A product team in Singapore, Seoul, Bengaluru, Tokyo or Hong Kong already has something in market. It might be software that screens CVs, a credit model, a customer chatbot, or a machine that uses an AI model. Then a European customer sends a questionnaire, a data-protection addendum, or a clause for the SaaS contract. That is when these searches start. They are not searches for a new model. They are searches for what Europe may ask.

Does the EU AI Act apply to companies outside the EU?

It can. The EU AI Act may apply to companies established outside the EU when their AI systems or outputs are placed on the EU market or used in the EU, depending on the circumstances and the role of the company.

That is the useful answer at this stage. It is not a classification of a system, and it is not a conclusion on compliance. The calendar, the roles the regulation uses, and what a company inside the EU usually reviews first are in the AI Act guide for companies. This article stays with the question from outside the EU.

Does it apply if you have no office in Europe?

It can. No subsidiary, no branch and no staff in the EU does not close the question. An office is the fact a company can see. The facts that usually matter more are whether an AI system, or its output, is placed on the EU market or used in the EU, and what role the company plays.

A first review separates those facts. It does not decide that the regulation applies to every product a company ships from Asia.

What if the AI output is used in the EU?

That is one of the situations companies ask about. A European customer using the output — a shortlist of candidates, a credit suggestion, a chatbot reply, a movement from a robot — is a reason to look at the question. The EU AI Act may apply when outputs are used in the EU, depending on the system, the use and the role of the company.

The product type does not decide the role. HR software, a credit tool, a chatbot and a robot with an AI model are simply the products that are already built when the European customer writes. Each one opens different questions. None of them is classified from the name of the product.

Does GDPR apply to an Asian AI company?

It can. GDPR may apply to organisations outside the EU when they process personal data in connection with offering goods or services to individuals in the EU or monitoring their behaviour, depending on the circumstances.

Two questions usually sit next to that one. The first is selling AI to users in the EU: an account, a subscription or a service aimed at people there. The second is personal data in AI training, or in the prompts the product handles. Either one is a reason to identify the data-protection questions. Neither one means GDPR applies to every dataset a company holds.

Selling AI software in Europe

There is no single list that fits every AI product. When a company wants to sell AI software in Europe, the questions that come up are the same four: whether the EU AI Act may apply, whether GDPR may apply, what the contract says, and who is the provider or the deployer.

The practical place to start is the contract the European customer has already sent, or the one you are about to send. A checklist for the clauses that usually appear is in AI clauses in SaaS contracts.

An AI SaaS contract with a European customer

The customer often asks who answers if the system is questioned, what happens to personal data, which suppliers sit behind the product, and what the liability cap covers. Those are contract questions. They are also the place where the role — provider or deployer — gets written down, sometimes without anyone noticing.

A review of that contract is a document review. It is not a certificate that the product meets the EU AI Act or GDPR.

Provider or deployer, when you integrate AI for an EU client

The regulation distinguishes a provider, who develops an AI system or places it on the market or puts it into service, from a deployer, who uses that system in a professional activity. Integrating AI for a European client does not decide which one you are. The system, the contract, and who places it on the market are the questions to review.

An integrator can be closer to a provider on one project and closer to a deployer on the next. The title of the engagement is not the classification.

A European legal partner for an AI project

AI integrators, technology consultancies and technology companies do not have to build a European legal team to answer one customer questionnaire. Legal Stones works as that legal layer: European AI governance for the project, while the technology team keeps the build and, in the partner model, the client. The partner page is Become a partner.

The page for companies in Vietnam, Singapore and across Asia is EU AI Act for companies in Asia. It answers whether the EU AI Act may apply with no office in Europe, and the separate GDPR question. Not a certification and not a conclusion on compliance.

Questions companies ask before that assessment

Does the EU AI Act apply to companies outside the EU?

It can. The EU AI Act may apply to companies established outside the EU when their AI systems or outputs are placed on the EU market or used in the EU, depending on the circumstances and the role of the company. Legal Stones can help assess how the rules may apply to your specific situation.

Does it apply if we have no office in Europe?

It can. No office, subsidiary or staff in the EU does not close the question. Whether the EU AI Act may apply still depends on the circumstances and the role of the company, including whether a system or its output is placed on the EU market or used in the EU.

What if the AI output is used in the EU?

That is one of the situations companies ask about. The EU AI Act may apply when AI outputs are used in the EU, depending on the system, the use and the role of the company. A European customer using the output is a reason to review the question. It is not, by itself, a classification of the system.

Does GDPR apply to an Asian AI company?

It can. GDPR may apply to organisations outside the EU when they process personal data in connection with offering goods or services to individuals in the EU or monitoring their behaviour, depending on the circumstances. We can help identify the relevant data protection considerations for your AI activities.

Are we the provider or the deployer if we integrate AI for a European client?

Integrating AI for a European client does not decide the role. A provider develops an AI system or places it on the market. A deployer uses it in a professional activity. The system, the contract and who places it on the market are the questions to review. This is not a classification of a project.