[nonimo]
EN
Download

Does the EU AI Act apply to you if you are outside the EU?

· Updated · Written and maintained by Joaquín Trapero, Nonimo

Often yes, because what triggers it is where the output is used, not where your office is. Article 2(1)(c) of the AI Act reaches providers and deployers established or located in a third country when the output produced by the AI system is used in the Union, which is a sentence written to catch exactly the organisation reading this one.

The second half of the answer is the one nobody sells you, because there is no product in it. If you are a deployer of ordinary AI tools rather than a provider of AI systems, what you owe under this Regulation is short, and most of it is paperwork you can write yourself. This guide separates the two, with the article numbers, and with the timetable as it stands after the Digital Omnibus moved it in July 2026.

It is written for the UK, the United States and Australia, where the question arrives as “does this even apply to us”. If your organisation is established in the Union the answer is simply yes, and you can skip the first section. Either way, the duty that costs small firms money in practice is not in this Regulation, and the cheapest thing you can do about any of it is write down your rules.

Does the EU AI Act apply to you if you are outside the EU?

Three of the seven categories in Article 2(1) can catch an organisation with no European establishment at all. They are worth reading in the Regulation’s own order, because the third one is the one that surprises people.

Route inArticleWhat triggers it
You put an AI system on the EU market2(1)(a)Placing or putting into service in the Union, wherever you are established
You use AI and you are in the EU2(1)(b)Your place of establishment is in the Union
You are outside the EU and your output is used there2(1)(c)The output produced by the AI system is used in the Union

The third row is the extraterritorial hook, and it does not require you to sell anything to a European. It requires the output of your AI system to be used in the Union. A recruitment screening tool run in Sydney on candidates in Dublin produces output used in the Union. So does a report drafted with AI that a London consultancy delivers to a client in Milan who acts on it.

What it does not catch

Article 2 also fences the Regulation off in ways that matter to a small organisation. Paragraph 6 excludes AI systems developed and put into service for the sole purpose of scientific research and development. Paragraph 8 excludes research, testing and development activity before a system is placed on the market, though testing in real-world conditions stays inside.

Paragraph 10 is the one to know by heart: the Regulation does not apply to the obligations of deployers who are natural persons using AI systems in the course of a purely personal non-professional activity. Read it the right way round. Your own use at home is out. The same person doing the same thing for a client is in.

Nothing here depends on Brexit, or on your state

A recurring confusion in the UK and the United States is that leaving a bloc, or living in a state with no AI statute, settles the question. It does not, because Article 2(1)(c) attaches to the output rather than to your legal home.

The domestic picture still matters, and it changes what else you owe, which is why the UK, the United States and Australia get a section of their own further down. It just never switches the EU regulation off, and neither does a change of government at home. What each country adds at home is covered in our guides on AI and client data.

Provider or deployer: the word that decides everything else

Almost every disagreement about the AI Act that we have watched go round in circles was really a disagreement about this definition. The Regulation splits the world into roles, and the duties attach to the role, not to the company.

Article 3(3) defines a provider as whoever develops an AI system, or has one developed, and places it on the market or puts it into service under their own name or trademark, whether for payment or free of charge. Article 3(4) defines a deployer as anyone using an AI system under their authority, except in a purely personal non-professional activity.

Under your own name
The phrase in Article 3(3) that turns a deployer into a provider. Rebrand a system you bought as your own and you inherit the provider's duties. Regulation (EU) 2024/1689.

For most readers of this page the answer is settled in one line: if your team logs into somebody else’s AI tool and does work with it, you are a deployer. OpenAI, Microsoft, Anthropic and Google are the providers. The duties that dominate the coverage you have been reading, conformity assessment, technical documentation, quality management systems, sit on them.

The two ways an ordinary business becomes a provider by accident

The first is rebranding. Put your own name or trademark on a system you bought and Article 3(3) treats you as its provider. Wrapping a model in your own product and selling it is the clearest case, and it is exactly what a lot of small software firms did in 2025 without reading this far.

