Ali Zamanian Startup Legal Strategy
AI Governance & Compliance9 min read

Does the EU AI Act apply to your US startup? A 2026 founder's guide.

The short answer is: probably, if your AI reaches the EU. The Act deliberately borrows GDPR's long arm, and with the main deadline landing on August 2, 2026, "we are a US company" is no longer a compliance strategy. Here is who is in scope, what actually changes, and what a lean startup should do about it.

Most founders meet the EU AI Act the same way they met GDPR: a customer sends a security questionnaire with a question nobody on the team can answer. By then the answer is due, not optional. The good news is that the Act is more navigable than the headlines suggest, and for most startups the practical burden is a fraction of what a 35-million-euro penalty figure implies. The bad news is that scope does not care about your incorporation state, and the clock is real.

This guide answers the question founders actually type into a search bar, does the EU AI Act apply to US startups, and then translates the regulation into the handful of moves that matter before the August 2026 deadline. If you build with AI, sell to companies that operate in the EU, or have an app EU users can open, read on. For the broader operating layer this connects to, see AI governance and risk readiness.

The short answer, and why "we're a US company" does not save you

The EU AI Act applies based on where your AI, or its output, is used, not where your company is registered. If you place an AI system on the EU market, or if the output your system produces is used by people in the EU, the Act can reach you regardless of where your servers, staff, or headquarters sit. This is the same extraterritorial design that made GDPR a global standard rather than a European one.

That means a US startup with no European entity, no European employees, and no European bank account can still be in scope. A single EU-based enterprise customer, a reseller who deploys your model to EU users, or a self-serve product that anyone in the EU can sign up for is enough to pull you in. Founders who assume that "we are based in the US" is a shield are making the exact mistake that cost a generation of companies a scramble under GDPR.

When the EU AI Act actually reaches your startup

Scope turns on your role and your reach. In plain terms, you are likely in scope if any of the following is true:

Notice what is missing from that list: your incorporation, your office location, your team's passports. The Act is built around the market and the people affected, not the corporate address. If your product can be opened, resold, or felt inside the EU, start from the assumption that you are in scope and work backward.

The four risk tiers, and where most startups land

The Act does not treat all AI the same. It sorts systems into risk tiers, and your obligations follow the tier, not the hype. Getting your classification right is the single most useful thing you can do, because it determines whether you have a light transparency duty or a heavy compliance program.

  1. Prohibited. A small set of uses are banned outright, such as certain social scoring, manipulative systems, and untargeted scraping of facial images. Most startups are nowhere near this line, but you should confirm you are not.
  2. High-risk. AI used in sensitive contexts the Act lists, including hiring and employment, education, credit and essential services, biometric identification, and critical infrastructure. High-risk carries the real weight: risk management, data governance, documentation, human oversight, accuracy and robustness, and registration. If your product makes or materially influences decisions in these areas, assume high-risk until proven otherwise.
  3. Limited risk (transparency). The bucket most AI products fall into. If users interact with a chatbot, or your system generates synthetic content, you generally must disclose that they are dealing with AI and, for generative output, label it as machine-generated. This is a labeling and disclosure duty, not a compliance department.
  4. Minimal risk. Everything else, from spam filters to most productivity features, carries no specific obligations under the Act.

For a large share of AI startups, the honest answer is "limited risk," and the work is a transparency notice plus clean records, not a rebuild. But the only way to earn that answer is to run the classification deliberately, because guessing wrong in the high-risk direction is expensive and guessing wrong in the minimal direction is dangerous.

The regulation is not the risk. The risk is a customer, a partner, or an investor asking how you handle it, and the company having no answer on file.

The dates that matter

The Act entered into force on August 1, 2024, and phases in rather than switching on all at once. Three dates matter to founders:

If you build on top of a general-purpose model such as a large language model, note that the GPAI obligations flow partly to the model providers, but they also create pass-through documentation you may be asked to hold. If you are the provider of a high-risk system, the August 2026 date is your line, and readiness work should already be underway rather than pending.

