Skip to main content
    AI & Automation

    EU AI Act Compliance for US Companies: What Actually Applies

    The EU AI Act reaches US companies through customers, not borders. Here is how to classify your systems, what obligations attach, and what to document now.

    James Tuttle·Founder & Fractional CTO/CISO
    2 min readeu ai act compliance, ai act us companies, ai governance

    Last updated:

    Most US executives assume the EU AI Act is somebody else's problem. It reaches you the same way GDPR did: through your customers. If output from your AI system is used in the EU, or you sell into an EU-based enterprise, the obligations flow downstream into your contracts long before any regulator writes to you.

    Step 1: Classify Every AI System You Operate

    The Act is risk-tiered, not technology-tiered. The same model can sit in two tiers depending on use.

    • Prohibited: social scoring, manipulative techniques, most real-time biometric identification in public spaces.
    • High risk: employment screening, credit decisioning, education access, critical infrastructure, and safety components. This is where the heavy obligations live.
    • Limited risk: chatbots and synthetic content — transparency duties, primarily disclosure.
    • Minimal risk: everything else, with voluntary codes of conduct.

    Practical trap: an internal résumé-ranking tool used on EU applicants is high risk even though you would never call it a "product."

    Step 2: Know Your Role

    Provider, deployer, importer, and distributor carry different duties. Fine-tuning a third-party model and putting your name on it can make you the provider — inheriting the full high-risk obligation set from a vendor you assumed carried it.

    Step 3: Build the Documentation Now

    Whatever your tier, these artifacts are what auditors, customers, and regulators ask for:

    • An AI system inventory with owner, purpose, data sources, and risk classification.
    • Risk management records covering foreseeable misuse, not just intended use.
    • Data governance notes on training data provenance, bias testing, and known limitations.
    • Human oversight design: who can override the system, and how that is evidenced.
    • Logging sufficient to reconstruct a decision after the fact.
    • Transparency notices where users interact with AI or AI-generated content.

    Where It Meets Your Existing Program

    If you already run SOC 2 or ISO 27001, you have change management, vendor risk, and incident response. The AI Act adds model-specific risk assessment and human oversight. Map to the NIST AI Risk Management Framework and ISO/IEC 42001 and you will satisfy most of what US enterprise buyers put in their AI questionnaires too.

    What to Do in the Next 30 Days

    1. Inventory every AI system, including the ones a department bought on a credit card.
    2. Classify each by use case and jurisdiction of the affected people.
    3. Write one page per high-risk system covering purpose, data, oversight, and limits.
    4. Add AI clauses to vendor contracts so your suppliers carry their share.

    Meridian Governance handles the classification, documentation, and board reporting so AI oversight stops being a legal fire drill.

    Share

    This article is part of our comprehensive AI & Automation guide.

    Read the complete guide →

    We value your privacy

    We use cookies to analyze site traffic and improve your experience. You can customize your preferences or accept all cookies. Cookie Policy · Privacy Policy