The second is substantial modification of a high-risk system, which is dealt with in Article 25 rather than Article 3. If none of that is you, the rest of this guide is the deployer’s half of the Regulation, and it is much shorter than the provider’s. Our guide to using AI at work without leaking client data covers the duty that actually bites daily, which is not this one.

Does it apply if all you do is use ChatGPT or Copilot at work?

Yes, formally, and then almost nothing follows. That answer, in two parts, is the single most useful thing on this page, and it is why so much AI Act content aimed at small firms reads as though everyone has a compliance department waiting.

4articles a deployer of ordinary AI tools has to read
0registrations or filings to make
0mandatory audits
Articles 4, 5, 50(4) and 26 of Regulation (EU) 2024/1689. The Regulation imposes no registration or conformity assessment on the deployer of a general-purpose AI tool.

You are a deployer under Article 3(4) the moment your staff use a tool under your authority for work. Being a deployer is not itself an offence or a burden. It is a label that determines which articles you then read, and for a general-purpose chatbot used for drafting, summarising and research, the list is genuinely this short.

  1. Article 4, AI literacy. In force since 2 February 2025, and it applies to deployers regardless of size or sector.
  2. Article 5, the prohibitions. They bind everyone, though a normal office is unlikely to be near them.
  3. Article 50(4), deployer transparency. Only if you generate deepfakes, or publish text generated by AI to inform the public on matters of public interest.
  4. Article 26, deployer duties for high-risk systems. Only if the system is high risk, which a general chatbot is not.

What matters is what is missing from that list. There is no registration, no filing, no notification to an authority, no conformity assessment and no mandatory audit for the deployer of an ordinary AI tool. If a vendor tells you the AI Act requires you to buy their product, ask which article they mean, and then read it. The free policy template covers more of that list than any software does.

The timeline, date by date, after the Digital Omnibus

The AI Act entered into force on 1 August 2024 and applies in stages. Article 113 sets the base dates, and Regulation (EU) 2026/1744, the Digital Omnibus on AI, rewrote several of them on 8 July 2026. It was published in the Official Journal on 24 July 2026 and entered into force on the third day after that.

Put this table somewhere you will see it again rather than committing it to memory, because it has already moved twice and the Commission itself maintains a version.

DateWhat appliesSource
2 February 2025Definitions, AI literacy (Art. 4), prohibitions (Art. 5)Art. 113(a)
2 August 2025General-purpose AI rules, penalties chapter, national authorities designatedArt. 113(b)
2 August 2026General application, transparency (Art. 50), enforcement beginsArt. 113
2 December 2026Two new prohibitions; Art. 50(2) transition endsOmnibus, Art. 1(40)(a) and 1(39)(b)
2 December 2027High risk under Annex IIIOmnibus, Art. 1(40)(b)(i)
2 August 2028High risk under Annex IOmnibus, Art. 1(40)(b)(ii)
2 August 2030High-risk systems used by public authoritiesOmnibus, Art. 1(39)(a)

What 2 August 2026 actually changed

Less than the headlines suggested, and the distinction is worth carrying. The prohibitions in Article 5 and the literacy duty in Article 4 had already been law since 2 February 2025. What arrived in August 2026 was the Regulation’s general application, the transparency rules of Article 50, and the enforcement machinery.

The Commission’s own timeline puts it plainly: from that date, enforcement starts at national and EU level concerning general-purpose AI models, prohibitions, transparency rules and AI literacy. So the duty did not appear in August. The authority able to act on it did.

What the Omnibus moved, and what it left alone

It moved the high-risk rules, in full, for providers and deployers alike. Annex III systems, the recruitment, credit and essential services category, went to 2 December 2027. Annex I systems, the ones embedded in regulated products, went to 2 August 2028. Public authorities deploying high-risk systems already on the market get until 2 August 2030 under the amended Article 111(2).

It did not move the prohibitions, the transparency rules, the literacy duty or the general-purpose AI chapter. A page telling you the AI Act has been postponed is describing one third of it. Our guides on AI and client data follow the pieces that change most often.

