Scope: who the Act reaches — including outside Europe

Lesson 3 of 5 in The EU AI Act at a Glance: Purpose, Scope, and the Risk Pyramid.

A San Francisco company with no EU office, no EU servers, and no EU customers of record can still be squarely inside the AI Act. Understanding why is the single most practical skill in this module — it is the first question every client asks.

Article 2 hangs the Act on three hooks. Placing on the market: a provider anywhere in the world makes a system available in the Union — first supply counts, paid or free. Putting into service: supplying a system for first use in the EU, including a deployer building one for its own use. And the long-arm hook: providers and deployers located in a third country, where the output produced by the system is used in the Union. That third hook is what catches the San Francisco company: a US firm running its own hiring model in Texas is caught the moment it screens applicants for its Dublin office, because the output — the shortlist — is used in the EU.

Non-EU providers of high-risk systems must also appoint an authorised representative established in the Union (Art 22) — a mandated local anchor that regulators can actually reach, the same device medical-device law uses.

Does the AI Act reach you?

Interactive decision tree — outcomes:

  • Outside the definition

    If nothing is inferred — the logic is fully human-specified — the product is not an AI system under Art 3(1) and the Act does not apply. Document that analysis: the definitional boundary is the first thing a regulator will test.

  • Excluded by Art 2

    Exclusive military/defence/national-security purposes and pure scientific R&D sit outside the Act. Exclusivity is load-bearing: a dual-use system with any civilian application loses the exclusion, and research systems lose it the moment they are placed on the market or tested in real-world conditions.

  • In scope — market hook

    You are placing on the market or putting into service in the Union. The Act applies irrespective of where you are established (Art 2(1)(a)). If you are a third-country provider of a high-risk system, appoint an EU authorised representative (Art 22). Next step: classify the system against the risk tiers.

  • In scope — output hook

    This is the long arm of Art 2(1)(c): third-country providers and deployers are covered where the output produced by the system is used in the Union. No EU sales, servers, or subsidiaries are required. Classify the system as if you were operating inside the EU.

  • Currently out of scope — keep watching

    With no EU market presence and no EU output use, the Act does not reach you today. But scope is a fact pattern, not a permanent status: one EU client, one EU office screening hires, and the analysis flips. Re-run this check as the business changes.

Exclusion: military, defence, and national security

Systems placed on the market or used exclusively for military, defence, or national-security purposes are outside the Act (Art 2(3)) — those competences belong to Member States. The trap is exclusively: a general-purpose drone-vision system sold to both an army and a logistics firm is fully in scope for its civilian life. And a system built for national security that is later used for ordinary policing re-enters the Act at that moment.

Exclusion: third-country public authorities under international agreements

Public authorities of third countries and international organisations using AI within international cooperation or agreements for law enforcement and judicial cooperation with the Union or Member States are excluded (Art 2(4)) — provided adequate fundamental-rights safeguards apply. Narrow, and mostly relevant to cross-border policing arrangements.

Exclusion: scientific research and development

AI developed and put into service for the sole purpose of scientific research and development is excluded (Art 2(6)). The Act protects the lab, not the launch: the exclusion ends when the system is placed on the market or put into service for anything beyond research.

Exclusion: pre-market development and testing

Research, testing, and development activity on AI systems before they are placed on the market or put into service is outside the Act (Art 2(8)) — with one carve-back that matters: testing in real-world conditions is not covered by this exclusion. Once you test on real people outside the lab, the Act’s real-world-testing rules (Arts 60–61) apply.

Exclusion: purely personal, non-professional use

Natural persons using AI in a purely personal, non-professional activity are not deployers under the Act (Art 2(10)). Your holiday-photo enhancer and hobby chatbot are safe. The line is professional context: the same person using the same tool to screen tenants for a rental business has crossed it.

Partial carve-out: free and open-source AI

AI released under free and open-source licences falls outside most of the Act (Art 2(12)) — but the carve-out has hard limits. It does not apply if the system is a prohibited practice, is high-risk, or falls under Art 50 transparency duties. And open-source GPAI models keep their copyright-policy and training-content-summary duties, losing the exemption entirely at systemic-risk scale. Open source softens the Act; it never neutralises it where risk is real.

Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.