AI Compliance · 2026-07-30 · 10 min read
Does the EU AI Act Apply to My Company? A US Startup's Guide
The EU AI Act reaches US companies through market effect, not incorporation: EU users, EU operations, or output used in the EU puts you in scope. Here are the three nexus tests, the four roles, what's genuinely out of scope, and why frontier-law thresholds like SB 53's don't exempt you.
The EU AI Act applies to your company if you place an AI system on the EU market, put one into service in the EU, or the output of your AI system is used in the EU — regardless of where you are incorporated. A US startup with EU users, EU customers, or an EU-facing AI feature is in scope; incorporating in Delaware does not exempt you.
The full answer turns on two questions: do you have an EU nexus, and which role do you play — provider, deployer, importer, or distributor. This guide covers both, what is not in scope, and the frontier-law confusion: California SB 53 and New York's RAISE Act are different laws with different thresholds.
Want to skip ahead? Run your product through our free EU AI Act checker — risk tier and role-scoped obligations, with citations, in about three minutes. No signup.
The EU AI Act is extraterritorial: where you're incorporated doesn't matter
Like the GDPR before it, the AI Act's scope provision (Article 2) is written around market effect, not corporate registration. It reaches non-EU companies whenever their AI systems reach the EU: no "we're a US company" defense, no EU-office requirement, no revenue floor for the core obligations. If your product is available to users in France, it does not matter that your engineering team sits in Austin.
The three nexus tests: do you touch the EU at all?
If any one is true, part of the Act applies to you.
- You place an AI system or general-purpose AI model on the EU market. "Placing on the market" means making it available in the EU in the course of commercial activity. A SaaS product that accepts EU signups counts — no EU entity, sales team, or euro pricing required.
- You put an AI system into service, or use one, in the EU. Operating AI inside the EU — through an EU subsidiary, EU-based employees, or EU-hosted operations — puts you under the Act even if you never sell AI.
- The output of your AI system is used in the EU. The test that surprises people: a US company running AI whose results are intended for use in the EU — screening decisions, generated content, scores delivered to EU recipients — can be in scope without selling anything into the EU market.
If none of the three is true, the EU AI Act does not apply to you today. US state law is a separate question — see the complete map of US state AI laws.
Which role are you? Provider, deployer, importer, or distributor
The Act assigns obligations by role, not company size. The same startup often holds two at once — provider of the AI feature it sells, deployer of the AI tools its staff uses.
| Role | You are this if you... | Typical example | Obligation weight |
|---|---|---|---|
| Provider | Develop an AI system and place it on the market or into service under your own name or brand | A startup selling an AI screening, support, or drafting product | Heaviest — transparency now; conformity duties when the high-risk regime applies |
| Deployer | Use an AI system under your authority in a professional context | A company using an AI hiring tool or internal chatbot | Moderate — AI literacy, use-level transparency, oversight |
| Importer | Are established in the EU and place a non-EU provider's system on the EU market | An EU entity bringing a US vendor's AI product in | Verification duties |
| Distributor | Make someone else's system available on the EU market without modifying it | A reseller or marketplace | Lightest — diligence duties |
Two role traps:
- White-labeling makes you the provider. Put your brand on someone else's AI system and you take on the provider role.
- AI literacy is not provider-only. The Article 4 duty to ensure staff AI literacy binds providers and deployers — in force since 2 February 2025 and already live for any in-scope team.
Building on the OpenAI or Anthropic API? You're likely a provider
The most common US-startup question: "We don't train models — we just call an API. Surely the model vendor carries the compliance load?"
Building on a model API typically makes you the provider of your downstream feature, while the model vendor holds the general-purpose AI (GPAI) duties for the underlying model. OpenAI or Anthropic answers for the model; you answer for the chatbot, copilot, or generator you shipped with it.
Concretely: ship a customer-facing AI chat feature on a foundation-model API and the Article 50 duty to disclose AI interaction lands on your feature — and Article 50, together with GPAI enforcement, applies from 2 August 2026 — backed by the general penalty regime of up to €15M or 3% of worldwide turnover, which has been in force since 2 August 2025. Our breakdown of the Article 50 transparency obligations covers what disclosure and content marking require.
What is NOT in scope
The Act is broad, not boundless:
- No EU nexus. Fail all three nexus tests and you are out of scope. Blocking EU signups is a legitimate, if commercially painful, scoping decision.
- Purely personal, non-professional use. An individual using AI privately is not a "deployer." The Act regulates professional and commercial contexts.
- Internal R&D that never reaches the market. Prototypes not placed on the market or put into service generally do not trigger provider duties — the clock starts when the system reaches users.
- Deferred ≠ exempt. The Digital Omnibus (adopted June 2026) deferred the high-risk regime — Annex III standalone systems apply from 2 December 2027, Annex I embedded systems from 2 August 2028 — but that is timing relief for one chapter, not a scope exemption. Articles 4, 5, and 50, the GPAI rules, and the penalty regime were not deferred.
"But we're not a frontier lab" — SB 53 and RAISE are different laws
Founders read that new AI safety laws only hit companies training massive models, conclude "AI regulation isn't for us," and stop looking. It's behind the most dangerously wrong scoping decisions of 2026.
