← Back · ← Home · ← Back to list

The EU AI Act’s Extraterritorial Reach: Analyzing the Impact on Companies in Morocco and Other Third Countries

Category
Current Watch
Published
September 5, 2026
Illustration

Executive Summary

The EU AI Act extends its regulatory scope to companies in third countries that provide services to European customers, regardless of whether they have a physical presence within the EU. The case of Morocco illustrates a structure where a company acquires "provider" status the moment it sells scoring software to a French firm, exposing the entire Francophone call center and BPO industry to the dual pressures of AI automation and regulatory compliance. The EU is expanding its phased enforcement, focusing on large operators by enforcing transparency obligations from August 2026 and designating Very Large Online Platforms like ChatGPT. This should be seen not as a grace period but as a precursor to a wider regulatory scope. Korean companies must proactively assess their "provider" status for EU-bound services and manage the compliance risks of local partners as their own when entering the market through third countries. A strategic approach is required to turn regulatory compliance from a cost into a competitive advantage with European clients.

Diagram

I. Situational Analysis

The EU AI Act’s Extraterritorial Application and Its Impact on Companies in Morocco and Other Third Countries: A Situational Analysis

1. Background and Developments

Since coming into force in 2024, the EU AI Act has been gradually expanding its scope of application. As of August 2, 2026, the European Commission began enforcing new transparency obligations. Conversational AI systems like chatbots must inform users that they are interacting with an AI, and labeling requirements have been imposed on deepfake content [2]. The core of this regulation is its extraterritorial application clause: companies are subject to the Act if they provide services to European customers, even without a business establishment within the EU.

The Moroccan media outlet Le Matin du Sahara addressed this issue directly from the perspective of domestic companies, presenting the specific case of a Moroccan firm selling scoring software to a French company [1]. In this scenario, the Moroccan company could be classified as a "provider (fournisseur)" under the AI Act [1]. The outlet noted that this logic also extends to some professional users, meaning that not only Moroccan AI developers but all B2B businesses providing outsourced services to European clients are potentially subject to the regulation [1].

This has significant repercussions given Morocco's economic structure. As a hub for the Francophone call center and Business Process Outsourcing (BPO) industry, Morocco has long handled a large volume of back-office tasks for European companies. The national federation for the call center and outsourcing sector, under the Moroccan Labour Union (UMT), warned in an official letter to the government that the industry is at a "decisive turning point" [17]. It argued that thousands of jobs are threatened by the combined impact of new foreign regulations and the spread of AI and automation [17]. At the same time, the federation added that with proactive and fair policy support, this crisis could be transformed into an opportunity [17].

2. Current Situation

In parallel with implementing the AI Act, the European Commission is also strengthening its enforcement of the Digital Services Act (DSA). On August 31, 2026, the EU designated ChatGPT as a "Very Large Online Platform" (VLOP) for the first time [9][12][14]. Reddit and Roblox were designated at the same time [9][10]. The criterion for designation is having over 45 million monthly active users in the EU [10]. These services are now obligated to assess and mitigate systemic risks related to illegal content, protection of minors, electoral processes, and public security within four months of notification, i.e., by January 2027 [10]. Henna Virkkunen, the EU's Executive Vice-President for Digital, stated, "ChatGPT, Reddit, and Roblox will now be subject to a higher level of supervision and accountability standards commensurate with their significant impact on citizens and society" [9].

Within Morocco, data protection regulations are also being strengthened, separate from the AI Act. Ahead of the September 23 general election, Morocco's National Commission for the Control of Personal Data Protection (CNDP) notified political parties of their compliance obligations for processing personal data [5]. This notice also included the requirement to label AI-generated content [5]. This situation illustrates that the Moroccan government and businesses are facing dual compliance pressures, with EU-led regulations overlapping with domestic rules governing election data.

3. Key Actors and Positions

European Commission (DG CONNECT)is operating the AI Act and the DSA as a single regulatory package, making clear its intent to enforce them against operators outside the EU [2][10]. From the Commission's perspective, extraterritorial application is not an exception but a core design principle. Its logic holds that the location of a business is irrelevant as long as it provides services to European citizens.

