EU AI Act

Do You Need to Comply with the EU AI Act if You're Not in the EU?

Yes, almost certainly. The EU AI Act's extraterritorial reach catches any company whose AI outputs are used by people in the EU, regardless of where the company is incorporated or where its servers sit. If you have EU customers and you use AI, you're in scope.

← Back to EU AI Act Complete Guide

The EU AI Act (Regulation 2024/1689) applies extraterritorially, meaning it reaches companies based outside the EU. The trigger isn't where your company is registered or where your data centers are. It's whether EU residents use the output of your AI systems. This article explains exactly how the scope works, what it means for US and UK fintechs specifically, what the difference between provider and deployer obligations is, and how enforcement reaches non-EU companies in practice.

The short answer: extraterritorial scope catches most global companies

Article 2(1) of the Act sets out four categories of entity that are in scope:

The third category is the key one for non-EU companies. It applies regardless of where you're based. If your AI system produces an output (a recommendation, a decision, a generated text, a risk score) that is used by someone in the EU, you are a subject of the Act. Full stop.

How Article 2 defines who must comply

The Act defines two primary roles with different obligations:

In practice, most companies are both. A fintech that uses OpenAI's API to power its customer service chatbot is a deployer of that GPAI model and a provider of its chatbot product. Each role carries distinct compliance obligations, and you need to assess each layer of your stack separately.

The "output used in the EU" trigger

The clearest test for extraterritorial scope is Article 2(1)(c): an entity is in scope if the output produced by its AI system is used in the EU. "Output" under the Act means any content, prediction, recommendation, decision, or other result generated by the AI system and acted upon by a person or another system.

This is deliberately broad. It includes:

If any of those scenarios describe your product, you're in scope. The location of the server, the company, or the data doesn't change this.

What this means for US and UK fintechs specifically

US and UK fintechs are among the most exposed non-EU companies for two reasons: their products tend to use AI for consequential decisions (credit, fraud, identity), and they often have EU customers either directly or through white-label arrangements with EU financial institutions.

For a US fintech:

For a UK fintech, the position is even more direct. UK companies that were subject to EU AI rules through GDPR equivalence and existing EU market access maintain that exposure post-Brexit. The Act doesn't include a Brexit carve-out; if your product reaches EU users, you're in scope on the same terms as any other non-EU company.

What this means for SaaS companies with EU customers

B2B SaaS companies often assume they aren't in scope because they don't serve EU consumers directly. That assumption needs re-examination:

The only genuinely out-of-scope scenario for a SaaS company is one where no AI output of any kind reaches a user in the EU, directly or via your client's deployment. For most SaaS companies serving global markets, that scenario doesn't exist.

The 2 August 2026 deadline applies to you regardless of where you're based. Better Societies specialises in helping non-EU AI and fintech companies navigate extraterritorial scope, determine their exact obligations, and get compliant before the fines apply. Start your compliance assessment.

The difference between provider and deployer obligations

Understanding whether you're primarily a provider or deployer (or both) shapes what you actually need to do:

If you use a third-party AI API and integrate it into your own product that you then deploy to customers, you're a deployer of that model and a provider of your product. The provider of the underlying model owes you technical documentation and a declaration of conformity. You, as the downstream provider, must ensure your product layer meets high-risk requirements if applicable.

How enforcement reaches non-EU companies

A common assumption is that enforcement against non-EU companies is weak or theoretical. That assumption is wrong, and GDPR enforcement history demonstrates it. Several mechanisms bring non-EU companies into enforcement reach:

What "placing on the EU market" means in practice

"Placing on the EU market" is the Act's core jurisdictional concept, and it's interpreted broadly. It means making an AI system available for the first time in the EU, whether for free or for payment. Practical examples:

You don't need a physical presence in the EU, a registered subsidiary, or an EU customer contract to be on the EU market. If EU users can access your AI system and use its output, you're there.

Related reading

Frequently asked questions

Does the EU AI Act apply to companies outside the EU?

Yes. The EU AI Act has explicit extraterritorial scope under Article 2. It applies to any provider or deployer whose AI system outputs are used in the EU, regardless of where the company is established. This mirrors the GDPR's approach and means US, UK, and other non-EU companies serving EU customers are in scope.

What is the "output used in the EU" test?

Under Article 2(1)(c), the Act applies to providers and deployers established outside the EU when the output produced by their AI system is used in the EU. If an EU resident receives an output from your AI system, whether a credit decision, a chatbot response, or a risk score, your company is subject to the Act.

Do US fintechs need to comply with the EU AI Act?

Yes, if they have EU customers who use their AI-powered products. A US fintech whose credit scoring model, fraud detection system, or AI-powered customer service reaches EU residents is in scope. The Act applies regardless of where the fintech is incorporated or where its servers are located.

What is the difference between a provider and a deployer under the EU AI Act?

A provider develops an AI system and places it on the market. A deployer uses an AI system under its authority for professional purposes. Providers face heavier obligations including conformity assessment and technical documentation. Deployers face lighter obligations focused on appropriate use, human oversight, and transparency to end users.

How does the EU AI Act enforce fines against non-EU companies?

Non-EU companies must designate an EU representative in the member states where their AI systems are available. Enforcement actions and fines can be directed at the representative. Market access bans are also an effective enforcement mechanism that doesn't require a fine to have immediate business impact.

Does the EU AI Act apply to SaaS companies with EU customers?

Yes. If a SaaS company integrates AI into its product and that product is used by EU customers or their employees, the SaaS company is in scope as either a provider (if it built the AI system) or a deployer (if it integrates a third-party AI model). Both roles carry real compliance obligations.

What does "placing on the EU market" mean in practice?

Placing an AI system on the EU market means making it available to users in the EU for the first time, whether for payment or free of charge. This includes a SaaS product accessible from the EU, an API consumed by EU-based companies, or any AI-powered service that EU residents can access via the internet.

Does the EU AI Act apply to open-source AI?

Open-source AI models face limited but real obligations under the Act. Providers of open-source GPAI models still need to publish technical documentation and comply with EU copyright law. If an open-source model is modified and deployed commercially to EU users, the deployer takes on provider-level obligations.

In scope? Get ahead of the 2 August 2026 deadline

If your AI reaches EU users, you're in scope for the EU AI Act. Better Societies delivers a full compliance assessment and documentation package. Article 99 fines reach EUR 35M or 7% of global turnover. The cost of compliance is a fraction of that.