Skip to content
HDQ Consulting

Latest update

Whose Ai rules apply to you

Published Last reviewed

Ask an Australian executive whether the EU AI Act applies to them and you usually get "we don't sell into Europe". Right instinct, wrong law. Its scope asks where your system, or what it produces, ends up — not where you sit.

The three limbs that reach Australia

Article 2(1) lists seven categories. Three reach here.

Article 2(1)(a) covers providers placing Ai systems or general-purpose Ai models on the EU market, "irrespective of whether those providers are established or located within the Union or in a third country". Australia is a third country.

Article 2(1)(c) is the sleeper: providers and deployers in a third country where the output produced by the system "is used in the Union". A model that never leaves Adelaide can still be in scope. The provision says nothing about intent, while Recital 22 speaks of output "intended to be used in the Union". That gap is unresolved.

Article 2(1)(e) was written for people who make things: "product manufacturers placing on the market or putting into service" an Ai system "together with their product and under their own name or trademark". It has to ship with the product — Ai used only inside your plant is a different limb. Put your badge on the machine and you are a provider in your own right; licensing the model from a vendor does not shift that back. For high-risk systems Article 25 says so outright: your name on one makes you the provider, and the vendor, owing only a duty to "closely cooperate", stops being the provider of that system.

The carve-outs are narrow. Article 2(6) excludes what is developed and put into service for the sole purpose of scientific research and development. Article 2(8) excludes research, testing and development before market — but "Testing in real world conditions shall not be covered by that exclusion". Article 2(12) excludes free and open-source releases, unless they are high-risk or caught by Article 5 or Article 50.

What the fines actually are

Everyone quotes 7% of global turnover. Article 99 sets three ceilings. EUR 35 million or 7% of total worldwide annual turnover, whichever is higher, attaches to the Article 5 prohibited practices and nothing else. EUR 15 million or 3% covers the obligations on providers, deployers, importers, distributors, authorised representatives and notified bodies, including Article 50 transparency. EUR 7.5 million or 1% covers incorrect, incomplete or misleading information given to an authority or a notified body.

Article 99(6) reverses the arithmetic for SMEs, including start-ups: their cap is "whichever thereof is lower". Lower, not higher. On the EU definition — broadly under 250 staff, with turnover of EUR 50 million or less or a balance sheet of EUR 43 million or less — most readers here sit well below the headline. Article 99 sets ceilings; Member States lay down the penalties.

The dates moved in July

The simplification package the Commission dubbed the AI Omnibus was proposed on 19 November 2025, politically agreed on 7 May 2026 and in force on 27 July 2026. It pushed the heavy obligations out, added a prohibition, and strengthened the AI Office's hand over general-purpose models.

Binding now: definitions, the Ai literacy duty and the prohibited practices since 2 February 2025; general-purpose model obligations, governance rules and the penalties regime since 2 August 2025; the Act generally, including Article 50 transparency, since 2 August 2026. Implementation, supervision and enforcement sit with the AI Office and the authorities of the Member States.

Two things land on 2 December 2026: providers of synthetic-content systems already on the market before 2 August 2026 have until then to meet Article 50(2), and the ninth prohibited practice starts, covering non-consensual sexually explicit and intimate content or child sexual abuse material.

Annex III high-risk uses move to 2 December 2027 — biometrics, critical infrastructure, education, employment, access to essential private and public services such as credit scoring, insurance pricing and eligibility for public benefits, law enforcement, migration, asylum and border control, and the administration of justice. Annex I high-risk, Ai embedded in products already regulated such as lifts, toys and machinery, moves to 2 August 2028. For high-risk systems, conformity assessment, technical documentation and post-market monitoring wait on those dates.

The voluntary layer that ends up in your contract anyway

ISO/IEC 42001:2023 sets the requirements for an Ai management system: scope, risks, approvals, records, review. It is certifiable, but not by ISO — accredited bodies do that, so the right phrase is "certified to ISO/IEC 42001", not "ISO certified". It becomes binding the day a customer or a tender writes it into the terms, which is how it reaches most Australian suppliers.

