Traveling Under European Rules
The EU AI Act entered into force on August 1, 2024. It establishes the first comprehensive, EU-wide legal framework for artificial intelligence—and its scope does not end at the EU’s borders.
A company may be subject to these regulations even if it does not have a branch, subsidiary, or employees in the European Union. It may be sufficient simply to offer a general-purpose AI system or AI model in the EU. The same applies if a system is operated outside the EU but its output is used within the EU.
This guide explains when the regulation applies internationally, how its risk model works, and what internationally active companies should prioritize next.
The Most Important Thing
Understanding the Context
What the regulation governs, when it applies, and how risk determines obligations.
Check for EU relevance
When market access, results, or supply chains affect a company outside the EU.
Building the Path to Compliance
From the initial AI inventory to documentation and corrective actions, all the way to ongoing monitoring.
Be aware of the sharp edges
Deadlines, fines, bans, and the high-risk regime—without a smoke machine.
Fundamentals of the EU AI Act
When?
A phased launch
The regulation will be implemented gradually, not with a single ceremonial kickoff. The effective date depends on the system, the company's role, and the specific requirement.
-
Prohibited practices and the first basic regulations came into effect.
-
Governance rules and obligations for general-purpose AI models followed.
-
Most of the remaining provisions took effect, including transparency requirements.
-
The high-risk rules for sensitive use cases set forth in Annex III are to become applicable.
-
The high-risk rules for AI in regulated products listed in Annex I are to become applicable.
The last two figures take into account the AI Omnibus, which took effect on July 27, 2026.
What?
A policy that applies company-wide
The regulation is directly applicable throughout the EU and stands alongside data protection, product safety, labor, consumer, and industry laws. It may apply to organizations that develop, offer, introduce, distribute, or use AI systems.
How?
Risk determines the effort required
The higher the risk, the more extensive the regulatory work. A robust classification of each system is therefore less of a paperwork exercise and more of a compass.
Unacceptable
Prohibited AI Practices.
High
Extensive obligations for systems and stakeholders.
Transparency
Specific disclosure requirements for individual systems.
Minimal
Few risk-specific mandatory requirements.
And what about GPAI? General-purpose AI models are subject to their own set of rules. These include documentation, copyright, and transparency obligations, as well as additional requirements for models posing systemic risk. For certain providers based outside the EU, an authorized representative in the EU may also be required.
When the regulation extends beyond the EU
Not having an office in the EU does not automatically mean having no obligations in the EU. International reach may stem from the market, the outcome of a system, or a company’s role in the supply chain.
The regulation may apply if an organization:
- offers or puts into operation an AI system in the EU
- makes a general-purpose AI model available on the EU market
- offers or operates a system outside the EU whose results are used in the EU
- markets a product with a built-in AI system under its own name or brand
- refers to an importer who is making the system available in the EU for the first time
- makes the system available on the European market through a distributor
It all comes down to the details. The location alone is not a cloak of invisibility. What matters for the assessment is the exact role, the contract chain, the intended purpose, and the use of the results.
Six Practical Examples
How the Regulation Travels
-
01
Seoul → Paris
A Korean company offers an AI portrait service online. People in the EU upload photos and use the generated images.
-
02
Singapore → EU Workforce
A Singapore-based provider is developing an AI training platform for a multinational employer with employees in the EU.
-
03
India → EU Staff Team
An Indian HR provider uses AI to screen job applications; the resulting rankings are used by an HR team in the EU to make hiring decisions.
-
04
Japan → Roads in the EU
A Japanese manufacturer sells vehicles in the EU under its own brand name that feature an AI-powered braking system.
-
05
Taiwan → EU Banking Sector
A Taiwanese company is licensing an AI-based credit scoring system to business customers in the EU.
-
06
India → EU Support
An Indian company acquires a customer support system that is already available in Europe and grants sublicenses for it within the EU.
What Companies Should Do Now
Capture. Categorize. Act.
A sensible program starts with three questions. The answers don't have to be perfect on the first day. However, they should be there.
Where is AI already being used?
Evaluate products, services, internal tools, and purchased software. AI is often hidden in solutions for recruiting, customer service, fraud detection, training, analytics, and IT security.
Which category and role apply?
Classify each system and determine whether a general-purpose AI model is involved. Next, determine who the supplier, operator, importer, or distributor is.
What's missing?
Compare existing controls with the applicable requirements. Prohibited practices must be eliminated; high-risk systems require a structured approach, and other systems may also trigger transparency or governance measures as well.
A Five-Step Program
From Inventory to Documentation
01 Take it all in Take in the entire landscape first. Then choose your hiking boots. +
- Assign Responsibilities
- Document Relevant Processes
- Create an inventory of AI systems and models
- Review supplier, customer, and license agreements
02 Define A tool list is transformed into a list of legal and operational requirements. +
- Determine the legal role of each party
- Classifying Systems and Models
- Identify the EU AI Act and other applicable laws
- Define controls, documentation, and transparency measures
03 Analyze Compare current practices with the position that will be sustainable in the future. +
- Document technical and organizational gaps
- Prioritize based on exposure, risk, and implementation effort
- Determine responsible parties, supporting documentation, and target dates
04 Implement Closing gaps in systems, contracts, and human habits. +
- Train the relevant teams
- Prepare Notes and User Information
- Implement technical and organizational controls
- Establish documentation, guidelines, and approval processes
05 Monitoring Compliance is a cycle, not a laminated certificate. +
- Regularly review systems and controls
- Track changes in usage, data, suppliers, and regulations
- Adjust the program when the facts change
What Companies Need to Know
Scope of Application
What applies if we operate entirely outside the EU?
