Does the EU AI Act Apply to You If You Are Not in the EU?

The Act reaches companies with no EU entity, no EU staff and no EU servers. What that means in practice for businesses in the US, UK, Middle East and Asia, and where the regional answers genuinely differ.

By Rafal Skucha

The question we get asked most often about the EU AI Act is whether it applies to a company that is not in the EU. The answer is that establishment has almost nothing to do with it.

Article 2 sets the scope by reference to two things: whether an AI system is placed on the EU market, and whether the output of that system is used in the Union.1 Where your company is registered, where your engineers sit and where your servers run are not part of the test. A business with no European presence of any kind is in scope if a European uses what its system produces.

That is a deliberately long reach, and it is the same architecture GDPR used. It worked then and it will work now, because the enforcement lever is market access rather than jurisdiction over your legal entity.

The two questions that decide it

Before the regional detail, get these right, because they determine everything else.

Are you a provider or a deployer? A provider develops a system and places it on the EU market under its own name. A deployer uses a system under its own authority. Providers carry conformity assessment, technical documentation, and - if they are outside the EU and the system is high-risk - an obligation to appoint an authorised representative established in the Union. Deployers carry lighter duties around correct use, oversight and logging.

What risk tier is the system in? Prohibited, high-risk, transparency-only, or minimal. Most business software sits in transparency-only, which means telling people they are dealing with AI and marking synthetic content. That obligation applied from 2 August 2026. The heavy regime for Annex III high-risk systems does not arrive until 2 December 2027.

Get those two answers and you can usually size the problem in an afternoon. We have set out the full timetable in what actually applies and when.

United States

The largest population of companies caught by the extraterritorial clause without expecting it.

The specific American complication is that you are now managing two regimes that do not agree with each other. Since 1 January 2026 Texas, California and Illinois have had AI statutes in force. Colorado repealed its original AI Act and replaced it with a new automated decision-making law whose obligations start on 1 January 2027; notably the “follow a recognised framework and you have a defence” provision did not survive into the replacement. New York’s RAISE Act, aimed at frontier developers, also starts on 1 January 2027.

Meanwhile the December 2025 executive order set up a Department of Justice task force to challenge state AI laws as inconsistent with national policy.2 An executive order cannot repeal state law - only Congress or the courts can do that - so the practical position for a US business is that state obligations are live, contested, and may or may not survive.

The useful asymmetry: Texas grants protection from enforcement to organisations substantially complying with the NIST AI Risk Management Framework. NIST is voluntary, free, and maps reasonably well onto what the EU expects.3 If you are a US company doing business in Europe, building on NIST gives you a defensible position domestically and most of the documentation Europe will ask for. That is the cheapest single move available to an American business here.

United Kingdom

There is no UK AI Act. There is no UK AI bill before Parliament. The UK regulates AI through existing regulators applying existing law - the ICO where personal data is involved, the FCA in financial services, the MHRA for medical devices.4

This is often reported as the UK being behind. For a business it is better understood as: your domestic obligations are lighter, and your export obligations are unchanged. A UK company selling into Europe faces exactly the same AI Act analysis as an American one. The absence of a UK statute does not reduce it by a word.

The practical UK risk is not regulatory, it is commercial. European customers are writing AI Act compliance into procurement. UK suppliers who cannot answer those questions lose deals to suppliers who can, long before any regulator becomes involved. We have written that up in detail, using our own company as the worked example, in supplying technology services to EU clients from the UK.

Middle East

The most interesting divergence, and the one least covered.

The UAE and Saudi Arabia are not converging on the European model. Both are building national AI strategies oriented towards adoption and capability rather than restriction, with substantial state investment behind them. A business operating primarily in the Gulf faces domestic expectations that look nothing like the AI Act.

Two things follow. First, if your Gulf-based business also sells into Europe, you will be running two quite different postures at once, and the European one will be stricter on documentation and human oversight than anything your local market requires. Second - and this is the part worth planning for - European compliance is becoming a credential in Gulf markets rather than a burden. A supplier who can produce AI Act documentation is demonstrating a level of engineering discipline that buyers there increasingly ask about, whether or not local law requires it.

The trap is assuming that a permissive home regulator means a permissive customer. Multinational clients in Dubai and Riyadh frequently apply their global standard, which is usually the European one.

Asia Pacific

Fragmented, and generalising is a mistake.

Singapore’s approach is framework-based and voluntary rather than statutory - the IMDA model governance frameworks and AI Verify testing rather than a prohibition regime. Japan and South Korea have taken their own paths. China regulates AI heavily but on entirely different principles, oriented to content control rather than fundamental rights.

For an APAC business the practical answer is usually that domestic obligations are lighter than Europe’s, so European compliance becomes the ceiling. Build to the EU standard and you are comfortably above everything else in the region, with the significant exception of China, where the requirements are different in kind rather than in degree and cannot be satisfied by doing more of what Europe asks.

Where the regions actually differ

Strip out the noise and there are three genuine differences.

On what triggers obligations. Europe triggers on the use case and its risk to people. The US triggers on the sector and increasingly on the size of the developer. The Gulf largely does not trigger at all yet. Asia Pacific mostly triggers on voluntary frameworks with procurement consequences.

On whether following a framework helps you. In Texas, demonstrably following NIST is a defence. In Europe, following ISO/IEC 42001 or NIST is evidence of diligence but not a safe harbour - conformity with harmonised standards is the route that carries legal weight for high-risk systems. Colorado removed its framework defence entirely. Do not assume a certificate buys you protection; check whether that jurisdiction actually says so.

On who carries the obligation. Europe splits provider and deployer with real consequences. Most other regimes do not draw the line as sharply, which means a company operating across regions can be a lightly-regulated vendor at home and a heavily-obligated provider in Europe for the same product.

What to do, wherever you are

Inventory the AI systems you provide and the ones you use, and note for each whether any output reaches the EU. That single list answers most of the scope question.

Classify each one against the four EU tiers, because the EU tiers are the strictest and everything else fits inside them.

Pick one framework and actually follow it. NIST if you have meaningful US exposure, ISO/IEC 42001 if you want something certifiable that European buyers recognise. The value is less in the certificate than in having your documentation already assembled when a customer questionnaire arrives.

Then stop. Most businesses reading this are deployers of ordinary tools with a transparency obligation and nothing more. The compliance industry has an incentive to tell you otherwise.

If you want an independent read on which parts genuinely apply to your business, book a free consultation. We have no software to sell you at the end of it.

References

  1. Regulation (EU) 2024⁄1689, Article 2, and the European Commission’s regulatory framework overview.
  2. The White House - Ensuring a National Policy Framework for Artificial Intelligence, December 2025.
  3. NIST - AI Risk Management Framework.
  4. Information Commissioner’s Office - Guidance on AI and data protection.
← Back to Blog