The most common assumption among UK, US, Canadian, and Swiss businesses encountering the EU AI Act for the first time is that territorial scope follows establishment. If you are not incorporated in an EU member state, the Act does not apply to you.
This assumption is incorrect, and acting on it creates material regulatory and commercial exposure.
The EU AI Act establishes jurisdiction through three distinct routes, set out in Article 2(1) of Regulation (EU) 2024/1689. Only one of the three requires any EU presence. The other two apply regardless of where your business is registered, where your infrastructure sits, or whether you have a single employee in the European Union.
What Is the EU Nexus
The EU nexus is the connection between your business and EU law that brings you within the scope of the AI Act’s obligations.
Once a nexus is established, you are subject to the same requirements as an EU-established provider or deployer:
- Risk classification
- Technical documentation
- Cnformity assessment
- Human oversight
- Post-market monitoring
- If you are a non-EU business, the mandatory appointment of an EU-established Authorised Representative.
Understanding which nexus applies to your business is the first step in any EU AI Act compliance analysis.
Route One: Placing an AI System on the EU Market
Article 2(1)(a) brings within scope any provider that places an AI system on the EU market, regardless of whether that provider is established in the EU.
Placing on the market means making an AI system available for the first time in the EU in the course of a commercial activity, whether for payment or free of charge. If you sell, licence, or otherwise make your AI system available to any person or organisation in the EU, you have placed it on the EU market.
The geographic location of your servers, your development team, or your registered office is irrelevant. A US SaaS company licensing its AI-powered recruitment platform to a German employer has placed that system on the EU market. A Canadian fintech company providing AI-driven credit scoring to a Dutch bank has placed that system on the EU market. A UK startup selling an AI content moderation tool to a French media company has placed that system on the EU market.
If your AI system is high-risk under Article 6, full provider obligations apply from the moment of market placement. If you are established outside the EU, you must appoint an EU-established Authorised Representative before that placement occurs.
Route Two: Putting a System Into Service in the EU
Article 2(1)(b) extends the Act’s scope to providers that put an AI system into service in the EU, meaning they make the system available for use for the first time by a deployer or end user in the EU.
This route captures a scenario that non-EU businesses frequently overlook: deploying an AI system for your own EU operations, through an EU subsidiary, branch, or for EU-based clients under a service agreement. The system does not need to be sold to a third party. Internal deployment for EU-based operations triggers the nexus.
A UK company running an AI-powered HR system for its own employees based in Amsterdam is putting that system into service in the EU. A US technology company deploying an AI customer service agent for its Dublin support centre is putting that system into service in the EU. The fact that the system is internally operated, rather than sold to a third party, does not remove EU jurisdiction.
Route Three: Output Used in the EU
Article 2(1)(c) is the provision that most consistently surprises non-EU businesses, and the one with the widest practical reach.
Article 2(1)(c) extends the Act to providers and deployers that are not established in the EU, where the output of the AI system is used in the EU.
Output means what the AI system produces: a decision, a prediction, a recommendation, a classification, a score, or generated content. If that output affects people or transactions in the EU, the Act applies to the system producing it, regardless of where that system operates, who runs it, or how the output reaches the EU.
A UK credit scoring model that produces risk assessments used by EU lenders in their lending decisions is within scope under Article 2(1)(c). A US AI system that generates content moderation decisions affecting EU users of a platform is within scope. A Canadian CV screening tool that ranks candidates for EU-based roles is within scope. None of these scenarios requires an EU entity. The output is sufficient to establish the nexus.
This provision follows the same extraterritorial logic as the GDPR’s Article 3(2), which extends data protection obligations to non-EU businesses processing personal data of EU residents. The AI Act’s drafters were explicit that this approach was intentional.
What This Means for UK Businesses Specifically
Brexit did not remove UK businesses from the scope of EU digital regulation. It removed the UK from the regulatory framework that would have aligned UK law with EU requirements automatically.
The practical consequences for UK businesses are more complex than for businesses in other third countries. A UK business subject to the EU AI Act cannot use a UK-established entity as its EU Authorised Representative, because UK establishment does not satisfy the EU establishment requirement following Brexit. It cannot rely on UK data residency to satisfy EU compliance requirements. It cannot assume that serving EU clients through a UK contracting entity places it outside the Act’s territorial scope.
At the same time, the UK government has confirmed it will not replicate the EU AI Act framework domestically in the near term. UK businesses therefore face EU obligations without a domestic equivalent to benchmark against, creating a compliance asymmetry that affects product development, documentation, and governance decisions.
