For US companies · Regulation (EU) 2024/1689
You do not need an EU office to be covered by the EU AI Act.
If you are a US company whose AI product reaches people in Europe, this page explains what applies to you, when, and what it costs to get it wrong.
Or skip ahead and book a 15-minute call
1 · Why it reaches you
The Act follows the output, not the company. It applies to providers and deployers established outside the Union where the output produced by their AI system is used inside it.
Your incorporation, your hosting region, and where your model weights sit are not the test. A Delaware company running inference in us-east-1 for a customer in Munich is inside the Act's reach.
The version that catches teams out is indirect. You sell to a US enterprise; that enterprise has employees in Dublin; your system screens those employees. The output is used in the Union, and you are likely in scope — even though you never signed an EU customer.
2 · Which role you play
Obligations attach to roles, not to companies, and one company can hold different roles for different systems.
Provider. You develop an AI system and place it on the EU market under your own name or trademark. This carries the heaviest set of duties — documentation, quality management, conformity readiness, post-market monitoring. If you ship an AI product, this is usually you.
Deployer. You use an AI system under your own authority. Lighter, but not light: human oversight, use in line with instructions, and monitoring duties.
Importer and distributor. Mostly relevant when you resell or channel someone else's system into the EU market.
One trap worth naming: substantially modifying a third-party system, or putting your name on it, can turn a deployer into a provider. Teams that fine-tune a foundation model and ship it as a feature should check which side of that line they are on.
3 · Which tier your system falls into
The Act is risk-tiered. Classification decides every obligation that follows, which is why it is the first thing worth getting right.
- Banned outright since 2 February 2025 Unacceptable
- Social scoring, certain biometric categorisation, emotion inference in workplaces and schools, and other listed practices. If you are here, the answer is to stop, not to comply.
- Obligations apply from 2 December 2027 High-risk
- Annex III use cases — employment and worker management, credit scoring, education, essential services, and others. This is where most US SaaS, FinTech, HR Tech and HealthTech products land if they land anywhere.
- Transparency duties from 2 August 2026 Limited risk
- Systems people interact with directly, or that generate synthetic content. The duty is disclosure: users must know they are dealing with AI, and generated content must be marked.
- No specific obligations Minimal risk
- The majority of AI systems. Spam filters, recommendation engines in low-stakes contexts, most internal tooling. Worth documenting the conclusion — not worth a programme.
4 · The dates that matter
The high-risk deadline moved. The Digital Omnibus on AI, adopted in June 2026, deferred Annex III high-risk obligations from 2 August 2026 to 2 December 2027, and Annex I embedded systems to 2 August 2028.
2 August 2026 is still live for Article 50 transparency: disclosing that users are interacting with AI, and marking generated content. That was not deferred.
Treating December 2027 as breathing room is the mistake. Conformity work — data governance, documentation, oversight design, logging architecture — typically runs 12–18 months. The runway is shorter than the date suggests.
Being late is not a quiet failure. Authorities can require corrective action, restrict availability, or order a system withdrawn from the Union market.
5 · What exposure looks like
Fines are set as the higher of a fixed ceiling or a percentage of total worldwide annual turnover — group revenue, not EU revenue.
- €35M or 7%
- Engaging in a prohibited practice
- €15M or 3%
- Breaching most other obligations, including the high-risk duties
- €7.5M or 1%
- Supplying incorrect, incomplete or misleading information to authorities
Lower caps apply to SMEs and start-ups, for whom the lower of the two figures is used rather than the higher.
In practice the commercial cost usually arrives first. European enterprise procurement has started asking suppliers to evidence their AI Act posture, and "we are working on it" loses deals well before a regulator is involved.
General information — not legal advice
This page summarises Regulation (EU) 2024/1689 for orientation. It is not legal advice and does not create a client relationship. The Act's application depends on specific facts about your systems, roles and deployments, and guidance from the Commission and national authorities continues to develop.
Read the official text at EUR-Lex, check the current Commission implementation timeline, and take advice from qualified counsel before acting.
Last reviewed 20 July 2026 against the Commission's published timeline, following the Digital Omnibus on AI.
Find out which of these applies to you.
Six questions, two minutes, no email required. You get your likely scope, tier and evidence gap before you talk to anyone.