Moroccan Companies and Industry Associationsperceive this as a sudden burden. As illustrated by the scoring software case highlighted by Le Matin du Sahara, Moroccan IT and fintech firms serving European clients now need legal reviews to determine if they qualify as "providers" [1]. The call center federation under the UMT is framing the issue as a threat to jobs and demanding government intervention to protect the industry [17].

Moroccan Government (Domestic regulators like the CNDP)is enforcing its domestic data protection laws independently of EU regulations [5]. However, it is not yet clear from available information whether these efforts are part of a broader national strategy to address the AI Act.

Governments of Neighboring Non-EU Countries like Libyaare responding by participating in international discussions on AI governance. Libya's Minister of State for Digital Economy and AI, Ziad Al-Hajaji, attended the International Dialogue on AI Governance in Geneva, stating his country's commitment to international cooperation aligned with the Sustainable Development Goals [16]. This represents a strategy of engaging in intergovernmental norm-setting, distinct from firm-level compliance responses.

U.S. Big Tech (e.g., OpenAI)faces rising compliance costs as it is brought into the dual regulatory framework of the EU's DSA and AI Act [9][12][14]. However, with a user base too large to abandon access to the EU market, these companies have limited alternatives to regulatory acceptance.

4. Key Issues

The first key issue is the ambiguity in determining "provider" status. As the Moroccan case illustrates, legal precedent has not yet established whether simply selling an algorithm-based service to a European client is sufficient to bring a company under the purview of the AI Act [1]. This creates uncertainty for all non-EU businesses providing outsourcing services to Europe, not just those in Morocco.

The second issue is the asymmetry between the employment impact and the capacity for regulatory response. Industries that rely on low-wage, repetitive tasks, like Morocco's call center and BPO sector, must now bear the dual burden of advancing AI automation and EU regulatory compliance [17]. Unlike large multinational corporations, small and medium-sized outsourcing firms often lack dedicated compliance staff, meaning the regulatory requirements themselves can act as a barrier to entry.

The third issue is the potential for EU regulations to become de facto international standards. The combination of the AI Act and the DSA is solidifying a structure where any global business wishing to access the European market must comply with EU standards, regardless of its location [2][9][10]. This is an AI version of the "Brussels Effect," adding a third axis of EU-led regulatory competition to the U.S.-China tech rivalry [7]. Third countries like Morocco, which are not aligned with either the U.S. or China, are likely to remain rule-takers, excluded from the norm-setting process.

II. In-Depth Analysis

The EU AI Act’s Extraterritorial Application and Its Impact on Companies in Morocco and Other Third Countries: An In-Depth Analysis

1. Analysis of Root Causes

The AI Act's extraterritorial application clause is no legislative accident. Since the GDPR, the EU has explicitly utilized the "Brussels Effect" as a strategy to export its norms, using its market size as leverage to compel businesses in third countries to adopt EU standards. The AI Act continues this legacy. The structure in which a Moroccan company becomes a "provider" the moment it sells scoring software to a French firm [1] is a direct result of the regulation being based on access to the EU market, rather than on physical presence within it.

This design is rooted in the EU's internal industrial policy calculations. The EU perceives itself as lagging behind the United States and China in AI model competitiveness. Instead of trying to win the model development race, it has chosen a strategy of shaping market rules by preemptively seizing regulatory power [7]. The designation of ChatGPT as a VLOP using the 45-million-user threshold is an extension of this logic [10]. In a market where U.S. Big Tech has overwhelming dominance, regulation based on user numbers effectively targets American companies [12][14].

In the case of Morocco, there is an additional root cause: the economy's structural dependence on providing services to Europe. Leveraging its French language proficiency and competitive labor costs, Morocco's call center and outsourcing industry has long handled back-office operations for French and Belgian companies. The federation under the UMT diagnoses that this industry now faces the dual pressures of AI automation and EU regulation [17]. Thus, the impact of the extraterritorial regulation stems less from the legal text itself and more from the Moroccan industrial structure's dependence on European clients.

2. Structural Context

Politically, the European Commission must enforce a single legal framework to prevent regulatory fragmentation among its member states. If each of the 27 members created its own AI rules, the integrity of the single market would be threatened. The AI Act addresses this by effectively transferring these coordination costs to non-EU businesses. Applying the same standards to both internal and external companies is necessary to avoid accusations of distorting competition. As a result, this logic is applied equally to firms in non-member countries like Morocco.