The Three Routes: Summary Table
| Route | Legal basis | What triggers it | EU establishment required |
|---|---|---|---|
| Placing on the EU market | Article 2(1)(a) | Selling, licensing, or making an AI system available to EU customers | No |
| Putting into service in the EU | Article 2(1)(b) | Deploying an AI system for use by EU operations or clients | No |
| Output used in the EU | Article 2(1)(c) | AI system output affects people or transactions in the EU | No |
The Authorised Representative Requirement
Once a non-EU business establishes that it falls within the Act’s scope through any of the three routes above, and its AI system is high-risk or it provides a general-purpose AI model, the Authorised Representative requirement under Articles 22 and 54 applies.
An Authorised Representative is an EU-established natural or legal person appointed by written mandate to act on the provider’s behalf in relation to EU compliance obligations. The representative verifies technical documentation, retains records for ten years, engages with market surveillance authorities and the AI Office, and carries direct regulatory liability for the obligations within the scope of the mandate.
The representative must be appointed before the system is placed on the EU market or put into service. Appointment after market entry does not remedy the prior breach.
| System type | Authorised Representative deadline |
|---|---|
| GPAI model providers | 2 August 2025 |
| High-risk AI system providers | 2 December 2027 |
A UK-established entity does not qualify as an Authorised Representative. The appointment must be an entity established in an EU member state.
Practical Steps for Non-EU Businesses
Step 1: Determine whether any of the three routes applies to your business.
Review your AI systems against each route in Article 2(1). The output route under Article 2(1)(c) is the most easily overlooked and the most broadly applicable.
Step 2: Classify each in-scope system by risk tier.
High-risk classification under Article 6 determines the full scope of your obligations. Limited-risk systems carry transparency obligations only. Minimal-risk systems carry the AI literacy obligation and nothing more.
Step 3: Identify your role for each system.
Provider obligations are more extensive than deployer obligations. If you developed the system and placed it on the market under your name, you are a provider. If you use a third-party system in a professional context, you are a deployer.
Step 4: Address the Authorised Representative requirement if applicable.
If you are a non-EU provider of a high-risk AI system or GPAI model, identify and appoint a qualified EU-established Authorised Representative before the applicable deadline.
Step 5: Build your compliance programme around your classification.
Technical documentation, risk management, conformity assessment, and post-market monitoring for high-risk systems. Transparency disclosures for limited-risk systems. AI literacy for all staff dealing with AI systems, regardless of risk tier, from February 2025.
Frequently Asked Questions
We are a UK company. Does the EU AI Act apply to us?
Yes, if any of the three routes in Article 2(1) applies to your business. Brexit removed the UK from the EU regulatory framework but did not remove UK businesses from the territorial scope of EU law where their activities affect the EU market. The AI Act’s extraterritorial reach follows the same logic as the GDPR.
We do not sell to EU customers directly. We sell to a UK distributor who resells in the EU. Are we in scope?
Possibly. If your UK distributor places your AI system on the EU market under your name or trademark, you may be treated as the provider for EU regulatory purposes. If the distributor places it on the market under their own name, they become the provider. The contractual and branding arrangements determine the answer.
Our AI system produces outputs that are used by EU clients of our UK client. Are we in scope under Article 2(1)(c)?
This depends on the specific facts of the output use. If your system produces decisions, scores, or recommendations that directly affect EU persons or EU transactions in a meaningful way, Article 2(1)(c) is potentially triggered regardless of the intermediary in the supply chain. The further removed the output is from direct EU effect, the weaker the nexus argument becomes.
We have a US parent company and a UK subsidiary. Which entity is the provider?
The provider is the entity that places the AI system on the market or puts it into service under its own name. If the US parent licenses the system to EU clients under its own brand, the US parent is the provider. If the UK subsidiary places it on the market under its own brand, the UK subsidiary is the provider.
The corporate structure does not determine the answer. The commercial arrangements and branding do.
We are already GDPR compliant. Does that satisfy the AI Act requirements?
No. GDPR compliance addresses data protection obligations. The AI Act imposes entirely separate requirements: risk classification, technical documentation, conformity assessment, human oversight design, post-market monitoring, and incident reporting.
The two frameworks apply concurrently and must be satisfied independently, though they interact where AI systems process personal data.
How European Compliance Suite Can Help
European Compliance Suite provides EU AI Act compliance services for non-EU businesses navigating territorial scope questions, risk classification, and Authorised Representative appointments.
If you are a UK, US, Canadian, or Swiss business placing AI products on the EU market and are not certain whether the Act applies to you, or what it requires if it does, contact European Compliance Suite for an initial scoping assessment.
This post reflects the text of Regulation (EU) 2024/1689 as published in the Official Journal on 12 July 2024 and applicable guidance issued by the European AI Office through July 2026. It is published by European Compliance Suite for general informational purposes and does not constitute legal advice.
