Governance · 5 minute read
EU AI Act Compliance for US Companies: Scope, Obligations, Preparation
The EU AI Act applies to US companies that place AI systems on the EU market, deploy them in the EU, or whose AI outputs are used there, regardless of where the company sits. It classifies systems by risk, prohibits some uses, imposes extensive obligations on high-risk systems, adds duties for general-purpose models, and carries significant penalties.
US companies that never planned to think about EU regulation find themselves in scope of the EU AI Act because a product is sold in Europe, an EU subsidiary uses an internal tool, or a customer in the EU relies on an AI-generated output. The law is the most comprehensive AI regulation in force, its obligations for high-risk systems are extensive, and its penalties are substantial. The good news for companies with a US governance program is that most of what the Act requires overlaps with controls they already need. This guide covers scope, tiers, obligations, timelines, and preparation, drawing on FISTA Solutions' AI enablement practice. The US landscape is in ai regulation in the united states and the certifiable management system in iso 42001 explained. This article is general guidance, not legal advice; the Act's provisions, guidance, and dates should be confirmed with counsel.
When does the Act reach a US company?
| Situation | In scope |
|---|---|
| Selling or offering an AI system or AI-enabled product in the EU | Yes, as provider |
| Deploying AI in EU operations or subsidiaries | Yes, as deployer |
| AI outputs produced elsewhere but used in the EU | Yes, in defined circumstances |
| Providing a general-purpose model available in the EU | Yes, as GPAI provider |
| Importing or distributing AI systems into the EU | Yes, with importer or distributor duties |
| No EU market presence, use, or output | Generally no |
Scope questions turn on definitions and facts; confirm each with counsel.
What are the risk tiers?
| Tier | Examples | Obligations |
|---|---|---|
| Prohibited | Certain manipulation, exploitation of vulnerabilities, social scoring, specified biometric practices | Banned |
| High-risk | Employment, credit, education, essential services, migration, law enforcement, justice, plus safety components of regulated products | Full provider and deployer obligations |
| Limited risk | Chatbots, emotion recognition, deepfakes, generated content | Transparency duties |
| Minimal risk | Most other systems | None specific; voluntary codes |
Classification depends on annexed lists and definitions; the high-risk list resembles the consequential decision areas in US state laws. Comparison is in colorado ai act explained.
What must providers of high-risk systems do?
Establish and maintain a risk management system across the lifecycle; apply data governance to training, validation, and testing data including bias examination; prepare technical documentation; build automatic logging; provide transparency and instructions for use to deployers; design for effective human oversight; achieve appropriate accuracy, robustness, and cybersecurity; operate a quality management system; complete conformity assessment and affix marking; register in the EU database; and conduct post-market monitoring and incident reporting. Each maps to practices in ai model risk management, ai data governance, and ai record-keeping requirements.
What must deployers of high-risk systems do?
Use systems according to instructions; assign human oversight to people with competence, training, and authority; ensure input data is relevant and representative where under their control; monitor operation and inform providers and authorities of risks and serious incidents; keep logs for the required period; inform workers and affected people where required; and, for certain deployers such as public bodies and some private entities, conduct fundamental rights impact assessments. Oversight design is in ai human oversight requirements.
What duties apply to general-purpose models?
Providers of general-purpose AI models must maintain technical documentation, provide information to downstream providers, comply with copyright rules, and publish training content summaries; models designated as posing systemic risk carry additional evaluation, adversarial testing, incident reporting, and cybersecurity duties. US companies offering models in the EU should assess whether they are providers. Supply chain implications are in ai supply chain security.
What transparency duties apply?
Informing people when they interact with an AI system unless obvious; labeling AI-generated or manipulated content including deepfakes; disclosing emotion recognition and biometric categorization; and marking synthetic content in machine-readable form where required. Notice design is in ai transparency notices and provenance in ai content provenance.
How is the Act phased in and enforced?
Obligations apply in stages over several years from entry into force: prohibitions first, general-purpose model duties next, then most high-risk obligations, with product-embedded high-risk systems later. Penalties scale by violation type up to percentages of global annual turnover. National authorities and an EU-level office enforce. Dates and guidance continue to develop; track them with counsel.
How should a US company prepare without duplicating its US program?
Determine scope; classify systems by tier; map high-risk obligations to existing controls from model risk, privacy, and state law programs; close the gaps, typically in conformity assessment, technical documentation format, logging requirements, quality management, registration, and EU representation; align transparency practices; and track the timeline. One governance program with jurisdiction-specific additions serves the EU and US. Program structure is in what is ai governance and certification that evidences it in iso 42001 explained.
What mistakes leave US companies exposed?
Assuming no EU office means no scope; missing that EU use of outputs triggers coverage; classifying systems optimistically; treating vendor systems as the vendor's problem when deployer duties apply; documentation in a form that does not satisfy conformity requirements; and no EU representative where required.
What does prepared practice look like?
A US software company with EU customers classifies its hiring-assistance feature as high-risk, maps obligations to its existing model risk and bias testing program, completes technical documentation and conformity assessment, builds logging and oversight instructions for deployers, appoints an EU representative, registers the system, and labels its chatbot and generated content. Its EU subsidiary, as deployer, assigns oversight and keeps logs. The program extends existing controls rather than building a parallel one.
How FISTA Solutions helps with EU AI Act preparation
FISTA Solutions builds AI systems with the risk management, data governance, documentation, logging, oversight, and evaluation evidence the Act requires, and helps US clients determine scope, classify systems, and map obligations to existing programs with their counsel. The AI enablement practice leads governance design, AI agents ship with transparency and oversight built in, and forward deployed engineers embed with client compliance teams. The record behind the approach is 150+ projects across 12+ countries.
To extend your governance program to EU obligations without duplicating it, message FISTA on WhatsApp, or read iso 42001 explained for the management system that evidences compliance.
Share-ready article cover
Download the generated social format.
Clear answers
Questions raised by this field note.
Straightforward guidance for evaluating scope, fit, and the next step.
01Does the EU AI Act apply to a US company?
Yes if it places AI systems on the EU market, puts them into service in the EU, or if the output of its AI systems is used in the EU, and also if it deploys AI in EU operations. A US company with EU customers, EU employees, or EU-facing products should assume scope and confirm with counsel.
02What are the risk tiers?
Prohibited practices such as certain manipulation, social scoring, and specified biometric uses; high-risk systems in listed areas such as employment, credit, education, essential services, and law enforcement, plus safety components of regulated products; limited-risk systems with transparency duties; and minimal-risk systems with no specific obligations.
03What must high-risk system providers do?
Establish a risk management system, data governance for training and testing data, technical documentation, logging, transparency and instructions for deployers, human oversight design, accuracy, robustness, and cybersecurity, a quality management system, conformity assessment, registration, and post-market monitoring.
04What must deployers of high-risk systems do?
Use systems per instructions, assign human oversight to competent people, ensure input data is relevant, monitor operation, keep logs, inform affected people and workers where required, and in certain cases conduct fundamental rights impact assessments, with cooperation duties toward providers and authorities.
05How should a US company prepare?
Determine scope, classify systems by tier, map high-risk obligations to existing controls from US programs, close gaps in documentation, data governance, logging, oversight, and conformity, track the phased timeline, and appoint EU representatives where required, coordinating with counsel.
Continue exploring
Related capabilities
Start with the hard problem
Need the outcome owned, not merely analyzed?
Tell us where delivery is constrained. We’ll map the fastest credible path from intent to verified production.