Guide
EU AI Act for Non-EU Companies: Provider, Deployer or Neither?
Reviewed 2026-08-21
Short answer
Being established outside the EU does not automatically exclude a company from the AI Act. The first question is role: provider, deployer, importer, distributor, or provider of a general-purpose AI model. The Act defines each differently, and a role is not chosen by label or contract. The second question is territorial scope under Article 2: whether the company places an AI system on the EU market, puts one into service there, or, for providers and deployers outside the EU, whether the system's output is used in the Union. The third question is the risk/system category, which decides which specific duties, if any, follow. Different roles carry different obligations, and none of these questions can be skipped by the fact of using AI alone.
See the full 11-step checklist below.Why this matters
- Who should care
- Providers, integrators and deployers of AI systems used in the EU.
- Typical trigger
- Your role (provider, integrator or deployer) for AI output used by people in the Union.
- What buyers may ask for
- an AI system inventoryyour role/classification recordrisk documentation
Where this fits
01
Provider
Places an AI system on the EU market or puts it into service under its own name.
02
Deployer
Uses an AI system under its own authority within the EU.
03
Integrator
Makes an AI system available in the EU supply chain without being the original provider.
Who this is relevant to
Companies developing, placing, integrating, importing, distributing or deploying AI systems or general-purpose AI models in contexts connected to the EU.
It is also for teams that have been asked by an EU customer to explain an AI system's role, documentation, safeguards, transparency position or evidence of human oversight.
- AI providers placing a system or model on the market or putting it into service
- Companies integrating, modifying, rebranding or deploying a third-party AI system
- Products whose AI output is used in the Union where the third-country nexus needs review
- Teams assessing prohibited-practice, high-risk, transparency or GPAI questions
Why AI system, role and use facts matter
The AI Act is a risk-based instrument. It does not treat every AI-enabled feature, AI system, general-purpose AI model, provider and deployer as the same category.
The first questions are factual: what system or model is involved, who develops or supplies it, who deploys or uses it, whether it is placed on the market or put into service, and where the relevant use or output occurs.
Article 2 sets the territorial reach: it covers providers placing an AI system on the EU market or putting it into service there regardless of where the provider is established, and separately, providers and deployers established in a third country whose AI system's output is used in the Union. That third-country-output route is a real extraterritorial hook, not a reason to assume every EU-visible output brings a company into scope. The output still has to be "used in the Union" in the sense the Article addresses, and the role and system-category questions still apply on top of it.
The Act contains different concepts for prohibited practices, high-risk systems, transparency duties and general-purpose AI models. A role or product label alone is not enough to self-classify the outcome. Importer and distributor are also defined as EU-located roles in the supply chain. A genuinely non-EU company does not itself hold those two roles, though it may work with an EU importer or distributor as a separate legal person.
Direct application vs customer requirements
A company may have a direct AI Act question because of its own role, system, market activity or EU nexus. Separately, an EU customer may request model or system documentation, testing information, human-oversight material, security details or contractual assurances because of its own obligations and risk controls.
A customer request can be important evidence of commercial pressure without proving that the supplier is a provider, deployer or high-risk system under the Act. Record the customer's request alongside, not instead of, the underlying AI facts.
- Direct: depends on the relevant system/model, role, market or use facts
- Customer-driven: documentation, safeguards and evidence requested by an EU customer
- Possible: role, AI category, EU use or risk facts are not yet established
Typical readiness areas
The evidence depends on the system, model, role and risk path. A useful starting pack should make those boundaries explicit and show how the organization manages the relevant risks without claiming a classification it has not established.
- System or model inventory, intended purpose and deployment context
- Role analysis for provider, deployer, importer, distributor or integrator activity
- Technical documentation, instructions, data and testing records where relevant
- Risk-management, human-oversight, logging and incident processes
- Transparency, user information and limitation controls where relevant
- Evidence of model, system and third-party component governance
- A named owner for customer questions and AI Act evidence
Common misconceptions
- “Using AI means the EU AI Act applies to us.”
- Use of AI is a starting fact, not the conclusion. The system or model, role, market or service context, EU nexus and applicable risk category still need to be assessed.
- “Every AI system is a high-risk system.”
- High-risk status is a distinct concept with its own conditions. It cannot be inferred merely from the presence of AI or from a provider/deployer label.
- “A GPAI model and an AI system are the same thing.”
- They are different concepts with different roles and obligations. The model, downstream system and organization using or supplying them should be mapped separately.
- “A customer asking for an AI dossier makes us the provider.”
- A customer request may reflect its own governance or procurement needs. It does not by itself establish the supplier's legal role or the system's risk category.
- “We are outside the EU, so the AI Act cannot apply to us.”
- Location alone does not settle the question either way. Article 2 reaches providers placing a system on the EU market or putting it into service there regardless of where they are established, and separately reaches providers and deployers in a third country whose AI system's output is used in the Union. That extraterritorial route still depends on the actual facts, not on having any EU-visible output at all.
- “Our EU customer's contract calls us the provider, so legally we are one.”
- Contract wording is commercially useful but does not itself satisfy or override the Act's own statutory definition. Whether a company develops the system, has it developed, or places it on the market or puts it into service under its own name are the facts that decide the role. A label in a customer's paperwork is evidence to record, not the legal answer.
