dealrescueGuides › EU AI Act for non-EU vendors

Guide · EU AI Act

Does the EU AI Act apply to your non-EU SaaS? The two triggers that decide it — and the questionnaire that arrives either way

Vendors headquartered in the US, Canada, LatAm, Israel or APAC keep answering the AI section of enterprise questionnaires with a variant of "we are not established in the EU, so the EU AI Act does not apply to us". For most B2B SaaS companies with any European customer — or any customer with European operations — that answer is wrong on the law, and buyers' legal teams know it. Like the GDPR before it, the AI Act was written to reach across borders.

The two triggers in Article 2

Article 2(1) defines the Regulation's scope. Two of its clauses do the extraterritorial work:

TriggerText (paraphrased)Typical non-EU SaaS example
Art. 2(1)(a) — market triggerProviders placing on the market or putting into service AI systems in the Union, irrespective of whether they are established in the Union or in a third country.A US vendor sells its AI-powered product to a customer in Germany. The vendor is in scope as provider, US headquarters notwithstanding.
Art. 2(1)(c) — output triggerProviders and deployers of AI systems established in a third country, where the output produced by the AI system is used in the Union.A Singapore vendor's AI generates reports, scores or content that its multinational customer's EU teams consume. No EU contract needed — the output crossing into the Union is enough.

The output trigger is the one non-EU vendors underestimate. Selling exclusively to a US enterprise does not keep you out of scope if that enterprise uses your AI's output in its European subsidiaries — which, for Fortune-500-grade customers, is the norm rather than the exception.

What a non-EU SaaS vendor actually owes (and what it doesn't)

Being in scope does not mean the whole Regulation lands on you. For most B2B SaaS — limited-risk systems outside Annex III — the practical obligations are the Article 50 transparency duties, in force since 2 August 2026:

Equally important is what you likely do not owe:

The dates that matter for a non-EU vendor

Enforcement against a company with no EU presence — the honest assessment

Fines for Article 50 infringements can reach €15,000,000 or 3% of worldwide turnover (Art. 99(4)(g)) — with SMEs paying the lower of the two amounts (Art. 99(6)). Enforcement is by member-state authorities, several of which are still standing up their regimes in 2026. Direct regulatory action against a vendor with no EU establishment is, realistically, not the near-term risk.

The near-term risk is contractual, and it is already here. Your enterprise customers are in scope, so their procurement teams push the compliance question down to you: AI-CAIQ and SIG 2026 questionnaires, and AI sections in RFPs, now routinely ask non-EU vendors to state their EU AI Act position. The buyer doesn't care where you're headquartered — they care whether your answer survives their legal review. An unconvincing answer doesn't get you fined; it gets the deal parked.

How to answer "Does the EU AI Act apply to you?" from outside the EU

  1. Scope, honestly — if EU customers or EU-used output exist, say you are in scope via Art. 2(1)(a) or 2(1)(c) and name which. Claiming "not applicable" with a Frankfurt logo on your customers page is the fastest way to lose the reviewer.
  2. Classify — state your risk tier (most B2B SaaS: limited/minimal risk, outside Annex III) and therefore which obligations attach.
  3. Name your duties with dates — typically Art. 50(1) and/or 50(2) as provider, applicable from 2 August 2026.
  4. State measures and gaps — disclosure labels, output marking, human review, and a proportionate plan for what's pending. A cited "here is exactly what applies to us and what we do about it" reads as competence; a blanket "yes, fully compliant" reads as bluff.
Primary sources
  • Regulation (EU) 2024/1689, Official Journal — Art. 2(1)(a), 2(1)(c), Art. 22, Art. 50, Art. 54, Art. 99, Art. 113 (ELI: data.europa.eu/eli/reg/2024/1689/oj)
  • Digital Omnibus: European Parliament position 16 June 2026; Council adoption 29 June 2026 (consilium.europa.eu press releases)
  • Cloud Security Alliance — AI-CAIQ; Shared Assessments — SIG 2026 (AI domain)

A buyer just asked where you stand on the EU AI Act?

We draft every answer with this level of citation, in 48 hours, $490 flat — paid after delivery. Not sure yet? Send it anyway: the first 3 answers are free.

Send your questionnaire →