A U.S. address does not settle the question
Start with where the AI system is offered and where its output is used. A company can develop software in the United States and still supply an EU-facing AI service. Another company may use a system internally with no relevant EU connection. The facts are different even when both vendors describe their product as “AI powered.”
The Commission's Article 2 explorer describes scope that can include third-country providers supplying systems into the Union and providers or deployers whose system outputs are used there.1 It is a useful starting reference, not an automated legal determination. The explorer also warns that affected provisions are not fully updated for Digital Omnibus amendments; have the current consolidated text checked before drawing a company-specific conclusion.
This guide is for organizing that review. It does not decide whether a particular product complies, classify a system conclusively or replace legal advice.
First establish your role
Using an AI application is different from developing and supplying one. Identify whether the business is a provider, deployer, importer, distributor or another participant, and distinguish an AI system from an underlying general-purpose model.
Do not assume the model vendor handles every obligation of the application you build around it. Equally, buying a chatbot does not automatically turn your company into a model provider. Record the system, intended purpose, branding, configuration and contractual relationship.
Changes can matter. The Commission's Article 25 explanation highlights circumstances in which rebranding, substantial modification or a changed purpose can alter high-risk-system provider responsibilities.2 Because that page carries an amendment disclaimer, use it to identify review questions, then verify the applicable current text with appropriate expertise.
Original scope-review worksheet
Complete one record per materially distinct system or use. Keep evidence and uncertainty alongside the answer.
| Review area | Facts to collect | Question to resolve |
|---|---|---|
| System identity | Application, supplier, version and model relationship | What exactly is being assessed? |
| Business role | Who develops, brands, supplies and uses it? | Which responsibilities attach to this activity? |
| EU connection | Market offering, deployment location and output destination | Which territorial-scope provision is relevant? |
| Intended purpose | Actual task, affected people and decision consequences | Does the use require prohibited/high-risk/transparency review? |
| Changes | Branding, modifications, new purpose and permissions | Could the role or classification change? |
| Applicable date | Obligation category and transition conditions | Which current milestone applies? |
| Other laws | Privacy, employment, consumer and sector rules | What remains applicable independently? |
| Decision record | Reviewer, sources, date, limits and next trigger | What is resolved, and what still needs advice? |
“No EU office” is one fact, not a complete conclusion. “Output may be used in the EU” also needs a precise explanation of the activity; do not mark every Internet-connected system covered by default.
Dates changed: use the current official timeline
Checked October 1, 2026: The Commission announced that the AI Omnibus entered into force on July 27, 2026.3 Its updated implementation timeline incorporates those amendments.4 Older articles that describe every high-risk obligation as applying in August 2026 can now mislead readers.
| Milestone in current Commission timeline | What to distinguish |
|---|---|
| February 2, 2025 | Initial general provisions and prohibitions milestone; later amendments must be considered |
| August 2, 2025 | General-purpose-model and governance milestone |
| August 2, 2026 | Article 50 transparency obligations and applicable enforcement milestone |
| December 2, 2026 | New prohibitions and a limited Article 50(2) transition for certain existing synthetic-content systems |
| December 2, 2027 | Annex III high-risk-system rules milestone |
| August 2, 2028 | High-risk AI embedded in regulated Annex I products milestone |
The table is an orientation to categories, not a company-specific legal schedule. Transition conditions, existing-system provisions, exact role and use can affect the analysis. A later high-risk date does not imply that every other rule is postponed. The Omnibus also changed some provisions, including AI-literacy arrangements, so do not reuse old summaries without review.3
Keep a reviewed deadline record for each applicable obligation. Record the official source checked and the date of review. A compliance calendar populated from a generic AI blog is not a sound substitute.
Worked example: a U.S. hiring-software supplier
Fictional scenario: A U.S. company sells an AI-assisted applicant-ranking feature to customers that recruit people in EU locations. The product uses a third-party model but is sold under the company's own name.
The team documents the application boundary, ranking function, users, affected applicants and how output influences hiring. It does not assume the underlying model supplier's general terms answer the application-provider question. It flags employment-related high-risk classification for qualified review and checks the current transition rules rather than taking the revised date as permission to ignore governance.
Separately, the team examines data protection and employment requirements, transparency, human review and customer instructions. It preserves evidence of testing and limitations. Removing the word “ranking” from a sales page would not change the actual intended use.
The immediate output is a scope memorandum with unresolved questions and owners, not a self-issued “AI Act compliant” label. The decision may lead to restrictions, further evidence gathering or a changed product scope before deployment.
Worked contrast: an internal drafting tool
A second fictional company uses AI to rewrite public U.S. marketing copy, with staff checking every output. It has no identified EU offering or EU output-use relationship for that activity. Its reviewer documents those facts and checks whether an exception or scope conclusion is appropriate.
That conclusion cannot automatically cover a later customer-support connector, EU sales campaign or employee-screening use. It also does not remove ordinary privacy, security, intellectual-property or consumer obligations. Reassessment follows material changes in purpose and reach.
Prepare evidence before asking for a conclusion
Bring reviewers a useful packet: product description, intended-purpose statement, screenshots of actual behavior, user instructions, data flows, model/supplier relationships, marketing destinations and change history. Redact unnecessary personal data and keep sensitive architecture in appropriate restricted channels.
List the legal questions explicitly. For example: “Does this output-use relationship fall within territorial scope?” is more actionable than “Are we compliant?” A record should distinguish a supplier representation, an internal assumption and a reviewed conclusion.
Ask what evidence would change the decision. A system described as advisory may be used as an automatic gate in practice. Customer configuration and instructions can therefore matter as much as the original feature description.
Questions U.S. businesses ask
Does the Act apply only to EU companies?
No. The scope can extend to relevant third-country activities. The exact connection and role need assessment.
Does the high-risk extension mean we can wait?
Not for every obligation. Transparency, prohibitions, general-purpose-model rules and other laws have separate considerations. Use the applicable category and transition terms.
Does NIST AI RMF establish EU AI Act compliance?
No. It can organize risk work but is voluntary guidance with a different purpose. The NIST AI RMF business guide provides a practical worksheet; legal scope and obligations remain separate.
What is a useful next step?
Inventory one EU-relevant use, complete the scope record and obtain a reviewed answer to the unresolved questions. The readiness assessment is a general self-reported planning entry point, not an AI Act legal assessment.
Sources and references
-
European Commission AI Act Service Desk. Article 2: Scope. Commission explorer; its amendment disclaimer requires checking the current consolidated legal text for individual conclusions. ↩
-
European Commission AI Act Service Desk. Article 25: Responsibilities along the AI value chain. Commission explanation of role changes; page warns its text is not fully updated for Omnibus amendments. ↩
-
European Commission. AI Omnibus enters into force (2026-07-27). Official announcement confirms enactment and changed timelines, rather than treating the 2025 proposal as pending. ↩ ↩2
-
European Commission AI Act Service Desk. Timeline for the Implementation of the EU AI Act. Current official timeline incorporating Digital Omnibus on AI; checked October 1, 2026. ↩

