Does the EU AI Act Apply to My US Company? A Plain-English Guide to Article 2 Extraterritorial Scope

A US company with no European office, no European entity, no European servers and no European sales team can still be squarely within the EU AI Act. Not through an aggressive interpretation - through the plain text of Article 2(1)(c).
This surprises people who worked through GDPR, because the AI Act's reach is drafted differently. GDPR Article 3(2) requires targeting: offering goods or services to people in the Union, or monitoring their behaviour. The AI Act asks a simpler question. Is the output used in the Union?
Enforcement began on 2 August 2026. This guide walks through each limb of Article 2, which exclusions are real and which are narrower than they look, and what enforcement actually looks like against a company with nothing in Europe to seize.
1. The seven limbs of Article 2(1)
Article 2(1) is worth reading in full before anyone in your organisation concludes you are out of scope:
This Regulation applies to: (a) providers placing on the market or putting into service AI systems or placing on the market general-purpose AI models in the Union, irrespective of whether those providers are established or located within the Union or in a third country; (b) deployers of AI systems that have their place of establishment or are located within the Union; (c) providers and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union;[1] (d) importers and distributors of AI systems; (e) product manufacturers placing on the market or putting into service an AI system together with their product and under their own name or trademark; (f) authorised representatives of providers, which are not established in the Union; (g) affected persons that are located in the Union.
Four of these can catch a non-EU company:
Limb (a) - placing on the market, irrespective of establishment. If you make your AI system available on the Union market, you are in scope whether or not you have any European presence. Note that this limb separately covers general-purpose AI models, not just systems.
Limb (b) - deployers established or located in the Union. This is about location, not nationality. A US company's German subsidiary using an internal AI tool is a deployer in scope, even if the tool never leaves the group.
Limb (c) - the output limb. The widest hook, and the one that catches companies who believe they have no EU exposure. It applies to third-country providers and deployers where the output produced by the AI system is used in the Union.
Limb (g) - affected persons located in the Union. This is the basis on which someone in the EU can complain about your system under Article 85 even though you have no establishment there.
One important point for anyone tracking the Digital Omnibus: the territorial scope paragraphs were not touched. Regulation (EU) 2026/1744 amended Article 2(7) - adding a saving for the new Article 4a and Article 59 - and inserted a new Article 2(13) sectoral equivalence clause. Paragraphs 2(1)(a) to (g) are unchanged. The "simplification" package left the extraterritorial reach exactly where it was.
2. What "output used in the Union" actually means
This is where the honest answer is more interesting than the confident one.
Recital 22 gives the rationale:
"To prevent the circumvention of this Regulation and to ensure an effective protection of natural persons located in the Union, this Regulation should also apply to providers and deployers of AI systems that are established in a third country, to the extent the output produced by those systems is intended to be used in the Union.[2]"
Read the last clause against Article 2(1)(c) and you will notice they do not match. The recital says output "intended to be used in the Union." The operative provision says output that "is used in the Union." Recitals do not override operative text, but they inform its interpretation - and this gap has not been resolved by any Commission guidance we can identify. It is a live interpretive question, not a settled one.
Recital 22's worked example is narrower than most commentary suggests. It describes offshored processing:
"where an operator established in the Union contracts certain services to an operator established in a third country in relation to an activity to be performed by an AI system that would qualify as high-risk ... the AI system used in a third country ... could process data lawfully collected in and transferred from the Union, and provide to the contracting operator in the Union the output of that AI system ... without that AI system being placed on the market, put into service or used in the Union."
That is the paradigm case the drafters had in mind: an EU company outsources a regulated activity to a third-country processor, and the output comes back into the Union. Not "a European happened to visit your website."
The recital also confirms that the EU-side recipient does not escape either: "Recipient national authorities and Union institutions, bodies, offices and agencies making use of such outputs in the Union remain accountable to ensure their use complies with Union law.[2]"
What is clear from the face of the text is what the limb does not require. There is no targeting test. There is no personal-data nexus. There is no monitoring test. Legal commentary has converged on a broad reading - as Holland & Knight put it, "even if a company's servers are outside the EU, if the AI system's output affects EU residents, then the company may arguably be in scope," giving the examples of a non-EU employer screening EU-based candidates and a financial institution processing EU residents' credit data.
