Back to blog

Blog / US companies

Do US AI SaaS Companies Need to Comply with the EU AI Act?

Published 20 July 2026·Last updated 20 July 2026·6 min read
Author: ActBrief Editorial·Reviewer: External legal review pending

Not legal advice. This article is a preliminary technical guide for AI SaaS teams. Always confirm classification and obligations with qualified counsel. Effective dates reflect the Digital Omnibus updates as of July 2026.

The short answer

If you place an AI system on the EU market, or the output of your system is used in the Union, the AI Act may apply even if you are a US company. Like GDPR, it has extraterritorial reach — but scope still depends on role (provider, deployer, importer, distributor) and the Article 2 tests below. “Our website is accessible from the EU” alone is not a complete analysis.

The actual scope test (Article 2)

The AI Act can apply to:

  1. Providers placing AI systems on the market in the EU, regardless of where the provider is established.
  2. Providers and deployers in a third country where the output produced by the AI system is used in the EU.
  3. Importers and distributors of AI systems in the EU.
  4. Deployers of AI systems that have their place of establishment or are located within the EU.

Point 2 is the one US founders miss: you don't need EU offices, EU servers, or an EU entity. If EU-based users receive output from your AI system — a scored resume, a chatbot reply, a generated recommendation — you may be in scope. Confirm with counsel which role you actually hold.

Common "we're US-only" scenarios that are actually in scope

What's genuinely out of scope

What compliance actually looks like for a US-based team

You don't need an EU subsidiary for most obligations. What you may need:

  1. An EU representative (Article 22) if you're a non-EU provider placing a high-risk system on the EU market — this is a designated contact point in the EU, not a full legal entity.
  2. The same documentation obligations as an EU company — risk classification, technical file, human oversight, transparency disclosures — there's no "US company" carve-out on substance.
  3. A decision on whether to geofence EU users — some US companies choose to block EU signups entirely rather than build compliance. This is a legitimate business choice, but it needs to be a deliberate one, not a default.

Practical next steps for US SaaS teams

  1. Confirm whether EU users can receive output from your AI (signups, enterprise seats, public URLs).
  2. Determine if you are a provider, deployer, or both — and if you are primarily a deployer, read deployer obligations.
  3. Walk the EU AI Act compliance checklist — disclosure, model inventory, and oversight are the usual first gaps.
  4. Run a free readiness scan before booking legal counsel so the call starts with a concrete gap list.

The investor angle

US-based AI startups raising from EU-connected VCs, or selling into enterprise deals with EU counterparties, increasingly get AI Act questions in due diligence — independent of whether you have EU offices. "We're a US company" is not an answer that satisfies a diligence checklist anymore.

Bottom line

Being US-based does not exempt you. The relevant question isn't where you're incorporated — it's whether your AI system's output reaches EU users. If it does, scope the same way an EU company would — start with the checklist, then get legal review on the gaps that matter.

Official sources

Ready for legal review?

Get a free readiness brief for your product — not a commodity risk label.

Get a free readiness brief for your product