All resources
Written for: Selling into the EU and hitting AI Act questions

Does the EU AI Act apply to my US company?

You have no EU office, no EU entity and no plans for one. The Act can still reach you — and one obligation has applied since February 2025. What is actually in force, what moved, and what to do about it.

No EU office. No EU entity. No plans for one. You can still be in scope — and the test is broader than the one you already know from GDPR.


The short answer

If an AI system you build or use produces an output that gets used inside the European Union, the Act can reach you. It does not matter where your company is incorporated, where your servers are, or whether you have ever sold to a European customer directly.

That surprises people, so it is worth being precise about where it comes from.


Three ways in

Article 2 sets the scope. There are three separate hooks, and you only need one.

  1. You place an AI system on the EU market — you sell, license or otherwise make it available there, wherever you are established.
  2. You are a deployer located in the EU — not you, if you are reading this from the US.
  3. You are outside the EU, but the output produced by your AI system is used in the Union.

The third is the one that catches US businesses, and it is worth reading twice. Not your company is in the EU. Not you targeted EU customers. The output is used there.

Some concrete shapes that fall inside it:

  • A US software company whose product includes an AI feature, used by a customer with European staff.
  • A US recruiting firm screening or ranking candidates for a role based in Europe.
  • A US agency generating content or recommendations that a European client publishes.
  • A US company running an AI support agent that answers a customer in Ireland.

Why this is broader than GDPR

Most US businesses have internalised the GDPR test: are you offering goods or services to people in the EU, or monitoring their behaviour? Both of those have an element of aiming at Europe.

The AI Act's output hook does not. There is no targeting requirement, no intent test, and no need for personal data to be involved at all. A system producing outputs that end up in use in the Union is enough.

So a business that concluded years ago that GDPR did not reach it should not assume the same answer here. It is a different question with a wider net.


Which role are you in?

Obligations differ sharply depending on what you do, and this is the question to settle first, because everything downstream follows from it.

Role You are this if Weight of obligations
Provider You develop an AI system, or have one developed, and put it on the market or into service under your own name Heaviest
Deployer You use an AI system under your own authority — the most common role for a business that buys AI rather than builds it Moderate
Distributor / Importer You make someone else's AI system available in the EU chain Lighter, but real

Two traps worth naming.

Buying does not always make you only a deployer. Put your own name on a system, or substantially modify one, and you can become its provider — with a provider's obligations. Fine-tuning a model and shipping it as your feature is exactly the kind of thing that can cross this line.

You can be both. A software company is typically a provider for the AI in its product and a deployer for the AI tools its own staff use internally. Those are two different sets of duties over two different sets of systems, which is why the inventory matters.


What is actually in force

Here is where most reporting goes wrong, because the timeline has been amended. The dates below reflect the position on 4 August 2026, after the Digital Omnibus on AI — Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force since 27 July 2026 — amended the original schedule.

Date What applies Status
2 February 2025 Prohibited practices (Art. 5). AI literacy duty (Art. 4). In force
2 August 2025 General-purpose AI model obligations, governance structure, penalties In force
2 August 2026 Transparency obligations (Art. 50) — with Art. 50(2) not yet applying to systems already on the market In force
2 December 2026 Art. 50(2) reaches legacy systems; further prohibited practices Coming
2 December 2027 Stand-alone high-risk systems under Annex III — moved from 2 August 2026 Coming
2 August 2028 AI embedded in regulated products under Annex I — medical devices, machinery, vehicles Coming

The two nobody notices

The headlines have been about high-risk systems and the delay. Meanwhile two obligations have been live since February 2025, with no size threshold and no transition period:

Prohibited practices (Art. 5). A short list of uses that are simply not allowed — including emotion inference in the workplace and untargeted scraping of facial images to build recognition databases. If you are doing one of these, no amount of documentation fixes it. The answer is to stop.

AI literacy (Art. 4). Providers and deployers must take measures to ensure the people dealing with AI on their behalf have a sufficient level of AI literacy, in proportion to context and risk. There is no employee-count exemption. A ten-person company using AI in scope owes this the same as a ten-thousand-person one.

Art. 4 is the cheapest obligation in the entire Act to satisfy and among the most commonly unmet. It is usually a documented training session and a record that people attended.

And the one most likely to change your product

Article 50 transparency applied on 2 August 2026. In broad terms: people must be told when they are interacting with an AI system unless it is obvious; synthetic audio, image, video and text must be marked machine-readably; deepfakes and AI-generated text published on matters of public interest must be disclosed; and people must be told when emotion-recognition or biometric categorisation is being used on them.

For a lot of US businesses this is the first part of the Act that actually bites, and it is a product change rather than a paperwork exercise. If your AI talks to people in Europe, the disclosure question is live now, not in 2027.


Are you high-risk?

This is the tier everyone worries about, and most businesses are not in it — but the ones that are usually do not realise, because it is the use case that makes a system high-risk, not the technology.

