
Often, yes. The EU AI Act applies extraterritorially: if you place an AI system on the EU market, or your system's output is used in the EU, you are in scope even with no EU entity. Penalties for prohibited practices reach €35 million or 7% of global turnover, so a scope analysis is worth an afternoon.
What is the scope test?
Article 2 of the EU AI Act sets two triggers, and either one is enough. The first is placing an AI system on the EU market: selling it, licensing it, or otherwise making it available to EU customers. The second is the output limb: the Act also applies where an AI system's output is used in the EU, even if the system runs in Singapore or Sydney and was never sold into Europe.
Where your company is incorporated does not appear in the test. That is the design, not an oversight. The Act follows the system and its effects, much as the GDPR follows personal data.
The output limb is the one that surprises people. A scoring engine hosted in Singapore whose results are used by a customer's Frankfurt office is producing output used in the EU. No EU contract, no EU subsidiary, still potentially in scope.
Run both limbs against each product, and be honest about the second. Selling into the EU is easy to spot in a CRM. Output drifting into the EU through a multinational customer is not, and that is the limb that catches companies who never thought of themselves as exporting anything.
Are you a provider, deployer or importer?
Your role under the Act determines what you owe, so classify the role before worrying about obligations. The same company can hold different roles for different systems, and often does.
| Role | Who it is | What it carries |
|---|---|---|
| Provider | Develops an AI system (or has one developed) and places it on the EU market under its own name | The heaviest load: the design-side obligations, documentation and, for high-risk systems, conformity requirements |
| Deployer | Uses an AI system under its own authority in the course of business | The use-side obligations: operating the system as intended, with the oversight the Act requires |
| Importer | Places a third-country provider's system on the EU market | Verifying the provider has met its obligations before the system is sold |
A Singapore SaaS company selling an AI feature to EU customers is typically a provider. An Australian firm rolling out a US vendor's tool across offices that include Dublin is a deployer. Get the role wrong and you prepare for the wrong obligations entirely.
Roles also shift as products do. Rebrand a third-party model and sell it under your own name or trademark ("trade mark", in Australian drafting) and you have stepped from deployer territory into provider territory, heavier obligations included. Revisit the classification whenever the packaging changes, and treat the answer as versioned rather than settled.
What must a Singapore or Australian company actually do?
Risk-tier your systems. The Act's obligations scale with risk category, and most systems operated by Singapore and Australian companies land in the minimal or limited tiers, where the compliance load is light.
The exercise itself: inventory every AI system that touches the EU under either scope limb, assign each a risk tier, and record the reasoning. Minimal risk means little to do. Limited risk brings transparency-style duties. The point of the afternoon is finding the outliers, the one or two systems that might sit in the high-risk category, because those carry the regime worth planning around.
Timing matters as much as tiering. The Act phases in over several years, and our companion piece AI·08 tracks each deadline wave, so pair the scope answer with the date each obligation actually lands for you. A system out of scope today can also drift in later, when a customer changes how they use its output.
Neither home regime substitutes. Singapore's AI governance framework and Australia's Voluntary AI Safety Standard are both voluntary, and the AI Act does not recognise either as a compliance route. What they do provide is scaffolding: an AI inventory built for one maps onto the other with modest effort.
Then write the answer down. A documented scope analysis, even one that concludes "not in scope", is the artefact an EU customer's procurement team will actually ask to see.
What are the penalties?
Breaches of the prohibited-practices rules carry the top tier: up to €35 million or 7% of global turnover. Global turnover, not EU turnover. A fine calculated on worldwide revenue is the Act's way of making incorporation outside the EU irrelevant twice over. Other breaches carry lower ceilings. Most other obligation breaches run up to €15 million or 3% of total worldwide annual turnover, whichever is higher. Supplying incorrect, incomplete or misleading information to notified bodies or authorities tops out at €7.5 million or 1%. For SMEs and startups, each fine is capped at the lower of the fixed sum or the percentage rather than the higher.
Enforcement against a company with no EU presence is harder in practice, but harder is not impossible, and most companies genuinely in scope have something reachable: EU customers, EU revenue, or an importer whose own obligations point straight back at the provider.
The practical pressure arrives commercially before it arrives from any regulator. EU customers push the Act's requirements into contracts, and a vendor who cannot answer scope questions loses the deal long before a file gets opened.
Zavior keeps your AI system inventory with an EU-scope flag and a risk tier against each entry, so the scope analysis stays current instead of living in a slide from last year.
Frequently asked questions
Does serving EU visitors on a website trigger the Act?
Mere reachability from the EU does not place a system on the EU market; the question is whether you offer the system to EU users or its output is used there. A chatbot handling EU customer queries sits closer to scope than a marketing page that happens to load in Berlin. Edge cases deserve legal advice, not a guess.
Do APIs count as market placement?
Delivering an AI system by API rather than as installed software does not change the analysis. If EU customers can buy access, you are making the system available on the EU market. The delivery mechanism is irrelevant; availability is what counts.
Is there a Singapore or Australian adequacy shortcut?
No. The AI Act has no adequacy mechanism equivalent to the GDPR's data-transfer decisions. Scope turns on market placement and output use, and no home-country framework, Singapore's or Australia's, substitutes for compliance.
Zavior · AI Governance
Whether you run out of Singapore or Australia, a European law can reach your systems, and the answer to "are we in scope" only holds up if the controls behind it are real. Zavior maps the AI your staff actually use and puts governance around it, so when an EU customer, a regulator, or your board asks how AI is controlled here, you can show them rather than guess.
Book a free 30-minute business assessment →This is general information, not legal advice.