Back to Guides
Guide16 September 2026

Does the EU AI Act apply to U.S. companies?

Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.

In this guide
  1. Does the EU AI Act apply to U.S. companies?
  2. What are the three jurisdiction hooks?
  3. When do the obligations start?
  4. What are the potential penalties?
  5. Do I need an EU authorized representative?
  6. Practical checklist for U.S. businesses
  7. How to verify compliance without heavy legal spend
  8. Bottom line

Does the EU AI Act apply to U.S. companies?

The short answer is yes. The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) has extraterritorial scope and can bind U.S. - based AI providers, deployers, importers or distributors whenever any of the three jurisdiction hooks in Article 2 (1) are satisfied.

What are the three jurisdiction hooks?

When do the obligations start?

What are the potential penalties?

Fines can reach up to €35 million or 7 % of worldwide annual turnover, whichever is higher, for the most serious breaches such as prohibited practices or non - compliance with high - risk requirements.

Do I need an EU authorized representative?

If you are a non - EU provider of a high - risk AI system, Article 22 requires you to appoint an EU - based authorized representative before placing the system on the market.

Practical checklist for U.S. businesses

  1. Map your AI portfolio - Identify every system whose output is consumed by EU persons, even indirectly through a reseller.
  2. Determine your role - You may be a provider, a deployer, or both, depending on the hook that applies.
  3. Fundamental Rights Impact Assessment (FRIA) - Required for high - risk AI systems.
  4. Technical documentation - Prepare a dossier that includes system description, training - data summary and copyright policy.
  5. Transparency compliance - Implement Article 50 notices and AI - generated content labeling by 2 Aug 2026 (labeling by 2 Dec 2026).
  6. Conformity assessment & registration - For high - risk AI, complete the conformity assessment, set up post - market monitoring, and register in the EU AI database by 2 Dec 2027.
  7. Appoint an EU authorized representative - Required for high - risk systems if you have no EU establishment.

Bottom line

The EU AI Act applies to U.S. companies whenever their AI systems are offered to EU users, placed on the EU market, or produce output that is used in the Union - regardless of corporate domicile, server location, or marketing intent. Treat compliance as a global risk - management issue and start the mapping and documentation process now to avoid steep fines later.


Key takeaways

Free security scan

See what's actually exposed on your site.

Decloak's free scan runs in about 15 seconds, no account required, and covers:

  • HTTP/TLS security posture
  • JavaScript CVEs
  • Exposed Supabase/Lovable/Base44 misconfigurations
  • AI-written executive summary