In many cases, yes. A US business does not need an EU office to fall under the EU AI Act. The regulation applies to any business — wherever it is based — where AI system outputs are used by people in the EU. It is the same output-based reach US companies already know from GDPR.
The EU AI Act applies to US businesses where AI system outputs are used by people in the EU. This is established directly in Article 2(1)(c) of the regulation, which explicitly covers providers and deployers established in third countries — including the United States — where the output produced by the AI system is used in the Union.
A US business does not need an EU office, subsidiary, or establishment to be in scope. This is the same extraterritorial logic US companies already know from GDPR. The relevant question is not where your business is based — it is where your AI outputs are used.
Unlike some extraterritorial claims that rest on analogy or interpretation, the EU AI Act’s reach to US businesses is stated explicitly in the text of the regulation.
“This Regulation applies to: … (c) providers and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union.”
The United States is a third country under EU law. A US business that uses AI systems in a professional context — as a deployer — falls within Article 2(1)(c) where the outputs of those systems are used in the EU. The trigger is output use, not the location of the business.
The precise trigger under Article 2(1)(c) is that the output produced by the AI system is used in the Union. This is more specific than saying the regulation applies whenever a US business has EU customers.
A US business using AI purely internally, with no EU-facing outputs and no EU customers or employees, has a reasonable argument that it falls outside the scope of Article 2(1)(c). A US business whose AI outputs are used by EU customers, EU-based employees, or EU users is clearly within scope.
The questions below reflect how the output-use test applies in practice for a typical US business.
If you answer yes to any of these, the EU AI Act is likely to apply to your business.
If your product includes an AI-powered chatbot, recommendation engine, or any feature that uses AI to generate outputs your EU customers receive — you are in scope.
EU-based employees using AI tools provided or approved by your business are covered. The outputs of those tools are used in the Union.
AI-generated emails, marketing content, personalised recommendations, or automated decisions directed at EU recipients are outputs used in the Union.
This is the clearest case for being outside scope. A US business using AI purely for internal purposes, with no outputs reaching people in the EU, has the strongest argument that Article 2(1)(c) does not apply.
A US business that falls within the scope of the EU AI Act faces the same obligations as an EU-based business in the same position. The most immediately relevant obligation for the majority of US businesses is the AI literacy requirement under Article 4, which has applied since 2 February 2025 and is enforced by national authorities from 2 August 2026.
Take measures supporting AI literacy among staff and others who deal with AI systems on the business’s behalf — proportionate to their knowledge, experience and how the systems are used. Demonstrating this involves a written AI usage policy, an AI tools register, per-employee literacy records, a role-based training matrix, and an AI Compliance Documentation Pack. In force since February 2025.
Applies nowBusinesses using AI in high-risk categories — such as HR and recruitment decisions, credit scoring, healthcare diagnostics, or law enforcement — face significantly stricter obligations including conformity assessments, technical documentation, and EU database registration. Enforceable from 2 December 2027 under the Digital Omnibus (in force since 27 July 2026).
Deadline: 2 December 2027Providers of AI systems — businesses that develop and place AI systems on the EU market — must appoint an authorised representative established in the EU before making their system available. This is especially relevant for US AI developers and SaaS companies, but it applies to providers, not to most businesses that simply use AI tools built by others.
Providers onlyMost US businesses fall into the deployer category — they use AI systems built by others in a professional context. A US agency using ChatGPT for client work is a deployer. A US e-commerce business using an AI recommendation engine is a deployer.
A US business is a provider if it develops an AI system and places it on the EU market under its own name. Because a large share of AI systems are built by US companies, the provider obligations — including the authorised representative requirement — catch more US businesses than they do elsewhere. For most US SMEs using off-the-shelf AI tools, though, the deployer obligations — principally the Article 4 AI literacy requirement — are the relevant ones.
For many US businesses, the most immediate pressure to address EU AI Act compliance is not regulatory enforcement — it is commercial. EU-based enterprise clients are increasingly adding AI compliance checks to supplier questionnaires. A US supplier that cannot produce EU AI Act compliance documentation risks losing procurement decisions to competitors who can.
This is particularly relevant for US agencies and professional services firms with EU clients, US SaaS businesses with EU customers, and US suppliers to EU-regulated industries such as financial services, healthcare, and legal.
The EU Digital Omnibus — now signed law, in force since 27 July 2026 (Regulation (EU) 2026/1744) — softened the AI literacy obligation to an efforts-based standard, shifting the emphasis from proving an outcome to demonstrating the steps taken. This applies equally to US businesses in scope. The extraterritorial provisions in Article 2(1)(c) were not changed.
The EU AI Act’s jurisdiction is based on where AI outputs are used, not on where a business is established. This is the same extraterritorial logic US businesses already know from GDPR, which has applied to US companies handling EU personal data for years. Under Article 2(1)(c), a US business whose AI outputs are used by people in the EU is in scope regardless of whether it has any physical or legal presence in the EU.
No. The United States has no single comprehensive federal AI law comparable to the EU AI Act. AI is governed by a patchwork of state laws — such as those in California, Texas, Illinois, and Colorado’s incoming framework — together with federal agency enforcement under existing authorities and executive-branch policy. None of that displaces the EU AI Act: a US business whose AI outputs reach the EU faces the EU AI Act directly, and compliance with US state law does not satisfy it.
The EU AI Act’s output-use test does not distinguish between B2B and B2C. If your AI outputs are used by people in the EU — whether those people are consumers or employees of an EU business — the regulation applies. A US business supplying AI-powered tools or services to EU businesses, where those businesses’ employees interact with the AI outputs, is within scope.
Enforcement against businesses outside the EU is practically more challenging than enforcement against EU-based entities. However, practical enforcement difficulty is not a compliance strategy. EU-based enterprise clients increasingly require AI compliance documentation as part of procurement — a US business that cannot produce it risks losing contracts regardless of whether a regulator ever investigates. The commercial pressure is the more immediate driver for most US SMEs.
Technically, Article 2(1)(c) does not specify a threshold — one EU user whose experience involves AI outputs is sufficient to bring your business within the scope of the provision. In practice, proportionality applies: a business with minimal EU exposure faces far lower regulatory and commercial risk than one with substantial EU operations. The obligation to take measures supporting AI literacy is also proportionate, meaning the steps required are calibrated to your context. Taking reasonable, documented steps is more defensible than taking none.
Whether you are based in the EU, the US, or anywhere else, if the EU AI Act applies to your business you need to be able to demonstrate it. Our platform generates your complete compliance pack — tailored to your business, formatted professionally, and ready to produce on request — and you regenerate it whenever your tools, staff or the rules change.
Start your free assessment