# AI Act Territorial Scope — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/ai-act-territorial-scope
> Sources are cited per item. Verify against the official texts before relying on them.

The scope section of the AI Act includes specific provisions on territorial applicability and which providers are subject to the regulation regardless of their location, warranting a dedicated topic.

## Overview

## Legal Framework

The AI Act's territorial scope is governed primarily by Article 2, which extends the regulation's reach well beyond EU borders. The regulation applies to three categories of actors. First, providers placing AI systems on the EU market or putting them into service in the Union, irrespective of whether the provider is established within the EU or in a third country. Second, deployers of AI systems that have their place of establishment within the Union. Third — and most expansively — providers and deployers of AI systems established in a third country, where the output produced by the AI system is used in the Union.

This third category represents a significant extraterritorial extension, analogous to the market-place targeting logic familiar from GDPR Article 3(2). The establishment-based criterion under Article 2 mirrors the approach taken in EU data protection law, where the CJEU has interpreted the concept of an "establishment" broadly. In *Google Spain v. AEPD* (C-131/12), the Court held that a subsidiary in the Union that promotes and sells advertising space for a parent search engine operator constitutes a sufficient establishment nexus, even if the data processing technically occurs outside the EU. This interpretive framework is directly relevant to assessing whether a non-EU AI provider falls within the AI Act's scope through an EU-based presence.

Recital 131 adds a complementary obligation: providers of high-risk AI systems (other than those covered by existing Union harmonisation legislation) must register themselves and their systems in an EU database managed by the Commission, reinforcing the territorial reach through a transparency mechanism.

## Key Developments

The CJEU's ruling in *Google Spain* established that the concept of establishment is not limited to the entity performing the processing but extends to any entity acting on behalf of and under the authority of the controller, where that entity is involved in activities central to the service offered. Applied to the AI Act context, a third-country AI provider with an EU subsidiary engaged in marketing, sales, distribution, or technical support for its AI systems will likely be deemed established in the Union for Article 2 purposes.

The European Commission's enforcement posture under GDPR Article 3(2) — targeting non-EU entities based on output use and monitoring behavior — signals that the analogous AI Act provision will be enforced against providers whose systems generate outputs used by EU-based deployers, even absent any physical EU presence. National market surveillance authorities, empowered under Article 76, will oversee compliance including testing in real-world conditions, creating a decentralized but coordinated enforcement architecture.

## Practical Guidance

- **Map your establishment nexus**: Assess whether any EU-based subsidiary, branch, or agent is involved in promoting, selling, distributing, or supporting your AI system. Under the *Google Spain* logic, such involvement likely triggers full AI Act obligations even for third-country providers.

- **Evaluate output usage in the EU**: If your AI system is deployed from outside the EU but its outputs are used within the Union — for instance, credit scoring, recruitment screening, or biometric identification results consumed by EU-based clients — you fall within Article 2's third category and must comply.

- **Register high-risk systems**: Providers of high-risk AI systems not covered by existing harmonisation legislation must register in the EU database before placing systems on the market. Third-country providers should determine early whether their systems meet the high-risk thresholds in Annex III.

- **Structure contractual allocations carefully**: Contracts between third-country providers and EU deployers should clearly delineate compliance responsibilities, but recognize that contractual allocation does not eliminate direct regulatory obligations under Article 2.

- **Monitor market surveillance engagement**: Article 76 empowers national authorities to supervise real-world testing conditions. Providers should prepare for potential authority engagement in any Member State where their systems are placed on the market, given the decentralized enforcement model.

## Legislation (full text of key provisions)

### Supervision of testing in real world conditions by market surveillance authorities

*Source: AI Act, aiact-art-76-en, 2024-06-12 — https://overview.legal/posts/93261*

### Right to lodge a complaint with a market surveillance authority

*Source: AI Act, aiact-art-85-en, 2024-06-12 — https://overview.legal/posts/93389*

Without prejudice to other administrative or judicial remedies, any natural or legal person having grounds to consider that there has been an infringement of the provisions of this Regulation may submit complaints to the relevant market surveillance authority.In accordance with Regulation (EU) 2019/1020, such complaints shall be taken into account for the purpose of conducting market surveillance activities, and shall be handled in line with the dedicated procedures established therefor by the market surveillance authorities.

### Recital 128 — substantial modification triggering new conformity assessment

*Source: AI Act, aiact-rec-128-en, 2024-06-12 — https://overview.legal/posts/93938*

In line with the commonly established notion of substantial modification for products regulated by Union harmonisation legislation, it is appropriate that whenever a change occurs which may affect the compliance of a high-risk AI system with this Regulation (e.g. change of operating system or software architecture), or when the intended purpose of the system changes, that AI system should be considered to be a new AI system which should undergo a new conformity assessment. However, changes occurring to the algorithm and the performance of AI systems which continue to ‘learn’ after being placed on the market or put into service, namely automatically adapting how functions are carried out, should not constitute a substantial modification, provided that those changes have been pre-determined by the provider and assessed at the moment of the conformity assessment.