Annex III covers stand-alone systems used for:

  • Employment and worker management — recruitment, screening, filtering applications, evaluating candidates, promotion and termination decisions, task allocation, monitoring performance
  • Education and vocational training — admissions, evaluating learning outcomes, proctoring
  • Essential private and public services — creditworthiness and credit scoring, risk assessment and pricing in life and health insurance, emergency triage
  • Biometrics — remote identification, categorisation by sensitive attributes, emotion recognition
  • Critical infrastructure, law enforcement, migration and border control, and administration of justice

If you are a recruiting firm, an HR software company, a lender, an insurance broker or an education provider, read that list again slowly. Your core product may be the thing the Act is aimed at.

The obligations that attach are substantial — risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness, registration. That is a programme of work, not a weekend.

Being in scope is not the same as being high-risk. Most businesses using AI for drafting, summarising, support and internal productivity land in the transparency or minimal tiers, where the obligations are far lighter. Knowing which of those describes you is the single most valuable thing to establish, because it determines whether you are looking at a disclosure change or a compliance programme.


What it costs to get wrong

Penalties are tiered: up to €35 million or 7% of worldwide annual turnover for prohibited practices; up to €15 million or 3% for most other breaches; up to €7.5 million or 1% for supplying incorrect or misleading information to authorities.

One provision genuinely matters for smaller businesses: for SMEs and start-ups, the fine is capped at whichever of the two figures is lower, not higher. That materially changes the exposure — but it does not remove it, and it says nothing about the commercial cost of a customer's procurement team deciding you are not worth the risk.

In practice, for most businesses this size, the enforcement risk is not the first thing to arrive. The customer question is. Which is why this shows up in vendor questionnaires long before it shows up in a regulator's letter.


"It got delayed, so we have time"

The high-risk deadline moved from August 2026 to December 2027. That is real, and it is reasonable to re-plan around it. Three cautions.

The delay is narrow. It applies to high-risk classification. Prohibited practices, AI literacy and now transparency are unaffected and already apply.

The dates have moved twice. They were amended by a regulation that entered force in July 2026. Anyone telling you today what the position will be in 2027 is guessing, and a plan whose only load-bearing element is a date is fragile by construction.

The work does not compress. Building an inventory, establishing human oversight and producing technical documentation for a high-risk system takes quarters. Starting in mid-2027 means doing it badly, under pressure, while a customer waits.

The better reason to act is not the deadline anyway. It is that your customers are asking now.


What to do this quarter

None of this requires a compliance department.

  1. Work out whether output reaches the EU. Not whether you sell there — whether anything your AI produces is used there, including through a customer. This is a conversation with sales and product, not with lawyers.
  2. Build the AI inventory. Every AI system you provide and every one you use, what it does, and who it affects. Nothing else can be answered without it.
  3. Check yourself against the prohibited list. Short, absolute, already in force.
  4. Close the Art. 4 gap. Documented AI training for the people using AI. It has been owed since February 2025 and it is a day's work.
  5. Handle the transparency questions. If people interact with your AI or consume its output, work out what disclosure you owe now that Article 50 applies.
  6. Then, and only then, ask whether anything is high-risk. Do it against the Annex III use cases, honestly, on a system-by-system basis.

Steps 1 through 5 are achievable in a few weeks. Step 6 is where the real scoping happens, and it is worth doing carefully rather than quickly.


What this guide does not do

It sets out the shape of the Act and the dates as they stand today. It does not tell you whether your systems are in scope or how they classify — that turns on what each system does, whose data it touches, who it affects and where those people are, and it genuinely differs between two companies that look similar from the outside.

It is not legal advice. It does not certify anything, and it does not establish that you meet any obligation.

And it will go out of date. This Act has been amended once already. Anything you read about it — including this — should be checked against the current text before you rely on it. The position above reflects 4 August 2026.


If you want the answer for your business

Atolus runs a structured assessment that starts with exactly this question. Before scoring anything, it works out which regulations actually reach you — from your jurisdiction, sector, data and what your AI does — and it classifies each of your AI systems so you know which tier you are actually in.

Most owners are surprised by that first answer, in both directions. Some discover the Act reaches them through a customer they had not thought about. Others discover that what they were bracing for does not apply at all, which is worth knowing before you spend anything.

Book a free 30-minute call — we will work through the scope question with you and tell you honestly whether this is something you need to act on now.


Atolus Intelligence LLC. Reflects the position at 4 August 2026, following Regulation (EU) 2026/1744. General information, not legal advice. Nothing here certifies or establishes compliance with any regulation.

Written:
Tue Aug 04 2026 00:00:00 GMT+0000 (Coordinated Universal Time)
Regulatory position reflects:
Tue Aug 04 2026 00:00:00 GMT+0000 (Coordinated Universal Time)

Want the answer for your own business?

A free 30-minute call. We will work through which of this actually applies to you, and be honest if none of it does.

Book a free 30-minute call