Why the EU AI Act affects Latin American companies
The most common misconception about the EU AI Act is that it only applies to European companies. It does not. The law applies to any organisation that places AI systems on the European market or operates them in the EU, or any organisation outside the EU where the output of its AI systems is used in the EU.
A Mexican company that processes credit applications from Spanish or German customers is within scope. A Colombian software company whose AI is used by European businesses is within scope. An Argentine company offering AI analytics services to EU-based organisations is within scope. The location of the organisation provides no protection; what matters is where the outputs of the AI take effect.
The key deadlines
Prohibited AI practices have been illegal since February 2025. Obligations for general-purpose AI models have applied since August 2025. The main requirements for high-risk AI (conformity assessments, technical documentation, human oversight, EU registration) were postponed, for Annex III systems, from 2 August 2026 to 2 December 2027 by Regulation (EU) 2026/1744. Organisations that have not yet begun assessing the requirements are behind.
High-risk AI categories relevant to Latin America
Annex III of the EU AI Act lists the high-risk AI categories. The most relevant for Latin American companies with European customers include: credit scoring systems and financial institutions serving European customers; recruitment and personnel selection AI affecting European candidates; clinical decision support AI used in European medical settings; biometric recognition systems; and AI in education affecting European students.
Deployer obligations: the distinction many companies overlook
The law distinguishes between providers (organisations that develop AI) and deployers (organisations that deploy AI in their operations). The obligations are cumulative: buying AI from a provider does not transfer regulatory responsibility to that provider. Organisations using third-party AI in high-risk contexts have direct obligations as deployers, including: implementing human oversight mechanisms, monitoring the performance of the AI system, carrying out fundamental rights impact assessments, and notifying affected individuals about the use of AI in decisions concerning them.
Where to start
For Latin American companies beginning their EU AI Act assessment: first, identify which AI systems you place on the EU market or put into service in the Union, and which produce outputs that are used in the Union; second, classify them against the Annex III risk categories; third, run a gap analysis against the requirements for high-risk AI; fourth, prioritise closing the gaps on the basis of greatest regulatory exposure. This sequence is the same regardless of where the organisation is located.