The NIST AI Risk Management Framework is "intended for voluntary use", in NIST's words. Version 1.0, from January 2023, is being revised as part of the White House AI Action Plan, and NIST added a concept note on trustworthy Ai in critical infrastructure on 7 April 2026. Watch that one if you run process control or utilities.

The United States is not one jurisdiction

Colorado is the cautionary tale. SB 24-205 was repealed and reenacted by SB 26-189, effective 14 May 2026 and rebuilt around "automated decision-making technology" and "consequential decisions". Developer and deployer duties start on 1 January 2027, after moving from 1 February 2026 and then 30 June 2026. The Attorney General enforces it under the Colorado Consumer Protection Act, with a 60-day notice and cure period for actions started before 1 January 2030, and the act creates no new private right of action. The "Colorado AI Act" people still cite no longer exists in that form.

California's SB 53, signed on 29 September 2025, is operative and narrow: a large frontier developer has annual gross revenues, counting affiliates, above US$500 million in the preceding calendar year. Those developers publish a safety framework, report critical safety incidents and protect whistleblowers. It says nothing to a business that buys or deploys Ai.

Federal policy runs through executive action, not statute. Executive Order 14365 of 11 December 2025 directs officials to prepare legislative recommendations that would pre-empt conflicting state Ai laws — fair evidence that none exists yet.

What to do with all of this

Know where your output goes, system by system. Know whose name is on the product: if it is yours, Article 2(1)(e) makes you the provider of the Ai inside it. Keep a register — what Ai is in use, who approved it, what data goes in, who reviews what comes out — because none of it can be reconstructed after the fact. And decide whether ISO/IEC 42001 is a contract requirement waiting to happen in your sector; building it before a customer names a deadline costs less.

Australia's own position is a separate question, and for most readers a more immediate one. We've set it out in Ai compliance and governance in Australia.

Sources

  1. Regulation (EU) 2024/1689 — Artificial Intelligence Act, consolidated text as at 27 July 2026 European Parliament and Council of the European Union eur-lex.europa.eu (opens in a new tab)
  2. Regulation (EU) 2024/1689 — Artificial Intelligence Act, original Official Journal text European Parliament and Council of the European Union eur-lex.europa.eu (opens in a new tab)
  3. Regulatory framework for artificial intelligence European Commission digital-strategy.ec.europa.eu (opens in a new tab)
  4. Timeline for the implementation of the EU AI Act European Commission, AI Act Service Desk ai-act-service-desk.ec.europa.eu (opens in a new tab)
  5. ISO/IEC 42001:2023 — Information technology, Artificial intelligence, Management system International Organization for Standardization iso.org (opens in a new tab)
  6. Certification — ISO does not perform certification International Organization for Standardization iso.org (opens in a new tab)
  7. NIST AI Risk Management Framework National Institute of Standards and Technology, US Department of Commerce nist.gov (opens in a new tab)
  8. Senate Bill 26-189, Automated Decision-Making Technology Colorado General Assembly leg.colorado.gov (opens in a new tab)
  9. Senate Bill 24-205, Consumer Protections for Artificial Intelligence Colorado General Assembly leg.colorado.gov (opens in a new tab)
  10. Senate Bill 25B-004, Increase Transparency for Algorithmic Systems Colorado General Assembly leg.colorado.gov (opens in a new tab)
  11. Senate Bill 53, Transparency in Frontier Artificial Intelligence Act California State Legislature leginfo.legislature.ca.gov (opens in a new tab)
  12. Executive Order 14365, Ensuring a National Policy Framework for Artificial Intelligence Office of the Federal Register, United States federalregister.gov (opens in a new tab)

Not sure if we're a fit?

Book a short discovery call. We'll learn about your business and tell you straight.

Book a discovery call

General information only, current at the date of last review. It isn't legal advice, and it isn't a substitute for reading the source documents or getting advice on your own circumstances.