Skip to main content
All articles

AI Governance

Does the EU AI Act Apply to Your U.S. Business? Roles, Scope, and Dates

By RiskSensai6 min read
Editorial archive date
First published
Facts checked

The archive date places this article in the editorial collection. It is not an original publication date. Guidance reflects the fact-check date above.

Does the EU AI Act Apply to Your U.S. Business? Roles, Scope, and Dates: original RiskSensai editorial cover

A U.S. address does not settle the question

Start with where the AI system is offered and where its output is used. A company can develop software in the United States and still supply an EU-facing AI service. Another company may use a system internally with no relevant EU connection. The facts are different even when both vendors describe their product as “AI powered.”

The Commission's Article 2 explorer describes scope that can include third-country providers supplying systems into the Union and providers or deployers whose system outputs are used there.1 It is a useful starting reference, not an automated legal determination. The explorer also warns that affected provisions are not fully updated for Digital Omnibus amendments; have the current consolidated text checked before drawing a company-specific conclusion.

This guide is for organizing that review. It does not decide whether a particular product complies, classify a system conclusively or replace legal advice.

First establish your role

Using an AI application is different from developing and supplying one. Identify whether the business is a provider, deployer, importer, distributor or another participant, and distinguish an AI system from an underlying general-purpose model.

Do not assume the model vendor handles every obligation of the application you build around it. Equally, buying a chatbot does not automatically turn your company into a model provider. Record the system, intended purpose, branding, configuration and contractual relationship.

Changes can matter. The Commission's Article 25 explanation highlights circumstances in which rebranding, substantial modification or a changed purpose can alter high-risk-system provider responsibilities.2 Because that page carries an amendment disclaimer, use it to identify review questions, then verify the applicable current text with appropriate expertise.

Original scope-review worksheet

Complete one record per materially distinct system or use. Keep evidence and uncertainty alongside the answer.

Review areaFacts to collectQuestion to resolve
System identityApplication, supplier, version and model relationshipWhat exactly is being assessed?
Business roleWho develops, brands, supplies and uses it?Which responsibilities attach to this activity?
EU connectionMarket offering, deployment location and output destinationWhich territorial-scope provision is relevant?
Intended purposeActual task, affected people and decision consequencesDoes the use require prohibited/high-risk/transparency review?
ChangesBranding, modifications, new purpose and permissionsCould the role or classification change?
Applicable dateObligation category and transition conditionsWhich current milestone applies?
Other lawsPrivacy, employment, consumer and sector rulesWhat remains applicable independently?
Decision recordReviewer, sources, date, limits and next triggerWhat is resolved, and what still needs advice?

“No EU office” is one fact, not a complete conclusion. “Output may be used in the EU” also needs a precise explanation of the activity; do not mark every Internet-connected system covered by default.

Dates changed: use the current official timeline

Checked October 1, 2026: The Commission announced that the AI Omnibus entered into force on July 27, 2026.3 Its updated implementation timeline incorporates those amendments.4 Older articles that describe every high-risk obligation as applying in August 2026 can now mislead readers.

Milestone in current Commission timelineWhat to distinguish
February 2, 2025Initial general provisions and prohibitions milestone; later amendments must be considered
August 2, 2025General-purpose-model and governance milestone
August 2, 2026Article 50 transparency obligations and applicable enforcement milestone
December 2, 2026New prohibitions and a limited Article 50(2) transition for certain existing synthetic-content systems
December 2, 2027Annex III high-risk-system rules milestone
August 2, 2028High-risk AI embedded in regulated Annex I products milestone

The table is an orientation to categories, not a company-specific legal schedule. Transition conditions, existing-system provisions, exact role and use can affect the analysis. A later high-risk date does not imply that every other rule is postponed. The Omnibus also changed some provisions, including AI-literacy arrangements, so do not reuse old summaries without review.3

Keep a reviewed deadline record for each applicable obligation. Record the official source checked and the date of review. A compliance calendar populated from a generic AI blog is not a sound substitute.

