The EU AI Act for US Companies: Who Is Actually in Scope

The EU AI Act for US Companies: Who Is Actually in Scope

American companies often assume the EU AI Act is Europe's problem. It is not. Like GDPR before it, the Act reaches beyond EU borders. If your AI system's output is used in the EU, you can be in scope no matter where your company sits.

Here is who the Act actually covers, how its risk tiers work, and what a US company should do about it.

Why It Reaches US Companies

The Act applies to providers and deployers of AI systems whose output is used within the EU, regardless of where the provider is established. If you sell AI-enabled products to EU customers, embed AI in services used by people in the EU, or your platform's AI outputs reach EU users, the Act can apply to you. GDPR taught this lesson already. The location of your headquarters does not decide scope. Where your product is used does.

The Risk Tiers

The Act sorts AI uses by risk, and your obligations follow the tier.

Most of the compliance weight lands on high-risk systems. The first job is figuring out which tier each of your AI uses falls into.

The Stakes

The Act's obligations phase in over time, and its penalties are significant. For the most serious violations, fines can reach into the tens of millions of euros or a percentage of global annual revenue, whichever is higher. This is not a regime to discover after the fact.

What to Do Now

None of this is wasted effort even if your EU exposure is small. The same governance stands up to customer reviews, other regulations, and your board.

How It Fits With Other Frameworks

The EU AI Act is a law, not a management system. An ISO 42001 program or alignment with the NIST AI Risk Management Framework gives you the structure to meet it: the inventory, risk assessment, documentation, and oversight the Act expects. Build the program once and it serves the Act, your customers, and the next regulation.

Frequently Asked Questions

We are a US company with no EU office. Are we really in scope?

Possibly. The Act follows where AI output is used, not where your company is based. If your AI reaches EU users or customers, it can apply, the same way GDPR does.

What triggers the heaviest obligations?

High-risk classification. AI used in areas like hiring, credit, education, and critical infrastructure carries requirements for risk management, documentation, human oversight, and conformity assessment.

How does ISO 42001 help with the EU AI Act?

It provides the management-system structure the Act assumes: inventory, risk assessment, documentation, and oversight. It does not replace the law, but it makes meeting it far more manageable.

If your AI reaches customers or users in the EU, the first step is knowing which systems are in scope and at what tier. A scoped assessment answers that. Talk with a senior advisor at JBW Group.

← Back to all posts