The economic structure is asymmetrical. As one of the world's largest single markets, the EU possesses the negotiating leverage to demand regulatory compliance in exchange for market access. For Moroccan companies, however, abandoning their EU clients is not a viable alternative, as the revenue base of the country's outsourcing industry depends on European contracts [17]. This asymmetry follows a pattern established during the rollout of the GDPR, when non-EU companies that handled European customer data had no choice but to comply.

From a security perspective, the U.S.-China technological rivalry forms the backdrop. The United States promotes the global expansion of its AI models as a national strategy, while China targets developing markets with the free distribution of open-weight models [3]. In this context, the EU is seeking to assert its influence not through competition over models but through competition over norms. Countries in Africa and the Middle East, including Morocco, which are not fully aligned with either the U.S. or China, must now contend with EU regulations as a third major force. Libya's participation in the Geneva AI governance dialogue [16] can be interpreted as an attempt to secure its position amid these multipolar regulatory pressures.

3. Historical Precedents and Comparison with Similar Cases

The most direct precedent is the GDPR. Implemented in 2018, the GDPR explicitly established its extraterritorial application to all businesses processing the data of EU data subjects. At the time, multinational corporations faced substantial compliance costs, including appointing EU representatives and data protection officers. The AI Act follows this model, simply expanding its scope from data processing to the supply and use of AI systems. However, the AI Act's extraterritorial impact is broader, as it goes a step further than the GDPR by potentially regulating not only "providers" but also "users" under specific conditions [1].

The DSA demonstrates a similar logic of extraterritorial expansion. The designation of ChatGPT, Reddit, and Roblox as VLOPs [9][10] was based on a single criterion—the size of their user base within the EU, not their corporate location. With TikTok and Meta already subject to the same rules [12], the EU had already gained experience with extraterritorial enforcement in platform regulation. The AI Act is essentially transplanting this experience into the domain of AI systems.

From the perspective of developing countries, relevant precedents are scarce. During the GDPR implementation, companies in Africa and the Middle East generally reacted passively. The case of Morocco, where the domestic media identified specific risks for key industries, is relatively unusual [1]. This reflects Morocco's high dependence on service exports to Europe, a structure in which regulatory risks quickly translate into tangible employment problems [17].

4. Key Variables Shaping Future Developments

The first variable is the European Commission's enforcement intensity. Although the text of the AI Act allows for broad extraterritorial application, it is uncertain whether actual enforcement and penalties will focus on companies within the EU or extend to their non-EU partners. A key indicator will be whether the transparency obligations, enforced from August 2026 [2], are substantively applied to non-EU businesses in practice.

The second variable is the pace of domestic legislative responses in third countries like Morocco. The CNDP's notification to political parties regarding the labeling of AI-generated content before the general election [5] indicates that Morocco already has some elements of an independent regulatory system. If this domestic framework evolves toward alignment with EU standards, the dual compliance burden on Moroccan firms could be alleviated. If, however, the two systems remain misaligned, the burden will intensify.

The third variable is the negotiating power of the call center and BPO industry. The survival of the sector hinges on whether the "proactive and fair policies" demanded by the UMT-affiliated federation [17] are translated into concrete government action. With the industry facing simultaneous pressures from automation-driven restructuring and the costs of EU compliance, an employment shock is likely to materialize if the Moroccan government fails to implement measures to support industrial transition.

The fourth variable is the competition with U.S. and Chinese norms. As long as China continues its strategy of freely distributing open-weight models in African markets [3], the EU's high-cost compliance model may become less attractive. Whether Moroccan companies are increasingly incentivized to shift their business focus from European clients to other markets with lighter regulatory burdens will be a key test of the effective binding power of EU regulations.

3 credits are required from here

The body beyond the scenario analysis is available with credits.

Sign in to continue reading

*This text is an AI translation of an original written in Korean. Some translations or nuances may be inaccurate.

This report is an in-depth analysis planned by an EAI researcher, grounded in sophisticated AI-assisted research, and finalized by the EAI researcher.

← Back · ← Home · ← Back to list