AI system, and the results come back and get used in the EU. That third-country operator is in scope specifically so companies can't route processing offshore to escape the Regulation.
- Does the EU AI Act's military exclusion mean any AI system with a defense application is out of scope?
- No — the exclusion in Article 2(3) is narrow and applies only where a system is placed on the market, put into service, or used exclusively for military, defense, or national security purposes. A dual-use system also deployed for civilian, humanitarian, or law-enforcement functions stays in scope for those uses, regardless of what entity operates it.
- Can a non-EU company avoid EU AI Act obligations just by not selling directly into the EU?
- Not reliably. If the company's AI system's output is used by anyone in the Union, Article 2(1)(c) can bring the company into scope even without a direct EU sale, EU customer contract, or EU market-entry decision on its part — that's precisely the circumvention scenario Recital 22 was written to close.
- What's the first concrete obligation a non-EU company faces once it's in scope for a high-risk AI system?
- Under Article 22, a non-EU provider of a high-risk AI system must appoint, by written mandate, an authorised representative established in the Union before placing the system on the market. That representative becomes the point of contact for competent authorities and must be able to verify the provider's declaration of conformity and technical documentation, and to terminate the mandate if it has reason to believe the provider is non-compliant.
Sources & references
Suggested next reading
regulations eu
The EU AI Act
regulatory checklists
EU AI Act High-Risk Classification Checklist
regulations