American companies often assume the EU AI Act is Europe's problem. It is not. Like GDPR before it, the Act reaches beyond EU borders. If your AI system's output is used in the EU, you can be in scope no matter where your company sits.
Here is who the Act actually covers, how its risk tiers work, and what a US company should do about it.
Why It Reaches US Companies
The Act applies to providers and deployers of AI systems whose output is used within the EU, regardless of where the provider is established. If you sell AI-enabled products to EU customers, embed AI in services used by people in the EU, or your platform's AI outputs reach EU users, the Act can apply to you. GDPR taught this lesson already. The location of your headquarters does not decide scope. Where your product is used does.
The Risk Tiers
The Act sorts AI uses by risk, and your obligations follow the tier.
- Unacceptable risk. A short list of prohibited practices, such as certain manipulative or social-scoring uses. These are banned outright.
- High risk. AI used in sensitive areas like employment, credit, education, and critical infrastructure. This tier carries the heaviest obligations: risk management, data governance, documentation, human oversight, and conformity assessment.
- Limited risk. Systems like chatbots and generated content carry transparency obligations. People must know they are interacting with AI or seeing AI-generated output.
- Minimal risk. Most AI uses fall here, with few specific obligations.
Most of the compliance weight lands on high-risk systems. The first job is figuring out which tier each of your AI uses falls into.
The Stakes
The Act's obligations phase in over time, and its penalties are significant. For the most serious violations, fines can reach into the tens of millions of euros or a percentage of global annual revenue, whichever is higher. This is not a regime to discover after the fact.
What to Do Now
- Inventory your AI and identify which systems touch the EU market.
- Classify each in-scope system by risk tier.
- For anything high-risk, map the obligations and the gap between them and your current practice.
- Build the documentation, human oversight, and governance the tier requires.
- Track the phased deadlines so obligations do not arrive unmet.
None of this is wasted effort even if your EU exposure is small. The same governance stands up to customer reviews, other regulations, and your board.
How It Fits With Other Frameworks
The EU AI Act is a law, not a management system. An ISO 42001 program or alignment with the NIST AI Risk Management Framework gives you the structure to meet it: the inventory, risk assessment, documentation, and oversight the Act expects. Build the program once and it serves the Act, your customers, and the next regulation.
Frequently Asked Questions
We are a US company with no EU office. Are we really in scope?
Possibly. The Act follows where AI output is used, not where your company is based. If your AI reaches EU users or customers, it can apply, the same way GDPR does.
What triggers the heaviest obligations?
High-risk classification. AI used in areas like hiring, credit, education, and critical infrastructure carries requirements for risk management, documentation, human oversight, and conformity assessment.
How does ISO 42001 help with the EU AI Act?
It provides the management-system structure the Act assumes: inventory, risk assessment, documentation, and oversight. It does not replace the law, but it makes meeting it far more manageable.
If your AI reaches customers or users in the EU, the first step is knowing which systems are in scope and at what tier. A scoped assessment answers that. Talk with a senior advisor at JBW Group.