Last updated: 29 July 2026

Summary

The EU AI Act applies to anyone who develops, sells, or uses an AI system whose output reaches the EU market, regardless of where that company is based. It catches four main actors: providers (who build or sell the system), deployers (who use it in their own operations), importers, and distributors. A US company with no EU office is in scope the moment its AI system’s output is used by someone in the EU. A handful of exclusions exist: military and national security use, pre-market research, and purely personal use by individuals. Everything else is presumed in scope until you check it against Article 2.

The Digital Omnibus on AI (Regulation (EU) 2026/1744) entered into force on 27 July 2026. It changed the compliance deadlines for high-risk systems. It did not change who is caught by the Act. If your organisation touches an AI system that reaches EU users, that question was already settled before the Omnibus and remains settled now.

The Short Answer

You are in scope of the EU AI Act if any of the following is true:

  • You build or sell an AI system or a general-purpose AI model that gets placed on the EU market, wherever you are based.
  • You use an AI system in your own operations and you are established or located in the EU.
  • You are established outside the EU, but the output of your AI system is used by people in the EU.
  • You import AI systems into the EU under someone else’s name, or you distribute them in the EU supply chain.
  • You manufacture a physical product that has an AI system built into it and you put that product on the EU market under your own brand.

There is no EU-entity requirement anywhere in that list. Physical presence is irrelevant. Output reaching the EU is what triggers the Act.

Who Counts as Each Actor

Article 3 defines the roles that Article 2 then hooks the Act’s scope onto. Getting your role right matters, because obligations are role-specific: a provider carries far more weight than a deployer.

RoleDefinitionExample
ProviderDevelops an AI system or GPAI model, or has one developed, and places it on the market or puts it into service under its own name or trademark, whether for payment or free of chargeA software company selling an AI-powered CV screening tool to employers
DeployerUses an AI system under its own authority in a professional context, other than personal non-professional useAn HR department running that CV screening tool to shortlist candidates
ImporterEstablished in the EU, places on the market an AI system that bears the name or trademark of a non-EU providerAn EU distributor bringing a US vendor’s AI product into the EU market
DistributorMakes an AI system available on the EU market without being the provider or importerA reseller or marketplace listing the system for EU buyers
Product manufacturerPlaces an AI system on the market together with a physical product, under its own name, where the AI system is a safety component or the product itself is the AI systemA machinery manufacturer embedding an AI-based safety controller
Authorised representativeEstablished in the EU, appointed in writing by a non-EU provider to carry out specified compliance tasks on the provider’s behalfAn EU-based AR acting for a US GPAI model provider
Affected personA natural person in the EU subject to or affected by the output of a high-risk AI system, without being a provider or deployerA job applicant assessed by an AI recruitment tool

Most organisations reading this are either a provider (you build the thing) or a deployer (you use the thing someone else built). Many organisations are both, for different systems, at the same time.

Territorial Scope: In or Out

Article 2(1) sets out the geographic hooks. The table below works through the scenarios people actually ask about.

ScenarioIn scope?
EU-established provider selling an AI system in the EUYes
Non-EU provider selling an AI system that is placed on the EU marketYes
Non-EU provider, no EU sales, but the system’s output is used by someone in the EUYes
EU-established deployer using an AI system in its own operationsYes
Non-EU deployer whose AI system’s output is used in the EUYes
Non-EU company using AI purely for internal operations with no EU output or EU market presenceNo
EU company using AI purely for military, defence, or national security purposesNo
Individual using a consumer AI tool for a purely personal, non-professional reasonNo

The “output used in the EU” hook is the one that catches most non-EU companies off guard. It does not require an EU office, an EU subsidiary, EU marketing, or an EU billing address. A US employer running AI-based candidate screening on applicants who happen to be in the EU is in scope. A US company whose product is used exclusively by US employees, with no EU output at all, is not.

What Falls Outside the Act

Article 2 also lists specific exclusions. These are narrow. None of them is a general “we’re a small company” or “we’re not really an AI company” carve-out.

