Territorial scope

Does it apply outside the EU?

"We're not a European company" is the most expensive misreading of the Act. Article 2 reaches providers and deployers wherever they are established - and the catch-all limb follows where the output is used.

Last updated 24 August 2026 · Regulation (EU) 2024/1689 as amended by the June 2026 Omnibus · Self-assessment, not legal advice

"We're not a European company, so this doesn't apply to us" is the most common and most expensive misreading of the EU AI Act. Article 2 reaches providers and deployers irrespective of where they are established. Incorporation is not the test. What matters is where your system is placed on the market, where your deployer sits, and - the catch-all almost everyone misses - where the output is used.

Article 2(1)(c) applies the Regulation to providers and deployers in third countries "where the output produced by the AI system is used in the Union". A San Francisco company with no EU entity, no EU servers and no EU staff is in scope the moment a customer in Dublin uses what its model produces.

The seven ways you are in scope

Art 2(1)WhoWhat triggers it
(a)ProvidersPlacing an AI system or GPAI model on the Union market, irrespective of establishment
(b)DeployersBeing established or located in the Union
(c)Providers and deployers in third countriesThe output is used in the Union
(d)Importers and distributorsBringing someone else's system to the Union market
(e)Product manufacturersPlacing an AI system on the market with their product, under their own name or trademark
(f)Authorised representativesActing in the Union for a non-EU provider
(g)Affected personsLocated in the Union - this is who the rights run to

The cases that actually come up

US SaaS with EU customers. In scope. You are the provider of the AI features you ship, and your customers' use puts the output in the Union. Delaware incorporation is irrelevant. SaaS specifics.

UK company post-Brexit. The UK is a third country for these purposes, so the analysis is identical to the US one - EU users means in scope. The UK has no equivalent statute of its own, which means UK companies get the AI Act's obligations without a domestic regime to align them with.

EU company selling only outside the EU. Still in scope as a deployer under 2(1)(b) for systems you use yourself, because that limb turns on where you are established, not where your customers are. Your internal AI tooling is caught even if no customer is European.

Non-EU company, EU staff. Your use of AI on those employees is deployer activity affecting people in the Union. HR tooling is the usual trigger - and it is also the Annex III area with the heaviest obligations. HR detail.

Processing EU personal data but output used elsewhere. This is where the AI Act and the GDPR come apart. GDPR follows the personal data. The AI Act follows the system, the market and the output. You can be squarely in GDPR scope and outside the AI Act, or the reverse. The mapping, for privacy teams.

Non-EU providers of high-risk systems need someone in the Union

Under Article 22, a provider established in a third country must appoint, by written mandate, an authorised representative established in the Union before making a high-risk AI system available on the Union market. The representative holds documentation, cooperates with authorities and can terminate the mandate if the provider acts contrary to its obligations.

There is a parallel requirement for third-country providers of general-purpose AI models under Article 54.

This is the obligation most non-EU teams discover last, because it is administrative rather than technical - and it is a precondition for market access, not a filing you catch up on afterwards. It only applies if something you ship is genuinely high-risk, which is worth establishing before you go looking for a representative.

What is genuinely out of scope

ExclusionArticleThe limit of it
Military, defence and national security2(3)Only where used exclusively for those purposes. Dual-use tooling is not excluded
Scientific research and development2(6)Systems developed and put into service for the sole purpose of scientific R&D
Pre-market research, testing, development2(8)Ends at real-world testing - and entirely once you place it on the market
Purely personal, non-professional use2(10)Natural persons only. An employee using AI at work is not covered by this
Free and open-source AI2(12)Does not apply where the system is placed on the market as high-risk, or falls under Article 5 or Article 50

The open-source exclusion is the one most often over-claimed. Releasing a model under a permissive licence does not exempt it if it is put into service as a high-risk system, if it engages a prohibited practice, or if Article 50 transparency duties apply.

Being in scope is not the same as being burdened

This is the part that gets lost. Scope and tier are separate questions, and almost every non-EU company that panics about the first discovers the second is undemanding.

Most non-EU SaaS companies in scope end up as providers of limited or minimal risk systems. What that means in practice: Article 50 disclosure if your product converses with users, Article 4 literacy for staff, and an Article 5 check. Chapter III - conformity assessment, CE marking, EU database registration - applies only if something you ship is genuinely Annex III high-risk.

The deliverable that actually matters for a non-EU company is a dated written position: which of your systems are in scope, under which limb of Article 2, at which tier, and what follows. That is what EU enterprise procurement asks for, and it is usually a day's work rather than a compliance programme.

Territorial scope is settled by Article 2 on the facts of your deployment, not by where your servers sit. Hosting in the US does not remove you from scope, and hosting in the EU does not put you in it. The free check works through the Article 2 limbs before it looks at tier, because getting scope wrong makes everything downstream wrong.

In scope, but at what tier?

Being in scope is not the same as being burdened. The free check works through the Article 2 limbs first, then your tier.

Start the free scan

No card, no account. Full gap report from €59. See a real report first.

Self-assessment, not legal advice. This page and the Reglynn report are a structured self-assessment based on the EU AI Act (Regulation 2024/1689, as amended by the June 2026 Omnibus). They indicate where you likely stand and what to verify with a qualified advisor. Reglynn is not a notified body and issues no certification.

How this was made. Reglynn reports are generated by an AI system built on Anthropic's Claude and reviewed before delivery. Reglynn is a Limited Risk AI system under Article 50; we disclose AI involvement wherever it occurs, including in our chat assistant. Our own self-assessment.