Applied Oversight

EU AI Act · For US companies

The EU AI Act doesn't stop at the EU border.

Timeline last verified against the amended Act: July 11, 2026

The EU's Artificial Intelligence Act is the first comprehensive AI law anywhere, and it was written to travel: it can apply to a company with no European offices, no European customers it knows about, and no idea it's in scope. Most US companies are genuinely outside its reach. Some are inside it and haven't checked. This page is how you check.

The three hooks — how a US company ends up in scope

The Act's reach (Article 2) doesn't turn on where your company is incorporated. It turns on three questions.

1. Do you operate in the EU? A subsidiary, branch, or establishment in any EU country makes you a deployer in scope for the AI systems used there. This is the obvious hook. Most companies with EU offices already know they have EU law to deal with.

2. Do you place AI-powered products or services on the EU market? If your product ships to EU users and AI is part of it, the Act can treat you as a provider, regardless of where you're established. "Placing on the market" is about where the product goes.

3. Is the output of your AI used in the EU? This is the hook companies miss. The Act expressly covers providers and deployers located outside the EU where the output produced by the AI system is used in the European Union. Concretely: a US company using an AI tool to screen candidates for its Dublin office. A US insurer whose underwriting model prices policies for EU residents. A US platform whose recommendation engine serves EU users. None of these require an EU entity — the output crossing the border is enough.

If none of the three describe you (no EU footprint, no EU-bound products, no EU-touching output), the Act most likely doesn't reach you today. The Act also carves some things out entirely, whatever the hooks say: military and national-security uses, AI developed and used solely for scientific research, and purely personal, non-professional use. That's a real answer, and it's worth documenting that you checked.

What the Act actually does

The Act sorts AI systems into risk tiers, and your obligations depend on the tier and on your role: whether you built the system (provider) or use it (deployer). Most US mid-market companies are deployers.

  • Prohibited practices are banned outright and already in force: social scoring, manipulative techniques that exploit vulnerabilities, emotion recognition in the workplace and education (narrow medical/safety exceptions), untargeted scraping of facial images, and more. These bans apply to private companies as well as governments.
  • High-risk systems are permitted but heavily regulated. The high-risk list includes exactly the systems mid-market companies actually use: AI in hiring and employment decisions, credit scoring, and life and health insurance pricing. If you deploy these with an EU hook, this is the tier that matters to you.
  • Transparency obligations are lighter: chatbots must disclose they're AI, synthetic media must be labeled, and people exposed to emotion recognition or biometric categorization must be told.
  • Minimal risk covers most AI systems and is largely unregulated.

One regime sits outside the tiers. General-purpose AI models, the foundation models underneath chatbots and copilots, carry their own provider obligations, in force since August 2025: technical documentation, an EU copyright-compliance policy, and a public summary of training content. If you build such models and offer them in the EU, that regime is yours; if you only use tools built on them, it isn't.

What a US deployer owes, if covered

For a covered deployer, the duties are concrete and operational, and they add up to a program you have to build and run. In plain terms:

  • Already in force (since February 2025): ensure your staff have adequate AI literacy for the systems they operate, and screen your AI portfolio against the prohibited-practices list.
  • From August 2, 2026: transparency duties (chatbot disclosure and synthetic-content labeling).
  • From December 2, 2027, for high-risk systems (hiring, credit, insurance among them): use the system according to the provider's instructions; assign human oversight to people with real competence and authority; ensure the input data you control is relevant and representative; monitor operation and report serious incidents; keep the system's logs at least six months; tell workers and their representatives before deploying AI on them in the workplace; tell individuals when a high-risk system is used in decisions about them; and, for some categories (including credit and life/health insurance), complete a fundamental-rights impact assessment before first use.
  • One trap worth knowing by name: if you rebrand a vendor's AI system under your own name, substantially modify it, or repurpose it into a high-risk use, you can stop being a deployer and become the provider. You inherit the full obligation set in the next section, including the conformity assessment, CE marking, and registration your vendor was supposed to carry. Vendor AI is not automatically someone else's problem.

