The EU AI Act for US software vendors: what actually applies to you
The United States has more AI vendors than any other market — and produces most of the "EU law doesn't apply to us" answers that European legal teams reject every week. One EU customer, or a US customer whose European teams use your product's output, and Regulation (EU) 2024/1689 almost certainly reaches you. Here is what a US vendor actually owes, what it doesn't — and the second question EU buyers ask in the same breath: data transfers.
Does the EU AI Act reach you?
Two clauses of Article 2(1) do the extraterritorial work — neither cares about a Delaware incorporation:
- Art. 2(1)(a) — the market trigger. Providers placing AI systems on the market or putting them into service in the Union are in scope irrespective of whether they are established in the Union or in a third country. One paying customer in Munich or Paris is enough, with you as provider.
- Art. 2(1)(c) — the output trigger. Providers and deployers established in a third country are in scope where the output produced by the AI system is used in the Union. Selling only to US enterprises does not keep you out: if their EU subsidiaries consume your AI's reports, scores or content, the trigger fires with no EU contract at all.
Both triggers, with worked examples, are in the full non-EU vendor guide. For a US B2B SaaS with any European exposure, "not applicable" is the answer most likely to be wrong on the law.
What you owe if it does
Being in scope does not drop the whole Regulation on you. Most B2B SaaS products are limited-risk systems outside Annex III, leaving the Article 50 transparency duties, applicable since 2 August 2026 — a date the Digital Omnibus did not postpone:
- Art. 50(1) — AI that interacts directly with people must disclose it is a machine. Mind the rebranding rule: whoever ships an AI system under their own brand, or substantially modifies it, is the provider — a US SaaS wrapping GPT or Claude under its own brand owns this duty itself, not its model supplier.
- Art. 50(2) — synthetic audio, image, video or text must carry machine-readable marking; systems already on the market have until 2 December 2026.
High-risk duties attach only to Annex III use cases and, after the Omnibus, apply from 2 December 2027. Article 50 fines can reach €15,000,000 or 3% of worldwide turnover, whichever is higher (Art. 99(4)(g)); SMEs pay the lower (Art. 99(6)). Unsure what lands on your product? The Article 50 checker takes two minutes.
What being US-based adds (and what it doesn't)
For a US vendor, the AI section of an EU questionnaire rarely arrives alone. There is no general EU adequacy decision for the United States: personal data flowing from your EU customer to your US infrastructure needs a named transfer mechanism under GDPR Chapter V. The adequacy-based route is the EU–US Data Privacy Framework — the Commission's adequacy decision of 10 July 2023 (C(2023) 4745), upheld at first instance by the EU General Court on 3 September 2025 (the Latombe challenge) and still in force as of this guide's last update, though an appeal is pending before the Court of Justice (C-703/25 P) — and it covers only US organizations holding an active DPF certification, verifiable company by company on the public DPF list. Not blanket adequacy for the country. If you are not certified, the mechanism is the Standard Contractual Clauses (Implementing Decision (EU) 2021/914) incorporated into your DPA.
What DPF status does not add: it is a GDPR transfer mechanism, full stop. Certification says nothing about your EU AI Act position, and vice versa. Buyers ask both and expect two separate answers.
The questionnaire reality
Direct enforcement against a vendor with no EU establishment is not the near-term risk — procurement is. Your EU customers are in scope themselves, so AI-CAIQ and SIG 2026 questionnaires and RFP AI sections put the question to you, usually as a pair: your EU AI Act position, and your transfer mechanism. An answer that scopes honestly via Art. 2(1)(a) or 2(1)(c), classifies the system (limited risk, outside Annex III), names the Art. 50 duties with dates, and states the transfer mechanism as verified fact survives legal review. A blanket "compliant" — or "not applicable" — parks the deal. If one just landed, start with the first-24-hours playbook and the model answer to "Are you EU AI Act compliant?".
US vendors and the EU AI Act: quick answers
Does the EU AI Act apply to a US company with no EU office?
Yes, if either trigger fires: placing an AI system on the EU market (Art. 2(1)(a)) — one EU customer is enough — or the system's output being used in the Union (Art. 2(1)(c)). US incorporation is expressly irrelevant.
Is Data Privacy Framework certification the same as EU AI Act compliance?
No. DPF is a GDPR transfer mechanism; the AI Act is a separate regulation. Neither answers for the other, and buyers ask about both.
Which deadlines should a US vendor care about?
2 August 2026 — Art. 50 duties apply (not postponed). 2 December 2026 — end of the Art. 50(2) marking transition. 2 December 2027 — postponed Annex III high-risk date, if it concerns you at all.
- Regulation (EU) 2024/1689, Official Journal — Art. 2(1)(a), 2(1)(c), Art. 50, Art. 99, Art. 113 (ELI: data.europa.eu/eli/reg/2024/1689/oj)
- Digital Omnibus: European Parliament position 16 June 2026; Council adoption 29 June 2026 (consilium.europa.eu press releases)
- Commission Implementing Decision C(2023) 4745 of 10 July 2023 (EU–US Data Privacy Framework); DPF certification list: dataprivacyframework.gov/list
- EU General Court, judgment of 3 September 2025 dismissing the Latombe annulment action against the DPF adequacy decision; appeal pending before the Court of Justice (C-703/25 P)
- Commission Implementing Decision (EU) 2021/914 (Standard Contractual Clauses)