PowerQuant provides technical compliance documentation — not legal advice.
The EU AI Act (Regulation (EU) 2024/1689) is not a European regulation only for European companies. Like the GDPR, the EU AI Act has extraterritorial reach: any organisation that places AI systems on the EU market, or whose AI systems affect persons in the EU, is in scope — regardless of whether the organisation is based in the United States, the United Kingdom, Asia, or elsewhere.
Following the entry into force of the Digital Omnibus (Regulation (EU) 2026/1744, published in the Official Journal of the EU on 24 July 2026, in force from 27 July 2026), the timeline is now settled. Global organisations have a clearer compliance calendar — but that does not mean obligations can be deferred.
Extraterritorial Scope: Article 2(1)
EU AI Act Article 2(1) provides that the Regulation applies to:
- Providers that place AI systems on the market or put them into service in the EU — regardless of whether the provider is established in the EU or a third country
- Deployers of AI systems established or located within the EU
- Providers and deployers established in third countries where the output of the AI system is used in the EU
- Importers and distributors of AI systems
A US-based SaaS company selling an AI recruitment system to European customers is a provider under the EU AI Act. It does not matter where the servers are located. What matters is whether the system targets the EU market and whether its output affects persons in the EU.
Key Deadlines After the Digital Omnibus
The Digital Omnibus (Regulation (EU) 2026/1744, in force 27 July 2026) changed the central deadlines for Annex III high-risk AI systems. Here is the updated picture:
- 2 February 2025 — AI Literacy (Art. 4): Already in force. Providers and deployers must ensure that staff working with AI systems have sufficient AI literacy to understand the systems' capabilities and limitations.
- 2 August 2026 — Article 50 Transparency: In force. UNCHANGED by the Digital Omnibus. Systems interacting with users must disclose AI interaction. AI-generated content must be machine-readably marked.
- 2 December 2027 — Annex III Standalone High-Risk (Regulation (EU) 2026/1744, in force 27 July 2026): Deferred from 2 August 2026. Full obligation catalogue for standalone Annex III systems: technical documentation (Annex IV), conformity assessment, CE marking, EU database registration (Art. 49), Art. 9–15 provider obligations.
- 2 August 2028 — Annex I Embedded Systems: High-risk AI systems embedded in products regulated by Annex I sector legislation (Machinery Regulation etc.).
Source: Regulation (EU) 2026/1744, Art. 1, published in the Official Journal of the EU on 24 July 2026.
EU Representative: Mandatory for Non-EU Providers (Art. 22)
Providers established outside the EU that place high-risk AI systems on the EU market must appoint an EU representative (Art. 22). The representative must:
- Be established in the EU
- Have a mandate to act on behalf of the provider before authorities
- Ensure that the EU declaration of conformity and technical documentation are retained and accessible to market surveillance authorities
- Be registered in the EU AI database as the provider's point of contact
This mirrors the GDPR Article 27 requirement for an EU representative for non-EU data controllers. For organisations that already have a GDPR representative, it is not automatically the same legal entity that can serve as EU AI Act representative — the roles and responsibilities differ and should be assessed separately.
The SME Threshold Is Raised — But the Exemption Is Narrow
The Digital Omnibus raised the SME threshold from 250 employees / EUR 43 million turnover to 750 employees / EUR 150 million turnover globally. Companies below this threshold remain subject to the EU AI Act but may benefit from:
- Reduced fees for EU database registration
- Easier access to regulatory sandboxes (Art. 62)
- Proportionate implementation guidance from national authorities
SME status does not exempt from the substantive obligations: Article 5 prohibitions, Article 50 transparency, Article 4 AI literacy, and — from 2 December 2027 (Regulation (EU) 2026/1744, in force 27 July 2026) — the Annex III high-risk catalogue apply regardless of company size.
GPAI Obligations: In Force Now for Foundation Model Providers
Articles 51–56 (GPAI — General Purpose AI) apply to providers of general purpose AI models, including large language models. These obligations apply regardless of the provider's nationality:
- Art. 53: Technical documentation, usage documentation for downstream providers, copyright compliance (Art. 53(1)(c)), and publication of a training data summary
- Art. 54: GPAI models with systemic risk (trained with >10²⁵ FLOPS): adversarial testing (red teaming), serious incident reporting, cybersecurity protection
US and UK AI laboratories placing GPAI models on the EU market — via API, cloud services, or direct distribution — are in scope. The EU AI Office is the primary supervisory authority for GPAI.
What a Global Organisation Should Have in Place Now
1. AI System Inventory With Scope Assessment
Map all AI systems used by, sold to, or affecting EU-based users. For each system: is it Annex III high-risk? Is it a GPAI model (Art. 51–56)? Is it Article 5 prohibited? The result is a prioritised compliance register with roles (provider / deployer / importer / distributor).
2. Article 50 Transparency: Act Now
Article 50 applies from 2 August 2026, unchanged by the Digital Omnibus. Chatbots, AI assistants and systems interacting with EU users must disclose AI interaction at session start. AI-generated content (images, audio, video, text) must be machine-readably marked. Review all user-facing AI interfaces now.
3. EU Representative: Appoint and Register
Non-EU providers of high-risk AI must appoint an EU representative before the Annex III deadlines. The representative must be registered in the EU AI database from 2 December 2027 (Regulation (EU) 2026/1744, in force 27 July 2026). The process takes time — legal agreements and registration require advance preparation.
4. Supply Chain: AI Act Clauses in Contracts
Global organisations that purchase AI services from EU-based or non-EU providers and use them in an EU context are deployers. This entails obligations around human oversight (Art. 14), logs (Art. 26(6)) and information to affected persons (Art. 26(11)). Procurement contracts should secure access to the Art. 13 instructions for use and Annex IV technical documentation from the supplier.
Penalties: Global Turnover Is the Basis
Article 99 EU AI Act sets penalties based on global turnover — not EU-only revenue:
- Article 5 violations (prohibited practices): up to EUR 35 million or 7% of global annual turnover
- Breaches of Art. 9–15 and Art. 51–56 (high-risk + GPAI provider obligations): up to EUR 15 million or 3% of global turnover
- False or misleading information to authorities: up to EUR 7.5 million or 1% of global turnover
For a global organisation with EUR 1 billion in turnover, the 7% penalty means a theoretical exposure of EUR 70 million. The penalties are comparable to GDPR but apply to a broader set of obligations.
Sources: Regulation (EU) 2024/1689 (EU AI Act), Art. 2(1), 5, 14, 22, 26, 50, 51–56, 99; Digital Omnibus Regulation (EU) 2026/1744, published Official Journal of the EU 24 July 2026, in force 27 July 2026. Annex III standalone high-risk deadline: 2 December 2027 (Regulation (EU) 2026/1744, in force 27 July 2026). PowerQuant provides technical documentation — not legal advice.