Does the EU AI Act Apply to US Businesses?
Yes, in defined circumstances, the EU AI Act does apply to US businesses. Article 2 of the AI Act captures providers who place AI systems on the EU market or put them into service there, irrespective of whether they are established in the European Union or in a third country outside of the EU, such as the US. It also captures deployers established or located in the EU and, most importantly for US companies with no European presence, providers and deployers located outside the EU where the output produced by the AI system is used in the Union. Importers, distributors, product manufacturers and authorised representatives are covered too.
What actually determines your obligations is your role and the risk classification of the system, not your headquarters. A US SaaS company that builds an AI feature into its product and sells it to European customers is likely to be a provider. One that only uses a third-party tool internally is likely to be a deployer. Both carry obligations, but they are different ones, and the same business is frequently both at once for different systems. The level of obligation then depends on where the system sits in the risk framework, which runs from prohibited practices through high-risk systems to limited and minimal risk.
Practically, this means working system by system rather than reaching a single conclusion for the company. Build an inventory of each AI system you provide or use, decide your role for each, classify the risk, and check the transparency obligations that took effect on 2nd August 2026, since those apply widely and catch ordinary chatbots and generated content. If you provide a high-risk system into the EU without an establishment there, you will also need to appoint an authorised representative in a Member State before it goes on the market, according to Article 22.