Does the EU AI Act Reach Your US Company?
A US company with no European office can still fall under the EU AI Act, because Article 2 turns on where your system's output is used, not where you are. Here is what reaches you, which obligation lands first, and the dated calendar as amended in July 2026.
Start with the question you actually have: does the EU AI Act reach a US company with no European office, entity, or staff? Often, yes. The reach test in Article 2 of Regulation (EU) 2024/1689 does not turn on where your company sits. It turns on where your system is placed on the market, where your deployer sits, and — the limb most US companies miss — where your system's output ends up being used.
Here is the text that does the work.
Article 2(1)(c) of Regulation (EU) 2024/1689: "providers and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union".
The United States is a third country here. So the question is not whether you have an EU presence, but whether output from your AI system is used in the Union. Two other limbs of Article 2(1) matter alongside it. Point (a) catches "providers placing on the market or putting into service AI systems or placing on the market general-purpose AI models in the Union, irrespective of whether those providers are established or located within the Union or in a third country". Point (b) catches "deployers of AI systems that have their place of establishment or are located within the Union". Point (a) is about supply into the EU market; point (b) is about your EU customers, who carry their own duties. Point (c) is the one that reaches you with no EU market activity you recognized as such.
Three US situations, and what Article 2 does with them
A US SaaS company with paying EU customers. The clearest case. If you make your AI-enabled product available to customers in the Union, you are placing an AI system on the Union market or putting it into service there, and Article 2(1)(a) reaches you. Your EU customers are separately deployers under Article 2(1)(b). On the text, this is squarely within Article 2(1)(a).
A US company using an AI tool internally, with no EU users and no EU output. A US marketing team using a US AI tool to write copy read by US customers is not described by any limb of Article 2(1): nothing is placed on the Union market, you are not established there, and no output is used there. On the face of the text, you are out. The caution is that "no EU output" has to be true in fact, not just in intention — an EU subsidiary, an EU-based contractor using the tool, or copy published to EU readers changes the analysis.
A US firm whose model output is delivered to someone in the EU. A US analytics firm that scores résumés, prices risk, or drafts reports and sends the result to a client in Paris is exactly the case Article 2(1)(c) is written for. The system never leaves your US infrastructure. The output is used in the Union. On the text, you are in scope as a provider or a deployer, or both.
Where the text genuinely runs out
Be honest about this, because the confident versions of this article are the ones that get people in trouble. "Where the output produced by the AI system is used in the Union" is not defined in Article 3, and the regulation does not say how much use, by whom, or how deliberate it must be. The hard cases are real. If a US client forwards your generated report to a colleague in Munich, was the output used in the Union? If your chatbot answers a traveler who happens to be in Lisbon that week? If an EU-based freelancer uses your US product on a US project?
The text does not settle these, and you should not accept any source that says it does. What you can do is decide on facts rather than hope. Find out where your output actually goes: EU-billing customers, EU-resident users, EU-based staff or contractors touching the tool, deliverables routinely sent to a recipient in the Union. Where the answer is a clear and durable no, document that and revisit it when you enter the market. Where it is yes, or drifting toward yes, the scope provisions read as covering you, and that is the point to involve counsel rather than resolve an open interpretive question yourself.
The exclusions worth knowing
Article 2 carves out several commercially relevant things. Purely personal use is out: paragraph 10 provides that the Regulation "does not apply to obligations of deployers who are natural persons" "using AI systems in the course of a purely personal non-professional activity". That protects your employees' weekend use of a chatbot. It does nothing for your company's use of the same tool at work.
Research and development is largely out. Paragraph 6 excludes AI systems or models "specifically developed and put into service for the sole purpose of scientific research and development". Paragraph 8 excludes "any research, testing or development activity regarding AI systems or AI models prior to their being placed on the market or put into service" — with a limit in the same paragraph: "Testing in real world conditions shall not be covered by that exclusion." A pilot with live EU users is not shielded.
Open source is partly out. Paragraph 12 excludes systems "released under free and open-source licences, unless they are placed on the market or put into service as high-risk AI systems or as an AI system that falls under Article 5 or 50". Read the exception closely: Article 50 is exactly what a generative open-source system is most likely to trigger, so the carve-out often will not help. Paragraph 3 also puts national security and military and defense purposes outside the Regulation.
What applies, to whom, from when
Article 113 sets the calendar. Regulation (EU) 2026/1744 of 8 July 2026 — the AI Omnibus, in force 27 July 2026 — moved part of it. It left the general application date of 2 August 2026 in place, but it did not leave the early chapters untouched: it replaced Article 4 on AI literacy, amended Article 2 and the Article 3 definitions, and added two prohibitions to Article 5 that apply from 2 December 2026.
