K11 Practical Guide · EU AI Act

The EU AI Act for Companies Outside the EU

European Rules. Global Reach. A Practical Guide to the Risk Model, the International Scope of Application, and the Tasks That Need to Be Addressed Now.

Published on Aug. 18, 2026 Updated on Aug. 19, 2026 International

Traveling Under European Rules

The EU AI Act entered into force on August 1, 2024. It establishes the first comprehensive, EU-wide legal framework for artificial intelligence—and its scope does not end at the EU’s borders.

A company may be subject to these regulations even if it does not have a branch, subsidiary, or employees in the European Union. It may be sufficient simply to offer a general-purpose AI system or AI model in the EU. The same applies if a system is operated outside the EU but its output is used within the EU.

This guide explains when the regulation applies internationally, how its risk model works, and what internationally active companies should prioritize next.

01

The Most Important Thing

01

Understanding the Context

What the regulation governs, when it applies, and how risk determines obligations.

02

Check for EU relevance

When market access, results, or supply chains affect a company outside the EU.

03

Building the Path to Compliance

From the initial AI inventory to documentation and corrective actions, all the way to ongoing monitoring.

04

Be aware of the sharp edges

Deadlines, fines, bans, and the high-risk regime—without a smoke machine.

02

Fundamentals of the EU AI Act

When?

A phased launch

The regulation will be implemented gradually, not with a single ceremonial kickoff. The effective date depends on the system, the company's role, and the specific requirement.

  1. Prohibited practices and the first basic regulations came into effect.

  2. Governance rules and obligations for general-purpose AI models followed.

  3. Most of the remaining provisions took effect, including transparency requirements.

  4. The high-risk rules for sensitive use cases set forth in Annex III are to become applicable.

  5. The high-risk rules for AI in regulated products listed in Annex I are to become applicable.

Updated

The last two figures take into account the AI Omnibus, which took effect on July 27, 2026.

What?

A policy that applies company-wide

The regulation is directly applicable throughout the EU and stands alongside data protection, product safety, labor, consumer, and industry laws. It may apply to organizations that develop, offer, introduce, distribute, or use AI systems.

How?

Risk determines the effort required

The higher the risk, the more extensive the regulatory work. A robust classification of each system is therefore less of a paperwork exercise and more of a compass.

01

Unacceptable

Prohibited AI Practices.

02

High

Extensive obligations for systems and stakeholders.

03

Transparency

Specific disclosure requirements for individual systems.

04

Minimal

Few risk-specific mandatory requirements.

And what about GPAI? General-purpose AI models are subject to their own set of rules. These include documentation, copyright, and transparency obligations, as well as additional requirements for models posing systemic risk. For certain providers based outside the EU, an authorized representative in the EU may also be required.

03

When the regulation extends beyond the EU

Not having an office in the EU does not automatically mean having no obligations in the EU. International reach may stem from the market, the outcome of a system, or a company’s role in the supply chain.

The regulation may apply if an organization:

  • offers or puts into operation an AI system in the EU
  • makes a general-purpose AI model available on the EU market
  • offers or operates a system outside the EU whose results are used in the EU
  • markets a product with a built-in AI system under its own name or brand
  • refers to an importer who is making the system available in the EU for the first time
  • makes the system available on the European market through a distributor

It all comes down to the details. The location alone is not a cloak of invisibility. What matters for the assessment is the exact role, the contract chain, the intended purpose, and the use of the results.

Six Practical Examples

How the Regulation Travels

  1. 01

    Seoul → Paris

    A Korean company offers an AI portrait service online. People in the EU upload photos and use the generated images.

  2. 02

    Singapore → EU Workforce

    A Singapore-based provider is developing an AI training platform for a multinational employer with employees in the EU.

  3. 03

    India → EU Staff Team

    An Indian HR provider uses AI to screen job applications; the resulting rankings are used by an HR team in the EU to make hiring decisions.

  4. 04

    Japan → Roads in the EU

    A Japanese manufacturer sells vehicles in the EU under its own brand name that feature an AI-powered braking system.

