Why does the EU AI Act matter in Latin America?

The AI Act of the European Union (Regulation 2024/1689) defines its scope of application by the role performed and by the link with the Union (Article 2(1)). The three main cases are: the provider that places an AI system on the EU market or puts it into service in the Union, whether established in the Union or in a third country; the deployer established or located in the Union; and the third-country provider or deployer where the outputs produced by the AI system are used in the Union. A company in Mexico City, Bogotá, Santiago or Buenos Aires that sells its AI software in Europe is placing it on the EU market, and a company whose AI systems produce outputs that are used in the Union is also within the scope of application.

This is not theoretical. The European Commission has been explicit about the extraterritorial reach of the regulation, and the national supervisory authorities of the Member States have the power to investigate and sanction organisations outside the EU that breach its provisions.

The updated deadlines under the Digital Omnibus

The provisional agreement of 7 May 2026 between the Council of the EU and the European Parliament significantly changed the implementation timetable. Latin American companies should update their compliance planning to the new deadlines: prohibited practices in force since 2 February 2025, GPAI obligations since 2 August 2025, transparency (Article 50) from 2 August 2026, marking of AI-generated content from 2 December 2026, and Annex III high-risk AI from 2 December 2027.

Which Latin American sectors have the greatest exposure

The sectors most exposed to extraterritorial compliance are software and SaaS (especially HR, credit, health and education applications placed on the EU market), BPO services and contact centres whose AI systems produce outputs that are used in the Union, fintechs with users in the Latin American diaspora in Europe, and digital content companies with significant European audiences.