And if you're the provider

If hook #2 describes you — your AI-powered product reaches the EU market — your obligations are heavier than a deployer's, and they're front-loaded: most of the work has to be finished before the product can legally be there.

  • Conformity assessment, before market entry. For a high-risk system, the provider must put it through a conformity assessment that demonstrates it meets the Act's requirements (risk management, data governance, technical documentation, logging, human oversight, accuracy and cybersecurity), then issue an EU declaration of conformity and affix CE marking. For most of the high-risk categories US companies hit (hiring, credit, insurance), the provider runs a documented self-assessment; no outside auditor signs off. You still have to build the evidence.
  • Registration. Before the system is placed on the EU market, the provider registers itself and the system in the EU's public AI database.
  • An authorized representative inside the EU. A provider with no EU establishment must appoint, by written mandate, an authorized representative established in the Union, and must do it before making a high-risk system available there. The same duty applies to non-EU providers of general-purpose AI models. The Act does not accept "we have no European entity" as a reason these duties can't attach; it makes you create the European point of contact.
  • And it doesn't end at launch: quality management, post-market monitoring, incident reporting, and corrective action are ongoing provider duties.

The timeline (as amended)

The EU amended the Act's own schedule in June 2026. The "Digital Omnibus" package pushed the high-risk dates back and added new prohibitions. These are the current dates:

  • FEB 2 2025

    Prohibited practices + AI literacy

    Live now

    The prohibited-practices ban and the AI-literacy duty. Both are already in force, for deployers and providers alike.

  • AUG 2 2025

    General-purpose AI rules + penalties

    Live now

    The GPAI provider regime and the Act's penalty framework, both in force.

  • AUG 2 2026

    Transparency duties

    Upcoming

    Chatbot disclosure and synthetic-content labeling (systems already on the market get until Dec 2, 2026 for machine-readable marking).

  • DEC 2 2026

    New prohibitions

    Upcoming

    Added by the Omnibus: bans on AI generating non-consensual intimate imagery and CSAM.

  • DEC 2 2027

    High-risk obligations

    Ahead

    The hiring / credit / insurance tier: the full deployer and provider obligation sets described above (was Aug 2026 before the amendment).

  • AUG 2 2028

    Product-embedded high-risk

    Ahead

    High-risk rules for AI embedded in regulated products take effect.

Timeline last verified July 11, 2026, against the amended Act. The amending regulation awaits Official Journal publication; we re-verify this page on every EU development our watch system confirms.

Penalties scale to the violation: up to €35M or 7% of worldwide turnover for prohibited practices, and up to €15M or 3% for most other breaches. For a mid-market company, the practical risk is less the headline fine than discovering an obligation after you've built a process that violates it.

What to do with this

  1. Answer the three hooks in writing. A one-page determination ("we checked EU applicability on this date, here's what we found") is cheap, and it's the difference between being out of scope and being able to show you're out of scope.
  2. If any hook might apply, inventory the systems it touches. Scope attaches system by system, not company-wide. The AI screening résumés for your EU office is in; the AI routing your US warehouse tickets is not.
  3. Watch the August 2026 date even if you're only lightly exposed. Chatbot disclosure and content labeling are the first obligations most companies actually feel, and they are only weeks away.
  4. Don't wait on the 2027 high-risk date if you deploy hiring, credit, or insurance AI. Human oversight, data quality, logging, and impact assessments are program-building work, and most of it doubles as compliance with the US state laws that are already in force.
  5. If you sell AI into the EU, start earliest of all. The provider workload (conformity assessment, CE marking, registration, an authorized representative on EU soil) is the longest-lead-time item on this page, and EU market entry waits on it.

This page is educational commentary and is not legal advice. Every claim traces to the text of Regulation (EU) 2024/1689 as amended; timeline dates reflect the June 2026 Digital Omnibus amendments.

Ten minutes of questions.
A one-page map of your AI obligations.

Get your free exposure scan