What already binds you: the prohibited practices of Article 5

Article 5 is the short list of things nobody may place on the market, put into service or use at all. It has applied since 2 February 2025, it carries the heaviest penalties in the Regulation, and the Commission published guidelines on it on 4 February 2025.

Most of the list describes systems an ordinary business would never build: subliminal manipulation causing significant harm, exploitation of vulnerability, social scoring by public or private actors, predicting criminal offending from personality traits, untargeted scraping of facial images to build recognition databases, emotion inference in the workplace and in education, and biometric categorisation by protected characteristics.

2 Feb 2025the prohibitions became law
2 Aug 2026national authorities began enforcing them
2 Dec 2026two further prohibitions start
Regulation (EU) 2024/1689, Art. 113, as amended by Regulation (EU) 2026/1744, Art. 1(40)(a)

The one that catches real employers is emotion recognition in the workplace, because the category is broader than the sales material for these tools suggests. If anything in your stack claims to read sentiment, stress or engagement from a camera, a microphone or a keyboard, that is the article to check before the next renewal.

Two details make that check worth doing properly. The prohibition covers inferring emotions in the areas of the workplace and education, with a narrow exception for medical or safety reasons, and it does not care whether the inference is accurate. It also does not care whether anybody consented, because Article 5 is a flat prohibition rather than a balancing test. Naming the tool in your acceptable use rule is the cheapest way to find out you have one.

The two new prohibitions that start on 2 December 2026

The Digital Omnibus added them, and they have had almost no coverage. New points (ba) and (bb) of Article 5(1) prohibit AI systems that generate or manipulate realistic intimate imagery of an identifiable person without their freely given, specific, informed, unambiguous and explicit consent, and systems generating child sexual abuse material.

The new Article 5(1a) narrows both. For placing on the market, the prohibition bites only where that generation is the system’s intended purpose, or where the design makes it a reasonably foreseeable and reproducible outcome without significant technical modification and without adequate safeguards. For use, it bites only where the deployer uses the system for that purpose.

AI literacy: Article 4, and what the July 2026 rewrite took out

This is the one obligation on this page that applies to every deployer, of every size, from a business of one upward, and it has applied since 2 February 2025. It is also the one most often described in terms that would frighten anyone into buying a training platform.

The Digital Omnibus replaced Article 4 outright. Providers and deployers must take measures to support the development of AI literacy among their staff and others operating AI systems on their behalf, taking into account technical knowledge, experience, education and training, the context of use, and the people the systems are used on.

Not a guarantee
Article 4(1), as replaced in July 2026: the duty "does not require providers or deployers to guarantee any specific level of AI literacy of any individual". Reg. (EU) 2026/1744, Art. 1(5).

That sentence is new, and it settles an argument. The duty is to take proportionate measures, not to certify anybody. The rewritten Article also tells the Commission to publish practical examples of compliance on the single information platform, which means the cheapest way to satisfy Article 4 will shortly be free and official.

Until it lands, a short internal session on what your tools do with text, who may use them for what, and which categories of information never go in, recorded with a date and an attendance list, is a defensible answer. That is one afternoon, and the policy template supplies most of the content.

Article 50: labelling AI content, chatbots and deepfakes

Article 50 started to apply on 2 August 2026, and it is where the deployer obligations that could plausibly touch a normal business live. It splits along the provider and deployer line, and reading it in that order removes most of the anxiety.

Paragraphs 1 and 2 are provider duties. Systems that interact directly with people must be built so that people are informed they are dealing with an AI system, unless that is obvious to a reasonably well-informed observer. Systems generating synthetic audio, image, video or text must mark their outputs in a machine-readable format. Your vendor owes that, not you.

Paragraphs 3 and 4 are yours. Deployers of emotion recognition or biometric categorisation systems must inform the people exposed to them. Deployers who generate or manipulate image, audio or video content constituting a deepfake must disclose it.

