EU AI Act · Legal Services · International Businesses

EU AI Act Compliance
Services for
International Businesses

The EU AI Act is the world's first comprehensive AI regulation - and it does not stop at Europe's borders. If your business uses AI and serves EU customers, the Act may apply to you regardless of where you are based. Korean companies, US companies, SaaS providers, AI startups, clinics, and brands reaching European users all need to assess their obligations. This is where I help.

Book a Free Compliance Call View Compliance Packages
Aug 2026
High-Risk AI Obligations Enforced
€35M
Max Penalty Per Violation
7%
Max Global Turnover Fine
Important Legal Position
The EU AI Act does not automatically apply to every business outside Europe. The key legal question is whether your AI system is placed on the EU market, offered to users in the EU, or whether its output is used in the EU. Being based in Korea, the US, or anywhere outside the EU does not exempt you - but it also does not automatically make you subject to the Act. A proper compliance assessment is the only way to determine your actual obligations.
Overview

What Is the EU AI Act?

The EU AI Act (Regulation EU 2024/1689) entered into force on 1 August 2024 and is being phased in through 2027. It is the world's first binding, comprehensive legal framework specifically regulating artificial intelligence. The Act applies based on risk level - classifying AI systems as unacceptable risk, high risk, limited risk, or minimal risk - and imposes different legal obligations depending on that classification and the role a business plays in the AI supply chain.

The roles the Act defines include providers (those who develop or place AI systems on the market), deployers (those who use AI systems in the course of business), importers, and distributors. Each role carries specific compliance obligations around transparency, documentation, risk management, human oversight, and data governance.

The Act also establishes the EU AI Office, which oversees enforcement of the rules for general-purpose AI models - including large language models. Penalties for serious violations can reach 35 million EUR or 7 percent of global annual turnover, whichever is higher.

Unacceptable Risk
Prohibited outright. Social scoring, real-time biometric surveillance, manipulation of vulnerable groups.
High Risk
Strict obligations. Medical devices, recruitment, credit scoring, critical infrastructure, education.
Limited Risk
Transparency obligations. Chatbots, deepfakes, AI-generated content must be disclosed.
Minimal Risk
No mandatory obligations. Spam filters, AI in video games, basic recommendation systems.
Extraterritorial Scope

Does the EU AI Act Apply Outside Europe?

This is the most important question for non-EU businesses - and the answer is nuanced. The EU AI Act has extraterritorial scope, meaning it can reach businesses based entirely outside the European Union. Article 2 of the Act sets out three key triggers that can bring a non-EU business within scope:

1. Placing an AI system on the EU market. If you make an AI system available to EU users or businesses - whether through a product, SaaS platform, API, app, or digital service - you may be considered a provider or distributor under the Act.

2. Offering AI services to users located in the EU. If EU residents or businesses use your AI-powered service, the Act may apply based on where the users are, not where you are based.

3. AI output being used in the EU. If you operate outside the EU but the decisions, content, or recommendations generated by your AI system are used in an EU context, this can also trigger obligations.

What does not automatically bring you within scope: simply having a website accessible in the EU, selling non-AI products to EU customers, or having EU investors or partners. The specific AI use case matters significantly.

Korean SaaS Company Serving EU Clients
If AI is embedded in the service and EU clients use it, the Act may apply. Provider obligations possible.
Assess Required
Seoul Clinic Using AI for EU Patients
If AI assists in treatment recommendations for EU patients, high-risk classification may apply.
Assess Required
K-Beauty Brand Using AI for EU Marketing
AI-generated personalized marketing targeting EU consumers may require transparency disclosures.
Assess Required
US AI Startup Licensing Technology to EU Companies
Licensing AI to EU deployers likely brings the provider within scope of the Act.
High Likelihood
Korean Company with No EU Customers or Output
If AI is used purely domestically with no EU market presence, extraterritorial scope unlikely.
Lower Risk
Entertainment Platform Streaming to EU
AI-driven content recommendations to EU users may require limited risk transparency compliance.
Assess Required
Korean Market

The EU AI Act and Korean Businesses

South Korea has one of the most dynamic technology, AI, healthcare, beauty, and entertainment sectors in the world - and many Korean companies actively serve European customers. This creates a significant and largely unaddressed compliance gap.

