A striking share of the AI Act questions that come my way are from organisations outside Ireland, and a good number from outside the EU altogether. That surprises the people asking far more than it surprises me, and the reason sits in a part of the AI Act that almost everyone skips on a first read.
Article 2 does not care where you are incorporated
The scope provision of Regulation (EU) 2024/1689 reaches providers who place an AI system on the Union market irrespective of whether they are established inside the Union or in a third country. It also reaches providers and deployers established outside the Union where the output produced by the system is used within it. That second limb is the one that catches people. You can have no European entity, no European office and no European staff, and still sit squarely inside the Regulation because your model output lands in front of a European user.
There is no threshold of European revenue below which this stops applying, and no requirement to establish here before it starts. A company on another continent selling to European customers carries the same obligations as one based in Dublin. The obligations do not scale down for distance.
Where the question usually comes from
The trigger is rarely a compliance team reading the Official Journal. It is a European customer sending a procurement questionnaire that nobody internally can answer, or a distributor asking who the authorised representative is and receiving silence in return. Occasionally it is an investor or an auditor asking what the exposure looks like.
Whatever the source, the question tends to surface late, and by the time it is asked it has often stopped being a compliance project and become a commercial problem with a deal attached to it. That is a harder position to work from than the same conversation held six months earlier, and the cost difference is real.
The deferral coverage has made this harder, not easier
Regulation (EU) 2026/1744, the Digital Omnibus, came into force on 27 July 2026 and moved two sets of dates. Standalone high-risk obligations under Annex III shifted to 2 December 2027. High-risk obligations for systems embedded in regulated products under Annex I shifted to 2 August 2028. Both changes were widely reported, and the reporting was almost uniformly framed as a reprieve.
The Omnibus did not touch the Article 5 prohibitions or the Article 50 transparency obligations. Those were already in application and remain so. Nothing about them was deferred.
This is where the gap is widest between what companies believe applies to them and what actually does. A team that reads the deferral headlines and concludes it has until late 2027 has not separated the high-risk classification regime from the obligations sitting outside it. If your system interacts with people, generates synthetic audio, image, video or text, or produces deepfakes, the Article 50 disclosure duties reach you now and were never in scope for deferral.
There is one narrow transition inside Article 50 and it is worth knowing precisely how narrow it is. Generative systems already placed on the market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking and detection obligation in Article 50(2). Anything placed on the market from 2 August onwards had no transition at all, and the chatbot and deepfake disclosure duties applied from that date regardless.
A narrower question gets a more useful answer
Companies tend to open with a broad question about whether they need to comply with the AI Act. It is difficult to answer usefully because it bundles together several regimes with different triggers and different dates, and the honest response is almost always that some parts apply and others do not.
The productive version is narrower. Which specific obligations attach to which of your systems, and on what date does each one start to bite? Answering that means classifying each system, identifying whether you are acting as provider or deployer or both, and separating the prohibitions and transparency duties that apply today from the high-risk obligations now falling in 2027 and 2028. It is unglamorous work, but it is what makes the procurement questionnaire answerable and the deal survivable.
There is a further step that non-EU providers routinely miss. Article 22 requires a provider established outside the Union to appoint an authorised representative established in a Member State, by written mandate, before a high-risk system is placed on the market. It is a structural appointment rather than a documentation exercise, and it is usually discovered after distribution has already begun, at which point it becomes remediation rather than setup.
What that looks like in practice
There are four worked scenarios on the site showing how these questions resolve: a credit scoring system under Annex III, employment screening under Annex III, a diagnostic system embedded in a regulated medical device under Annex I, and a customer-facing chatbot producing generated content under Article 50. No organisation is named in any of them and no outcomes, timelines or figures are claimed, because inventing those would be a poor advertisement for a compliance firm. They simply show the classification reasoning being worked through.
If you would rather start with your own systems, the free AI Act assessment takes about ten minutes and returns a view of which obligations apply and when. If the result raises more questions than it settles, a scoping call is the next step and costs nothing.
See the example scenarios Take the free assessment Book a scoping call
EU AI Act Article 2 Article 22 Article 50 Digital Omnibus
Micheal Morrissey, Managing Director, Morclear Europe. Morclear Europe delivers EU regulatory compliance as a managed service, combining CORA™ (Compliance Operations & Risk Automation) with professional review of every output.