Blog posts written with AI, answered properly

The second limb of Article 50(4) is where a widely repeated myth starts. It requires deployers of an AI system that generates or manipulates text to disclose that, but only for text published with the purpose of informing the public on matters of public interest. A proposal, an internal memo, a client email and a product page are not that.

Then the same paragraph carves out even the text it does cover, where the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility for the publication. Between the narrow trigger and that exception, very little ordinary marketing copy is caught. Anyone telling you the AI Act requires a label on everything written with help from AI has not read to the end of the sentence.

Where you do owe a disclosure, Article 50(5) says how: clearly and distinguishably, at the latest at the time of the first interaction or exposure, and meeting the applicable accessibility requirements. There is no prescribed wording and no badge to license. A line at the top of the page, written by hand, satisfies it:

This article includes text generated with an AI system
and reviewed before publication by a named editor.
Published 20 September 2026 · Editorial responsibility: A. Editor

One transitional date belongs here. Under the new Article 111(4), providers whose synthetic content systems were already on the market before 2 August 2026 have until 2 December 2026 to comply with Article 50(2). That is a grace period for them, not for you, and it does not change what you publish. The same instinct applies to everything else you put in front of a client.

High risk: what it is, who it catches, and why the date moved

High risk is a classification, not an insult, and Article 6 creates it two ways. Annex I covers AI that is a safety component of a product already regulated under EU product legislation. Annex III lists the standalone uses, and that is the list a services business should read.

Annex III covers eight areas, and four of them reach organisations that have nothing to do with technology. Employment and worker management is the first, and it names recruitment and selection specifically, including targeted job advertisements, filtering applications and evaluating candidates, as well as systems that allocate tasks or monitor performance. Access to essential private services is the second, and it names evaluating creditworthiness and establishing a credit score.

The other two are narrower but worth checking. Education and vocational training covers admissions, marking, assessing the level of education somebody can access, and proctoring during tests. Access to essential public services covers eligibility for public assistance benefits, including healthcare, and the decisions to grant, reduce, revoke or reclaim them. Biometrics and critical infrastructure make up most of the rest.

8areas listed in Annex III
4that reach ordinary organisations
2 Dec 2027when Annex III obligations apply
Annex III to Regulation (EU) 2024/1689; date as amended by Regulation (EU) 2026/1744, Art. 1(40)(b)(i)

Buying a recruitment tool that ranks candidates makes you the deployer of a high-risk system. That is not a reason to panic in 2026, because Annex III obligations now apply from 2 December 2027, but it is a reason to put the question into your procurement now rather than inherit an answer later. Our read of seven insurer questionnaires found the same question arriving from a different direction.

What a deployer of a high-risk system actually has to do

Article 26 is readable in ten minutes, and the duties are operational rather than legal. Use the system according to the instructions for use. Assign human oversight to named people who have the competence, training and authority to exercise it, and the support to do so. Where you control the input data, make sure it is relevant and sufficiently representative for the intended purpose.

Then monitor, and keep the logs the system generates automatically, for a period appropriate to its purpose. If you have reason to think that use in line with the instructions presents a risk, inform the provider or distributor and the market surveillance authority, and suspend use. A serious incident goes to the provider first, and then to the importer or distributor and the authorities.

Public bodies carry one more document. Article 27 requires a fundamental rights impact assessment before putting certain high-risk systems into use, and the Digital Omnibus made it lighter rather than heavier: the amended Article 27(4) lets a deployer refer to the relevant sections of a data protection impact assessment it has already done, or fold parts of it in. The AI Office is to publish a template questionnaire for it. That thread continues in our guide for councils.

Penalties: the three bands, and who actually enforces them

Article 99 leaves penalties to the Member States but sets ceilings, and the ceilings are expressed in euros in the Regulation itself, so there is no exchange rate to apply. There are three bands, and the higher of the cash figure or the percentage applies.