What US founders actually have to do now

Strip away the volume of the regulation and a practical shortlist remains. None of it requires a European entity to begin.

  1. Classify each AI system you offer. Prohibited, high-risk, limited, or minimal. Write the reasoning down. This one step decides everything that follows.
  2. Turn on transparency where it applies. If users chat with an AI or see AI-generated content, disclose it and label it. This is cheap, and it is the most common obligation for startups.
  3. If any system is high-risk, build the file. Risk management, data governance, technical documentation, human oversight, and a plan for the required registration, plus an EU authorised representative if you are placing it on the EU market from outside the EU.
  4. Handle the GPAI layer. If you rely on a foundation model, keep the provider's documentation and confirm your use complies with their terms, so your customer promises do not outrun what the model stack allows. This overlaps directly with your model-provider and vendor terms.
  5. Write a short AI governance file. Even where nothing is high-risk, a two-to-five-page record of what your systems do, what data they use, how humans stay in the loop, and how you handle incidents is what enterprise buyers and investors ask to see. It is the artifact that turns "we take AI seriously" into something you can hand over.

The US layer: NIST AI RMF and the state patchwork

The EU is not the only regime tightening. In the US, the NIST AI Risk Management Framework is a voluntary baseline with no direct enforcement of its own, but it is increasingly referenced by state laws and by enterprise buyers as the expected shape of an AI governance program. A growing set of state rules add real obligations around automated decision-making and transparency. The practical takeaway is efficiency: a single, well-built governance file, mapped loosely to NIST, does double duty. It satisfies most US buyer diligence and gives you a running start on EU documentation, so you are not building two programs for two regulators.

What this looks like for a lean startup

None of this means an early-stage company needs a compliance department. The Act contains proportionate measures for small and medium enterprises: simplified technical documentation, capped penalties, and access to regulatory sandboxes designed to let smaller builders test systems with regulator engagement. The move for a lean team is not to over-build. It is to classify honestly, cover the transparency duty, keep the model-provider paperwork, write the short governance file, and revisit the moment a use case drifts toward high-risk or a European deal appears on the pipeline.

The founders who handle this well are not the ones with the biggest legal budgets. They are the ones who did the classification early, wrote down the answer, and could produce it the day a customer asked, instead of the week the deal stalled.

// what to take from this
  • Scope follows your AI and its output into the EU, not your incorporation. If EU users can reach it, assume you are in scope.
  • Classify every system into a risk tier first; most startups land in "limited risk," which means transparency, not a compliance department.
  • Circle August 2, 2026 for general application, and treat prohibited-practice and GPAI dates as already live.
  • Turn on AI disclosure, keep your model-provider documentation, and write a short AI governance file.
  • Build one governance file mapped loosely to NIST so it serves EU obligations, US state rules, and buyer diligence at once.

The EU AI Act is not a reason to slow down building. It is a reason to make a few decisions early and write them down, which is the same discipline that carries a company through every other kind of diligence. If you are shipping an AI product and want a clear read on your risk tier and the shortest compliant path, that is exactly the kind of upstream work where an hour of judgment saves a quarter of cleanup.

Read more about AI contracts, data, and privacy, see how this fits a full startup legal due diligence checklist, or start a conversation about your AI product. For the wider founder checklist on owning and selling an AI product, read the AI startup legal checklist. For the domestic side of the same map, see US state AI laws in 2026.

This article is general information for founders. It is not legal, regulatory, or compliance advice, and reading it does not create a professional relationship. The EU AI Act is complex and fact-specific, and its guidance continues to develop. Confirm your obligations against the current text and qualified guidance before acting.

Ali Zamanian

Startup Legal Strategy

Ali writes for founders and growing technology companies on AI governance, contracts, IP, data, formation, equity, and startup legal strategy. The work is built around a business-first lens: protect the upside, build leverage, and keep the paper trail clean.

Shipping an AI product? Get a clear read on your risk tier.

A focused first conversation on scope, classification, transparency, and the shortest compliant path for your product. No jargon, no pressure.

Start a conversation