Note the "arguably." The same analysis adds the realism caveat that belongs in any board memo on this: "the extent to which the EU can actually exercise jurisdiction and enforcement with respect to a U.S. business can heavily depend on the circumstances, as has been seen with respect to the GDPR.[3]"
The same logic runs through to models. The Commission's July 2025 guidelines on GPAI obligations confirm that providers are in scope if they place a model on the EU market irrespective of establishment, and that non-EU GPAI providers must appoint an EU authorised representative before doing so.
3. The exclusions - and how narrow they are
Several Article 2 exclusions get cited as escape routes. Most are tighter than they appear.
| Exclusion | Provision | The catch |
|---|---|---|
| Military, defence, national security | Art 2(3) | Applies only where the purpose is exclusive. Dual use kills it. |
| Scientific research and development | Art 2(6) | Only where developed and put into service for the sole purpose of scientific R&D. |
| Pre-market research and testing | Art 2(8) | Ends at market placement, and "testing in real world conditions shall not be covered by that exclusion." |
| Purely personal, non-professional use | Art 2(10) | Excludes only deployer obligations, and only for natural persons. |
| Free and open-source | Art 2(12) | Does not apply where placed on the market as high-risk, or as a system falling under Article 5 or Article 50. |
| Third-country public authorities | Art 2(4) | Only under law-enforcement or judicial-cooperation agreements with adequate fundamental-rights safeguards. |
Two deserve emphasis.
The national security exclusion was drafted against the output limb specifically. Article 2(3) has three cuts: areas outside the scope of Union law; systems used "exclusively for military, defence or national security purposes, regardless of the type of entity carrying out those activities"; and - the relevant one here - systems not placed on the EU market "where the output is used in the Union exclusively for military, defence or national security purposes." The drafters anticipated that Article 2(1)(c) would otherwise sweep in defence outputs, and closed it. The word "exclusively" appears in each limb.
The open-source carve-out does not cover what most people assume. Article 2(12) exempts systems released under free and open-source licences - "unless they are placed on the market or put into service as high-risk AI systems or as an AI system that falls under Article 5 or 50." Article 5 is prohibited practices. Article 50 is transparency. Those are precisely the two limbs that became enforceable on 2 August 2026. If you release an open-source generative system that produces synthetic content, the open-source status buys you nothing on the obligation that is live today.
4. If you are in scope: the authorised representative chokepoint
We have covered Article 22 in depth separately, so briefly: before making a high-risk AI system available on the Union market, a provider established in a third country must, by written mandate, appoint an authorised representative established in the Union. The representative must be able to verify the declaration of conformity and technical documentation, keep records for ten years, cooperate with authorities, and comply with Article 49 registration - and must terminate the mandate where it considers the provider to be acting contrary to the Regulation, immediately informing the market surveillance authority.
What is worth adding here is that this duty is policed downstream, which is how it becomes real for a company that would otherwise ignore it.
Under Article 23, before placing a high-risk system on the market the importer must verify that the conformity assessment was carried out, that technical documentation exists, that the CE marking, EU declaration of conformity and instructions are present, and that the provider has appointed an authorised representative under Article 22(1). Importers must also put their own name and contact address on the system or its packaging and retain records for ten years. Under Article 24, distributors must verify CE marking, the declaration of conformity, instructions for use, and that the provider and importer have met their obligations before making the system available.
The practical effect: your EU channel partners cannot lawfully carry your product if you have not appointed a representative. Non-compliance does not require a regulator to find you - it surfaces the first time a European distributor runs its own checks.
5. What enforcement against a non-EU company actually looks like
Enforcement began on 2 August 2026. The Commission's announcement: "From 2 August 2026, the European Commission's AI Office, together with national authorities, will begin enforcing the Artificial Intelligence (AI) Act.[8]" The live limbs are GPAI model rules, Article 50 transparency, and the prohibited practices in Article 5.