A prohibited practice under Article 5 carries up to 35 million euros or 7 per cent of total worldwide annual turnover for the preceding financial year. Most other operator duties, the ones a deployer could realistically breach, carry up to 15 million or 3 per cent. Supplying incorrect, incomplete or misleading information to a notified body or a national authority carries up to 7.5 million or 1 per cent.

Prohibited practices, Art. 5€35m / 7%
Most operator duties, incl. Art. 50€15m / 3%
Misleading information to authorities€7.5m / 1%
Regulation (EU) 2024/1689, Art. 99(3), (4) and (5). Percentages are of total worldwide annual turnover for the preceding financial year.

The middle band is the one to note, because Article 99(4)(e) names deployer obligations under Article 26 and Article 99(4)(g) names the transparency obligations of Article 50 for providers and deployers alike. Those are the two places where a deployer can be fined in its own right rather than as a bystander to a provider’s failure.

Small organisations get a deliberate break. Article 99(6) provides that for SMEs, including start-ups, each fine is capped at whichever of the percentage or the amount is lower, reversing the usual rule. The Digital Omnibus extended the same treatment to small mid-cap enterprises, and rewrote Article 99(1) to require Member States to take the economic viability of those firms into account.

Enforcement is national. Member States were required to designate competent authorities and adopt their penalty rules by 2 August 2025, and enforcement of the prohibitions, the transparency rules and AI literacy began on 2 August 2026.

So the authority that would come to you is the one in the Member State where your output lands, not a single European regulator, and for an organisation selling into several countries that is a real question rather than a formality. Before assuming which one, check the Commission’s own AI Act Service Desk rather than a vendor’s map, and read its answer next to what your insurer is already asking.

The UK, the United States and Australia: where the answer changes

Three points only, because the EU analysis above does not change by country and repeating it in three accents would waste your time. What changes is what else you owe at home, and how fast that is moving.

JurisdictionHorizontal AI statuteWhat to watch
United KingdomNoneA statutory ICO code on AI and automated decision-making
United StatesNo federal statuteState law, rewritten twice in Colorado alone
AustraliaNoneVoluntary guidance, consolidated in October 2025

The United Kingdom has no AI Act, and a code is coming anyway

The UK’s stated approach, set out in the 2023 white paper A pro-innovation approach to AI regulation, is to apply existing law through existing regulators rather than legislate horizontally. That has not changed, and it is the deliberate opposite of the EU model. That leaves UK GDPR doing the work wherever personal data is involved, and what it asks before an assistant sees a client file is answered product by product.

What has changed is quieter and more concrete. The Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026, made on 16 April 2026 and in force since 12 May 2026, require the Information Commissioner to prepare a statutory code of practice on the processing of personal data for developing and using AI and for automated decision-making, including children’s data.

12 May 2026
The date SI 2026/425 came into force, obliging the ICO to prepare a code of practice on AI and automated decision-making. legislation.gov.uk.

A statutory code is not an AI Act, and it is narrower: it runs on data protection powers and reaches AI only through personal data. For a UK firm that is still the more likely source of a knock on the door than anything in Brussels, and it is the frame the ICO’s existing AI guidance already works in.

The United States has no federal answer, and the state answer keeps changing

There is no general federal AI statute, so the question is which state, and any list of state laws written today will be wrong within a year. Colorado is the clearest illustration rather than the exception.

Colorado passed the first broad state AI act in 2024, delayed it, then repealed and replaced it: Senate Bill 26-189 was signed on 14 May 2026, replacing the earlier framework with a narrower one on automated decision-making technology and setting a new effective date of 1 January 2027. Two changes of direction in two years, for the same subject, in the same state.

The practical consequence for a US business is that the EU deadlines are currently the more stable planning horizon, which is an odd thing to write and is nonetheless true. Whatever your state does, Article 2(1)(c) keeps applying to output used in Europe, and none of it touches the everyday disclosure problem that sits under all of it.

Australia decided not to legislate, and published guidance instead

Australia has no AI Act. The Voluntary AI Safety Standard, published by the National AI Centre on 5 September 2024 and updated on 2 December 2025, sets out ten voluntary guardrails across the AI supply chain. On 21 October 2025 the Centre published the Guidance for AI Adoption, which consolidates those ten into six essential practices, with implementation guidance issued on 5 May 2026.