### Recital 22 — extraterritorial application to non-EU operators

*Source: AI Act, aiact-rec-22-en, 2024-06-12 — https://overview.legal/posts/93726*

In light of their digital nature, certain AI systems should fall within the scope of this Regulation even when they are not placed on the market, put into service, or used in the Union. This is the case, for example, where an operator established in the Union contracts certain services to an operator established in a third country in relation to an activity to be performed by an AI system that would qualify as high-risk. In those circumstances, the AI system used in a third country by the operator could process data lawfully collected in and transferred from the Union, and provide to the contracting operator in the Union the output of that AI system resulting from that processing, without that AI system being placed on the market, put into service or used in the Union. To prevent the circumvention of this Regulation and to ensure an effective protection of natural persons located in the Union, this Regulation should also apply to providers and deployers of AI systems that are established in a third country, to the extent the output produced by those systems is intended to be used in the Union. Nonetheless, to take into account existing arrangements and special needs for future cooperation with foreign partners with whom information and evidence is exchanged, this Regulation should not apply to public authorities of a third country and international organisations when acting in the framework of cooperation or international agreements concluded at Union or national level for law enforcement and judicial cooperation with the Union or the Member States, provided that the relevant third country or international organisation provides adequate safeguards with respect to the protection of fundamental rights and freedoms of individuals. Where relevant, this may cover activities of entities entrusted by the third countries to carry out specific tasks in support of such law enforcement and judicial cooperation. Such framework for cooperation or agreements have been established bilaterally between Member States and third countries or between the European Union, Europol and other Union agencies and third countries and international organisations. The authorities competent for supervision of the law enforcement and judicial authorities under this Regulation should assess whether those frameworks for cooperation or international agreements include adequate safeguards with respect to the protection of fundamental rights and freedoms of individuals. Recipient national authorities and Union institutions, bodies, offices and agencies making use of such outputs in the Union remain accountable to ensure their use complies with Union law. When those international agreements are revised or new ones are concluded in the future, the contracting parties should make utmost efforts to align those agreements with the requirements of this Regulation.

### Recital 131 — EU database for high-risk AI registration

*Source: AI Act, aiact-rec-131-en, 2024-06-12 — https://overview.legal/posts/93944*

In order to facilitate the work of the Commission and the Member States in the AI field as well as to increase the transparency towards the public, providers of high-risk AI systems other than those related to products falling within the scope of relevant existing Union harmonisation legislation, as well as providers who consider that an AI system listed in the high-risk use cases in an annex to this Regulation is not high-risk on the basis of a derogation, should be required to register themselves and information about their AI system in an EU database, to be established and managed by the Commission. Before using an AI system listed in the high-risk use cases in an annex to this Regulation, deployers of high-risk AI systems that are public authorities, agencies or bodies, should register themselves in such database and select the system that they envisage to use. Other deployers should be entitled to do so voluntarily. This section of the EU database should be publicly accessible, free of charge, the information should be easily navigable, understandable and machine-readable. The EU database should also be user-friendly, for example by providing search functionalities, including through keywords, allowing the general public to find relevant information to be submitted upon the registration of high-risk AI systems and on the use case of high-risk AI systems, set out in an annex to this Regulation, to which the high-risk AI systems correspond. Any substantial modification of high-risk AI systems should also be registered in the EU database. For high-risk AI systems in the area of law enforcement, migration, asylum and border control management, the registration obligations should be fulfilled in a secure non-public section of the EU database. Access to the secure non-public section should be strictly limited to the Commission as well as to market surveillance authorities with regard to their national section of that database. High-risk AI systems in the area of critical infrastructure should only be registered at national level. The Commission should be the controller of the EU database, in accordance with Regulation (EU) 2018/1725. In order to ensure the full functionality of the EU database, when deployed, the procedure for setting the database should include the development of functional specifications by the Commission and an independent audit report. The Commission should take into account cybersecurity risks when carrying out its tasks as data controller on the EU database. In order to maximise the availability and use of the EU database by the public, the EU database, including the information made available through it, should comply with requirements under the Directive (EU) 2019/882.

### Recital 130 — rapid deployment of innovative AI systems

*Source: AI Act, aiact-rec-130-en, 2024-06-12 — https://overview.legal/posts/93942*

Under certain conditions, rapid availability of innovative technologies may be crucial for health and safety of persons, the protection of the environment and climate change and for society as a whole. It is thus appropriate that under exceptional reasons of public security or protection of life and health of natural persons, environmental protection and the protection of key industrial and infrastructural assets, market surveillance authorities could authorise the placing on the market or the putting into service of AI systems which have not undergone a conformity assessment. In duly justified situations, as provided for in this Regulation, law enforcement authorities or civil protection authorities may put a specific high-risk AI system into service without the authorisation of the market surveillance authority, provided that such authorisation is requested during or after the use without undue delay.