Responsibility is split three ways. The AI Office enforces for AI systems offered by the same provider as the underlying GPAI model, and for systems integrated into very large online platforms and search engines designated under the DSA. National competent authorities cover other AI systems. The EDPS covers EU institutions.
How you get found. The Commission has launched an AI Act Complaint Tool open to natural and legal persons, a Whistleblower Tool, and a dedicated channel for downstream providers to report GPAI model providers. Complaint-driven enforcement does not require a regulator to be watching you; it requires one person to file.
What the fines are. Article 99 sets three tiers: up to €35 million or 7% of total worldwide annual turnover, whichever is higher, for breaching the Article 5 prohibitions; up to €15 million or 3% for non-compliance by providers, authorised representatives, importers, distributors, deployers and notified bodies - the tier the Commission cited for the new transparency duties; and up to €7.5 million or 1% for supplying incorrect, incomplete or misleading information to authorities.
The lever that does not depend on collecting money. Failure to appoint an authorised representative is a listed ground of formal non-compliance under Article 83(1). If not cured within the prescribed period, the market surveillance authority "shall take appropriate and proportionate measures to restrict or prohibit the high-risk AI system being made available on the market or to ensure that it is recalled or withdrawn from the market without delay.[10]" Against a company with no European assets, market exclusion is the practical sanction - and it does not require cross-border enforcement of a fine.
New investigative powers, with a territorial limit. The Digital Omnibus gave the AI Office antitrust-style powers in new Articles 75a to 75d, exercisable from 2 August 2026: all market surveillance powers, simple and decision-based requests for information, remote and on-site inspections including entry to "business premises, land or property in the Union," the power to seal premises and records, binding commitment decisions, and periodic penalty payments of up to 5% of average daily worldwide turnover per day.
Note the "in the Union." Inspection powers stop at the border. That is a genuine constraint - and a reason the market-access levers matter more than the investigative ones against a company with no European footprint.
The capacity gap is real. The Commission itself concedes that "effective enforcement will also depend on Member States ensuring that national competent authorities are properly designated and adequately resourced." The numbers back that up: Member States were required to designate competent authorities and single points of contact by 2 August 2025, but as of March 2026 the list comprised eight single contact points out of 27.
Should you count on that? The most recent evidence says no. On 23 July 2026 the Commission fined Google €890 million under the Digital Markets Act, with 60 days to comply or face periodic penalties of up to 5% of worldwide turnover. That is not an AI Act precedent - no AI Act enforcement action against a third-country operator has been brought as of this writing - but it establishes that the Commission is willing and able to impose material penalties on US companies. The AI Act's enforcement machinery is younger, not weaker.
6. The transatlantic divergence is widening
If your compliance strategy rests on the assumption that US law will converge with the EU's, 2026 has gone the other way.
- A White House executive order in December 2025 created a DOJ AI Litigation Task Force to challenge state AI laws on interstate-commerce and preemption grounds, and a National Policy Framework for AI released in March 2026 urged Congress to preempt state AI laws that "unduly burden" AI-assisted activity.
- Colorado repealed its AI Act. SB 26-189, signed 14 May 2026, replaced the "high-risk AI system" regime - the closest US analogue to the EU model - with a narrower automated-decision-making framework focused on disclosure, correction rights and human review, effective 1 January 2027.
- New York's RAISE Act was realigned to California's transparency-and-reporting model in March 2026.
So the US is narrowing and fragmenting while the EU's output-based extraterritorial hook survived a package explicitly branded as simplification. For a US company, that widening gap means domestic compliance work increasingly does not transfer.
Are US companies actually complying? The best available signal is participation rather than compliance: the Commission published a first list in July 2026 of more than 180 organisations that signed the Code of Practice on Transparency of AI-Generated Content. The counter-example is instructive too - Meta publicly declined to sign the GPAI Code of Practice in July 2025, while 26 companies including Anthropic, Google, Microsoft, OpenAI and Mistral signed. Declining a code is not an exemption; non-signatories must demonstrate compliance by other means, usually at greater cost.