All of it is voluntary. The binding obligations for an Australian organisation sit in the Privacy Act and in sector rules, not in law specific to AI, and the six practices are best read as a checklist an insurer or an enterprise client may one day hand you. Read alongside the policy template, they cover much the same ground as Article 4 does in Europe.

The paperwork worth having, cheapest first

Everything in this section is free, and between them these four documents answer most of what a regulator, an insurer or an enterprise client will ask. None of them requires software.

  1. An inventory of the AI tools actually in use. Not the ones you approved. The ones people log into. One line per tool is enough to start, and it is the document every other one depends on.
  2. A written acceptable use rule. Who may use what, for which work, and which categories of information never go in. Ours is a free template with fifteen numbered clauses, with no email required.
  3. A training record. A date, an attendance list and a summary on a single page of what was covered. This is the evidence for Article 4, and it is the one people skip.
  4. A note of who is accountable. One named person, with the authority to turn something off. Article 26(2) requires this for high-risk systems and it is good practice everywhere else.

An inventory row does not need a tool to produce. It needs four facts, and the discipline to keep them current:

Tool          Microsoft 365 Copilot
Used by       Client services, 14 people
Used for      Drafting, meeting summaries
Role          Deployer (Art. 3(4)); not high risk
Reviewed      2026-09-20

Keep it where the next person will find it. The single most common failure we see is not an absent document but an orphaned one, written once by somebody who has since left, describing tools the firm no longer uses. Our notes for IT providers treat this as a recurring review rather than a project.

What the AI Act does not fix: the file an employee pastes

Here is the gap the Regulation was never designed to close. It governs AI systems and the people who build and deploy them. It says almost nothing about the oldest problem in the room, which is a member of staff putting a client’s document into a chatbot to get a first draft out faster.

That was a data protection question before the AI Act, it stayed one on 2 August 2026, and the moment of risk is a browser tab and a keyboard shortcut. No article number in this Regulation reaches it.

The AI Act and the GDPR are two different laws, and they stack

They are often discussed as one compliance project and they are not. The AI Act regulates AI systems: who may build them, who may deploy them, and with what documentation. Data protection law regulates the processing of personal data, whoever does it and with whatever technology.

Article 2(7) of the AI Act says so directly. Union law on the protection of personal data, privacy and the confidentiality of communications applies to personal data processed in connection with the rights and obligations in the Regulation, and the Regulation does not affect the GDPR. The Digital Omnibus rewrote that paragraph in July 2026 and kept the principle intact.

The practical test is short. If your question is about what a system may do, you are in the AI Act. If your question is about whose information went where, you are in data protection law, and the answer does not change because the tool was clever. Most of what a small firm gets wrong sits on the second side, which is the subject of our guide on whether client data in ChatGPT is a breach.

  1. Is the question about what an AI system may do?

    YesYou are in the AI Act.

    NoAsk the next question.

  2. Is it about whose information went where?

    YesYou are in data protection law, whatever the tool.

The same paste can raise both, because the two laws stack.

The practical test above, read with Article 2(7) of Regulation (EU) 2024/1689

Why a policy on its own does not close it

A written policy helps and does not stop it, because the policy is read during onboarding and the paste happens eight months later under deadline. What changes the outcome is something acting at that moment, on the machine, before the text leaves.

That is the problem Nonimo works on. The Mac and Windows apps mask client names, identifiers and case numbers in text you hand them, on your own computer rather than on someone else’s server.

It is worth being exact about what that is. The mapping is reversible and kept encrypted on your machine, which makes it pseudonymisation, and pseudonymised data is still personal data for whoever holds the key. Before anyone calls a cleaned file anonymous, it pays to know where masking ends and anonymisation begins, because only anonymisation takes a file outside data protection law.

What the app keeps on your disk is set out on Nonimo’s security page.

