Skip to content
Topic Developing

AI Act Territorial Scope

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal โ€” legal information, not advice.

The scope section of the AI Act includes specific provisions on territorial applicability and which providers are subject to the regulation regardless of their location, warranting a dedicated topic.

34 linked items 34 Laws

Overview

9 sources ยท Jul 23, 2026

Legal Framework

The AI Act's territorial scope is governed primarily by Article 2, which extends the regulation's reach well beyond EU borders. The regulation applies to three categories of actors. First, providers placing AI systems on the EU market or putting them into service in the Union, irrespective of whether the provider is established within the EU or in a third country. Second, deployers of AI systems that have their place of establishment within the Union. Third โ€” and most expansively โ€” providers and deployers of AI systems established in a third country, where the output produced by the AI system is used in the Union.

This third category represents a significant extraterritorial extension, analogous to the market-place targeting logic familiar from GDPR Article 3(2). The establishment-based criterion under Article 2 mirrors the approach taken in EU data protection law, where the CJEU has interpreted the concept of an "establishment" broadly. In Google Spain v. AEPD (C-131/12), the Court held that a subsidiary in the Union that promotes and sells advertising space for a parent search engine operator constitutes a sufficient establishment nexus, even if the data processing technically occurs outside the EU. This interpretive framework is directly relevant to assessing whether a non-EU AI provider falls within the AI Act's scope through an EU-based presence.

Recital 131 adds a complementary obligation: providers of high-risk AI systems (other than those covered by existing Union harmonisation legislation) must register themselves and their systems in an EU database managed by the Commission, reinforcing the territorial reach through a transparency mechanism.

Key Developments

The CJEU's ruling in Google Spain established that the concept of establishment is not limited to the entity performing the processing but extends to any entity acting on behalf of and under the authority of the controller, where that entity is involved in activities central to the service offered. Applied to the AI Act context, a third-country AI provider with an EU subsidiary engaged in marketing, sales, distribution, or technical support for its AI systems will likely be deemed established in the Union for Article 2 purposes.

The European Commission's enforcement posture under GDPR Article 3(2) โ€” targeting non-EU entities based on output use and monitoring behavior โ€” signals that the analogous AI Act provision will be enforced against providers whose systems generate outputs used by EU-based deployers, even absent any physical EU presence. National market surveillance authorities, empowered under Article 76, will oversee compliance including testing in real-world conditions, creating a decentralized but coordinated enforcement architecture.

Practical Guidance

  • Map your establishment nexus: Assess whether any EU-based subsidiary, branch, or agent is involved in promoting, selling, distributing, or supporting your AI system. Under the Google Spain logic, such involvement likely triggers full AI Act obligations even for third-country providers.

  • Evaluate output usage in the EU: If your AI system is deployed from outside the EU but its outputs are used within the Union โ€” for instance, credit scoring, recruitment screening, or biometric identification results consumed by EU-based clients โ€” you fall within Article 2's third category and must comply.

  • Register high-risk systems: Providers of high-risk AI systems not covered by existing harmonisation legislation must register in the EU database before placing systems on the market. Third-country providers should determine early whether their systems meet the high-risk thresholds in Annex III.

  • Structure contractual allocations carefully: Contracts between third-country providers and EU deployers should clearly delineate compliance responsibilities, but recognize that contractual allocation does not eliminate direct regulatory obligations under Article 2.

  • Monitor market surveillance engagement: Article 76 empowers national authorities to supervise real-world testing conditions. Providers should prepare for potential authority engagement in any Member State where their systems are placed on the market, given the decentralized enforcement model.

Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 34
Art. 1(2)(a) harmonised rules for the placing on the market, the putting into service, and the use of AI systems in the Union; AI Act Art. 1(2)(e) harmonised rules for the placing on the market of general-purpose AI models; AI Act Art. 2(1)(a) providers placing on the market or putting into service AI systems or placing on the market general-purpose AI models in the Union, irrespective of whโ€ฆ AI Act Art. 2(1)(e) product manufacturers placing on the market or putting into service an AI system together with their product and under their own name or trademark; AI Act rec 128 Recital 128 โ€” substantial modification triggering new conformity assessment AI Act Jun 2024 rec 22 Recital 22 โ€” extraterritorial application to non-EU operators AI Act Jun 2024 art 76 Supervision of testing in real world conditions by market surveillance authorities AI Act Jun 2024 rec 131 Recital 131 โ€” EU database for high-risk AI registration AI Act Jun 2024 rec 130 Recital 130 โ€” rapid deployment of innovative AI systems AI Act Jun 2024 rec 73 Recital 73 โ€” human oversight of high-risk AI AI Act Jun 2024 rec 114 Recital 114 โ€” systemic risk AI model obligations AI Act Jun 2024 rec 123 Recital 123 โ€” conformity assessment for high-risk AI systems AI Act Jun 2024 rec 129 Recital 129 โ€” CE marking for high-risk AI systems AI Act Jun 2024 rec 139 Recital 139 โ€” AI regulatory sandboxes innovation objectives AI Act Jun 2024 rec 141 Recital 141 โ€” real world testing conditions without sandbox AI Act Jun 2024 rec 149 Recital 149 โ€” AI Board establishment and advisory tasks AI Act Jun 2024 rec 156 Recital 156 โ€” market surveillance and compliance enforcement framework AI Act Jun 2024 rec 158 Recital 158 โ€” financial services authorities for AI oversight AI Act Jun 2024 rec 159 Recital 159 โ€” biometric AI surveillance authority powers AI Act Jun 2024 rec 160 Recital 160 โ€” joint market surveillance and investigation activities AI Act Jun 2024 rec 161 Recital 161 โ€” Union and national supervision responsibilities for general-purpose AI AI Act Jun 2024 rec 162 Recital 162 โ€” Commission AI Office general-purpose model supervision AI Act Jun 2024 rec 84 Recital 84 โ€” Third parties becoming high-risk AI providers AI Act Jun 2024 rec 112 Recital 112 โ€” general-purpose AI systemic risk classification procedure AI Act Jun 2024 Show 14 more โ†’