Article 113 of Regulation (EU) 2024/1689: "This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union. It shall apply from 2 August 2026. However: (a) Chapters I and II shall apply from 2 February 2025; (b) Chapter III Section 4, Chapter V, Chapter VII and Chapter XII and Article 78 shall apply from 2 August 2025, with the exception of Article 101".
| Date | What applies | Who it binds |
|---|---|---|
| 2 February 2025 | Chapters I and II: definitions, AI literacy, Article 5 prohibitions | Anyone in scope under Article 2, third-country parties included |
| 2 August 2025 | Chapter V (general-purpose AI models), Chapter III Section 4, Chapters VII and XII, Article 78; Article 101 excepted | GPAI model providers; governance bodies |
| 2 August 2026 | General application, including Article 50 transparency; enforcement begins | Providers and deployers of systems Article 50 covers |
| 2 December 2026 | Article 50(2) marking deadline for systems placed on the market before 2 August 2026; added prohibitions | Providers of generative AI systems already on the market |
| 2 August 2027 | Compliance deadline for models placed on the market before 2 August 2025 (Article 111(3)) | Providers of pre-existing GPAI models |
| 2 December 2027 | Chapter III Sections 1-3, Article 6(2) and Annex III high-risk (moved by Regulation (EU) 2026/1744) | Annex III high-risk providers and deployers |
| 2 August 2028 | Chapter III Sections 1-3, Article 6(1) and Annex I high-risk (moved by Regulation (EU) 2026/1744) | Providers of AI embedded in regulated products |
The obligation that lands first for most US companies
Two things are already live: the Article 5 prohibitions since 2 February 2025, and Chapter V for general-purpose AI model providers since 2 August 2025. For most US SaaS and automation companies, though, the obligation that actually bites is Article 50 transparency, which has applied since 2 August 2026.
Article 50 splits duties between providers and deployers, and that split is the part people get wrong. Providers carry paragraphs 1 and 2. Paragraph 1 requires systems "intended to interact directly with natural persons" to be built so people are informed they are interacting with an AI system, "unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect". Paragraph 2 is the marking duty.
Article 50(2): "Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, shall ensure that the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated."
That duty is qualified: technical solutions must be "effective, interoperable, robust and reliable as far as this is technically feasible", and it does not apply where the system performs "an assistive function for standard editing" or does not substantially alter the deployer's input data or its semantics. Article 50(2) is the provision that reaches a generative feature supplied into the Union. For systems already on the market before 2 August 2026, the Omnibus took the Article 50(2) marking obligation to 2 December 2026.
Deployers carry paragraphs 3 and 4. Paragraph 4 is the deepfake rule: deployers of a system generating or manipulating image, audio or video content constituting a deep fake "shall disclose that the content has been artificially generated or manipulated". Where the content forms part of "an evidently artistic, creative, satirical, fictional or analogous work or programme", the duty is limited to disclosing the existence of generated content "in an appropriate manner that does not hamper the display or enjoyment of the work" — a narrowing of how you disclose, not an exemption from disclosing. Paragraph 4 also covers AI-generated text published to inform the public on matters of public interest, unless the content had human review or editorial control with a person holding editorial responsibility.
Prohibited practices, briefly
Article 5 has applied since 2 February 2025 and bans, in summary: subliminal or manipulative techniques; exploitation of the vulnerabilities of specific groups; social scoring; individual criminal-offense risk prediction based on profiling or personality traits; untargeted scraping of facial images to build recognition databases; emotion inference in the workplace and in education; biometric categorization to infer sensitive characteristics; and real-time remote biometric identification in publicly accessible spaces for law enforcement, subject to narrow exceptions. Most US automation work is nowhere near these. Workplace emotion inference is the one that shows up in HR and sales tooling, and it deserves a direct look.
General-purpose AI models, and penalties
Chapter V has bound providers of general-purpose AI models since 2 August 2025: technical documentation, information for downstream providers integrating the model, a copyright policy, and a public summary of training data content. If you build on someone else's model rather than releasing your own, your exposure usually runs through Article 50 rather than Chapter V — but check whether your modifications make you a provider of a model in your own right.
On penalties, Article 99 sets tiers rather than a single number. Breach of the Article 5 prohibitions carries administrative fines of up to EUR 35 000 000 "or, if the offender is an undertaking, up to 7 % of its total worldwide annual turnover for the preceding financial year, whichever is higher." Most other operator breaches sit at up to EUR 15 000 000 or 3 % on the same construction, and supplying incorrect or misleading information to authorities at up to EUR 7 500 000 or 1 %. For smaller companies the construction inverts: "In the case of SMEs, including start-ups, each fine referred to in this Article shall be up to the percentages or amount referred to in paragraphs 3, 4 and 5, whichever thereof is lower."
Those figures are a reason to be accurate, not a reason to panic. The practical work is smaller than the headline suggests: establish where your output goes, decide in writing whether Article 2(1)(c) reaches you, and if it does, treat the Article 50 disclosure and marking duties as live, with a 2 December 2026 backstop for anything shipped before 2 August 2026. No tool you buy resolves this for you — obligations under the Regulation attach to your organization and to how you use the system, not to a vendor's feature list.
This article is general information based on the text of Regulation (EU) 2024/1689, Regulation (EU) 2026/1744 and official European Union sources, and is not legal advice. The Bot Desk is not a law firm. Your obligations depend on your specific systems, uses and customers — consult qualified counsel before making compliance decisions.
Read next
- What Automation Platforms Let You Take With YouRisk & rules
- Automating New-Hire Paperwork: What Must Stay ManualHow to automate
- How to auto-triage support tickets, and catch missesHow to automate
Sources
- Regulation (EU) 2024/1689 (AI Act), EUR-Lex
- Regulation (EU) 2026/1744 of 8 July 2026 (AI Omnibus), EUR-Lex
- Article 2: Scope, European Commission AI Act Service Desk
- Article 50: Transparency obligations, AI Act Service Desk
- Timeline for the Implementation of the EU AI Act, AI Act Service Desk
- AI Act, European Commission (Shaping Europe's digital future)