Does the EU AI Act apply to U.S. companies?
It can. Article 2 reaches certain non-EU providers placing AI systems or GPAI models on the EU market and certain non-EU providers/deployers where the output produced by the AI system is used in the Union. The correct analysis identifies the system, actor, EU nexus and relevant exclusions.
Read the Article 2 scope guide →
What EU AI Act obligations are already active in 2026?
The currently applicable framework includes prohibited-practice rules, Article 4 AI-literacy measures, GPAI obligations and Article 50 transparency duties. Enforcement powers for applicable provisions expanded from 2 August 2026.
Did the high-risk deadline remain 2 August 2026?
No. Regulation (EU) 2026/1744 moved the main Chapter III high-risk dates. Article 6(2)/Annex III systems move to 2 December 2027; Article 6(1)/Annex I product-linked systems move to 2 August 2028.
See the current timeline →
What is Article 50 and why does it matter now?
Article 50 contains transparency obligations for specified direct AI interactions, synthetic content, deepfakes and other listed uses. These rules apply from 2 August 2026, with a limited Article 50(2) transition to 2 December 2026 for certain generative systems placed on the market before 2 August.
Read the Article 50 guide →
Do GPAI obligations already apply?
Yes. GPAI-provider obligations have applied since 2 August 2025. They include technical documentation, downstream information, copyright-policy and training-content-summary requirements, with additional duties for GPAI models with systemic risk.
Read the GPAI guide →
What does Article 4 require for AI literacy?
Providers and deployers must take measures to support AI literacy for staff and others dealing with AI-system operation/use on their behalf, considering knowledge, experience, education/training, context and affected persons. The amended Article 4 expressly says this does not require guaranteeing a specific literacy level for each individual.
Read the Article 4 guide →
Does every U.S. company need an EU Authorised Representative?
No. Article 22 applies to providers established in third countries before making high-risk AI systems available on the EU market. Article 54 separately addresses third-country GPAI providers, subject to its rules and exceptions. Scope should be determined before appointing a representative.
Read the representative guide →
If our vendor says the tool is compliant, are we covered?
Not necessarily. Your organisation may hold its own deployer/provider obligations. Vendor documentation is an input to your compliance assessment, not a substitute for role mapping, intended-purpose analysis, Article 50/high-risk assessment and operational controls.
See vendor due diligence →
Does ISO/IEC 42001 or NIST AI RMF make us EU AI Act compliant?
No. They can support governance processes and evidence reuse, but the AI Act is binding law with its own definitions, scope, roles and obligations. A defensible program maps framework controls to specific legal requirements rather than claiming equivalence.
Does EU AI Act compliance replace GDPR compliance?
No. The two regimes regulate different questions. The AI Act focuses on AI systems, actors, risk categories and system obligations; GDPR focuses on personal-data processing. U.S. companies can need separate scope, Article 22, DPIA, transparency and data-transfer analysis alongside AI Act compliance.
Read the EU AI Act + GDPR U.S. company guide →
What should a U.S. company do first?
Build an AI-system inventory; identify EU nexus and actor role; screen prohibited practices, Article 50 and GPAI; identify potential high-risk systems; then map controls, evidence, owners and effective dates.
Start the scoping assessment →
Is an EU AI Act readiness review a certification?
No. A readiness review can identify scope, classification, gaps and evidence requirements, but it is not itself an official conformity assessment, regulator approval or guarantee of compliance.