EU AI Act: Practical Guide to International Business

EU AI Act: How Technology Companies Can Enter the EU Market Without Sanctions
Mainstream
Compliance with the EU AI Act is not about filling out a self-assessment form. It is a strategy to access the largest regulated artificial intelligence market in the world.
The question is not whether you have received the certificate. The key question is whether your company can continuously and seamlessly develop, implement and sell AI solutions in the European Union.
Effective international compliance begins with three checks:
- Is your AI system regulated and what risk category does it fall into?
- What role do you play and who bears the brunt of responsibility?
- Are your internal processes ready for post-marketing monitoring and ongoing oversight?
If these three issues are not resolved before the product is launched, the company risks more than a fine of up to 35 million euros or 7% of global turnover. It risks a forced recall of the product from the market, a reputational disaster and the loss of the right to work in the EU.
When the EU AI Act is required
International compliance with the AI Act is required if:
- You develop AI systems and place them on the EU market.
- you are integrating an AI component into your products sold in Europe;
- You are an importer or distributor of AI solutions in the European Union.
- your AI system is used in the EU to make decisions about people
- your product interacts with EU citizens, even if you are abroad;
- You are engaged in biometric categorization, emotion recognition or scoring;
- You are using AI in critical infrastructure, education, HR or law
- you have received a request from a European regulator or counterparty for compliance status;
- You are planning an M&A transaction with a European AI asset and assess the risks.
- You want to avoid qualifying your system as a prophibited AI.
The mistake most international companies make
Many technology teams start with the question:
What documents do you need to collect for the regulator?
That's the wrong first question.
The right question is:
What compliance model should I implement so that the product does not stop at the border and the responsibility does not become personal for the management?
Sometimes the best result is to give up risky functionality at the start. Sometimes, the AI module is isolated into a separate product in the orbit of a European representative. Sometimes, there is a deep modernization of data governance. Sometimes, it is the structuring of relationships with providers and users in such a way as to shift the burden of compliance to the best prepared party.
Compliance with the EU AI Act does not require formal certification, but a commercial strategy for managing technology risks.
Step 1. Determine whether a product is subject to the AI Act
The first thing to study is not the technical documentation, but the definition of the AI system in the Regulations and the territorial scope of its application.
Key points for analysis:
- The presence of machine learning or logical/statistical approaches.
- The ability of the system to influence the environment or make decisions;
- degree of autonomy;
- placing the product on the EU market or putting it into service;
- the location of the provider, importer or user;
- Whether the system is operating in the EU;
- whether personal data of EU residents is used;
- whether the system is applied by EU public authorities;
- exceptions: R&D, military objectives, national security, open source (with reservations);
- purely auxiliary IT tools without AI-specificity.
If the system does not fall within the definition, formal responsibilities are minimal. But it will need to be proven in a documentary.
Step 2. Classification of the system by risk level
The level of risk determines the scope of the requirements.
The category should be clearly defined:
- Prohibited AI (Subliminal techniques, general purpose social scoring, real-time remote biometric identification in public spaces (with narrow exceptions)
- High-risk AI – systems in critical infrastructure, education, employment, access to basic services, law enforcement, migration, justice. Some products that are subject to harmonised EU legislation (medicine, cars, toys).
- Limited risk: chatbots, emotion recognition, generative content (GPAI), where transparency is key.
- Minimum risk is spam filters, AI in video games, recommendation systems without significant exposure.
A classification error is the most expensive mistake. It can lead to the development of a product that is generally prohibited from being brought to market.
Step 3. Determine your role in the value chain
The AI Act imposes different responsibilities on different participants:
- Provider – someone who develops and hosts an AI system under their brand. It has the primary responsibility for compliance.
- An importer is someone who imports an AI system from a non-EU provider. You must check compliance and register if necessary.
- Distributor: Sells or distributes the system to the EU market without changing its nature.
- Deployer – uses the system in its professional activities. For high-risk systems, human oversight and monitoring responsibilities are required.
The company can combine several roles. The compliance strategy is built around the role with the greatest burden.