That's true of exactly one narrow category. The frontier-model laws — California SB 53, New York's RAISE Act, and Illinois SB 315 — bind trainers at roughly the 10^26-FLOP scale or above $500 million in revenue; below those thresholds, those particular laws impose zero duties.
The EU AI Act works the opposite way: its transparency, literacy, and prohibited-practice rules have no compute threshold and no revenue floor. Many US state laws are threshold-free too — California AB 2013 (Civ. Code §§3110–3111), in force since 1 January 2026, requires developers including fine-tuners to publish a training-data summary with no size threshold at all. Our California AI laws guide covers what applies below the frontier.
Decision table: does the EU AI Act apply to your company?
| Your situation | In scope? | Likely role | Start here |
|---|---|---|---|
| US SaaS with EU customers using your AI feature | Yes | Provider (and deployer internally) | Art. 50 readiness; Art. 4 literacy |
| EU subsidiary or EU-based staff using AI tools | Yes | Deployer | Art. 4 literacy (in force since 2 Feb 2025) |
| No EU sales, but AI output delivered to EU recipients | Likely yes | Provider or deployer, facts-dependent | Nexus analysis, then role mapping |
| Customer-facing feature on a model API, EU users | Yes | Provider of the downstream feature | Art. 50 (applies from 2 Aug 2026) |
| White-labeling another vendor's AI for the EU market | Yes | Provider (your brand, your duties) | Full provider obligations |
| No EU users, no EU operations, no output used in the EU | No | — | US state laws still apply — see the state map |
The deadlines that actually apply to you
"The EU delayed the AI Act" is dangerously imprecise — only the high-risk conformity regime moved. The real calendar:
| Obligation | Status |
|---|---|
| Art. 4 AI literacy (providers and deployers) | In force since 2 February 2025 |
| Art. 5 prohibited practices | In force since 2 February 2025 — penalties up to €35M or 7% of worldwide turnover |
| Art. 50 transparency + general penalties (up to €15M or 3%) + GPAI enforcement | Applies from 2 August 2026 |
| Watermarking for systems already on the market before 2 Aug 2026 | Grandfathered until 2 December 2026 |
| High-risk: Annex III standalone systems | Applies from 2 December 2027 |
| High-risk: Annex I embedded systems | Applies from 2 August 2028 |
Two obligations are already live and a third arrives on 2 August 2026; the deferred dates buy time only for the high-risk conformity chapter.
How to find out where you stand — in about three minutes
- Run the nexus tests. EU market availability, EU operations, or output used in the EU — any one puts you in scope.
- Map your roles. List every AI feature you ship (provider) and every AI tool your team uses (deployer). Most companies are both.
- Classify each system. The free EU AI Act checker returns a risk tier and role-scoped obligation list with statutory citations — deterministic rules, not LLM guesses.
- Work the near-term list first. Article 4 literacy and Article 50 transparency, then the longer-horizon high-risk items. Our EU AI Act compliance checklist for 2026 sequences the whole program.
In scope? Shieldra tracks the EU AI Act alongside eight other AI frameworks — including the US state laws that apply regardless of EU exposure — from $299/month, with a 14-day free trial, no credit card.
FAQ
Does the EU AI Act apply to US companies with no EU office?
Yes, if there is an EU nexus. The Act applies based on where AI systems are marketed, used, or where their output is used — not where the company is registered. A US startup with EU users or EU-facing AI features is in scope without any EU office.
Am I a provider or a deployer if I build on the OpenAI or Anthropic API?
Typically a provider — of your downstream feature. The model vendor holds the general-purpose AI duties for the underlying model, but the chatbot or copilot you shipped under your brand is your AI system, and duties like the Article 50 disclosure requirement (applies from 2 August 2026) attach to it. You are also a deployer for third-party AI tools your own team uses.
Did the EU delay the AI Act until 2027?
No — only the high-risk conformity regime was deferred. The Digital Omnibus (adopted June 2026) moved Annex III standalone systems to 2 December 2027 and Annex I embedded systems to 2 August 2028. It did not defer Article 4 literacy or Article 5 prohibitions (in force since 2 February 2025), and Article 50 transparency and GPAI enforcement apply from 2 August 2026; the general penalty regime has applied since 2 August 2025.
Does the EU AI Act only apply to big AI companies?
No. The core transparency, literacy, and prohibited-practice obligations have no compute threshold and no revenue floor. The frontier thresholds people cite — roughly 10^26 FLOPs or $500M+ revenue — belong to different laws: California SB 53, New York's RAISE Act, and Illinois SB 315. Being too small for those says nothing about your EU AI Act exposure.
What are the penalties if my company ignores the EU AI Act?
Prohibited practices under Article 5 carry penalties up to €35M or 7% of worldwide turnover — in force since 2 February 2025. The general penalty regime, up to €15M or 3% of worldwide turnover, has applied since 2 August 2025; the Article 50 transparency obligations begin 2 August 2026. Extraterritorial scope means US companies with an EU nexus face the same exposure as EU ones.