EU AI Act — Global Jurisdiction & Extraterritorial Scope

Image AI-generated. All  text human-written

No EU office. No EU employees. No EU investors. None of that decides the question — the EU AI Act’s jurisdictional test was never about where a company sits, but where its AI’s output lands. If your system serves users in Europe, or its results are used there, you are inside the scope of the world’s most consequential AI regulation — and part of its clock is already running.

How the Act claims jurisdiction over non-EU companies

The scope sits in Article 2, and it is deliberately extraterritorial. Article 2(1)(a) applies the Regulation to providers placing AI systems or general-purpose AI models on the EU market or putting them into service in the Union — expressly irrespective of whether the provider is established in the Union or a third country. Article 2(1)(c) reaches further: providers and deployers established in third countries are caught where the output produced by the AI system is used in the Union.

One precision the online versions keep getting wrong: the trigger is where the output is used — not the user’s nationality, and not their email domain. An EU citizen using a US-only product from Chicago does not bring the Act down on the vendor; a system whose results are received and acted on in Frankfurt does, wherever it runs. The accurate test is alarming enough without the inflated one.

The Brussels Effect, briefly

This is the architecture the EU used for the GDPR — the mechanism scholars call the Brussels Effect: companies wanting EU market access comply, and that compliance reshapes their products globally. US companies dismissing the EU AI Act as a European problem are running the calculation many ran on the GDPR in 2017; some spent 2019 in emergency compliance mode, or lost enterprise deals that made compliance a procurement condition.

Three scenarios, tested against the text

The SaaS platform with global sign-ups. Open registration, no geo-restriction — in virtually all cases that means EU users and serving them means the system is on the EU market and its output used in the Union. The provider obligations attach to the US operator, whatever share of revenue Europe represents. Small EU exposure is not partial exposure.

The API provider with downstream EU customers. Where downstream businesses deploy your API to serve EU users, your output is being used in the Union. Depending on how the system is structured — and whether what you supply is a general-purpose model — provider or GPAI obligations may follow. This one warrants written analysis, not assumption.

The US company with a single EU enterprise client. One signed EU contract places the system on the EU market. Which obligations follow depends on classification — and on two clocks. The transparency duties of Article 50, and national enforcement powers, have been live since 2 August 2026. The heavy high-risk programme — conformity assessment, technical documentation, registration, CE marking — applies from 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for AI embedded in regulated products, under Article 113 as amended.

The obligation most US companies have never heard of

For non-EU providers of high-risk AI systems, Article 22 creates a precondition of market access: before making the system available on the Union market, the provider must appoint, by written mandate, an authorised representative established in the EU. This is not a filing formality. The representative verifies that the declaration of conformity and technical documentation exist, keeps them — and the provider’s details — at the disposal of authorities for ten years, provides authorities with documentation and access to logs on request, and cooperates on any corrective action.

And the clause that should genuinely concentrate minds: the representative must terminate the mandate if it considers the provider to be acting contrary to its obligations — and immediately inform the market surveillance authority. Your own compliance infrastructure is designed to walk out and report you. A non-EU provider of high-risk AI cannot lawfully be on the EU market as a ghost — and an absent representative is itself a breach.

For providers of general-purpose AI models established outside the EU, the equivalent requirement — Article 54 — has applied since 2 August 2025. That clock is not coming. It has been running for a year.

What distance does and doesn’t protect you from

It does not protect you from the Regulation applying — Article 2 is explicit. It does not protect you from market exclusion: when the high-risk regime applies, a system without its conformity preconditions cannot lawfully be placed on the EU market — and an EU client using one carries exposure of its own, which is why procurement teams are asking for evidence ahead of any regulator. What distance complicates is enforcement mechanics against a company with no EU presence — the gap the authorised representative requirement exists to close. The exposure that arrives first is commercial: the stalled deal, the unanswered questionnaire.

The questions that actually matter

For most US AI companies with EU users, “does this apply” is settled. Three questions matter. Is anything you run high-risk under Annex III, or transparency-tier only — the classification that decides the entire architecture and which clock governs you? Do you provide a general-purpose AI model with EU reach — in which case the Article 54 representative duty already applies? And does an EU enterprise client require compliance evidence contractually — in which case the commercial deadline will arrive before the regulatory one? The companies in the hardest position next year will not be those that assessed their obligations — they will be the ones that never asked.

Classification is the first step — role by role, system by system, traced to the Official Journal text. ExecLevel AI builds exactly that record, in weeks.

Find out whether — and where — the EU AI Act reaches your company: a free assessment conversation at www.execlevelai.eu

Disclaimer: This article is for general informational purposes only and does not constitute legal or compliance advice. EU AI Act requirements may vary depending on your organisation, AI system, and use case. For advice on EU AI Act compliance, visit www.exclevelai.eu