Does the EU AI Act apply to your non-EU SaaS? The two triggers that decide it — and the questionnaire that arrives either way
Vendors headquartered in the US, Canada, LatAm, Israel or APAC keep answering the AI section of enterprise questionnaires with a variant of "we are not established in the EU, so the EU AI Act does not apply to us". For most B2B SaaS companies with any European customer — or any customer with European operations — that answer is wrong on the law, and buyers' legal teams know it. Like the GDPR before it, the AI Act was written to reach across borders.
The two triggers in Article 2
Article 2(1) defines the Regulation's scope. Two of its clauses do the extraterritorial work:
| Trigger | Text (paraphrased) | Typical non-EU SaaS example |
|---|---|---|
| Art. 2(1)(a) — market trigger | Providers placing on the market or putting into service AI systems in the Union, irrespective of whether they are established in the Union or in a third country. | A US vendor sells its AI-powered product to a customer in Germany. The vendor is in scope as provider, US headquarters notwithstanding. |
| Art. 2(1)(c) — output trigger | Providers and deployers of AI systems established in a third country, where the output produced by the AI system is used in the Union. | A Singapore vendor's AI generates reports, scores or content that its multinational customer's EU teams consume. No EU contract needed — the output crossing into the Union is enough. |
The output trigger is the one non-EU vendors underestimate. Selling exclusively to a US enterprise does not keep you out of scope if that enterprise uses your AI's output in its European subsidiaries — which, for Fortune-500-grade customers, is the norm rather than the exception.
What a non-EU SaaS vendor actually owes (and what it doesn't)
Being in scope does not mean the whole Regulation lands on you. For most B2B SaaS — limited-risk systems outside Annex III — the practical obligations are the Article 50 transparency duties, in force since 2 August 2026:
- 50(1) — if your product includes AI that interacts directly with people (chatbots, voice agents), users must be informed they are dealing with a machine. As the company shipping the system under your own brand, this duty is yours as provider — not your foundation-model supplier's.
- 50(2) — if your product generates synthetic audio, image, video or text, outputs must be marked machine-readable as artificially generated. For systems already on the market, a transition period runs until 2 December 2026.
Equally important is what you likely do not owe:
- No authorised representative in the Union is required for limited-risk systems. The authorised-representative duty (Art. 22) attaches to providers of high-risk AI systems (and, under Art. 54, to providers of general-purpose AI models). If your product is neither, a questionnaire answer claiming you've "appointed an EU representative" is over-compliance theatre — and a claim you'll be asked to evidence.
- No high-risk obligations unless your use case sits in Annex III (employment screening, credit scoring, education access, and the other listed areas) — and after the Digital Omnibus, those duties apply from 2 December 2027, not 2026.
The dates that matter for a non-EU vendor
- 2 August 2026 — Article 50 transparency duties apply (Art. 113). The Digital Omnibus (Parliament 16 June 2026, Council 29 June 2026) did not postpone them.
- 2 December 2026 — end of the marking transition for Art. 50(2) systems already on the market.
- 2 December 2027 — postponed date for high-risk (Annex III) obligations, if any apply to you.
Enforcement against a company with no EU presence — the honest assessment
Fines for Article 50 infringements can reach €15,000,000 or 3% of worldwide turnover (Art. 99(4)(g)) — with SMEs paying the lower of the two amounts (Art. 99(6)). Enforcement is by member-state authorities, several of which are still standing up their regimes in 2026. Direct regulatory action against a vendor with no EU establishment is, realistically, not the near-term risk.
The near-term risk is contractual, and it is already here. Your enterprise customers are in scope, so their procurement teams push the compliance question down to you: AI-CAIQ and SIG 2026 questionnaires, and AI sections in RFPs, now routinely ask non-EU vendors to state their EU AI Act position. The buyer doesn't care where you're headquartered — they care whether your answer survives their legal review. An unconvincing answer doesn't get you fined; it gets the deal parked.
How to answer "Does the EU AI Act apply to you?" from outside the EU
- Scope, honestly — if EU customers or EU-used output exist, say you are in scope via Art. 2(1)(a) or 2(1)(c) and name which. Claiming "not applicable" with a Frankfurt logo on your customers page is the fastest way to lose the reviewer.
- Classify — state your risk tier (most B2B SaaS: limited/minimal risk, outside Annex III) and therefore which obligations attach.
- Name your duties with dates — typically Art. 50(1) and/or 50(2) as provider, applicable from 2 August 2026.
- State measures and gaps — disclosure labels, output marking, human review, and a proportionate plan for what's pending. A cited "here is exactly what applies to us and what we do about it" reads as competence; a blanket "yes, fully compliant" reads as bluff.
- Regulation (EU) 2024/1689, Official Journal — Art. 2(1)(a), 2(1)(c), Art. 22, Art. 50, Art. 54, Art. 99, Art. 113 (ELI: data.europa.eu/eli/reg/2024/1689/oj)
- Digital Omnibus: European Parliament position 16 June 2026; Council adoption 29 June 2026 (consilium.europa.eu press releases)
- Cloud Security Alliance — AI-CAIQ; Shared Assessments — SIG 2026 (AI domain)