dealrescueGuides › EU AI Act for Australian vendors

Country guide

The EU AI Act for Australian software vendors: what actually applies to you

Australian SaaS vendors often arrive at the EU AI Act section of a buyer's questionnaire with a reasonable-sounding objection: Australia chose guidance over legislation, so a Sydney or Melbourne company answers to the AI Ethics Principles, not to Brussels. The objection fails on the Regulation's first pages: scope turns on where your system is sold and where its output is used, not on what your home jurisdiction chose to regulate.

Does the EU AI Act reach you?

Two clauses of Article 2(1) decide it for an Australian vendor:

These two clauses are the whole doorway. If neither applies, you are out of scope and entitled to say so. Our Article 50 checker runs the test question by question; the full non-EU vendor guide covers both triggers in depth.

What you owe if it does

For most B2B SaaS — limited-risk systems outside Annex III — the obligations are the Article 50 transparency duties, applicable since 2 August 2026. The Digital Omnibus postponed high-risk obligations; it did not postpone Article 50.

Mind the rebranding rule: a deployer becomes the provider when it markets a system under its own brand or substantially modifies it. An Australian SaaS that wraps GPT, Claude or any third-party model under its own name is the provider of the resulting system — the Article 50 duties are yours, not your model supplier's.

High-risk (Annex III) obligations apply from 2 December 2027, and only if your use case is listed. Article 50 fines can reach €15,000,000 or 3% of worldwide turnover, whichever is higher (Art. 99(4)(g)); SMEs pay the lower of the two (Art. 99(6)).

What Australian law adds (and what it doesn't)

Domestically, Australia has so far chosen voluntary settings over a standalone AI act: the AI Ethics Principles, the Voluntary AI Safety Standard (September 2024, updated by the National AI Centre's Guidance for AI Adoption in October 2025) and the National AI Plan of December 2025 — which confirmed reliance on existing technology-neutral laws and sector regulators, shelving the earlier proposal for mandatory guardrails in high-risk settings — alongside a rolling reform of the Privacy Act 1988. Canberra has since signalled that binding rules may follow, but as at this guide's legal base date there is no general, binding Australian AI act in force — verify the current state before asserting otherwise to a buyer. That cuts both ways: nothing domestic duplicates your Article 50 duties, but nothing Australian answers a buyer asking about the EU AI Act either. "We follow the AI Ethics Principles" or "we apply the Voluntary AI Safety Standard" answers a different, voluntary framework — reviewers notice.

Australian vendors inherit a second gap in EU deals: no EU adequacy decision. Transfers of personal data from EU customers to your Australian operations typically rest on Article 46 safeguards — in practice the Standard Contractual Clauses (Implementing Decision (EU) 2021/914) in your DPA. That is GDPR, not AI Act — but the same buyer reviews both, usually in the same document.

The questionnaire reality

Direct enforcement against a vendor with no EU establishment is not the near-term risk. The near-term risk arrives by email: your enterprise customers are in scope, so AI-CAIQ and SIG 2026 questionnaires — and AI sections in RFPs — now ask Australian vendors to state their EU AI Act position, and the buyer's legal team reads the answer.

An unconvincing answer doesn't get you fined; it gets the deal parked. The answer that survives scopes honestly under Art. 2(1), classifies the system, names the Article 50 duties with dates, and states measures and gaps. Just received one? Start with what to do when you receive a security questionnaire and our worked answer to "Are you EU AI Act compliant?".

Mini-FAQ

Australia has no binding AI law — does that keep the EU AI Act away from us?

No. The Act's scope is set by its own Article 2(1), irrespective of where the provider is established: placing a system on the EU market (Art. 2(1)(a)) or output used in the Union (Art. 2(1)(c)) is enough, whatever Australian law requires at home.

Do we need to appoint an authorised representative in the EU?

Not for a limited-risk system. The authorised-representative duty (Art. 22) attaches to providers of high-risk systems; Art. 54 extends a similar duty to general-purpose AI model providers. Most B2B SaaS is neither.

What about data transfers from EU customers to Australia?

A GDPR question, not an AI Act one — but it lands in the same questionnaire. Without an adequacy decision, EU-to-Australia transfers typically rely on the Standard Contractual Clauses in your DPA. Expect the buyer to check both sections.

Primary sources
  • Regulation (EU) 2024/1689, Official Journal — Art. 2(1)(a), 2(1)(c), Art. 22, Art. 50, Art. 54, Art. 99, Art. 113 (ELI: data.europa.eu/eli/reg/2024/1689/oj)
  • Digital Omnibus — Parliament 16 June 2026; Council 29 June 2026 (consilium.europa.eu)
  • Commission Implementing Decision (EU) 2021/914 — Standard Contractual Clauses (GDPR Chapter V)
  • Australian Government — AI Ethics Principles; Voluntary AI Safety Standard (Sept 2024, updated Oct 2025 by the Guidance for AI Adoption); National AI Plan (Dec 2025) — all voluntary; Privacy Act 1988 (Cth), under reform

A buyer just asked where your Australian company stands on the EU AI Act?

We draft every answer with this level of citation, in 48 hours, $490 flat for up to 60 questions — paid after delivery, and late means free. Not sure yet? Send it anyway: the first 3 answers are free, back within 24 hours.

Send your questionnaire →