The EU AI Act for companies outside Europe

Regulation (EU) 2024/1689 reaches companies established outside the European Union. The four risk tiers, the phased calendar, the fines, and the three routes by which it arrives at a non-EU company.

Updated August 15, 2026 · 12 min read

Regulation (EU) 2024/1689 — the EU AI Act— is the world’s first comprehensive artificial-intelligence legislation. The natural reaction of a company established outside Europe is to file the subject under “European problem” and move on. That misreading already proved expensive with the GDPR, and the mechanics here are the same.

The regulation has extraterritorial reach: it does not ask where the company is, it asks where the system is placed on the market and where the output is used. This guide covers when it reaches a company outside the EU, what it requires, and what to do about it.

Informational material, not legal advice. Classifying a risk tier and a role — provider, importer, distributor or deployer — depends on the specific case and should be validated with specialised counsel.

The three routes by which it arrives

  • 1. Direct sale. Your company offers a product or service with AI embedded to customers in the European Union. The most obvious case and the least frequent.
  • 2. Output used in the EU. The system runs at home, but what it produces is used inside the Union — an analysis, classification, recommendation or decision that reaches a European recipient. This is the route that catches most people by surprise.
  • 3. Contractual cascade. The likeliest of the three. Your company supplies a multinational that must comply; it passes the requirement down its chain, and compliance reaches you as a contract clause and a vendor questionnaire — not as a direct legal obligation.

Note the asymmetry: on the third route, the cost of being unprepared is not a fine, it is losing the contract. And it tends to arrive without warning, in the middle of a renewal.

The four risk tiers

The regulation’s logic is proportional: obligations scale with potential harm, not with technical sophistication.

TierWhat it coversObligation
UnacceptableProhibited practices, such as manipulation exploiting vulnerabilities, social scoring by public authorities, and certain forms of biometric identification.Prohibition. This tier carries the highest penalties.
High riskSystems listed in the regulation — among them employment and recruitment, education, credit, essential services, critical infrastructure and safety components of products.The heavy set: risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy and robustness, and conformity assessment.
Limited riskSystems that interact with people or generate synthetic content.Transparency: disclose that this is an AI and label artificially generated content.
Minimal riskThe vast majority of ordinary corporate uses.No specific obligations — which does not exempt data protection law or internal policy.

There is also a distinct regime for general-purpose AI models (GPAI), with documentation and transparency duties for those who provide them, and additional duties where the model presents systemic risk. For most companies outside the EU, that chapter matters as a user of those models: the documentation is something to demand from the provider.

The most common classification in a typical mid-sized company is minimal risk — with one exception that shows up almost every time: CV screening. Using AI in recruitment and selection sits among the high-risk cases. Plenty of companies that consider themselves out of scope have, in HR, the single system that puts them in.

The calendar

The regulation entered into force in August 2024, but application is phased — and this is the detail most people get wrong:

FromWhat starts applying
February 2025Prohibited practices and the AI literacy duty — training for those who operate and are affected by the systems.
August 2025Obligations for general-purpose AI models (GPAI), plus the governance and penalties structure.
August 2026The bulk of the high-risk obligations listed in Annex III, and the transparency duties.
August 2027High-risk systems that are safety components of products already covered by sectoral legislation.

For those reached by the contractual cascade, that is not the relevant calendar: theirs is the one their European customers follow, and those customers start demanding evidence from the chain well before their own deadline.

The penalties

  • Up to EUR 35 million or 7% of total worldwide annual turnover, whichever is higher — for prohibited practices.
  • Up to EUR 15 million or 3% — for breaching the other obligations, including the high-risk ones.
  • Up to EUR 7.5 million or 1% — for incorrect, incomplete or misleading information supplied to authorities.

The 7% ceiling is higher than the GDPR’s, which signals how seriously the European legislator treats the prohibited-practices tier.

What to do, without turning it into a two-year project

For most companies outside the EU, proportionate preparation fits into four moves:

  • 1. Inventory. There is no way to classify by risk tier what you do not know exists. It is the same prerequisite as every other framework — see how to build an AI-BOM.
  • 2. Classify.Place each system in one of the four tiers and record the rationale. In most cases the answer is “minimal risk” — and having that documented is what answers the customer’s questionnaire.
  • 3. Handle the exceptions. The few systems that land in high risk get proportionate attention: human oversight, documentation and logging.
  • 4. Train. The AI literacy duty is the cheapest obligation to satisfy and the most forgotten: recorded training for those who operate and those affected by the systems.

Organisations that structure this inside a management system conforming to ISO/IEC 42001 cover much of the ground with a single artefact — which is the practical reason the standard gained commercial traction so quickly.

And Brazil’s own framework

There is a bill before the National Congress proposing an AI framework with a risk-tiered approach, structurally close to the European one. Since text and stage change through the legislative process, the current status is worth confirming before any compliance decision.

The practical point is independent of the outcome: inventory, risk classification, human oversight and evidence records are the common denominator of data protection law, ISO/IEC 42001, the EU AI Act and any framework still to come. Building that now is not betting on one specific legal text — it is building the base all of them require.

Frequently asked questions

Does the EU AI Act apply to companies outside the European Union?

It can. The regulation has extraterritorial reach: it covers those who place AI systems on the EU market regardless of where they are established, and also providers and deployers in third countries where the output produced by the system is used within the Union. A company with no direct European customer can still be reached contractually, as a supplier in the chain of an EU company.

What are the EU AI Act risk tiers?

Four. Unacceptable risk, covering prohibited practices. High risk, with the heaviest set of obligations — risk management, data governance, technical documentation, logging, human oversight, robustness and conformity assessment. Limited risk, with transparency duties such as disclosing that the counterpart is an AI or that content was artificially generated. And minimal risk, with no specific obligations.

What are the EU AI Act fines?

The most severe reach up to EUR 35 million or 7% of total worldwide annual turnover, whichever is higher, for prohibited practices. For breaching other obligations, up to EUR 15 million or 3%. For supplying incorrect or misleading information to authorities, up to EUR 7.5 million or 1%.

Is Brazil getting a similar law?

There is a bill before the National Congress proposing an AI regulatory framework with a risk-tiered approach, inspired by the European structure. Since the text and the stage of the legislative process change, the current status should be confirmed before compliance decisions. In practice, companies organising for the EU AI Act are well positioned for whatever arrives.

Where does your company stand today?

The free assessment is 9 questions, 5 minutes and no signup. It returns your maturity level per dimension and a prioritised action plan — enough to know where to start without buying anything.