Practical checklist
- 01Where the company is established, and where the AI system or model is placed on the EU market or put into service
- 02Inventory AI systems, models, providers, deployers and third-party components
- 03Who develops the system, or has it developed, and under whose name or trademark it is placed on the market
- 04Describe intended purpose, users, deployment and whether output is used in the Union
- 05Separate provider, deployer, importer, distributor and integrator questions
- 06Whether a general-purpose AI model is itself being provided, separately from any downstream system built on one
- 07Record whether the activity concerns a prohibited-practice, high-risk, transparency or GPAI path
- 08Map technical documentation, testing, logging, human oversight and incident evidence
- 09Record customer-driven requests and any contractual role labels without treating them as a statutory classification
- 10Assign an owner for AI governance and evidence maintenance
- 11Keep unknown role and use facts visible for verification
What RegRoute can and cannot determine
RegRoute can organize the AI system, role, EU-use, customer and evidence facts that identify which AI Act questions need review. It preserves possible and insufficient-information outcomes instead of forcing a high-risk or provider classification from incomplete answers.
It does not certify an AI system, determine a definitive legal classification, or turn a zero-result assessment into proof that the AI Act does not apply. Specialist review may still be needed for the system's exact use and role.
Provider, deployer or something else: a role comparison
The Act defines each role by what a company actually does with a system, not by which side of a sale it sits on. "We built it" is not automatically the same as provider, and "our customer uses it" is not automatically the same as deployer.
| Role | What it generally means | Typical technology-company scenario | What fact must still be established |
|---|---|---|---|
| Provider | Develops an AI system or GPAI model, or has one developed, and places it on the market or puts it into service under its own name or trademark | A company ships an AI-enabled feature under its own brand, whether built in-house or on top of a third-party model | Whether the company places the system on the market or into service under its own name, not merely whether it built something |
| Deployer | Uses an AI system under its own authority, other than purely personal, non-professional use | A company uses a third-party AI tool internally, or embeds it in an internal workflow without placing it on the market itself | Whether the company is using the system under its own authority, and whether it has in substance become the provider by materially modifying or rebranding it |
| Importer | An EU-located person that places on the market a system bearing a third-country person's name or trademark | Not typically the non-EU company itself. Its EU distribution partner may hold this role | Whether an EU-based importer exists in the supply chain, and what that importer's own obligations are |
| Distributor | A person in the supply chain, other than the provider or importer, that makes a system available on the EU market | An EU reseller or marketplace listing the product. Again, not usually the non-EU company itself | Whether an EU-based distributor exists, and whether the company's own role changes if it substantially modifies the system |
| GPAI model provider | Develops a general-purpose AI model, or has one developed, and places it on the market | A company builds and offers its own foundation model, as distinct from building a product on top of someone else's model | Whether the company is providing the underlying general-purpose model itself, not just a downstream system that uses one |
AI-enabled does not mean high-risk
High-risk status follows the Act's own classification mechanics, primarily Article 6 read together with Annex III. Even where an Annex III use case is listed, for example biometrics, employment, education, essential services, law enforcement, migration or justice, Article 6(3) treats the system as not high-risk if it only performs a narrow procedural task, improves the output of a completed human activity, detects patterns without replacing or influencing human assessment, or performs a preparatory task, provided it does not profile natural persons. A system that profiles people is treated as high-risk regardless of how narrow the task looks.
Following the Digital Omnibus amendment (Regulation (EU) 2026/1744) to the AI Act, the stand-alone high-risk obligations under Annex III now apply from 2 December 2027, and the rules for AI embedded in already-regulated products (Annex I) apply from 2 August 2028. "Our AI touches an Annex III area" is a fact to track toward those dates, not evidence of a duty that already binds a system today.
None of this means high-risk questions can be ignored. The label "AI-enabled" is a starting fact, and the actual classification, including any Article 6(3) exclusion and which compliance date applies, has to be worked through and documented, not assumed in either direction.
Using a general-purpose model is not the same as providing one
A general-purpose AI model displays significant generality, can perform a wide range of distinct tasks, and can be integrated into many different downstream systems. Its provider is the company that develops it, or has it developed, and places it on the market.
A company that builds a product on top of a third-party foundation model is not thereby the provider of that underlying GPAI model. It is integrating one, which is a different question from the GPAI-provider obligations that attach to whoever actually develops and places the model itself. Fine-tuning, prompting or wrapping a third-party model in a product does not by itself convert the integrator into the model's provider, though a company that develops its own model, or substantially changes one so that its own general-purpose capability is materially different, has a separate question to establish.
Article 4: AI literacy is broad, but not a universal catch-all
AI-literacy obligations under Article 4 have applied since 2 February 2025. Since the Digital Omnibus amendment (Regulation (EU) 2026/1744) took effect on 27 July 2026, Article 4 requires providers and deployers to take measures to support the development of AI literacy among staff and other people dealing with the operation and use of an AI system on their behalf, taking into account their technical knowledge, experience, education and training, the context the system is used in, and the people or groups of people it affects. This is an effort-based obligation: it does not require a provider or deployer to guarantee any specific level of AI literacy for any individual, and it is not limited to high-risk systems. It applies across the AI systems a provider or deployer actually operates.
Article 4 is tied to already being a provider or a deployer of a relevant AI system. It does not by itself establish that a company holds either role, and it is not a universal obligation on every company on earth that happens to use AI somewhere in its business. Establishing role and territorial scope comes first; Article 4 then follows for the systems within that scope.
Official EU sources
Every conclusion on this page traces back to the primary legal text. We link only to official EU sources.
Regulation (EU) 2024/1689 — Artificial Intelligence Act · Read on EUR-Lex (CELEX 32024R1689)Verified 2026-08-17
Regulation (EU) 2026/1744 — amending Regulation (EU) 2024/1689 · Read on EUR-Lex (CELEX 32026R1744)Verified 2026-08-17
RegulationsMethodologySee what the EU Readiness Pack includes
Mini-check: what AI Act questions should you review?
Two screening questions about your AI activity and EU nexus. Answers carry into the full assessment.