US SaaS guide

EU AI Act for US SaaS Companies

A US company can still have EU AI Act exposure when it places an AI system on the EU market, serves EU customers, supports EU deployers, or produces outputs used in the EU. Start with scope, then classify the use case.

Disclaimer: This guide is for general planning by SaaS teams. It is not legal advice and should not be used as a final cross-border compliance opinion.

Scope questions for US teams

QuestionWhy it matters
Do you offer the AI feature to EU customers or users?EU market availability can create review needs even when the company is incorporated in the United States.
Do EU-based customers deploy the feature inside their workflows?Your customer may be a deployer, while your company may still have provider or supplier duties depending on the product role.
Are AI outputs used in the EU?Article 2 includes certain providers and deployers outside the EU when output produced by the AI system is used in the Union.
Do you control the model, intended purpose, or key product behavior?Control over intended purpose and system design is important when assigning provider, deployer, importer, or distributor roles.
Do you sell through partners, marketplaces, or enterprise resellers?Distribution channels can add role-mapping and documentation requests.

Practical readiness checklist

Common SaaS examples to review

FeatureReview focus
AI support chatbotTransparency notice, escalation to human support, limitation language, and data handling.
AI hiring assistantEmployment high-risk signal, human oversight, documentation, evaluation, and vendor role mapping.
Lead scoring or fraud scoringWhether the score affects access, eligibility, pricing, services, or treatment of individuals.
Document summarizationTransparency, accuracy warnings, review path, and whether summaries are used for consequential decisions.
Generated marketing mediaAI-generated content disclosure and deepfake or synthetic media rules where relevant.

Check a SaaS feature

Official sources

Last reviewed: July 3, 2026.

practical AI compliance self-assessment

Practical notes for EU AI Act for US SaaS Companies

EU AI Act for US SaaS Companies | Practical Scope Guide is maintained for founders, product managers, compliance owners, agencies, and small teams building AI workflows who need AI governance workflow. The goal is to help visitors complete a real task and leave with an AI inventory, risk note, disclosure draft, vendor question set, policy outline, or review workflow report, not only read a generic summary.

guide

Define the system

Start by naming the AI feature, users, decision impact, data categories, vendors, and the team member responsible for maintaining the review record.

guide

Separate triage from advice

Use the generated output as first-pass operational triage. Legal, medical, hiring, credit, education, biometric, and public-sector uses still need specialist review.

guide

Keep evidence

Save the output, assumptions, date, source links, and reviewer notes so the team can explain why a risk level, disclosure, or vendor question set was chosen.

Before relying on this page

  • Review high-impact use cases manually.
  • Keep policies and disclosures aligned with the real product behavior.
  • Re-run the workflow when vendors, data, or user impact changes.

Review record

How to use EU AI Act for US SaaS Companies in an AI compliance file

A compliance tool is useful when it leaves a traceable record. The output should name the AI system, explain the assumptions, and show what the team still needs to verify with product, legal, security, or vendor owners.

Describe the real system

Record the feature name, user group, decision impact, data sources, vendor dependencies, and the human owner. A generic "chatbot" label is rarely enough. A hiring assistant, support summarizer, medical triage bot, and product recommender can have very different risk profiles even if they all use language models.

Separate signal from conclusion

Treat this page as first-pass triage. It can flag high-risk areas, transparency duties, missing evidence, and questions to ask a vendor. It should not be treated as legal approval, clinical advice, hiring approval, credit approval, or permission to launch without human review.

Save evidence and changes

Save the generated result with the date, reviewer, source links, and unresolved questions. Update the record when the model, data, users, product flow, vendor, or region changes. This keeps the site useful for actual operators rather than only being a static explanation page.

Evidence checklist

  • Document what the AI system does and what it does not do.
  • Record whether the system influences employment, education, credit, public benefits, healthcare, biometric identification, safety, or other high-impact outcomes.
  • Keep vendor documentation, model notes, data descriptions, user notices, human oversight notes, and monitoring plans together.
  • Re-run the review when the product behavior changes, not only when the law changes.
  • Use specialist review for high-impact or regulated workflows before relying on any generated text.