AI output used in the EU
One circumstance in which the EU AI Act may apply to a provider or deployer outside the EU. It still depends on the system and the role. It is not, by itself, a conclusion that the Act applies.
Vietnam · Singapore · companies outside the EU
EU AI Act, GDPR, AI governance and contracts for Asian technology companies entering European markets. We help AI developers and software integrators identify regulatory requirements, clarify responsibilities and prepare the documentation needed for their European projects.
No office in Europe.
Companies outside the EU
It can.
The EU AI Act may apply when an AI system or its output is placed on the EU market or used in the EU, depending on the circumstances and the role of the company. Where the team sits is part of the question. It is not the whole question.
The same care applies to GDPR for Asian AI companies: it may apply when personal data is processed to offer goods or services to people in the EU, or to monitor their behaviour.
Vietnam
Teams in Vietnam ask this when a European customer uses the product, or when the output of the system is used in the EU. No office in Europe does not close the question. It still depends on the system, the output and the role.
Legal Stones is based in Europe and will be in Vietnam for the coming year, working in English with companies that already build or sell toward Europe. Scope and fee are confirmed before any work starts. Not a certification and not a conclusion on compliance.
Ask about a product in VietnamSingapore
Singapore companies ask the same question when a product or its output reaches the EU. Singapore AI governance frameworks and the PDPA are separate questions from the EU AI Act and from GDPR. A European customer still asks about the product, the data and the contract.
We look at the European question for the product you describe. We do not treat a Singapore framework as that answer.
The phrases companies type
These are the questions to separate before anyone talks about a certificate.
One circumstance in which the EU AI Act may apply to a provider or deployer outside the EU. It still depends on the system and the role. It is not, by itself, a conclusion that the Act applies.
GDPR may apply outside the EU when personal data is processed to offer goods or services to people in the EU, or to monitor their behaviour. It is a different question from the EU AI Act.
The role can change with the product and the contract. The title of the engagement does not decide it. The useful first step is to see which question is actually open.
No office, subsidiary or staff in the EU does not close the question. Companies in Vietnam, Singapore and elsewhere start here, then look at the system and the output.
European Client AI Readiness Pack
Legal Stones helps Asian software companies and AI integrators identify the regulatory questions, documentation gaps and contractual responsibilities to address in AI projects connected with European markets.
Each proposal is prepared for the project and the needs identified. Not a certification and not a conclusion on compliance.
In the form, describe the project and what your European client asked for. Do not attach their data or the contract in the first note. Hiring, health and credit are a different engagement. See also the AI legal assessment, partners, and the guide for companies outside the EU.
Partners
The European question sits in your project.
You keep the technology relationship. If your client is in Vietnam, Singapore or elsewhere in Asia, and a European customer is in the picture, we look at the EU AI Act, GDPR and the contract questions inside the project. You do not build that capability in-house.
One project starts with the European Client AI Readiness Pack. A partner collaboration is how that work continues.
Become a Legal Stones partnerWhere the work sits
In Vietnam for the coming year.
Legal Stones is based in Europe. For the coming year the work with companies in Asia happens from Vietnam, in English, remote when the team is elsewhere. The contact page reaches the same inbox.
FAQ
It can. The EU AI Act may apply to companies established outside the EU when their AI systems or outputs are placed on the EU market or used in the EU, depending on the circumstances and the role of the company. Legal Stones can help assess how the rules may apply to your specific situation.
It can. GDPR may apply to organisations outside the EU when they process personal data in connection with offering goods or services to individuals in the EU or monitoring their behaviour, depending on the circumstances. We can help identify the relevant data protection considerations for your AI activities.
Depending on the AI system and business model, relevant considerations may include the EU AI Act, GDPR, contracts, roles and responsibilities across the AI supply chain, risk management and governance. A first assessment can help identify the main legal questions before you scale.
Yes. Legal Stones provides European AI governance and legal expertise to companies developing, deploying or selling AI in connection with European markets. We can help identify the legal and governance questions that should be addressed as part of your expansion.
Yes. We work with AI integrators, technology consultancies and technology providers that need European AI governance and legal expertise for their projects. Our partner model allows technology teams to add the legal layer without building that capability in-house.
It can. The same question applies to a company in Vietnam as to any company outside the EU: it depends on the system, its output and the role of the company, including whether the AI is placed on the EU market or used in the EU. No office in Europe does not close the question. Legal Stones can help identify the questions worth asking first. This is not a certification and not a conclusion on compliance.
It can. Singapore companies ask this when a product or its output reaches the EU. Singapore AI governance frameworks and the PDPA are separate questions from the EU AI Act and from GDPR. Legal Stones looks at the European question for the product you describe. This is not a certification and not a conclusion on compliance.
It can. No office, subsidiary or staff in the EU does not close the question. Whether the EU AI Act may apply still depends on the circumstances and the role of the company, including whether a system or its output is placed on the EU market or used in the EU.
That is one of the circumstances in which the EU AI Act may apply to a provider or deployer outside the EU. It still depends on the system and the role. Legal Stones can help identify what to look at for that product. This is not a conclusion that the Act applies, and not a conclusion on compliance.
It is a fixed-scope first look at one AI project connected with a European client. It covers an initial assessment of that project and its intended use in Europe, potentially applicable EU AI Act and GDPR requirements, a review of up to five agreed documents and the contractual responsibilities, and a written report with prioritised findings and practical next steps. Target delivery is 5 to 7 working days after all required information is received. The proposal is prepared for that project. It is not a certification and not a conclusion on compliance.
Company, country, and whether the output is used in the EU. Not a certification and not a conclusion on compliance.
Discuss your European client project