Step 4. Identify applicable requirements
For high-risk systems, requirements include:
- Risk management system throughout the life cycle;
- Data management (training, validation, test datasets);
- technical documentation;
- transparency and provision of information to the user;
- human supervision;
- accuracy, robustness and cybersecurity;
- Obligations for post-market monitoring;
- registration in the pan-European database;
- preparation of the EU Declaration of Conformity and the CE marking.
For limited risk systems, it is to inform that a person is interacting with AI and label the generated content.
Step 5. Conduct conformity assessment and prepare documentation
The conformity assessment procedure depends on the category:
- Most high-risk systems – internal controls under Annex VI
- harmonized legislation systems through notified bodies (Annex VII);
- General Purpose AI with System Risks – Extended Liabilities
The documentation shall be prepared before placing on the market and shall include:
- description of the system and its purpose;
- information about the provider and the authorized representative;
- Matrix of risks and measures for their mitigation;
- Logic of decision-making and human supervision;
- Testing and validation results;
- Incident monitoring policy;
- declaration of conformity.
The documentation must be kept for 10 years. His absence is an independent basis for a fine.
Step 6. Implementing a risk management system
Compliance is not a one-time project. It's a continuous process.
Risk Management System (RMS) should:
- Identify known and foreseeable risks;
- assess their severity and likelihood;
- implement measures to eliminate or reduce;
- Testing residual risks;
- Update as the system learns and the environment changes.
This is especially important for self-learning systems, whose behavior changes after deployment.
Step 7. Ensure transparency and human oversight
Compliance is not possible without built-in control mechanisms:
- understandable informing users about the system’s capabilities and limitations;
- for high-risk – the ability to intervene or reverse a decision;
- “Stop button” or bypass mechanisms;
- automatic recording of the fact of human participation;
- Transparency with respect to data sources and algorithmic logic (at the description level).
The lack of real human control is a common reason for claims of supervisory authorities.
Step 8. Appoint an authorized representative in the EU
This is a requirement for providers and importers outside the EU.
Authorized representative:
- must be established in one of the EU Member States;
- It acts as a point of contact for regulators.
- Keeps the documentation and the Declaration of Conformity;
- interacts with incidents;
- It may be brought before a court or supervisory authority.
The appointment of a nominee without a real mandate is a critical mistake.
Step 9. Register the system in the EU database
High-risk AI systems are subject to mandatory registration in the EU public database.
The registration data shall include:
- information about the provider and representative;
- purpose of the system;
- category of risk;
- results of conformity assessment;
- Technical documentation (to the extent determined by the Regulations).
Registration must be completed before the system is put into operation.
Step 10. Set up post-marketing monitoring
Once the market is in place, the responsibilities do not end.
It is necessary:
- collect and analyze data on the operation of the system;
- Investigate serious incidents (serious incidents)
- notify regulators within the prescribed timeframe;
- Initiate corrective actions (up to product recall);
- Update the documentation;
- interact with supervisory authorities during inspections.
Proper monitoring is about protecting not only users, but also the business itself from disproportionate sanctions.
Table: Structure of fines for violations of the EU AI Act
| Category of violation | Maximum fine | Example |
|---|---|---|
| Inadmissible practices | up to 35 million euros or 7% of global turnover | Use of the social scoring system |
| Violation of requirements for high-risk systems | up to 15 million euros or 3% turnover | Lack of human oversight or data governance |
| Providing incorrect information to the regulator | up to 7.5 million euros or 1.5% of turnover | Covering up a serious incident |
| Transparency (limited risk) | up to 15 million euros or 3% turnover | A chatbot that doesn’t tell you it’s AI |
Fines are imposed based on circumstances, but upper thresholds make compliance financially uncontested.
Common Mistakes of International AI Companies
- If the company is not in the EU, the AI Act does not apply. Extraterritorial action is based on the place of use of the result.
- Call AI “automation” and ignore regulation. Qualifications depend on the substance, not the name.
- High-risk systems are classified as minimal risk. The error will be revealed at the first incident.
