Does the EU AI Act Apply to US Companies? (Spoiler: Almost Certainly Yes)

The short answer: yes. The EU AI Act applies to any company — wherever incorporated — that places an AI system on the EU market, puts it into service in the EU, or whose system’s output is used in the EU. A US company with no European office, entity, or employees is fully in scope the moment EU users can use its AI product, or the moment its AI’s output reaches the EU. This is the same extraterritorial logic that made GDPR a global standard — and the deadlines are already running.

Where the law says so

Article 2 of the AI Act sets the territorial scope. It covers, among others:

  • providers (you build or sell the AI system) placing AI systems on the EU market or putting them into service in the EU — irrespective of where the provider is established;
  • providers and deployers located outside the EU, where the output produced by the AI system is used in the EU;
  • deployers (business users of AI) established in the EU;
  • importers and distributors bringing your system into the EU.

The second bullet is the one that surprises US founders: you can be in scope without selling anything in Europe, if your system’s output ends up used there.

The five scenarios founders actually ask about

1. «US SaaS, some EU users signed up themselves.» In scope. Your product is available on the EU market; you’re a provider placing an AI system on the market. Article 50 transparency duties (from August 2, 2026) apply to your chatbots and generated content.

2. «We only sell to US customers, but they have EU offices using our tool.» Likely in scope via the output-used-in-the-EU rule and your customer’s EU deployment. Enterprise buyers will push AI Act compliance duties into contracts either way.

3. «Our API is integrated by a European app.» In scope. Depending on the setup, you’re a provider whose system is placed on the EU market via the integrator — and your contract with the EU customer will allocate the compliance work. Expect AI Act clauses in every EU enterprise deal from now on.

4. «We geo-block the EU.» Genuinely out of scope for market-placement — if the block is real (payment, IP, ToS) and your output isn’t used in the EU. This is a legitimate short-term strategy; it’s also a decision to forfeit the EU market to competitors. If EU expansion is on your roadmap, the cheaper move is usually compliance, not exile.

5. «We’re just fine-tuning open models / doing R&D.» Pure scientific R&D and pre-market development activity is carved out — until you place the result on the market. The exemption ends where your go-to-market begins.

Which obligations hit a US company, and when

The full calendar is in our EU AI Act timeline 2026–2028. The compressed version for a non-EU provider:

Already in forceAug 2, 2026Dec 2, 2027 / Aug 2, 2028
Prohibited practices (since 02.2025) — social scoring, manipulation, emotion inference at work/schoolArticle 50 transparency — chatbot disclosure, AI-content marking, deepfake labels (details)High-risk obligations (Annex III, then Annex I) — risk management, documentation, conformity assessment
AI literacy duty (since 02.2025)Watermarking grace to 02.12.2026 for systems already on the marketPlus: non-EU providers of high-risk systems must appoint an EU authorised representative
GPAI model duties (since 08.2025)

Also on the calendar: from December 2, 2026, two new prohibitions added by the 2026 Omnibus apply — AI systems generating CSAM or non-consensual intimate content.

Penalties scale to global turnover: up to €35M/7% for prohibited practices, €15M/3% for most other violations (for SMEs and startups, each cap applies at the lower of the two amounts) — and “we’re a US company” is not a defence; it’s the fact pattern the extraterritorial clause was written for.

«But can they actually enforce against us?»

The honest answer: enforcement against a company with zero EU nexus is harder — and betting your EU go-to-market on that is a bad trade. Three reasons:

  1. Your customers enforce first. EU enterprises are already pushing AI Act warranties into vendor contracts. Non-compliance doesn’t show up as a fine; it shows up as a lost deal or an indemnity you can’t sign.
  2. Market surveillance has levers — from compelling app stores and distributors to withdraw products, to fining the EU importers and deployers who use you (who then stop using you).
  3. You’ll build the nexus yourself. The moment you open an EU entity, hire there, or bank there — everything retroactively matters. Cheaper to be clean before you land.

What a US company should do this quarter

  1. Scope check (1 day). Map EU exposure: users, revenue, integrations, output flows. Decide: comply or genuinely geo-block.
  2. Article 50 sprint (before Aug 2). Chatbot disclosures, content marking, deepfake labels — the three-week plan is here.
  3. Prohibited-practices audit (1 day). Anything on the roadmap touching social scoring, manipulation, emotion inference at work/school — kill or redesign now.
  4. High-risk triage (half a day). If your product smells like Annex III (hiring, credit, education, insurance), calendar a readiness project for early 2027 — the December 2027 deadline is a project, not a form.
  5. Paper trail. Document all of the above; EU buyers will ask before regulators do.

FAQ

Does the EU AI Act apply to US companies with no EU office?

Yes — to any company placing an AI system on the EU market or whose AI output is used in the EU, regardless of where it’s established.

Do we need an EU entity to comply?

No. Compliance is about your product and processes. (Non-EU providers of high-risk systems will additionally need an EU authorised representative by the high-risk deadline.)

Can we avoid the AI Act by geo-blocking Europe?

If the block is real and your output isn’t used in the EU — yes. It’s a market-exit decision, not a compliance strategy.

What applies to a US company first?

The rules already in force (prohibited practices, AI literacy, GPAI duties) and Article 50 transparency from August 2, 2026. High-risk obligations follow in December 2027.

Is the AI Act like GDPR in reach?

Same extraterritorial design, sharper teeth: the top fine tier reaches 7% of global turnover (GDPR tops out at 4%), and the output-used-in-the-EU trigger catches companies that GDPR’s targeting tests might miss.

Find out exactly which rules apply to your product

Montaire & Co.’s Europe Risk Scan maps your product against the AI Act, GDPR, and the rest of the EU stack — fixed fee, written report, one week.

30 minutes · senior advisor · no charge, no obligation

General information, not legal advice. Status as of July 16, 2026.