"We're not a European company, so this doesn't apply to us" is the most common and most expensive misreading of the EU AI Act. Article 2 reaches providers and deployers irrespective of where they are established. Incorporation is not the test. What matters is where your system is placed on the market, where your deployer sits, and - the catch-all almost everyone misses - where the output is used.
Article 2(1)(c) applies the Regulation to providers and deployers in third countries "where the output produced by the AI system is used in the Union". A San Francisco company with no EU entity, no EU servers and no EU staff is in scope the moment a customer in Dublin uses what its model produces.
The seven ways you are in scope
| Art 2(1) | Who | What triggers it |
|---|---|---|
| (a) | Providers | Placing an AI system or GPAI model on the Union market, irrespective of establishment |
| (b) | Deployers | Being established or located in the Union |
| (c) | Providers and deployers in third countries | The output is used in the Union |
| (d) | Importers and distributors | Bringing someone else's system to the Union market |
| (e) | Product manufacturers | Placing an AI system on the market with their product, under their own name or trademark |
| (f) | Authorised representatives | Acting in the Union for a non-EU provider |
| (g) | Affected persons | Located in the Union - this is who the rights run to |
The cases that actually come up
US SaaS with EU customers. In scope. You are the provider of the AI features you ship, and your customers' use puts the output in the Union. Delaware incorporation is irrelevant. SaaS specifics.
UK company post-Brexit. The UK is a third country for these purposes, so the analysis is identical to the US one - EU users means in scope. The UK has no equivalent statute of its own, which means UK companies get the AI Act's obligations without a domestic regime to align them with.
EU company selling only outside the EU. Still in scope as a deployer under 2(1)(b) for systems you use yourself, because that limb turns on where you are established, not where your customers are. Your internal AI tooling is caught even if no customer is European.
Non-EU company, EU staff. Your use of AI on those employees is deployer activity affecting people in the Union. HR tooling is the usual trigger - and it is also the Annex III area with the heaviest obligations. HR detail.
Processing EU personal data but output used elsewhere. This is where the AI Act and the GDPR come apart. GDPR follows the personal data. The AI Act follows the system, the market and the output. You can be squarely in GDPR scope and outside the AI Act, or the reverse. The mapping, for privacy teams.
Non-EU providers of high-risk systems need someone in the Union
Under Article 22, a provider established in a third country must appoint, by written mandate, an authorised representative established in the Union before making a high-risk AI system available on the Union market. The representative holds documentation, cooperates with authorities and can terminate the mandate if the provider acts contrary to its obligations.
There is a parallel requirement for third-country providers of general-purpose AI models under Article 54.
This is the obligation most non-EU teams discover last, because it is administrative rather than technical - and it is a precondition for market access, not a filing you catch up on afterwards. It only applies if something you ship is genuinely high-risk, which is worth establishing before you go looking for a representative.
What is genuinely out of scope
| Exclusion | Article | The limit of it |
|---|---|---|
| Military, defence and national security | 2(3) | Only where used exclusively for those purposes. Dual-use tooling is not excluded |
| Scientific research and development | 2(6) | Systems developed and put into service for the sole purpose of scientific R&D |
| Pre-market research, testing, development | 2(8) | Ends at real-world testing - and entirely once you place it on the market |
| Purely personal, non-professional use | 2(10) | Natural persons only. An employee using AI at work is not covered by this |
| Free and open-source AI | 2(12) | Does not apply where the system is placed on the market as high-risk, or falls under Article 5 or Article 50 |
The open-source exclusion is the one most often over-claimed. Releasing a model under a permissive licence does not exempt it if it is put into service as a high-risk system, if it engages a prohibited practice, or if Article 50 transparency duties apply.
Being in scope is not the same as being burdened
This is the part that gets lost. Scope and tier are separate questions, and almost every non-EU company that panics about the first discovers the second is undemanding.
Most non-EU SaaS companies in scope end up as providers of limited or minimal risk systems. What that means in practice: Article 50 disclosure if your product converses with users, Article 4 literacy for staff, and an Article 5 check. Chapter III - conformity assessment, CE marking, EU database registration - applies only if something you ship is genuinely Annex III high-risk.
The deliverable that actually matters for a non-EU company is a dated written position: which of your systems are in scope, under which limb of Article 2, at which tier, and what follows. That is what EU enterprise procurement asks for, and it is usually a day's work rather than a compliance programme.
Territorial scope is settled by Article 2 on the facts of your deployment, not by where your servers sit. Hosting in the US does not remove you from scope, and hosting in the EU does not put you in it. The free check works through the Article 2 limbs before it looks at tier, because getting scope wrong makes everything downstream wrong.
In scope, but at what tier?
Being in scope is not the same as being burdened. The free check works through the Article 2 limbs first, then your tier.
Start the free scanNo card, no account. Full gap report from €59. See a real report first.
Self-assessment, not legal advice. This page and the Reglynn report are a structured self-assessment based on the EU AI Act (Regulation 2024/1689, as amended by the June 2026 Omnibus). They indicate where you likely stand and what to verify with a qualified advisor. Reglynn is not a notified body and issues no certification.
How this was made. Reglynn reports are generated by an AI system built on Anthropic's Claude and reviewed before delivery. Reglynn is a Limited Risk AI system under Article 50; we disclose AI involvement wherever it occurs, including in our chat assistant. Our own self-assessment.