The pitch is not that every Korean company must comply with the EU AI Act. The legally accurate position is: if your Korean business uses AI and serves EU customers, you should assess whether and how the Act applies to you.

The industries most likely to need this assessment in Korea include cosmetic clinics and hospitals using AI diagnostics or treatment recommendation tools for EU patients, SaaS companies providing AI-powered software to EU businesses, K-beauty brands using AI for personalized product recommendations to EU consumers, entertainment companies using AI for content generation or recommendation to EU audiences, and AI startups licensing their technology to European clients.

Very few advisors in Korea are positioned at this intersection of EU AI regulation, IP law, and cross-border commercial contracts. This is the niche where Jessica Ingrid operates.

Example Scenario
A Seoul cosmetic clinic uses an AI system to analyze skin images, recommend treatments, and personalize follow-up marketing. It serves French, German, and Italian patients through online consultations. The AI Act's high-risk provisions for AI in medical contexts may apply. The clinic also has EU GDPR obligations on the data side. A proper assessment would clarify scope, identify obligations, and recommend a compliance pathway - before a European patient files a complaint or the EU AI Office initiates an inquiry.
Services

EU AI Act Legal Services

Jessica Ingrid provides practical, business-focused EU AI Act compliance services for international companies. All services are delivered remotely with fixed fees agreed upfront. Initial consultation is always free.

01
EU AI Act Compliance Assessment
A structured assessment to determine whether your business falls within the scope of the EU AI Act, what role you play in the AI supply chain, and what your actual obligations are.
  • Scope determination analysis
  • Risk classification of your AI systems
  • Role identification - provider, deployer, or importer
  • Gap analysis against Act requirements
  • Written compliance report with recommendations
02
AI Contract Review
Review of AI-related contracts to identify risks, missing compliance clauses, and obligations you may be taking on without realizing it.
  • AI vendor agreements
  • SaaS and API terms of service
  • AI licensing agreements
  • Procurement contracts for AI tools
  • AI clauses in commercial contracts
  • Data processing agreements linked to AI
03
AI Governance Documentation
Drafting and reviewing the internal and external documentation required or recommended under the EU AI Act for compliant AI deployment.
  • AI transparency notices and disclosures
  • Internal AI use policies
  • Technical documentation support
  • Human oversight procedures
  • Risk management documentation
  • AI system incident logging guidance
04
Intellectual Property and AI
AI compliance does not exist in isolation. It intersects with trademark, copyright, confidential information, and licensing. This service covers the IP dimension of your AI use.
  • AI-generated content and copyright ownership
  • Training data licensing and IP risk
  • Brand protection in AI contexts
  • Confidential information in AI inputs
  • AI output licensing and commercialization
  • Trademark strategy for AI products
05
AI Risk Assessment
Identify legal, contractual, IP, and compliance risks associated with your AI systems before deployment or before entering a new market.
  • Pre-deployment risk review
  • Market entry AI risk assessment
  • Third-party AI tool risk review
  • Cross-border AI regulatory comparison
  • Risk mitigation recommendations
06
AI Transparency Policy
Drafting clear, compliant AI transparency policies and disclosures for your website, product, and customer communications.
  • Website AI disclosure statements
  • Chatbot and AI interaction notices
  • AI-generated content labeling
  • Customer-facing AI policy pages
  • Internal AI ethics statements
Downloadable Guide · Instant PDF Delivery · Launch Offer - Save 50%

