Blog

    Does the EU AI Act Apply to Your Company? A 2026 Guide for Non-EU Businesses

    2026 Guide EU AI Act
    Does the EU AI Act Apply to Your Company? A 2026 Guide for Non-EU Businesses

    Yes. The EU AI Act can apply to your company even if you are headquartered outside the EU.

    Any provider or deployer whose AI system output reaches EU users is in scope, regardless of where they are based. The EU AI Act applies the same obligations to non-EU companies as to EU-based ones. Risk classification, technical documentation, and fines of up to €35 million for non-compliance.

    If your system is used by people in the EU, or if its output affects EU users, you are in scope. A US SaaS platform, a UK-based AI API, an Australian consumer app available in France: all of them fall within scope. The Act does not stop at borders. Article 2 of Regulation (EU) 2024/1689 covers both providers and deployers regardless of where they are established.

    This article walks you through a practical applicability test and a breakdown of what the Act means for companies in the US, UK, and other major markets. Start with our complete guide to the EU AI Act if you need the full regulatory picture first.

    Understand the Extra-Territorial Scope

    Who does the EU AI Act apply to? Any provider or deployer whose AI output reaches EU users regardless of where they are registered. Article 2(1)(c) is where that begins. Where servers sit does not matter.

    Two roles. Both in scope.

    Article 25(1) means your role can change. A distributor or deployer that makes a significant modification to a system is legally reclassified as a provider and takes on the full compliance burden that comes with it.

    Both roles. One rule. If the output reaches EU users, you are in scope. For a full breakdown of how the regulation is structured, read our guide on what the EU AI Act is and how it works.

    EU AI Act scope is defined by output, not origin. Article 2 asks where your system’s results land, not where your company is registered. The same obligations apply equally to US, UK, and every other third-country business.

    JAGGAER

    Every output logged. Humans accountable at every step.

    Run the Four-Question Applicability Test

    When does the EU AI Act apply? EU AI Act applicability turns on four questions. Answer them and you know exactly where you stand.

    EU AI Act, Article 2
    Does the Act Apply to Your Business?
    Answer four questions. Know where you stand.
    1
    Question 1 of 4
    Do you develop or deploy an AI system?
    If you build AI systems and bring them to market, you are a provider (Article 3(3)). If you use an AI system in a professional context, you are a deployer (Article 3(4)).
    You are not a provider or deployer. The Act does not apply to your organisation in this context.
    2
    Question 2 of 4
    Is it used by people in the EU, or does it affect people in the EU?
    One EU user on your platform is enough. No EU office, EU contract, or EU customer base required. Article 2(1)(c) covers third-country providers whose outputs reach EU users.
    Your system does not reach EU users. The Act does not apply to your current deployment.
    3
    Question 3 of 4
    Is your system in scope?
    The Act excludes military applications, systems used solely for national security, and pure scientific research. If your system falls outside these, it is in scope.
    Your system falls within an excluded category. The Act does not apply. Document that exclusion clearly.
    4
    Question 4 of 4
    What risk tier does your system fall into?
    Your tier determines your compliance obligations. Select the closest match.

    The test above maps EU AI Act scope to your specific deployment type.

    What This Means for US Companies

    The EU AI Act impact on businesses headquartered in the US is not hypothetical. It is already running on an active enforcement timeline.

    US EU AI Act obligations are identical to those facing any other non-EU business. If your AI product or service reaches EU users, you are in scope. No EU subsidiary required. No EU-registered customers required. One EU user is enough.

    HR screening tools, CRM software, recruitment platforms. The moment an employee or job candidate inside the EU interacts with your system, Article 2(1)(a) and (c) pulls you in scope.

    Credit scoring engines, LLM integrations. Recital 22 closes the remote processing loophole. If an EU-based developer calls your US-hosted API and the output flows back to EU end-users, the Act covers you.

    AI image generators, fitness apps, productivity tools. A user in France downloading your app triggers Article 3(3). The Act applies whether your product is paid or free.

    A US company deploying its own AI at an Italian branch office is a deployer under Article 2(1)(b) and Article 3(4). Location of deployment is what counts.