Worked example: a U.S. hiring-software supplier

Fictional scenario: A U.S. company sells an AI-assisted applicant-ranking feature to customers that recruit people in EU locations. The product uses a third-party model but is sold under the company's own name.

The team documents the application boundary, ranking function, users, affected applicants and how output influences hiring. It does not assume the underlying model supplier's general terms answer the application-provider question. It flags employment-related high-risk classification for qualified review and checks the current transition rules rather than taking the revised date as permission to ignore governance.

Separately, the team examines data protection and employment requirements, transparency, human review and customer instructions. It preserves evidence of testing and limitations. Removing the word “ranking” from a sales page would not change the actual intended use.

The immediate output is a scope memorandum with unresolved questions and owners, not a self-issued “AI Act compliant” label. The decision may lead to restrictions, further evidence gathering or a changed product scope before deployment.

Worked contrast: an internal drafting tool

A second fictional company uses AI to rewrite public U.S. marketing copy, with staff checking every output. It has no identified EU offering or EU output-use relationship for that activity. Its reviewer documents those facts and checks whether an exception or scope conclusion is appropriate.

That conclusion cannot automatically cover a later customer-support connector, EU sales campaign or employee-screening use. It also does not remove ordinary privacy, security, intellectual-property or consumer obligations. Reassessment follows material changes in purpose and reach.

Prepare evidence before asking for a conclusion

Bring reviewers a useful packet: product description, intended-purpose statement, screenshots of actual behavior, user instructions, data flows, model/supplier relationships, marketing destinations and change history. Redact unnecessary personal data and keep sensitive architecture in appropriate restricted channels.

List the legal questions explicitly. For example: “Does this output-use relationship fall within territorial scope?” is more actionable than “Are we compliant?” A record should distinguish a supplier representation, an internal assumption and a reviewed conclusion.

Ask what evidence would change the decision. A system described as advisory may be used as an automatic gate in practice. Customer configuration and instructions can therefore matter as much as the original feature description.

Questions U.S. businesses ask

Does the Act apply only to EU companies?

No. The scope can extend to relevant third-country activities. The exact connection and role need assessment.

Does the high-risk extension mean we can wait?

Not for every obligation. Transparency, prohibitions, general-purpose-model rules and other laws have separate considerations. Use the applicable category and transition terms.

Does NIST AI RMF establish EU AI Act compliance?

No. It can organize risk work but is voluntary guidance with a different purpose. The NIST AI RMF business guide provides a practical worksheet; legal scope and obligations remain separate.

What is a useful next step?

Inventory one EU-relevant use, complete the scope record and obtain a reviewed answer to the unresolved questions. The readiness assessment is a general self-reported planning entry point, not an AI Act legal assessment.

Sources and references

  1. European Commission AI Act Service Desk. Article 2: Scope. Commission explorer; its amendment disclaimer requires checking the current consolidated legal text for individual conclusions. ↩

  2. European Commission AI Act Service Desk. Article 25: Responsibilities along the AI value chain. Commission explanation of role changes; page warns its text is not fully updated for Omnibus amendments. ↩

  3. European Commission. AI Omnibus enters into force (2026-07-27). Official announcement confirms enactment and changed timelines, rather than treating the 2025 proposal as pending. ↩ ↩2

  4. European Commission AI Act Service Desk. Timeline for the Implementation of the EU AI Act. Current official timeline incorporating Digital Omnibus on AI; checked October 1, 2026. ↩

General educational information, not legal advice, a professional audit opinion, certification, or a guarantee. Applicability and conclusions depend on your organization and should be assessed by an appropriately qualified professional.

Prepared with AI assistance and automated editorial checks. This does not indicate independent professional review or verification of your organization.

  • EU AI Act
  • AI Governance
  • Regulatory Scope
Connecting to your conversation workspace…