EU AI Act Compliance Guide
2026

97 EUR49 EUR
EU AI Act Compliance Guide 2026
Understand the Law. Assess Your Risk. Build Your AI Compliance Strategy. A practical, plain-language guide for founders, SaaS companies, clinics, and international businesses using AI. No legal jargon.
Whether the EU AI Act applies to your business
AI risk categories and classification
Transparency and governance obligations
High-risk AI systems and prohibited practices
IP risks when using AI - copyright and trademark
AI contracts and legal considerations
Practical compliance checklist and roadmap
Get This Guide
Industries Served

Who This Applies To

The EU AI Act is not limited to technology companies. Any business that uses AI in its operations and serves EU customers - or licenses AI to EU businesses - may need to assess its obligations. The following industries are among those most likely to have EU AI Act exposure when operating internationally.

Technology Companies
SaaS Providers
AI Startups
K-Beauty Brands
Medical Clinics
Healthcare Providers
Entertainment Companies
Marketing Agencies
E-Commerce Platforms
Education Technology
Hospitality & Travel
Manufacturing
Financial Services
Legal Technology
HR & Recruitment Tech
Gaming Companies
Enforcement

Penalties for Non-Compliance

The EU AI Act's penalty structure is significant and mirrors the approach taken by the GDPR. Fines are calculated based on the nature of the violation and apply to global annual turnover - not just EU revenue. For international businesses, this means the financial exposure is not limited to what you earn from European customers.

€35M / 7%
Prohibited AI Systems
Using AI systems that are banned under the Act, such as social scoring or certain biometric surveillance.
€15M / 3%
High-Risk Violations
Failing to meet obligations for high-risk AI systems including documentation, human oversight, and transparency.
€7.5M / 1.5%
Incorrect Information
Providing incorrect or misleading information to authorities or notified bodies during compliance checks.
Frequently Asked Questions

