← Back to list

The AI Act Follows Your Output, Not Your Address

This is not just ‘European problems’ Doing business with Europe, deal with the EU AI Act.

Marco Kotrotsos in Autocomplete. Real World AI · 2026-07-10 09:31 · 54 claps · 7.2 min read paywalled
#ai #artificial-intelligence #europe #trade #business
Open on Medium ↗
Wiki topics: AI · AI · General ECO · Economy · General

The AI Act Follows Your Output, Not Your Address

This is not just ‘European problems’ Doing business with Europe, deal with the EU AI Act.

If your company is in the United States, you have probably filed the EU AI Act under “European problem.” No EU office, no EU servers, no EU staff, so no obligation. It is a comforting read, and it is wrong in exactly the way that “GDPR is a European problem” was wrong in 2016.

Mind you I am saying ‘United States’ here as an example, but this applies to all countries, anywhere.

We have seen this movie. Plenty of American companies waved off GDPR as somebody else’s regulation right up until 2018, when they discovered their signup form, their analytics, and their email list had quietly put them in scope. Then they paid consultants triple to catch up under deadline. The AI Act was deliberately built on the same jurisdictional logic, and the companies telling themselves the border protects them are setting up the same scramble.

The part that changes the math is simple: the AI Act does not follow your headquarters. It follows your output.

Three things to take away

  • A US company with no EU presence can still be fully in scope. The trigger is whether the output of your AI system is used in the EU, not where your company sits. Article 2 is written to catch exactly this.
  • It works the way GDPR does, on purpose. The Act mirrors GDPR’s extraterritorial reach because the EU watched that model work. The “we are not in Europe” defense failed then and it fails now.
  • The obligations that arrive in August 2026 apply to you too. Transparency and AI literacy are not waived because you are American. If your AI touches EU users, the same August 2 deadline is yours.

What GDPR already taught everyone

GDPR did something regulators had rarely pulled off before. It reached across borders and made non-EU companies comply by tying jurisdiction to the location of the people affected, not the location of the company. If you processed the personal data of people in the EU, you were in, wherever you were incorporated.

Lawyers call the follow-on pattern the Brussels Effect. The EU sets a rule for its market, the market is too big to walk away from, and rather than build one product for Europe and another for everyone else, companies adopt the EU standard globally because it is cheaper than maintaining two systems. GDPR became the de facto baseline for privacy worldwide not because other countries copied it, though many did, but because compliance teams found it simpler to apply everywhere.

The AI Act is the EU running the same play for artificial intelligence. If you assume it will not reach you, you are betting against a strategy that already worked once.

The actual mechanism: Article 2

Scope lives in Article 2, and it opens three doors. You only need to walk through one to be covered.

The first door is being a provider. If you place an AI system on the EU market or put one into service there, you are in, and the text is blunt about geography: this applies “irrespective of whether those providers are established or located within the Union or in a third country.” A US company selling an AI product to European customers is a provider on the EU market. Done.

The second door is being a deployer established in the EU. This one is the obvious case and probably not you if you are fully US-based.

The third door is the one that catches companies off guard, and it is the widest. The Act applies to “providers and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union.” Read that again. Third country. Output used in the Union. That is the whole test. Your servers, your incorporation, your staff, none of it appears in the sentence. If the thing your AI produces, a score, a decision, a recommendation, a translation, a generated image, is used inside the EU, the Act reaches back across the Atlantic and lands on you.

Three ways the AI Act reaches a US company: placing an AI system on the EU market, being a deployer established in the EU, or having your AI’s output used in the EU from a third country, all leading to in scope

Who this actually catches

Abstract scope language feels harmless until you map it onto normal business. A few examples that are not edge cases.

You run a US SaaS product with an AI feature, and some of your customers are European companies. The output of your model is used in the EU by those customers. You are in scope.

You are a US company using AI to screen job applicants, and some applicants are in the EU. The output, a ranking or a pass or fail, is used to make a decision about a person in the Union. In scope, and quite possibly in the high-risk category, which is a heavier tier.

You built an AI tool that scores or moderates user-generated content, and EU users pass through it. The output is used in the Union. In scope.

You are a US AI vendor whose model or API is embedded in products that European businesses use. You are a provider whose output is used in the EU. In scope.