    For US companies, the first practical question is straightforward: which tools in your stack actually reach EU users?

    JAGGAER

    Sourcing, contracts, suppliers, and spend one platform, no integration tax.

    What This Means for UK Companies

    Does the EU AI Act apply to the UK? Yes with no special carve-outs and no transitional exemptions. Post-Brexit, the UK is a third country under the Act. Article 2(1)(c) treats UK businesses the same as US or Australian ones. If your output reaches EU users, you are in scope.

    The UK runs a completely different framework at home. The DSIT pro-innovation white paper is principles-based and sector-led. No horizontal risk classifications. No centralized AI regulator. Existing bodies, the HSE, Ofgem, and the ICO, each apply the framework within their own remit. The UK also leans on regulatory sandboxes over outright bans, creating space for testing that the EU does not offer.

    How does the EU AI Act affect companies operating from the UK? The same way it affects any non-EU business the trigger is whether your output reaches EU users, not where your office is.

    That difference does not reduce EU exposure. A UK recruitment platform, proctoring tool, or automated grading system crossing into the single market triggers Annex III high-risk obligations under the EU Act. This applies regardless of what the UK requires domestically. Compliance with one framework does not satisfy the other.

    Two frameworks. Two compliance tracks. Neither cancels the other.

    What This Means for Companies in Other Markets

    The Act’s reach extends beyond the US and UK. Under international law, the EU AI Act operates as an extra-territorial regulation, the only framework of its kind with binding reach beyond its home borders. Any company whose AI output reaches EU users is in scope, regardless of where it was built.

    Operates a voluntary governance framework through the IMDA. Flexible domestically, but a Singaporean SaaS product serving European clients must meet EU standards as its binding legal baseline.

    Relies on existing legislation and sector-led oversight rather than a standalone AI law. Australian exporters navigate local privacy obligations and EU technical documentation requirements simultaneously.

    Working directly with European regulators through the Canada–EU Digital Partnership Council to keep its AI products eligible for European markets.

    EU AI Act influence on global standards is already visible. This is the Brussels Effect in practice. Companies building to EU standards adopt those standards globally. The EU AI Act regulates where your product operates, not where your company is incorporated.

    JAGGAER

    13M+ suppliers. $2.9T in annual spend managed. Configured for your operating footprint.

    What Obligations Follow If It Applies to You in 2026

    Your obligations depend on your risk tier. Prohibited system bans took effect in February 2025 and the enforcement window is already open. The Act demands architectural changes to how AI systems are designed, documented, and tested before going into service, not a legal sign-off and not a one-time exercise. EU AI Act compliance challenges for companies outside the EU centre on four areas: risk classification, technical documentation, conformity assessment, and database registration. The higher the tier, the heavier the load.

    High-Risk Operational Cost Realities · Per System
    €320K–
    €600K
    Upfront pre-market setup
    Engineering, documentation, and legal costs before EU deployment. European Parliament, Q E-001210/2026.
    €150K
    Annual maintenance cost
    Ongoing logging, monitoring, and bias audits per system, per year. The Parliament Magazine.
    Added overhead on core AI spending
    Compliance premium on core AI compute and R&D. European Commission / CEPS.
    Article 99 Non-Compliance Penalties
    Prohibited System Deployment
    €35M or 7%
    Social scoring, biometric scraping, subliminal manipulation Article 99(3)
    Core High-Risk Violations
    €15M or 3%
    Missing conformity assessments, unlogged high-risk data Article 99(4)
    False or Misleading Documentation
    €7.5M or 1%
    Falsified technical files, hidden data lineages Article 99(5)

    Everything starts here. Your tier determines what follows. For a full breakdown of where your system sits, read our guide on EU AI Act risk categories explained.

    High-risk systems cannot operate as a black box. Article 11 and Annex IV require providers to document architectural design, algorithmic logic, training data, risk management evaluations, and ongoing accuracy metrics before placing a product into service. See the full EU AI Act fines and compliance checklist for the documentation requirements by tier.

    Article 43 requires high-risk systems to pass a conformity assessment. Most software providers can run this internally. Systems embedded in regulated physical hardware require an external EU Notified Body.