The fact that an organization does not have a branch in the EU does not automatically exclude it from the scope of application. Key factors include, among others, whether a system or model enters the EU market, whether its results are used in the EU, and what role the organization plays in the supply chain.
Every company operating internationally that offers or uses AI should conduct this assessment. Not every company will be included. However, no company should rely solely on its location.
Schedule
When do we have to start complying with the requirements?
The Regulation is being implemented in phases. Prohibitions, GPAI obligations, and a large part of the rest of the legal framework are already applicable. The key high-risk deadlines are now December 2, 2027, for use cases under Annex III and August 2, 2028, for AI embedded in products under Annex I. Providers of GPAI models that were placed on the market before August 2, 2025, have a separate transition period until August 2, 2027.
Fines
How much can a violation cost?
The statutory maximum amount depends on the specific violation.
Prohibited AI Practices
Certain Operator, Compliance, and Transparency Obligations
Inaccurate, incomplete, or misleading information
For companies, the higher of the applicable ceilings generally applies; for SMEs, there is a special provision with a lower ceiling. The final fine must be proportionate in each individual case. Nevertheless, this is not a regulation that one should preferably wait until after the deadline to present to the finance department.
Prohibitions
What is an AI system with unacceptable risk?
The prohibited category includes practices that are considered incompatible with the EU's security and fundamental rights standards. These include, for example:
- manipulative or deceptive techniques that distort behavior and cause significant harm;
- prohibited social evaluation that results in unjustified or disproportionate discrimination;
- assessing the likelihood of a crime based solely on profiling or personality traits; and
- biometric categorization used to derive protected or particularly sensitive characteristics.
The statutory list is more detailed and includes conditions as well as exceptions. Each specific case must be reviewed based on the exact text of the law.
Classification
When does an AI system become a high-risk system?
Regulated Products
A system may be considered high-risk if it is itself a product or a safety component of a product that is subject to specific EU product safety regulations and is subject to a third-party conformity assessment. Examples include medical devices, machinery, toys, elevators, protective equipment, and vehicles.
Sensitive Use Cases
Appendix III lists potentially high-risk applications from eight areas. This list is not automatically exhaustive: the system’s function and statutory exceptions continue to be determining factors.
- 01Biometrics
- 02Critical Infrastructure
- 03Education and Training
- 04Employment and Human Resources Management
- 05Essential Private and Public Services
- 06Law Enforcement
- 07Migration, Asylum, and Border Control
- 08The Judiciary and Democratic Processes
System Requirements
Seven Requirements, One Life Cycle
-
01
Risk Management
A documented, continuous process covering the entire life cycle of the system.
-
02
Data Governance
Appropriate quality and governance for training, validation, and test data.
-
03
Technical Documentation
Documentation created prior to market entry or deployment and continuously updated.
-
04
Record-keeping Requirements
Technical logging that supports operational traceability.
-
05
Transparency
Guidance on the purpose, capabilities, limitations, and significance of the results.
-
06
Human supervision
Effective oversight to reduce risks to security and fundamental rights.
-
07
Accuracy, Ruggedness, and Cybersecurity
Performance, durability, and cybersecurity must be suitable for the intended use.
Provider
If you develop or offer a system
Providers bear the primary responsibility for ensuring that a high-risk AI system meets the applicable requirements. They must generally:
- ensure technical and organizational compliance
- Indicate the supplier on the system, on the packaging, or in the documentation
- maintain a quality management system
- prepare and retain the required documentation and records
- conduct the relevant conformity assessment
- Issue the EU Declaration of Conformity and affix the CE marking
- Make the required entries in EU databases
- conduct post-market surveillance and implement corrective action procedures
- As a provider based in a third country, designate an authorized representative in the EU in writing before making a high-risk AI system available in the EU
Operator
If you are using a system
Operators must monitor how the system is used in practice . Their responsibilities may include:
- to use the system in accordance with the provider's instructions for use
- to assign supervisory responsibilities to individuals with the necessary expertise, authority, and support
- to ensure that the input data they control is relevant and sufficiently representative
- monitor operations, report risks or incidents, and suspend operations if necessary
- retain automatically generated logs for the required period
- to inform affected employees before they begin work
- To inform individuals when a high-risk AI system is used to support decisions about them
Additional requirements may apply for certain operators or use cases.
Importers & Distributors
The supply chain also has responsibilities
Importers and distributors are not merely passive distribution channels. Before they deploy a high-risk AI system, they must perform certain checks regarding compliance, labeling, documentation, and information about the provider.
If you identify a nonconformity, you must withhold the system if necessary, support corrective actions, and notify the supplier and the relevant authorities. Additionally, storage, transportation, and record-keeping may also be relevant factors.
National law continues to play a role
The EU AI Act is one layer of the overall regulatory landscape, not the entire picture.
Many countries have introduced their own AI laws, frameworks, guidelines, or sector-specific requirements. International organizations should therefore always review national law in addition to the EU regime. Compliance is, in any case, difficult to assess on a country-by-country basis.
07 · Outlook
The law is in effect. Some of the furniture is still being delivered.
The regulation is in effect, but its supporting framework continues to evolve. Standards, common specifications, templates, and Commission guidelines will continue to shape what good compliance looks like in practice.
The sensible answer is a dynamic governance program: documented, regularly reviewed, and flexible enough to adapt as the rules change.