None of these companies have a European office. All of them are covered. That is the design, not an accident.

What it does not mean

Broad is not infinite, and the piece of this that people get wrong in the other direction is assuming any faint connection to Europe drags them in. It does not. The operative phrase is output “used in the Union,” not “theoretically reachable from the Union.” A European once loading your US website does not, by itself, put your AI in scope. There has to be actual use of the output inside the EU.

Several things are carved out entirely. Purely personal, non-professional use by an individual is exempt, so a European using your consumer app for personal reasons is not the hook that pulls your whole company in through the business-scope doors. AI built and used exclusively for military, defense, or national security purposes is out. Pure research and development before a system goes to market is out, though real-world testing is not. Free and open-source AI gets an exemption too, but with a sharp limit: it falls away the moment the system is high-risk or touches the prohibited practices in Article 5 or the transparency obligations in Article 50.

The honest summary is that the reach is deliberately wide but tied to a real connection. If your AI output genuinely gets used in Europe as part of doing business, assume you are in. If your only link to the EU is that the internet exists there, you are probably not.

The teeth

This is not a voluntary code with a stern letter at the end. The penalty ceiling for the prohibited practices in Article 5 is up to 35 million euros or 7 percent of total worldwide annual turnover, whichever is higher. For most other breaches it is up to 15 million euros or 3 percent of worldwide turnover. Worldwide, not European. The fine scales to your global revenue regardless of how much of it came from the EU.

There is also the access question, which for many companies bites harder than fines. If you cannot demonstrate compliance, your route into the EU market narrows, and EU customers who are themselves on the hook will start asking you for documentation as a condition of doing business, the same way GDPR data processing agreements became a standard line item in every enterprise contract.

What a US company should do now

Map where your AI output lands. Not where your company is, where the output gets used. If any meaningful amount ends up in the EU, proceed as if you are in scope, because you are.

Figure out your role. Provider and deployer carry different obligations, and a lot of US companies are providers without thinking of themselves that way, because they ship an AI feature that others use. If you are a provider of a high-risk system or a general-purpose AI model, you may need to appoint an authorized representative established in the EU. Find that out before a regulator or a customer does.

Treat the August 2, 2026 obligations as yours. The transparency rules under Article 50 and the AI literacy duty under Article 4 are live on that date, and nothing about them waits for you to open a European office. If your chatbot serves EU users, it discloses. If your synthetic media reaches EU audiences, it gets labelled. If your staff operate AI systems whose output is used in the EU, you take literacy measures and write them down.

Write everything down. As with GDPR, a large part of compliance is being able to show your reasoning: how you assessed scope, what role you concluded you hold, what measures you took. The documentation is not busywork, it is the evidence.

The border is not a strategy

The companies that got hurt by GDPR were not the ones that read it wrong. They were the ones that did not read it at all, because they had decided in advance it did not apply to them. The law did not care about that decision.

The AI Act is the same bet with a bigger number attached. “We are a US company” is not a compliance position, it is a hope, and it is a hope the EU specifically wrote Article 2 to defeat. If your product touches Europe, you are already part of this. The only open question is whether you deal with it now, on your schedule, or later, on a regulator’s.

Marco Kotrotsos, specializing in practical AI implementation for organizations ready to close the gap between AI hype and AI value. With 30 years of IT experience now focused purely on AI deployment, he works hands-on with companies to turn AI potential into measurable business outcomes.

This article is published in Autocomplete, a Medium publication about real-world AI for practitioners and decision-makers. We’re always looking for writers. If you’re building with AI and have something worth sharing, reach out.

My free Substack newsletter, also called Autocomplete, can be found here: https://acdigest.substack.com.

My books on Amazon: Claude Code for Everyone Else and From Vibe to Production.

I also take on a small number of mentees one-on-one on MentorCruise.


메타데이터
post_id
fd4f760f226f
slug
the-ai-act-follows-your-output-not-your-address-fd4f760f226f
url
https://medium.com/autocomplete-real-world-ai/the-ai-act-follows-your-output-not-your-address-fd4f760f226f
canonical_url
https://medium.com/autocomplete-real-world-ai/the-ai-act-follows-your-output-not-your-address-fd4f760f226f
author_url
https://medium.com/@kotrotsos
status
ok
fetched_at
2026-07-13 06:23:13