dealrescueGuides › EU AI Act for US vendors

Country guide

The EU AI Act for US software vendors: what actually applies to you

The United States has more AI vendors than any other market — and produces most of the "EU law doesn't apply to us" answers that European legal teams reject every week. One EU customer, or a US customer whose European teams use your product's output, and Regulation (EU) 2024/1689 almost certainly reaches you. Here is what a US vendor actually owes, what it doesn't — and the second question EU buyers ask in the same breath: data transfers.

Does the EU AI Act reach you?

Two clauses of Article 2(1) do the extraterritorial work — neither cares about a Delaware incorporation:

Both triggers, with worked examples, are in the full non-EU vendor guide. For a US B2B SaaS with any European exposure, "not applicable" is the answer most likely to be wrong on the law.

What you owe if it does

Being in scope does not drop the whole Regulation on you. Most B2B SaaS products are limited-risk systems outside Annex III, leaving the Article 50 transparency duties, applicable since 2 August 2026 — a date the Digital Omnibus did not postpone:

High-risk duties attach only to Annex III use cases and, after the Omnibus, apply from 2 December 2027. Article 50 fines can reach €15,000,000 or 3% of worldwide turnover, whichever is higher (Art. 99(4)(g)); SMEs pay the lower (Art. 99(6)). Unsure what lands on your product? The Article 50 checker takes two minutes.

What being US-based adds (and what it doesn't)

For a US vendor, the AI section of an EU questionnaire rarely arrives alone. There is no general EU adequacy decision for the United States: personal data flowing from your EU customer to your US infrastructure needs a named transfer mechanism under GDPR Chapter V. The adequacy-based route is the EU–US Data Privacy Framework — the Commission's adequacy decision of 10 July 2023 (C(2023) 4745), upheld at first instance by the EU General Court on 3 September 2025 (the Latombe challenge) and still in force as of this guide's last update, though an appeal is pending before the Court of Justice (C-703/25 P) — and it covers only US organizations holding an active DPF certification, verifiable company by company on the public DPF list. Not blanket adequacy for the country. If you are not certified, the mechanism is the Standard Contractual Clauses (Implementing Decision (EU) 2021/914) incorporated into your DPA.

What DPF status does not add: it is a GDPR transfer mechanism, full stop. Certification says nothing about your EU AI Act position, and vice versa. Buyers ask both and expect two separate answers.

The questionnaire reality

Direct enforcement against a vendor with no EU establishment is not the near-term risk — procurement is. Your EU customers are in scope themselves, so AI-CAIQ and SIG 2026 questionnaires and RFP AI sections put the question to you, usually as a pair: your EU AI Act position, and your transfer mechanism. An answer that scopes honestly via Art. 2(1)(a) or 2(1)(c), classifies the system (limited risk, outside Annex III), names the Art. 50 duties with dates, and states the transfer mechanism as verified fact survives legal review. A blanket "compliant" — or "not applicable" — parks the deal. If one just landed, start with the first-24-hours playbook and the model answer to "Are you EU AI Act compliant?".

US vendors and the EU AI Act: quick answers

Does the EU AI Act apply to a US company with no EU office?

Yes, if either trigger fires: placing an AI system on the EU market (Art. 2(1)(a)) — one EU customer is enough — or the system's output being used in the Union (Art. 2(1)(c)). US incorporation is expressly irrelevant.

Is Data Privacy Framework certification the same as EU AI Act compliance?

No. DPF is a GDPR transfer mechanism; the AI Act is a separate regulation. Neither answers for the other, and buyers ask about both.

Which deadlines should a US vendor care about?

2 August 2026 — Art. 50 duties apply (not postponed). 2 December 2026 — end of the Art. 50(2) marking transition. 2 December 2027 — postponed Annex III high-risk date, if it concerns you at all.

Primary sources
  • Regulation (EU) 2024/1689, Official Journal — Art. 2(1)(a), 2(1)(c), Art. 50, Art. 99, Art. 113 (ELI: data.europa.eu/eli/reg/2024/1689/oj)
  • Digital Omnibus: European Parliament position 16 June 2026; Council adoption 29 June 2026 (consilium.europa.eu press releases)
  • Commission Implementing Decision C(2023) 4745 of 10 July 2023 (EU–US Data Privacy Framework); DPF certification list: dataprivacyframework.gov/list
  • EU General Court, judgment of 3 September 2025 dismissing the Latombe annulment action against the DPF adequacy decision; appeal pending before the Court of Justice (C-703/25 P)
  • Commission Implementing Decision (EU) 2021/914 (Standard Contractual Clauses)

A buyer just asked where you stand on the EU AI Act?

We draft every answer with this level of citation, in 48 hours, $490 flat — paid after delivery. Not sure yet? Send it anyway: the first 3 answers are free.

Send your questionnaire →