A scoping exercise you can run this week
- Ask the output question first, not the establishment question. Not "do we operate in Europe?" but "does any output of any of our AI systems get used in the Union?" Include outputs delivered to an EU customer under contract, and outputs consumed by an EU affiliate.
- Check your EU subsidiaries as deployers. Limb (b) turns on location. Internal tools count.
- Test the exclusions against the exact wording. "Exclusively," "sole purpose," "natural persons" - each of these words is doing work, and each is narrower than the shorthand.
- If you ship open-source generative systems, assume Articles 5 and 50 apply. The Article 2(12) carve-out expressly does not reach them.
- Sort out Article 22 before your channel does. Importers and distributors must verify that you have appointed a representative. If you have not, they cannot carry the product.
- Diarise the real dates. 2 August 2026 (Article 50, prohibitions, GPAI, enforcement); 2 December 2026 (Article 50(2) marking for legacy systems; new Article 5 prohibitions); 2 December 2027 (Annex III high-risk); 2 August 2028 (Annex I high-risk); 2 August 2030 (high-risk systems used by public authorities).
- Do not plan around under-resourced regulators. The capacity gap is real today. Limitation periods are five years, and market-access sanctions do not need a well-staffed authority to bite.
The distinctive feature of the AI Act is that it does not ask where you are. It asks where your output lands. For a company that has never thought of itself as operating in Europe, that is an unfamiliar question - and it is the one that decides the answer.
- Article 2: Scope - AI Act Service Desk, European Commission
- Recital 22 - AI Act Service Desk, European Commission
- US Companies Face EU AI Act's August 2026 Compliance Deadline (Holland & Knight, 28 April 2026)
- Guidelines on the scope of obligations for providers of general-purpose AI models (European Commission, 18 July 2025)
- Article 22: Authorised Representatives of Providers of High-Risk AI Systems - EU AI Act
- Article 23: Obligations of Importers - EU AI Act
- Article 24: Obligations of Distributors - EU AI Act
- Commission starts enforcing AI Act rules and new transparency requirements (European Commission, 31 July 2026)
- Article 99: Penalties - EU AI Act
- Article 83: Formal Non-Compliance - EU AI Act
- Digital Omnibus on AI published in the Official Journal (NicFab, 24 July 2026)
- EU AI Act Update: Digital Omnibus Finalizes 8 Compliance Changes (Orrick, 29 July 2026)
- Enforcement of the AI Act (European Parliamentary Research Service, 18 March 2026)
- Commission fines Google EUR 890 million for breaches of the Digital Markets Act (23 July 2026)
- Colorado AI Act repealed, replaced with new transparency law (Davis Wright Tremaine, May 2026)
- State AI laws: where are they now? (Cooley, 24 April 2026)
- State AI laws under federal scrutiny: key takeaways from the executive order (White & Case, December 2025)
Related reading

EU AI Act and Medical Devices: How the MDR/IVDR Interplay Actually Works After the Digital Omnibus
AI-enabled medical devices now have until 2 August 2028 - but the notified body infrastructure still is not there. A plain-English guide to Article 6(1), the Article 43(3) integrated conformity assessment, and what MDCG 2025-6 says (and no longer says correctly).

Agentic AI and the EU AI Act: What the Rules Actually Say About Autonomous AI Agents
"AI agent" appears nowhere in the EU AI Act as a defined term - but the Act already binds them. Here is what the July 2026 Article 50 Guidelines, the draft high-risk Guidelines and the Digital Omnibus mean for anyone shipping autonomous agents into the EU.

EU AI Act Compliance Software: A Buyer's Guide to the Four Categories That Actually Matter
Evaluating EU AI Act compliance software? This independent guide maps the four tool categories, what each one can and cannot do, and the eight demo questions that separate real capability from a polished dashboard.