If you buy nothing at all, do these five things

  1. Work out your role. Provider or deployer, per Article 3(3) and 3(4). Almost everything else follows from that one answer, and most readers are deployers.
  2. Check Annex III against your stack. Recruitment screening and credit decisions are the two that catch ordinary businesses, and the deadline is now 2 December 2027.
  3. Do Article 4 this quarter. One session, dated, with an attendance list. It has been law since February 2025 and it costs an afternoon.
  4. Write the inventory. Four facts per tool. It is the document that makes the other three possible.
  5. Separate the two questions. AI Act for what the system may do, data protection law for whose information went where. Merging them is how firms answer the wrong one well.

None of that requires a purchase, and a vendor who cannot tell you which article their product addresses is not selling you compliance. If you want the shortest possible version of this page, it is that the AI Act probably does reach you, that being reached is mostly uneventful if you are a deployer, and that the thing most likely to cost you money is not in this Regulation at all.

Two things you will read elsewhere that are wrong today

A third one is quieter and costs more, because it sounds like caution rather than error: that a tool can make you compliant. No product is named anywhere in the Regulation, compliance attaches to the organisation, and the two obligations most likely to apply to you, Article 4 and an honest inventory, are documents rather than software. One of those two you can start from a template.

Sources

Checked 20 September 2026. The AI Act’s own text is the primary source throughout; where the Digital Omnibus changed it, both are cited.


This page is for information and is not legal advice. For your own organisation, ask your regulator or a qualified adviser.

Nonimo is the software that does this on your own computer: it masks client names and IDs before your text reaches ChatGPT . No account, and your client's details never leave your machine.

Common questions

Does the EU AI Act apply to companies outside the EU?

It can. Article 2(1)(c) catches providers and deployers established in a third country where the output produced by the AI system is used in the Union. Selling a service that uses AI to a customer in Europe is the common route in.

Does the EU AI Act apply to the UK?

Not as UK law. The UK has no AI Act and leaves AI to existing regulators. A UK organisation meets the EU regulation only through Article 2, most often because the output of its AI system is used in the Union.

Am I a provider or a deployer if I use ChatGPT at work?

A deployer. Article 3(4) defines a deployer as anyone using an AI system under their own authority, outside a purely personal non-professional activity. You become a provider only by putting a system on the market under your own name or trademark.

What actually changed on 2 August 2026?

Enforcement, mostly. The transparency rules in Article 50 started to apply and national authorities began enforcing the prohibitions, the transparency rules and AI literacy. Those prohibitions and the literacy duty had been law since 2 February 2025.

Did the Digital Omnibus delay the EU AI Act?

It delayed the high-risk rules. Regulation (EU) 2026/1744, in force since 27 July 2026, moved Annex III high-risk systems to 2 December 2027 and Annex I systems to 2 August 2028. The prohibitions and the transparency rules did not move.

Do I have to label content my team writes with AI?

Rarely, as a deployer. Article 50(4) covers deepfakes and text published to inform the public on matters of public interest, and even that carves out text reviewed by a human where someone holds editorial responsibility for it.

What are the fines under the EU AI Act?

Three bands, set in euros by Article 99: up to 35 million or 7 per cent of worldwide annual turnover for a prohibited practice, up to 15 million or 3 per cent for most other operator duties, and up to 7.5 million or 1 per cent for misleading information.

Does the AI Act replace the GDPR?

No. Article 2(7) says the Regulation does not affect the GDPR, and the Digital Omnibus kept that wording. A client file typed into a chatbot is a data protection question first, and the AI Act does not answer it for you.

Is AI literacy really a legal obligation?

Yes, for providers and deployers, since 2 February 2025. The version rewritten in July 2026 adds that the duty does not require anyone to guarantee a specific level of AI literacy in any individual. It asks for measures, not exam results.

Do I need to buy something to comply with the AI Act?

No. The Regulation names no product, and most of what an ordinary deployer owes is organisational: knowing which tools are in use, training the people who use them, and keeping a record. Software is one control among several.