- Do not distinguish between the roles of the provider and the user. This leads to the omission of critical responsibilities.
- Appoint a shell company as a representative in the EU. The regulator will quickly identify the lack of real control.
- Forget about monitoring obligations after sale. Selling is not the finale of compliance.
- Ignore the data requirements for training. Discriminatory bias or violation of GDPR are separate formulations.
- Not to include human oversight at the architectural level. Doing this after the fact is often impossible.
Checklist for International Business
Before entering the EU market, answer 15 questions:
- Does our product fall within the definition of an AI system?
- In which country and by whom will it be placed on the market?
- Who is our “provider” within the meaning of the Regulations?
- Do we have an importer or distributor in the EU?
- What risk category did we put the system in and why?
- Are there any signs of unacceptable practices in the product?
- Are the technical documentation and datasets ready?
- Has the conformity assessment been carried out according to the required procedure?
- Is an authorized representative with real powers appointed?
- Is the system registered in the EU database?
- Does the human surveillance mechanism work?
- Is the incident response system set up?
- Is a post-marketing monitoring plan ready?
- Do we have a strategy in place in case of a request from the supervisory authority?
- How do we prove compliance one year after launch?
What a strong AI Compliance strategy looks like
A strong strategy includes five levels:
- Regulatory Intelligence: The precise classification, monitoring and monitoring of the Commission’s regulatory updates and guidelines.
- Product Governance is the integration of compliance into the design of the system, not the “twisting” before launch.
- Documentation & Evidence – a complete package of documentation, declaration, logs of human participation.
- EU Representation & Engagement – an active dialogue with supervisory authorities through a real representative.
- Incident & Enforcement Readiness – prepared algorithms for actions in case of an incident, product blocking or unscheduled inspection.
Without a fifth level, the first four may not keep the business from shutting down.
FAQ
Does the EU AI Act apply to non-European companies? If your AI system is used for users in the EU or the result is used in the EU, you must comply with the Regulation, even if you are in another country.
More importantly: Getting CE marking or avoiding a penalty is more important than building a continuous risk management system. CE marking is an effect, not a goal. Without a compliance system, it will not protect against post-marketing sanctions.
Can you sell high-risk AI without a European representative? Providers and importers outside the EU are required to appoint an authorised representative in the Union before placing the system on the market.
Conduct a legal audit of risk classification and human oversight at the design stage, not before release.
Immediately initiate gap analysis, prioritize critical inconsistencies and possibly temporarily limit functionality for EU users until alignment.
The regulation provides some simplifications for small and micro-enterprises, but they do not exempt from the basic requirements of the high-risk category. Regulatory sandboxes can help with testing.
Is the AI Act related to GDPR? Data quality, transparency and non-discrimination requirements are closely related to the protection of personal data. The violation of one often entails the violation of the other.
Related services
- EU AI Governance, Compliance & Strategic Advisory
- International Technology Transactions & Commercial Contracts
- Data Protection, GDPR & Cross-Border Data Flows
- Corporate Investigations & Regulatory Defence
- International Arbitration & Tech Disputes
- M&A Due Diligence for AI Assets
Related material
- EU Data Strategy: How to prepare datasets for high-risk AI
- GDPR and AI Act: compliance
- How to structure the relationship between the provider and the AI Deployer
- Legal due diligence AI startup before entering Europe
- EU regulatory sandboxes: How to use it for international business
- Postmarketing AI monitoring: plan
Conclusion
Compliance with the EU AI Act requires not just a checklist, but a strategy of continuous management of regulatory and technological risks.
A strong position is based on accurate classification, the right distribution of roles in the supply chain, the built-in mechanism of human supervision and the willingness to prove compliance to the supervisory authority at any time.
In the European market of artificial intelligence, the winner is not the one who launched the product the fastest. The winner is the one who understands in advance how to cross the regulatory boundary without stopping business, preserve liquidity and turn compliance into a competitive advantage.
Have a question about the topic of this article?
Write to us and we will respond within one business day.


