The EU AI Act applies well beyond companies physically located in the EU, so a Turkish, US, or other non-EU company is in scope whenever it places an AI system on the EU market or the system's output is used within the EU, regardless of where the provider is headquartered. This extraterritorial reach mirrors how GDPR already operates and means a Turkish software vendor selling a hiring or credit-scoring tool to EU customers must meet the same risk classification and documentation duties as an EU-based provider. A company with no EU customers and no EU market presence generally falls outside the Act's scope, though it may still need to track the regulation if it plans to expand into Europe later. Turkey has its own draft artificial intelligence law under discussion and already regulates AI processing of personal data through KVKK, so a Turkish company can face both frameworks depending on where it operates. Determining exact applicability requires looking at where the system is deployed and who it affects, not just where the company is registered. This is general orientation rather than a legal opinion on any specific company's exposure. Nanobase AI advises non-EU clients on this cross-border scope question before they enter the EU market.
The scope test has nothing to do with headquarters
Companies outside the EU frequently assume their location settles the question of whether the AI Act applies to them. It does not. Article 2 defines scope by market effect, not by corporate domicile: the Act applies to any provider placing an AI system on the EU market, to any deployer of an AI system located within the EU, and, critically, to providers and deployers outside the EU whose AI system's output is used within the EU. A Turkish, American, or Indian company never opening an EU office can still fall squarely inside the Act's scope the moment its AI system's decisions touch someone in the EU.
Running the practical scope test
| Scenario | In scope? |
|---|---|
| Turkish SaaS company sells a hiring-screening tool to a German client | Yes, provider in scope |
| US company's AI-powered support agent serves EU customers of an EU business | Yes, output used in EU |
| Company builds AI purely for its own domestic, non-EU market with no EU customers | No, unless output otherwise reaches the EU |
| Non-EU company's AI system output is used by an EU-based team, even without a direct EU sale | Yes, output used in EU |
| Non-EU research use with no deployment or market placement | Generally no |
This mirrors how GDPR already reaches non-EU companies processing EU residents' data, and companies that already went through a GDPR extraterritoriality assessment will recognize the same underlying logic here. The determining question is always where the system's output lands, not where the company that built it is registered.
Why this matters more for Turkish companies specifically
Turkey sits in a particular position: it is not an EU member state, so the AI Act does not apply domestically by default, but Turkish companies selling software into the EU market, including AI-powered HR, credit scoring, or insurance tools, are directly affected by the extraterritorial provisions. This is a live compliance question for the country's growing SaaS and fintech export sector, distinct from Turkey's own domestic AI regulation discussions, which remain separate from the EU framework. A Turkish company navigating this dual exposure typically has to satisfy both the EU AI Act for its EU-facing product and KVKK, Turkey's own data protection law, for any personal data of Turkish or EU individuals it processes domestically. A Turkish AI vendor selling into the EU should treat AI Act exposure as a real export compliance question, not a distant EU-only concern.
Steps for a non-EU company that discovers it is in scope
- Confirm which specific product lines or features actually reach the EU market or affect EU-based individuals, rather than assuming the whole company is in scope.
- Appoint an EU-based authorized representative if the company has no EU establishment, a requirement for certain high-risk system providers.
- Apply the same risk classification and documentation process an EU-based provider would follow for the in-scope product.
- Track the phase-in schedule the same way an EU company would, since the compliance dates do not shift based on where the provider is located.
Being outside the EU changes nothing about the substantive obligations once a system is in scope; it only changes the practical mechanics of how the company demonstrates compliance, such as through a representative.
This is general information, not legal advice, and a company's specific market-reach exposure should be confirmed against its actual customer base and product distribution.
Frequently asked questions
Does the AI Act apply if we only sell to EU customers through a reseller?
Very likely yes. Market placement through an intermediary generally does not remove a provider from scope; regulators look at where the system ultimately reaches the market and is used, not the contractual path it took to get there.
Do we need an EU legal entity to comply?
Not necessarily an entity, but certain non-EU providers of high-risk systems must appoint an authorized representative established in the EU who can act as the compliance contact point, which is a lighter requirement than establishing a subsidiary.
Is a free trial or pilot with an EU customer enough to trigger scope?
Placing a system on the market generally includes making it available for use, which can include a paid or unpaid pilot. Treating a pilot as out of scope because no revenue changed hands is a common and risky assumption.
How does this interact with data residency requirements?
They are separate questions. AI Act scope concerns the AI system's classification and obligations, while data residency concerns where personal data physically sits, covered under GDPR and, for Turkish companies, KVKK's own cross-border transfer rules.
How Nanobase AI helps
Nanobase AI, headquartered in Silicon Valley with a corporate office in Delaware, works with companies on both sides of the Atlantic and helps non-EU teams determine their actual EU AI Act exposure before it becomes a customer-side compliance blocker. This sits alongside our AI security and compliance practice and the broader guidance in our EU AI Act, GDPR, and KVKK compliance checklist.
Ready to discuss your project? Contact Nanobase AI or email hello@bumu.tech.