“We’re Not in Europe” Is Not a Compliance Strategy

Image AI-generated. All  text human-written.


A post I came across recently (part of an ongoing EU AI Governance series) makes a point that a lot of non-EU companies still get wrong: geography does not decide whether the EU AI Act applies to you. Impact does.

It’s worth spelling out why — and worth updating, because part of the regulatory timeline has actually shifted since that piece was first published in April 2026.

How the AI Act draws its jurisdictional lines

Regulation (EU) 2024/1689 — the EU AI Act — entered into force on August 1, 2024. Its territorial reach is set out in Article 2, and legal analysis of that article is consistent: the Act applies to providers placing AI systems on the EU market, to deployers located in the EU, and — critically — to providers and deployers established outside the EU whenever the output of their AI system is intended to be used in the Union.

That third category is the one that trips people up. A company with no EU office, no EU subsidiary, and no direct EU sales team can still fall inside the regulation’s scope if its AI system’s outputs reach or affect people in the EU.

Why “the customer is responsible” doesn’t hold up

The Act assigns different obligations to different roles — providers, deployers, importers, distributors. A company that builds or places an AI system on the market is generally treated as the provider, and providers carry the heaviest compliance load for high-risk systems: risk management, technical documentation, conformity assessment. Selling through resellers or enterprise clients doesn’t automatically shift that role onto someone else — regulators look at who actually developed and controls the system, not how a contract is worded. The same logic applies to “we just offer an API”: supplying a model via API can still count as placing a system on the market if it ends up embedded in EU-facing products.

The timeline update the original piece missed

Here’s the correction. As of the Act’s original schedule, high-risk system obligations under Annex III were due to apply from August 2, 2026. But the European Commission’s “Digital Omnibus on AI,” published November 19, 2025, proposed delaying that. Parliament and Council reached political agreement on May 7, 2026, and the change formally entered into force on July 27, 2026. The result:

  • High-risk obligations for Annex III use cases (employment, education, financial services, critical infrastructure, biometrics, and similar sensitive areas) are now deferred to December 2, 2027.
  • High-risk obligations for AI embedded in already-regulated products (Annex I — things like medical devices or machinery) are deferred to August 2, 2028.
  • What did not move: prohibited AI practices have been enforceable since February 2, 2025; GPAI (general-purpose AI model) obligations took effect August 2, 2025; and Article 50 transparency duties (covering chatbots and synthetic content disclosure) still apply from August 2, 2026, alongside general application of the Act.

So the deadline pressure hasn’t disappeared — it’s been redistributed. Transparency obligations are still on schedule for this year. The heavier high-risk compliance machinery has more runway than it did when the original piece was written.

The bigger mistake: skipping classification anyway

None of this changes the most important operational point: many organizations assume they’re not high-risk without ever running the Annex I / Annex III classification exercise the Act actually requires. That assumption is often wrong, and an extended deadline doesn’t fix a wrong classification — it just changes when the fix is due.

Takeaway

If your AI system’s outputs touch people in the EU, “we’re not in Europe” was never a jurisdictional shield, and the extra runway on high-risk deadlines isn’t a reason to skip classification — it’s time to do it properly before December 2027 (or August 2028) instead of scrambling.

This post is for general informational purposes and isn’t legal advice. The EU AI Act’s implementation timeline is still being actively negotiated and interpreted — confirm current deadlines with qualified counsel before making compliance decisions.

EU AI Act Compliance Disclaimer

This article is provided for general informational and educational purposes only and should not be considered legal, regulatory, or compliance advice. The EU AI Act is evolving, and its requirements can vary depending on the organisation, AI system, role, and specific use case. For professional advice and guidance on EU AI Act compliance, visit www.exclevelai.eu.