FISTA Solutions does not load Google Analytics until you accept. Rejecting keeps optional analytics off. Read the Cookie Policy.

All field notes

Governance · 5 minute read

EU AI Act Compliance for US Companies: Scope, Obligations, Preparation

The EU AI Act applies to US companies that place AI systems on the EU market, deploy them in the EU, or whose AI outputs are used there, regardless of where the company sits. It classifies systems by risk, prohibits some uses, imposes extensive obligations on high-risk systems, adds duties for general-purpose models, and carries significant penalties.

By FISTA Solutions· AI-Native Engineering Team·
EU AI Act Compliance for US Companies: Scope, Obligations, Preparation article cover

US companies that never planned to think about EU regulation find themselves in scope of the EU AI Act because a product is sold in Europe, an EU subsidiary uses an internal tool, or a customer in the EU relies on an AI-generated output. The law is the most comprehensive AI regulation in force, its obligations for high-risk systems are extensive, and its penalties are substantial. The good news for companies with a US governance program is that most of what the Act requires overlaps with controls they already need. This guide covers scope, tiers, obligations, timelines, and preparation, drawing on FISTA Solutions' AI enablement practice. The US landscape is in ai regulation in the united states and the certifiable management system in iso 42001 explained. This article is general guidance, not legal advice; the Act's provisions, guidance, and dates should be confirmed with counsel.

When does the Act reach a US company?

SituationIn scope
Selling or offering an AI system or AI-enabled product in the EUYes, as provider
Deploying AI in EU operations or subsidiariesYes, as deployer
AI outputs produced elsewhere but used in the EUYes, in defined circumstances
Providing a general-purpose model available in the EUYes, as GPAI provider
Importing or distributing AI systems into the EUYes, with importer or distributor duties
No EU market presence, use, or outputGenerally no

Scope questions turn on definitions and facts; confirm each with counsel.

What are the risk tiers?

TierExamplesObligations
ProhibitedCertain manipulation, exploitation of vulnerabilities, social scoring, specified biometric practicesBanned
High-riskEmployment, credit, education, essential services, migration, law enforcement, justice, plus safety components of regulated productsFull provider and deployer obligations
Limited riskChatbots, emotion recognition, deepfakes, generated contentTransparency duties
Minimal riskMost other systemsNone specific; voluntary codes

Classification depends on annexed lists and definitions; the high-risk list resembles the consequential decision areas in US state laws. Comparison is in colorado ai act explained.

What must providers of high-risk systems do?

Establish and maintain a risk management system across the lifecycle; apply data governance to training, validation, and testing data including bias examination; prepare technical documentation; build automatic logging; provide transparency and instructions for use to deployers; design for effective human oversight; achieve appropriate accuracy, robustness, and cybersecurity; operate a quality management system; complete conformity assessment and affix marking; register in the EU database; and conduct post-market monitoring and incident reporting. Each maps to practices in ai model risk management, ai data governance, and ai record-keeping requirements.

What must deployers of high-risk systems do?

Use systems according to instructions; assign human oversight to people with competence, training, and authority; ensure input data is relevant and representative where under their control; monitor operation and inform providers and authorities of risks and serious incidents; keep logs for the required period; inform workers and affected people where required; and, for certain deployers such as public bodies and some private entities, conduct fundamental rights impact assessments. Oversight design is in ai human oversight requirements.

What duties apply to general-purpose models?

Providers of general-purpose AI models must maintain technical documentation, provide information to downstream providers, comply with copyright rules, and publish training content summaries; models designated as posing systemic risk carry additional evaluation, adversarial testing, incident reporting, and cybersecurity duties. US companies offering models in the EU should assess whether they are providers. Supply chain implications are in ai supply chain security.

What transparency duties apply?

Informing people when they interact with an AI system unless obvious; labeling AI-generated or manipulated content including deepfakes; disclosing emotion recognition and biometric categorization; and marking synthetic content in machine-readable form where required. Notice design is in ai transparency notices and provenance in ai content provenance.

How is the Act phased in and enforced?

Obligations apply in stages over several years from entry into force: prohibitions first, general-purpose model duties next, then most high-risk obligations, with product-embedded high-risk systems later. Penalties scale by violation type up to percentages of global annual turnover. National authorities and an EU-level office enforce. Dates and guidance continue to develop; track them with counsel.

How should a US company prepare without duplicating its US program?

Determine scope; classify systems by tier; map high-risk obligations to existing controls from model risk, privacy, and state law programs; close the gaps, typically in conformity assessment, technical documentation format, logging requirements, quality management, registration, and EU representation; align transparency practices; and track the timeline. One governance program with jurisdiction-specific additions serves the EU and US. Program structure is in what is ai governance and certification that evidences it in iso 42001 explained.

What mistakes leave US companies exposed?

Assuming no EU office means no scope; missing that EU use of outputs triggers coverage; classifying systems optimistically; treating vendor systems as the vendor's problem when deployer duties apply; documentation in a form that does not satisfy conformity requirements; and no EU representative where required.

What does prepared practice look like?

A US software company with EU customers classifies its hiring-assistance feature as high-risk, maps obligations to its existing model risk and bias testing program, completes technical documentation and conformity assessment, builds logging and oversight instructions for deployers, appoints an EU representative, registers the system, and labels its chatbot and generated content. Its EU subsidiary, as deployer, assigns oversight and keeps logs. The program extends existing controls rather than building a parallel one.

How FISTA Solutions helps with EU AI Act preparation

FISTA Solutions builds AI systems with the risk management, data governance, documentation, logging, oversight, and evaluation evidence the Act requires, and helps US clients determine scope, classify systems, and map obligations to existing programs with their counsel. The AI enablement practice leads governance design, AI agents ship with transparency and oversight built in, and forward deployed engineers embed with client compliance teams. The record behind the approach is 150+ projects across 12+ countries.

To extend your governance program to EU obligations without duplicating it, message FISTA on WhatsApp, or read iso 42001 explained for the management system that evidences compliance.

Share-ready article cover

Download the generated social format.

Download cover

Clear answers

Questions raised by this field note.

Straightforward guidance for evaluating scope, fit, and the next step.

01Does the EU AI Act apply to a US company?

Yes if it places AI systems on the EU market, puts them into service in the EU, or if the output of its AI systems is used in the EU, and also if it deploys AI in EU operations. A US company with EU customers, EU employees, or EU-facing products should assume scope and confirm with counsel.

02What are the risk tiers?

Prohibited practices such as certain manipulation, social scoring, and specified biometric uses; high-risk systems in listed areas such as employment, credit, education, essential services, and law enforcement, plus safety components of regulated products; limited-risk systems with transparency duties; and minimal-risk systems with no specific obligations.

03What must high-risk system providers do?

Establish a risk management system, data governance for training and testing data, technical documentation, logging, transparency and instructions for deployers, human oversight design, accuracy, robustness, and cybersecurity, a quality management system, conformity assessment, registration, and post-market monitoring.

04What must deployers of high-risk systems do?

Use systems per instructions, assign human oversight to competent people, ensure input data is relevant, monitor operation, keep logs, inform affected people and workers where required, and in certain cases conduct fundamental rights impact assessments, with cooperation duties toward providers and authorities.

05How should a US company prepare?

Determine scope, classify systems by tier, map high-risk obligations to existing controls from US programs, close gaps in documentation, data governance, logging, oversight, and conformity, track the phased timeline, and appoint EU representatives where required, coordinating with counsel.

Start with the hard problem

Need the outcome owned, not merely analyzed?

Tell us where delivery is constrained. We’ll map the fastest credible path from intent to verified production.

Start a project