Why this matters even for US companies
The EU AI Act applies based on where your users and outputs are, not just where your company sits, so a US business serving EU customers can fall in scope. It takes a risk-based approach: the higher the potential for harm, the more obligations attach.
This is general information, not legal advice. For anything that could carry real regulatory or contractual consequences, involve a qualified attorney. What we can do is help you build in a way that's ready to comply.
- Scope can follow your EU users and outputs, not just your HQ
- Obligations scale with the risk of the use case
- Some uses are effectively prohibited; some carry heavy duties
- Transparency duties often apply to everyday generative uses
- Timelines are phased, so requirements land on different dates
Practical steps you can take now
You don't need to predict every rule to prepare well. Most emerging frameworks reward the same fundamentals: know what AI you're using, document how it makes decisions, keep humans in control of consequential actions, and be transparent with people affected.
Building these habits in now is far cheaper than retrofitting them under deadline pressure later.
- Keep an inventory of where AI touches your operations
- Classify each use by how much harm a mistake could cause
- Document data sources, model choices, and known limits
- Keep a human in the loop for consequential decisions
- Disclose AI use to customers where it's expected or required
- Log decisions for auditability without storing needless personal data
Build for compliance from the start
Guardrails, audit logs, human review, and clear disclosure are much easier to design in than to bolt on. The same architecture that keeps you compliant also tends to make your AI safer and more trustworthy.
We build with these controls as defaults so that as rules firm up, you're adjusting settings rather than rewriting the system.
- Design human approval into high-stakes steps
- Make outputs traceable to sources and decisions loggable
- Minimize and protect any personal or sensitive data
- Keep model and prompt versions documented and reproducible
- Leave room to add controls as regulations mature
More on ai strategy & consulting
Frequently asked questions
Does the EU AI Act apply to my US business?
It can, if your AI system's outputs are used in the EU or you serve EU users, even without an EU office. Whether you're in scope is a legal question. We can help you build compliance-ready systems, but you should confirm your obligations with a qualified attorney.
Is this legal advice?
No. We're a technology agency, not a law firm, and nothing here is legal advice. We help you design AI with the transparency, human oversight, and documentation that regulations tend to require, and we work alongside your legal counsel.
What's the cheapest way to reduce our risk?
Start with an inventory of where AI is used and a simple risk ranking, then add human review and disclosure to the highest-risk uses first. A free consultation can help you map this before you invest in bigger changes.