    Article 49 blocks market entry until your system is publicly logged in the European Commission’s centralized database. No exceptions for third-country providers. Check the EU AI Act compliance deadlines to confirm when registration obligations apply to your system type.

    Prohibited System Deployments
    (e.g. social scoring, biometric scraping)

    €35M or 7%


    Article 99(3)

    Core High-Risk Violations
    (e.g. missing conformity assessments, unlogged data)

    €15M or 3%


    Article 99(4)

    Misleading or False Documentation
    (e.g. falsified technical files)

    €7.5M or 1%


    Article 99(5)

    JAGGAER

    Every transaction logged. Every supplier interaction traceable. No black box.

    Frequently Asked Questions

    The EU AI Act applies to any provider or deployer whose AI system output is used within the EU, regardless of where the company is registered or where its servers are located. Both providers and deployers are in scope and both carry compliance obligations.

    Yes. US EU AI Act obligations apply to any company whose AI product or service reaches EU users. This includes SaaS platforms, AI APIs, consumer apps, and enterprise software deployed at EU client sites.

    Yes. Post-Brexit, the UK is treated as a third country under the Act. The same extra-territorial logic applies. If your output reaches EU users, you are in scope regardless of what UK regulation requires.

    The trigger is use, not location. If your AI system is used by people in the EU, or if its output affects EU users, the Act applies. Where your company is incorporated is irrelevant.

    A provider, defined under Article 3(3), is any entity that develops an AI system and places it on the market under its own name. Providers carry the heaviest compliance obligations under the Act.

    A deployer, defined under Article 3(4), is any entity that uses an AI system in a professional context. Deployers are bound by operational logging and human oversight obligations under Article 26.

    Yes, if EU users interact with the platform. A SaaS product used by an employee or job candidate in the EU triggers Article 2(1)(a) and (c), regardless of where the software is hosted or the company is based.

    Article 99 sets three penalty tiers. Deploying a prohibited system carries fines of up to €35 million or 7% of worldwide annual turnover. Core high-risk violations, including missing conformity assessments and unlogged data, carry up to €15 million or 3%. Supplying false or misleading documentation carries up to €7.5 million or 1% of worldwide annual turnover. Market access to the EU can also be blocked.

    The US does not have a single federal AI law equivalent to the EU AI Act. The US approach is currently sector-led and largely voluntary at the federal level, making the EU Act significantly more prescriptive for companies operating across both markets.

    EU AI Act impact on startups can be disproportionately heavy. The cost baseline of €320,000–€600,000 per high-risk system makes compliance a significant burden for early-stage companies. Startups should prioritise risk tier identification before building at scale. If your system falls into high-risk categories such as recruitment or credit scoring, compliance costs need to be built into your product roadmap from day one.

    Yes. This is the Brussels Effect in practice. EU AI Act influence on global standards extends beyond direct compliance. Companies building to EU standards adopt those standards globally, and Canada, Singapore, and Australia are all actively aligning their domestic frameworks with EU requirements.

    Next Steps

    Now you know whether the Act applies to your business. The next question is what it requires. These guides take you through each step.

    The full regulatory picture. What the Act is, how it works, and what it covers.

    Identify which tier your system falls into and what that requires.

    Penalties broken down, deadlines mapped, and a step-by-step checklist for non-EU providers.

    Talk to a procurement expert.

    Tell us your challenge. We will show you exactly where JAGGAER One fits into your current setup — with specifics, not a generic demo.

    • Direct or indirect?
      We handle both — on one platform.
    • Already have an ERP?
      JAGGAER Link connects to 1,000+ systems, no rip-and-replace.
    • Need to show ROI fast?
      We define outcomes and KPIs before you sign.
    • Vertical-specific?
      Manufacturing, higher ed, public sector — configured, not customized.

    Related Articles

    Copyright © 2026 JAGGAER – All Rights Reserved

    JAGGAER and the JAGGAER logo are registered trademarks of JAGGAER, LLC. All other registered trademarks, trademarks, and service marks are the property of their respective owners.