AI Act Territorial Scope
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal โ legal information, not advice.The scope section of the AI Act includes specific provisions on territorial applicability and which providers are subject to the regulation regardless of their location, warranting a dedicated topic.
Overview
9 sources ยท Jul 23, 2026Legal Framework
The AI Act's territorial scope is governed primarily by Article 2, which extends the regulation's reach well beyond EU borders. The regulation applies to three categories of actors. First, providers placing AI systems on the EU market or putting them into service in the Union, irrespective of whether the provider is established within the EU or in a third country. Second, deployers of AI systems that have their place of establishment within the Union. Third โ and most expansively โ providers and deployers of AI systems established in a third country, where the output produced by the AI system is used in the Union.
This third category represents a significant extraterritorial extension, analogous to the market-place targeting logic familiar from GDPR Article 3(2). The establishment-based criterion under Article 2 mirrors the approach taken in EU data protection law, where the CJEU has interpreted the concept of an "establishment" broadly. In Google Spain v. AEPD (C-131/12), the Court held that a subsidiary in the Union that promotes and sells advertising space for a parent search engine operator constitutes a sufficient establishment nexus, even if the data processing technically occurs outside the EU. This interpretive framework is directly relevant to assessing whether a non-EU AI provider falls within the AI Act's scope through an EU-based presence.
Recital 131 adds a complementary obligation: providers of high-risk AI systems (other than those covered by existing Union harmonisation legislation) must register themselves and their systems in an EU database managed by the Commission, reinforcing the territorial reach through a transparency mechanism.
Key Developments
The CJEU's ruling in Google Spain established that the concept of establishment is not limited to the entity performing the processing but extends to any entity acting on behalf of and under the authority of the controller, where that entity is involved in activities central to the service offered. Applied to the AI Act context, a third-country AI provider with an EU subsidiary engaged in marketing, sales, distribution, or technical support for its AI systems will likely be deemed established in the Union for Article 2 purposes.
The European Commission's enforcement posture under GDPR Article 3(2) โ targeting non-EU entities based on output use and monitoring behavior โ signals that the analogous AI Act provision will be enforced against providers whose systems generate outputs used by EU-based deployers, even absent any physical EU presence. National market surveillance authorities, empowered under Article 76, will oversee compliance including testing in real-world conditions, creating a decentralized but coordinated enforcement architecture.
Practical Guidance
Map your establishment nexus: Assess whether any EU-based subsidiary, branch, or agent is involved in promoting, selling, distributing, or supporting your AI system. Under the Google Spain logic, such involvement likely triggers full AI Act obligations even for third-country providers.
Evaluate output usage in the EU: If your AI system is deployed from outside the EU but its outputs are used within the Union โ for instance, credit scoring, recruitment screening, or biometric identification results consumed by EU-based clients โ you fall within Article 2's third category and must comply.
Register high-risk systems: Providers of high-risk AI systems not covered by existing harmonisation legislation must register in the EU database before placing systems on the market. Third-country providers should determine early whether their systems meet the high-risk thresholds in Annex III.
Structure contractual allocations carefully: Contracts between third-country providers and EU deployers should clearly delineate compliance responsibilities, but recognize that contractual allocation does not eliminate direct regulatory obligations under Article 2.
Monitor market surveillance engagement: Article 76 empowers national authorities to supervise real-world testing conditions. Providers should prepare for potential authority engagement in any Member State where their systems are placed on the market, given the decentralized enforcement model.