Skip to content

Guide

EU AI Act for Non-EU Companies: Provider, Deployer or Neither?

Reviewed 2026-08-21

Short answer

Being established outside the EU does not automatically exclude a company from the AI Act. The first question is role: provider, deployer, importer, distributor, or provider of a general-purpose AI model. The Act defines each differently, and a role is not chosen by label or contract. The second question is territorial scope under Article 2: whether the company places an AI system on the EU market, puts one into service there, or, for providers and deployers outside the EU, whether the system's output is used in the Union. The third question is the risk/system category, which decides which specific duties, if any, follow. Different roles carry different obligations, and none of these questions can be skipped by the fact of using AI alone.

See the full 11-step checklist below.

Why this matters

Who should care
Providers, integrators and deployers of AI systems used in the EU.
Typical trigger
Your role (provider, integrator or deployer) for AI output used by people in the Union.
What buyers may ask for
an AI system inventoryyour role/classification recordrisk documentation

Where this fits

  1. 01

    Provider

    Places an AI system on the EU market or puts it into service under its own name.

  2. 02

    Deployer

    Uses an AI system under its own authority within the EU.

  3. 03

    Integrator

    Makes an AI system available in the EU supply chain without being the original provider.

Who this is relevant to

Companies developing, placing, integrating, importing, distributing or deploying AI systems or general-purpose AI models in contexts connected to the EU.

It is also for teams that have been asked by an EU customer to explain an AI system's role, documentation, safeguards, transparency position or evidence of human oversight.

  • AI providers placing a system or model on the market or putting it into service
  • Companies integrating, modifying, rebranding or deploying a third-party AI system
  • Products whose AI output is used in the Union where the third-country nexus needs review
  • Teams assessing prohibited-practice, high-risk, transparency or GPAI questions

Why AI system, role and use facts matter

The AI Act is a risk-based instrument. It does not treat every AI-enabled feature, AI system, general-purpose AI model, provider and deployer as the same category.

The first questions are factual: what system or model is involved, who develops or supplies it, who deploys or uses it, whether it is placed on the market or put into service, and where the relevant use or output occurs.

Article 2 sets the territorial reach: it covers providers placing an AI system on the EU market or putting it into service there regardless of where the provider is established, and separately, providers and deployers established in a third country whose AI system's output is used in the Union. That third-country-output route is a real extraterritorial hook, not a reason to assume every EU-visible output brings a company into scope. The output still has to be "used in the Union" in the sense the Article addresses, and the role and system-category questions still apply on top of it.

The Act contains different concepts for prohibited practices, high-risk systems, transparency duties and general-purpose AI models. A role or product label alone is not enough to self-classify the outcome. Importer and distributor are also defined as EU-located roles in the supply chain. A genuinely non-EU company does not itself hold those two roles, though it may work with an EU importer or distributor as a separate legal person.

Direct application vs customer requirements

A company may have a direct AI Act question because of its own role, system, market activity or EU nexus. Separately, an EU customer may request model or system documentation, testing information, human-oversight material, security details or contractual assurances because of its own obligations and risk controls.

A customer request can be important evidence of commercial pressure without proving that the supplier is a provider, deployer or high-risk system under the Act. Record the customer's request alongside, not instead of, the underlying AI facts.

  • Direct: depends on the relevant system/model, role, market or use facts
  • Customer-driven: documentation, safeguards and evidence requested by an EU customer
  • Possible: role, AI category, EU use or risk facts are not yet established

Typical readiness areas

The evidence depends on the system, model, role and risk path. A useful starting pack should make those boundaries explicit and show how the organization manages the relevant risks without claiming a classification it has not established.

  • System or model inventory, intended purpose and deployment context
  • Role analysis for provider, deployer, importer, distributor or integrator activity
  • Technical documentation, instructions, data and testing records where relevant
  • Risk-management, human-oversight, logging and incident processes
  • Transparency, user information and limitation controls where relevant
  • Evidence of model, system and third-party component governance
  • A named owner for customer questions and AI Act evidence

Common misconceptions

“Using AI means the EU AI Act applies to us.”
Use of AI is a starting fact, not the conclusion. The system or model, role, market or service context, EU nexus and applicable risk category still need to be assessed.
“Every AI system is a high-risk system.”
High-risk status is a distinct concept with its own conditions. It cannot be inferred merely from the presence of AI or from a provider/deployer label.
“A GPAI model and an AI system are the same thing.”
They are different concepts with different roles and obligations. The model, downstream system and organization using or supplying them should be mapped separately.
“A customer asking for an AI dossier makes us the provider.”
A customer request may reflect its own governance or procurement needs. It does not by itself establish the supplier's legal role or the system's risk category.
“We are outside the EU, so the AI Act cannot apply to us.”
Location alone does not settle the question either way. Article 2 reaches providers placing a system on the EU market or putting it into service there regardless of where they are established, and separately reaches providers and deployers in a third country whose AI system's output is used in the Union. That extraterritorial route still depends on the actual facts, not on having any EU-visible output at all.
“Our EU customer's contract calls us the provider, so legally we are one.”
Contract wording is commercially useful but does not itself satisfy or override the Act's own statutory definition. Whether a company develops the system, has it developed, or places it on the market or puts it into service under its own name are the facts that decide the role. A label in a customer's paperwork is evidence to record, not the legal answer.