EU AI Act FAQ

What is the EU AI Act?
The EU AI Act is the world's first comprehensive legal framework regulating artificial intelligence. It entered into force on 1 August 2024 and is being phased in through 2027. It classifies AI systems by risk and imposes obligations on providers, deployers, importers, and distributors of AI systems placed on or used in the EU market.
Does the EU AI Act apply to companies outside Europe?
Yes, under certain conditions. The Act has extraterritorial scope. It can apply when an AI system is placed on the EU market, when AI services are offered to users in the EU, or when the output of an AI system is used in the EU. Being based outside Europe does not automatically exempt a business.
Does the EU AI Act apply to Korean companies?
It may. If a Korean company uses AI in services or products offered to EU customers, or if the output of its AI system is used in an EU context, the Act can become relevant. The key factor is the connection between the AI system and the EU market - not the location of the company's headquarters.
Does the EU AI Act apply to US companies?
Yes, under the same conditions. US companies that provide AI systems or AI-powered services to EU users, or that license AI technology to EU businesses, may fall within scope as providers or importers under the Act.
Does the EU AI Act apply to SaaS businesses?
SaaS businesses that embed AI functionality in their products and offer those products to EU users may be classified as providers of AI systems under the Act. The extent of obligations depends on the risk classification of the AI involved and the specific functionality provided.
Does the EU AI Act apply to AI startups?
Yes. AI startups that develop or deploy AI systems are directly addressed by the Act. The Act includes specific provisions to reduce the administrative burden on SMEs and startups, but it does not exempt them from compliance obligations when their AI systems present significant risks or serve EU users.
Does the EU AI Act apply to clinics using AI?
Medical AI is one of the highest-risk categories under the Act. Clinics using AI for diagnosis, treatment recommendations, patient monitoring, or medical image analysis may be using high-risk AI systems and face the strictest compliance obligations, including technical documentation, human oversight requirements, and registration in the EU database.
Does the EU AI Act apply to marketing agencies using AI?
Marketing agencies using AI for content generation, personalization, or targeting directed at EU consumers should assess their obligations. AI-generated content targeting EU users typically requires transparency disclosures. Certain AI tools used in recruitment or profiling may fall into higher risk categories.
What happens if my company is not compliant?
Non-compliance can result in significant financial penalties, prohibition from placing AI systems on the EU market, and reputational damage. The EU AI Office and national competent authorities have enforcement powers. Penalties are calculated on global annual turnover, not just EU revenue.
What are the penalties for violating the EU AI Act?
Penalties range from 7.5 million EUR or 1.5 percent of global turnover for providing incorrect information, to 15 million EUR or 3 percent for high-risk AI violations, to 35 million EUR or 7 percent for using prohibited AI systems. The higher of the two figures applies in each case.
How do I know whether my business falls within the scope of the EU AI Act?
The assessment involves identifying whether you use or provide AI systems, determining the risk classification of those systems, and analyzing your connection to the EU market. A structured compliance assessment is the most reliable way to answer this question accurately. Book a free initial consultation to start the process.
When does the EU AI Act start being enforced?
The Act is being phased in: prohibited AI systems became unlawful from February 2025, general-purpose AI model obligations apply from August 2025, high-risk AI system obligations apply from August 2026, and the remaining provisions apply from August 2027. Enforcement is already underway for the earliest provisions.
What is a high-risk AI system under the EU AI Act?
High-risk AI systems are those used in critical infrastructure, education, employment and recruitment, essential private and public services, law enforcement, border management, administration of justice, and democratic processes. Medical devices and safety components in products are also classified as high-risk. These systems face the strictest compliance obligations.
What is the difference between an AI provider and an AI deployer?
A provider develops or places an AI system on the market. A deployer uses an AI system under its own responsibility in the course of business. Both have obligations under the Act, but providers carry heavier responsibilities around technical documentation, conformity assessment, and registration. Many businesses are both providers and deployers depending on the context.
Does the EU AI Act cover AI used internally within a company?
Yes, for high-risk applications. If a company uses a high-risk AI system internally - for example, for HR screening, employee monitoring, or access control - deployer obligations apply even if the AI is not sold externally. The obligations include transparency with affected individuals and human oversight requirements.
Does the EU AI Act apply to general-purpose AI models like ChatGPT or Claude?
Yes. The EU AI Act includes a dedicated chapter on general-purpose AI models (GPAI). Providers of GPAI models must meet transparency and documentation obligations. Those deemed to present systemic risk face additional requirements including adversarial testing and incident reporting.
What is an AI transparency disclosure?
A transparency disclosure informs users that they are interacting with an AI system. For chatbots, the Act requires that users are told they are speaking with AI. For AI-generated content including images and video, labeling requirements apply. Transparency disclosures must be clear, prominent, and easy to understand.
How does the EU AI Act interact with GDPR?
The EU AI Act and GDPR operate in parallel. AI systems that process personal data of EU individuals must comply with both frameworks simultaneously. GDPR governs data protection while the AI Act governs the AI system itself. High-risk AI systems that process personal data face obligations under both laws, and compliance assessments should address both.
Can I use AI-generated content commercially in the EU?
Yes, subject to disclosure and IP considerations. AI-generated content used commercially in the EU must be labeled under the Act's transparency requirements. Additionally, copyright ownership of AI-generated content is a separate but related question involving both EU copyright law and the law of the country where the content is created or published. See the IP and Copyright section for more.
What contracts should I review for EU AI Act compliance?
Any contract involving AI technology should be reviewed. Priority contracts include AI vendor agreements, SaaS agreements with AI functionality, API terms for AI services, AI licensing agreements, procurement contracts for AI tools, data sharing agreements feeding AI systems, and any contract with an EU counterparty that involves AI in the services delivered.

Does the EU AI Act
Apply to Your Business?

The only way to know for certain is a proper assessment. Book a free initial consultation - no obligation, no hourly billing. We determine your scope, your risk level, and your next steps together.

Book a Consultation View Compliance Packages