ExclusionCondition
Military, defence, national securityAI system’s output is used exclusively for these purposes, and the system is not placed on the market or put into service in the EU for any other purpose
Scientific research and developmentApplies before the system is placed on the market or put into service; the exclusion ends once you commercialise
Personal, non-professional useUse by a natural person, not in a professional or business capacity
Public authorities in third countries and international organisationsOnly where they use AI in the framework of law enforcement or judicial cooperation with the EU, and only where adequate fundamental rights safeguards apply
Open-source AI componentsPartial exclusion for free and open-source AI systems and components, unless they are high-risk, fall under Article 5 prohibited practices, or are GPAI models with systemic risk

None of these exclusions removes you from the prohibited practices in Article 5. Those apply regardless of sector, size, or purpose, with the narrow exceptions written into the Article itself.

What the Digital Omnibus Changed, and What It Didn’t

Regulation (EU) 2026/1744 was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It amends the AI Act’s timeline and adds new provisions. It does not touch Article 2’s scope test.

What changed:

  • High-risk obligations for standalone Annex III systems are deferred to 2 December 2027.
  • High-risk obligations for AI embedded in Annex I products are deferred to 2 August 2028.
  • A new Article 5 prohibition covers AI-generated non-consensual intimate imagery and AI-generated CSAM, applying from 2 December 2026.
  • The AI Office’s supervisory powers were extended over GPAI models and the systems built on them within the same corporate group.
  • Products inside the Machinery Regulation’s scope are carved out of direct AI Act application for the relevant high-risk requirements.

What didn’t change: whether you are a provider or deployer, whether your output reaching the EU puts you in scope, and whether you need to comply with the prohibited practices in Article 5 and the AI literacy obligation in Article 4, both of which have applied since February 2025.

If your scoping exercise concluded you were in before 27 July 2026, you are still in. The Omnibus moved deadlines. It did not move the door.

Frequently Asked Questions

Does the EU AI Act apply to companies with no office in the EU?

Yes, if the AI system is placed on the EU market or its output is used by someone in the EU. Physical presence, an EU subsidiary, and an EU bank account are all irrelevant to the scope test.

Does the EU AI Act apply to open-source AI models?

Partially. Free and open-source AI systems and components get a conditional exclusion from most obligations, but that exclusion does not cover high-risk systems, prohibited practices under Article 5, or GPAI models classified as carrying systemic risk.

Does the EU AI Act apply to a US company whose AI tool screens EU job applicants?

Yes. Output used in the EU triggers scope, regardless of where the company or its servers are based. This is one of the most commonly missed scope triggers for non-EU employers.

Am I exempt if my AI system is still in research and development?

Yes, but only until you place it on the market or put it into service. The R&D exclusion ends the moment you commercialise or deploy operationally.

Does the Act apply to individuals?

Only in a professional capacity. Purely personal, non-professional use by a natural person falls outside scope. Using an AI tool for your job, even informally, is professional use.

What’s the practical difference between a provider and a deployer?

A provider builds or brands the system and carries the heaviest obligations: technical documentation, conformity assessment, risk management, registration. A deployer uses the system operationally and carries a narrower set of obligations, mainly around human oversight, monitoring, and, for high-risk systems, a fundamental rights impact assessment in specific cases.

Does the Digital Omnibus remove anyone from scope?

No. It defers deadlines for high-risk obligations and adds new prohibited practices. It leaves the Article 2 scope test as it was.

Is a company exempt just because it’s small?

There is no general SME exemption from scope. Some obligations scale down for small and micro enterprises, for example lighter documentation formats, but the underlying scope question is answered the same way regardless of company size.

Does the Act apply to GPAI model providers based outside the EU, like most large US labs?

Yes. GPAI model providers are in scope if the model is placed on the EU market, irrespective of where the provider is established.

If my system’s output never reaches the EU, am I safe?

If there is genuinely no EU placement on the market and no EU output, you are outside Article 2. Given how many products route through EU customers, EU cloud regions, or EU-based end users indirectly, this needs an actual check rather than an assumption.

How European Compliance Suite Can Help

Scope determination is the first gate in any compliance programme, and it is where most organisations either over-scope everything and burn budget on obligations that don’t apply, or under-scope and miss a system that does. We run the Article 2 and Article 3 logic against your actual systems, not a generic checklist, and classifies role and territorial scope per system rather than per company. Book a demo.