Practical checklist

  1. 01Where the company is established, and where the AI system or model is placed on the EU market or put into service
  2. 02Inventory AI systems, models, providers, deployers and third-party components
  3. 03Who develops the system, or has it developed, and under whose name or trademark it is placed on the market
  4. 04Describe intended purpose, users, deployment and whether output is used in the Union
  5. 05Separate provider, deployer, importer, distributor and integrator questions
  6. 06Whether a general-purpose AI model is itself being provided, separately from any downstream system built on one
  7. 07Record whether the activity concerns a prohibited-practice, high-risk, transparency or GPAI path
  8. 08Map technical documentation, testing, logging, human oversight and incident evidence
  9. 09Record customer-driven requests and any contractual role labels without treating them as a statutory classification
  10. 10Assign an owner for AI governance and evidence maintenance
  11. 11Keep unknown role and use facts visible for verification

What RegRoute can and cannot determine

RegRoute can organize the AI system, role, EU-use, customer and evidence facts that identify which AI Act questions need review. It preserves possible and insufficient-information outcomes instead of forcing a high-risk or provider classification from incomplete answers.

It does not certify an AI system, determine a definitive legal classification, or turn a zero-result assessment into proof that the AI Act does not apply. Specialist review may still be needed for the system's exact use and role.

Provider, deployer or something else: a role comparison

The Act defines each role by what a company actually does with a system, not by which side of a sale it sits on. "We built it" is not automatically the same as provider, and "our customer uses it" is not automatically the same as deployer.

RoleWhat it generally meansTypical technology-company scenarioWhat fact must still be established
ProviderDevelops an AI system or GPAI model, or has one developed, and places it on the market or puts it into service under its own name or trademarkA company ships an AI-enabled feature under its own brand, whether built in-house or on top of a third-party modelWhether the company places the system on the market or into service under its own name, not merely whether it built something
DeployerUses an AI system under its own authority, other than purely personal, non-professional useA company uses a third-party AI tool internally, or embeds it in an internal workflow without placing it on the market itselfWhether the company is using the system under its own authority, and whether it has in substance become the provider by materially modifying or rebranding it
ImporterAn EU-located person that places on the market a system bearing a third-country person's name or trademarkNot typically the non-EU company itself. Its EU distribution partner may hold this roleWhether an EU-based importer exists in the supply chain, and what that importer's own obligations are
DistributorA person in the supply chain, other than the provider or importer, that makes a system available on the EU marketAn EU reseller or marketplace listing the product. Again, not usually the non-EU company itselfWhether an EU-based distributor exists, and whether the company's own role changes if it substantially modifies the system
GPAI model providerDevelops a general-purpose AI model, or has one developed, and places it on the marketA company builds and offers its own foundation model, as distinct from building a product on top of someone else's modelWhether the company is providing the underlying general-purpose model itself, not just a downstream system that uses one

AI-enabled does not mean high-risk

High-risk status follows the Act's own classification mechanics, primarily Article 6 read together with Annex III. Even where an Annex III use case is listed, for example biometrics, employment, education, essential services, law enforcement, migration or justice, Article 6(3) treats the system as not high-risk if it only performs a narrow procedural task, improves the output of a completed human activity, detects patterns without replacing or influencing human assessment, or performs a preparatory task, provided it does not profile natural persons. A system that profiles people is treated as high-risk regardless of how narrow the task looks.

Following the Digital Omnibus amendment (Regulation (EU) 2026/1744) to the AI Act, the stand-alone high-risk obligations under Annex III now apply from 2 December 2027, and the rules for AI embedded in already-regulated products (Annex I) apply from 2 August 2028. "Our AI touches an Annex III area" is a fact to track toward those dates, not evidence of a duty that already binds a system today.

None of this means high-risk questions can be ignored. The label "AI-enabled" is a starting fact, and the actual classification, including any Article 6(3) exclusion and which compliance date applies, has to be worked through and documented, not assumed in either direction.

Using a general-purpose model is not the same as providing one

A general-purpose AI model displays significant generality, can perform a wide range of distinct tasks, and can be integrated into many different downstream systems. Its provider is the company that develops it, or has it developed, and places it on the market.

A company that builds a product on top of a third-party foundation model is not thereby the provider of that underlying GPAI model. It is integrating one, which is a different question from the GPAI-provider obligations that attach to whoever actually develops and places the model itself. Fine-tuning, prompting or wrapping a third-party model in a product does not by itself convert the integrator into the model's provider, though a company that develops its own model, or substantially changes one so that its own general-purpose capability is materially different, has a separate question to establish.

Article 4: AI literacy is broad, but not a universal catch-all

AI-literacy obligations under Article 4 have applied since 2 February 2025. Since the Digital Omnibus amendment (Regulation (EU) 2026/1744) took effect on 27 July 2026, Article 4 requires providers and deployers to take measures to support the development of AI literacy among staff and other people dealing with the operation and use of an AI system on their behalf, taking into account their technical knowledge, experience, education and training, the context the system is used in, and the people or groups of people it affects. This is an effort-based obligation: it does not require a provider or deployer to guarantee any specific level of AI literacy for any individual, and it is not limited to high-risk systems. It applies across the AI systems a provider or deployer actually operates.

Article 4 is tied to already being a provider or a deployer of a relevant AI system. It does not by itself establish that a company holds either role, and it is not a universal obligation on every company on earth that happens to use AI somewhere in its business. Establishing role and territorial scope comes first; Article 4 then follows for the systems within that scope.

Official EU sources

Every conclusion on this page traces back to the primary legal text. We link only to official EU sources.

RegulationsMethodologySee what the EU Readiness Pack includes

Mini-check: what AI Act questions should you review?

Two screening questions about your AI activity and EU nexus. Answers carry into the full assessment.

Which role is closest to your activity?

A role answer is a screening input, not a final legal classification.

Is the output of an AI system or model used in the Union?

This is distinct from where the company is headquartered.

Start the full assessment instead

General information, not legal advice. Applicability can depend on facts and national implementation. Verify material legal conclusions with qualified counsel.