  5. 05

    Taiwan → EU Banking Sector

    A Taiwanese company is licensing an AI-based credit scoring system to business customers in the EU.

  6. 06

    India → EU Support

    An Indian company acquires a customer support system that is already available in Europe and grants sublicenses for it within the EU.

04

What Companies Should Do Now

Capture. Categorize. Act.

A sensible program starts with three questions. The answers don't have to be perfect on the first day. However, they should be there.

01

Where is AI already being used?

Evaluate products, services, internal tools, and purchased software. AI is often hidden in solutions for recruiting, customer service, fraud detection, training, analytics, and IT security.

02

Which category and role apply?

Classify each system and determine whether a general-purpose AI model is involved. Next, determine who the supplier, operator, importer, or distributor is.

03

What's missing?

Compare existing controls with the applicable requirements. Prohibited practices must be eliminated; high-risk systems require a structured approach, and other systems may also trigger transparency or governance measures as well.

A Five-Step Program

From Inventory to Documentation

01 Take it all in Take in the entire landscape first. Then choose your hiking boots.
  • Assign Responsibilities
  • Document Relevant Processes
  • Create an inventory of AI systems and models
  • Review supplier, customer, and license agreements
02 Define A tool list is transformed into a list of legal and operational requirements.
  • Determine the legal role of each party
  • Classifying Systems and Models
  • Identify the EU AI Act and other applicable laws
  • Define controls, documentation, and transparency measures
03 Analyze Compare current practices with the position that will be sustainable in the future.
  • Document technical and organizational gaps
  • Prioritize based on exposure, risk, and implementation effort
  • Determine responsible parties, supporting documentation, and target dates
04 Implement Closing gaps in systems, contracts, and human habits.
  • Train the relevant teams
  • Prepare Notes and User Information
  • Implement technical and organizational controls
  • Establish documentation, guidelines, and approval processes
05 Monitoring Compliance is a cycle, not a laminated certificate.
  • Regularly review systems and controls
  • Track changes in usage, data, suppliers, and regulations
  • Adjust the program when the facts change
05

What Companies Need to Know

Scope of Application

What applies if we operate entirely outside the EU?

The fact that an organization does not have a branch in the EU does not automatically exclude it from the scope of application. Key factors include, among others, whether a system or model enters the EU market, whether its results are used in the EU, and what role the organization plays in the supply chain.

Every company operating internationally that offers or uses AI should conduct this assessment. Not every company will be included. However, no company should rely solely on its location.

Schedule

When do we have to start complying with the requirements?

The Regulation is being implemented in phases. Prohibitions, GPAI obligations, and a large part of the rest of the legal framework are already applicable. The key high-risk deadlines are now December 2, 2027, for use cases under Annex III and August 2, 2028, for AI embedded in products under Annex I. Providers of GPAI models that were placed on the market before August 2, 2025, have a separate transition period until August 2, 2027.

Fines

How much can a violation cost?

The statutory maximum amount depends on the specific violation.

35 million euros or 7%

Prohibited AI Practices

15 million euros or 3%

Certain Operator, Compliance, and Transparency Obligations

7.5 million euros or 1%

Inaccurate, incomplete, or misleading information

For companies, the higher of the applicable ceilings generally applies; for SMEs, there is a special provision with a lower ceiling. The final fine must be proportionate in each individual case. Nevertheless, this is not a regulation that one should preferably wait until after the deadline to present to the finance department.

Prohibitions

What is an AI system with unacceptable risk?

The prohibited category includes practices that are considered incompatible with the EU's security and fundamental rights standards. These include, for example:

  1. manipulative or deceptive techniques that distort behavior and cause significant harm;
  2. prohibited social evaluation that results in unjustified or disproportionate discrimination;
  3. assessing the likelihood of a crime based solely on profiling or personality traits; and
  4. biometric categorization used to derive protected or particularly sensitive characteristics.

The statutory list is more detailed and includes conditions as well as exceptions. Each specific case must be reviewed based on the exact text of the law.

Classification

When does an AI system become a high-risk system?

