The EU AI Act, Explained for a Business That Isn't in the EU

By Mason Hughes

The EU Artificial Intelligence Act is the world's first comprehensive binding law for AI systems. It entered into force in 2024, and its most significant deadline landed August 2, 2026, when most of its rules became enforceable. It was modeled after GDPR, and it carries the same intention: set a global standard, and apply it far beyond companies actually headquartered in the EU.

Does This Actually Apply to a US Business?

The scope is broader than most owners assume, and that's deliberate. The Act applies to providers and deployers outside the EU wherever an AI system's output is used within the EU, not just marketed or targeted there. A US company with no EU office can still be in scope the moment its AI-driven output reaches an EU-based client through any chain, direct or indirect. Company size doesn't exempt anyone: the Act defines small-business treatment as proportionate enforcement, not an exemption from the underlying obligation.

What are the actual risk tiers?

Four. Prohibited practices are banned outright (things like social scoring and manipulative AI). High-risk covers AI making consequential decisions about people, hiring, credit, education. Limited-risk covers chatbots and AI-generated content, mainly a disclosure requirement. Minimal-risk, where most day-to-day business automation sits today, carries the lightest obligations.

What's the difference between a provider and a deployer?

A provider builds an AI system for others to use, the model companies themselves. A deployer uses that system in their own business. Every business running AI tools day to day is a deployer, and deployers carry lighter obligations than providers, mainly around oversight, data quality, and log retention for higher-risk uses.

What does non-compliance actually cost?

Penalties run in three tiers: up to €35 million or 7% of global turnover for prohibited practices, €15 million or 3% for high-risk violations, and €7.5 million or 1% for misleading information, whichever figure is higher. For a small business the real risk usually isn't the fine itself, it's the disruption of a regulatory inquiry into AI use with no documentation behind it.

Is there a standard that already covers most of this?

Yes. ISO 42001 covers an estimated 70 to 80 percent of the Act's high-risk governance requirements, and organizations already aligned to it tend to reach compliance meaningfully faster than starting from a blank page. MAIDEN's own systems are already built aligned to ISO 42001 for exactly this reason - see our plain-language explainer on the standard itself for what it actually requires.

Operational Health
Assessment

20 Questions  ·  5 Minutes

Prepare My Team

45 Minutes  ·  Free