Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.
In this guide
Does the EU AI Act apply to U.S. companies?
The short answer is yes. The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) has extraterritorial scope and can bind U.S. - based AI providers, deployers, importers or distributors whenever any of the three jurisdiction hooks in Article 2 (1) are satisfied.
What are the three jurisdiction hooks?
- Provider - placement (Article 2 (1)(a)) - If you place an AI system or a general - purpose model on the EU market or put it into service in the Union, you are a “provider” regardless of where your company is incorporated. Example: a U.S. SaaS vendor that sells an AI - powered feature to EU customers, prices in euros, or runs EU - targeted marketing.
- Deployer - location (Article 2 (1)(b)) - If a legal entity established in the EU uses the AI system, that entity is a “deployer.” A U.S. firm with an EU subsidiary that runs the model must meet the deployer obligations.
- Output - use (Article 2 (1)(c)) - The Act applies when the AI system’s output is used in the Union, even if the provider never has a physical presence in the EU. A U.S. hiring tool whose scores are acted on by a European employer, or an API that a European developer calls, triggers the scope.
When do the obligations start?
- Transparency duties (Article 50) become enforceable on 2 Aug 2026. This includes user notices and labeling of AI - generated content.
- High - risk regime (Annex III) is fully enforceable on 2 Dec 2027 after the Digital Omnibus delay (the next step, post - market monitoring, is due 2 Aug 2028).
What are the potential penalties?
Fines can reach up to €35 million or 7 % of worldwide annual turnover, whichever is higher, for the most serious breaches such as prohibited practices or non - compliance with high - risk requirements.
Do I need an EU authorized representative?
If you are a non - EU provider of a high - risk AI system, Article 22 requires you to appoint an EU - based authorized representative before placing the system on the market.
Practical checklist for U.S. businesses
- Map your AI portfolio - Identify every system whose output is consumed by EU persons, even indirectly through a reseller.
- Determine your role - You may be a provider, a deployer, or both, depending on the hook that applies.
- Fundamental Rights Impact Assessment (FRIA) - Required for high - risk AI systems.
- Technical documentation - Prepare a dossier that includes system description, training - data summary and copyright policy.
- Transparency compliance - Implement Article 50 notices and AI - generated content labeling by 2 Aug 2026 (labeling by 2 Dec 2026).
- Conformity assessment & registration - For high - risk AI, complete the conformity assessment, set up post - market monitoring, and register in the EU AI database by 2 Dec 2027.
- Appoint an EU authorized representative - Required for high - risk systems if you have no EU establishment.
How to verify compliance without heavy legal spend
- Use a free web security scan that checks for public - facing AI endpoints, TLS posture and third - party domains. While not a substitute for a full AI - Act audit, it quickly reveals if you expose an API that EU users can call.
- Run a static code analysis of your JavaScript bundles to ensure you are not unintentionally exposing API keys that could be used to access high - risk AI services from the EU.
- Leverage tag manager intelligence to confirm no EU - targeted tracking scripts are inadvertently loading AI - related content.
Bottom line
The EU AI Act applies to U.S. companies whenever their AI systems are offered to EU users, placed on the EU market, or produce output that is used in the Union - regardless of corporate domicile, server location, or marketing intent. Treat compliance as a global risk - management issue and start the mapping and documentation process now to avoid steep fines later.
Key takeaways
- The Act’s extraterritorial reach covers provider - placement, deployer - location and output - use.
- Compliance deadlines start 2 Aug 2026 for transparency and 2 Dec 2027 for high - risk obligations.
- Fines can reach €35 million or 7 % of global turnover.
- Non - EU high - risk providers must appoint an EU authorized representative.
- Begin mapping AI systems, assess roles, and start documentation early.
Related guides
What is NIST in cybersecurity and why should you care?
NIST is the U.S. agency that creates the Cybersecurity Framework and a suite of standards like SP 800 - 53 that guide risk management for both government and private organizations.
Which NIST Cybersecurity Standards Should My Organization Adopt in 2024 - 2025?
Learn the core NIST publications that form a practical, layered security program, how they map together, and concrete steps to start using them today.
Who Must Comply with the EU Digital Operational Resilience Act (DORA)?
DORA applies to all EU - authorized financial entities and any ICT service provider that supports them, with limited exemptions for very small firms.