### Recital 73 — human oversight of high-risk AI

*Source: AI Act, aiact-rec-73-en, 2024-06-12 — https://overview.legal/posts/93828*

High-risk AI systems should be designed and developed in such a way that natural persons can oversee their functioning, ensure that they are used as intended and that their impacts are addressed over the system’s lifecycle. To that end, appropriate human oversight measures should be identified by the provider of the system before its placing on the market or putting into service. In particular, where appropriate, such measures should guarantee that the system is subject to in-built operational constraints that cannot be overridden by the system itself and is responsive to the human operator, and that the natural persons to whom human oversight has been assigned have the necessary competence, training and authority to carry out that role. It is also essential, as appropriate, to ensure that high-risk AI systems include mechanisms to guide and inform a natural person to whom human oversight has been assigned to make informed decisions if, when and how to intervene in order to avoid negative consequences or risks, or stop the system if it does not perform as intended. Considering the significant consequences for persons in the case of an incorrect match by certain biometric identification systems, it is appropriate to provide for an enhanced human oversight requirement for those systems so that no action or decision may be taken by the deployer on the basis of the identification resulting from the system unless this has been separately verified and confirmed by at least two natural persons. Those persons could be from one or more entities and include the person operating or using the system. This requirement should not pose unnecessary burden or delays and it could be sufficient that the separate verifications by the different persons are automatically recorded in the logs generated by the system. Given the specificities of the areas of law enforcement, migration, border control and asylum, this requirement should not apply where Union or national law considers the application of that requirement to be disproportionate.

### Recital 114 — systemic risk AI model obligations

*Source: AI Act, aiact-rec-114-en, 2024-06-12 — https://overview.legal/posts/93910*

The providers of general-purpose AI models presenting systemic risks should be subject, in addition to the obligations provided for providers of general-purpose AI models, to obligations aimed at identifying and mitigating those risks and ensuring an adequate level of cybersecurity protection, regardless of whether it is provided as a standalone model or embedded in an AI system or a product. To achieve those objectives, this Regulation should require providers to perform the necessary model evaluations, in particular prior to its first placing on the market, including conducting and documenting adversarial testing of models, also, as appropriate, through internal or independent external testing. In addition, providers of general-purpose AI models with systemic risks should continuously assess and mitigate systemic risks, including for example by putting in place risk-management policies, such as accountability and governance processes, implementing post-market monitoring, taking appropriate measures along the entire model’s lifecycle and cooperating with relevant actors along the AI value chain.

### Recital 123 — conformity assessment for high-risk AI systems

*Source: AI Act, aiact-rec-123-en, 2024-06-12 — https://overview.legal/posts/93928*

In order to ensure a high level of trustworthiness of high-risk AI systems, those systems should be subject to a conformity assessment prior to their placing on the market or putting into service.

### Recital 129 — CE marking for high-risk AI systems

*Source: AI Act, aiact-rec-129-en, 2024-06-12 — https://overview.legal/posts/93940*

High-risk AI systems should bear the CE marking to indicate their conformity with this Regulation so that they can move freely within the internal market. For high-risk AI systems embedded in a product, a physical CE marking should be affixed, and may be complemented by a digital CE marking. For high-risk AI systems only provided digitally, a digital CE marking should be used. Member States should not create unjustified obstacles to the placing on the market or the putting into service of high-risk AI systems that comply with the requirements laid down in this Regulation and bear the CE marking.

## Related topics

- **Monitoring** — https://overview.legal/topics/monitoring
  Systematic observation and tracking of individuals
- **Authority Cooperation** — https://overview.legal/topics/cooperation-with-authorities-ai
  This new topic is needed because the AI Act establishes specific cooperation and coordination mechanisms between AI providers/deployers and competent authoritie
- **Market Surveillance and Control of AI Systems** — https://overview.legal/topics/market-surveillance-control-ai
  This new topic is needed to comprehensively cover the specific procedures, mechanisms, and authorities involved in market surveillance and control of AI systems
- **Market Surveillance Corrective Actions and Enforcement** — https://overview.legal/topics/market-surveillance-corrective-actions
  This topic addresses the specific enforcement and corrective actions available to authorities during market surveillance, including withdrawal, suspension, and 
- **Artificial Intelligence** — https://overview.legal/topics/ai
  AI systems and their implications for data protection
- **High-Risk AI Classification** — https://overview.legal/topics/high-risk-ai-classification
  The content specifically addresses classification rules for high-risk AI systems under the AI Act, which is a distinct regulatory concept requiring its own dedi

---
Generated by overview.legal · https://overview.legal/topics/ai-act-territorial-scope · 2026-08-22