Regulated Products

A system may be considered high-risk if it is itself a product or a safety component of a product that is subject to specific EU product safety regulations and is subject to a third-party conformity assessment. Examples include medical devices, machinery, toys, elevators, protective equipment, and vehicles.

Sensitive Use Cases

Appendix III lists potentially high-risk applications from eight areas. This list is not automatically exhaustive: the system’s function and statutory exceptions continue to be determining factors.

  1. 01Biometrics
  2. 02Critical Infrastructure
  3. 03Education and Training
  4. 04Employment and Human Resources Management
  5. 05Essential Private and Public Services
  6. 06Law Enforcement
  7. 07Migration, Asylum, and Border Control
  8. 08The Judiciary and Democratic Processes

System Requirements

Seven Requirements, One Life Cycle

  1. 01

    Risk Management

    A documented, continuous process covering the entire life cycle of the system.

  2. 02

    Data Governance

    Appropriate quality and governance for training, validation, and test data.

  3. 03

    Technical Documentation

    Documentation created prior to market entry or deployment and continuously updated.

  4. 04

    Record-keeping Requirements

    Technical logging that supports operational traceability.

  5. 05

    Transparency

    Guidance on the purpose, capabilities, limitations, and significance of the results.

  6. 06

    Human supervision

    Effective oversight to reduce risks to security and fundamental rights.

  7. 07

    Accuracy, Ruggedness, and Cybersecurity

    Performance, durability, and cybersecurity must be suitable for the intended use.

Provider

If you develop or offer a system

Providers bear the primary responsibility for ensuring that a high-risk AI system meets the applicable requirements. They must generally:

  • ensure technical and organizational compliance
  • Indicate the supplier on the system, on the packaging, or in the documentation
  • maintain a quality management system
  • prepare and retain the required documentation and records
  • conduct the relevant conformity assessment
  • Issue the EU Declaration of Conformity and affix the CE marking
  • Make the required entries in EU databases
  • conduct post-market surveillance and implement corrective action procedures
  • As a provider based in a third country, designate an authorized representative in the EU in writing before making a high-risk AI system available in the EU

Operator

If you are using a system

Operators must monitor how the system is used in practice . Their responsibilities may include:

  • to use the system in accordance with the provider's instructions for use
  • to assign supervisory responsibilities to individuals with the necessary expertise, authority, and support
  • to ensure that the input data they control is relevant and sufficiently representative
  • monitor operations, report risks or incidents, and suspend operations if necessary
  • retain automatically generated logs for the required period
  • to inform affected employees before they begin work
  • To inform individuals when a high-risk AI system is used to support decisions about them

Additional requirements may apply for certain operators or use cases.

Importers & Distributors

The supply chain also has responsibilities

Importers and distributors are not merely passive distribution channels. Before they deploy a high-risk AI system, they must perform certain checks regarding compliance, labeling, documentation, and information about the provider.

If you identify a nonconformity, you must withhold the system if necessary, support corrective actions, and notify the supplier and the relevant authorities. Additionally, storage, transportation, and record-keeping may also be relevant factors.

06

National law continues to play a role

The EU AI Act is one layer of the overall regulatory landscape, not the entire picture.

Many countries have introduced their own AI laws, frameworks, guidelines, or sector-specific requirements. International organizations should therefore always review national law in addition to the EU regime. Compliance is, in any case, difficult to assess on a country-by-country basis.

07 · Outlook

The law is in effect. Some of the furniture is still being delivered.

The regulation is in effect, but its supporting framework continues to evolve. Standards, common specifications, templates, and Commission guidelines will continue to shape what good compliance looks like in practice.

The sensible answer is a dynamic governance program: documented, regularly reviewed, and flexible enough to adapt as the rules change.

Looking for an AI officer? We advise you free of charge!

Simply enter your contact details and we will get back to you immediately - the AI consultation with us is free and non-binding.

🔒 Your data is processed in accordance with the GDPR and in compliance with the highest security standards (e.g. ISO/IEC 27001). We only use it to send you relevant information. You can object to this use at any time.