What will you learn from this article?
- When might a U.S. company be subject to the AI Act even if it does not have a registered office in the European Union?
- When might a U.S. company be considered a provider?
- What risks may arise when using other entities’ technologies?
- Why can improper regulation of liability hinder the sale of a product to customers in the EU?
Can the AI Act apply to a U.S. company?
The AI Act is a European Union regulation, but its scope is not limited solely to companies based in the EU. A U.S. company may be subject to its provisions if it offers an AI system on the European market, places a product using artificial intelligence on the market, or if the output of the system is used within the European Union.
For U.S. companies, therefore, it is not only the place of incorporation that matters. The manner in which the product is offered, its intended use, the target audience, and the role the company plays in the technology delivery process are also significant.
The Scope of the AI Act Extends Beyond the European Union
Pursuant to Article 2 of the AI Act, the regulation may apply to third-country providers who place AI systems or general-purpose AI models on the EU market. It may also apply when the provider or the entity using the system is located outside the EU, but the output of the AI is used within its territory.
Consequently, a U.S. company cannot rule out the application of the AI Act solely on the grounds that the product was developed and is maintained in the United States. If the solution reaches European customers or supports processes carried out in the EU, a separate legal analysis may be required. Keep in mind that this is not the only legal aspect of expansion – also check what to do when a US company hires a programmer in Poland.
This applies not only to companies whose main product is an artificial intelligence system. AI may be one of the features of a SaaS platform, an analytics system, a cybersecurity tool, financial software, or a solution used in manufacturing.
Is the company a provider or an AI user?
One of the first steps should be to correctly classify the company’s role under the AI Act. Article 3 of the Regulation distinguishes, among other things:
A provider is an entity that develops an AI system or a general-purpose AI model, or commissions its development, and then places it on the market or puts it into service under its own name or brand.
A deployer is an organization that uses an AI system as part of its professional activities.
An importer is an entity established in the European Union that places an AI system bearing the name or trademark of an entity from a third country on the EU market.
A distributor makes an AI system available on the EU market but is neither its supplier nor its importer.
Determining the correct role is of practical importance, as it determines the scope of the company’s obligations, responsibility for documentation, and how risks are allocated in contracts with suppliers and customers.
The situation may be more complex when a company modifies a third-party system, integrates it with its own product, or makes it available to customers under its own brand. In such cases, simply classifying the company as a technology user may not be sufficient.
Not every system is subject to the same requirements
The AI Act is based on a risk-based approach. The scope of obligations will therefore depend on the system’s function, its intended use, and its impact on users.
The scope of obligations depends primarily on the system’s function and the effects of its use. A solution that merely supports the user should be assessed differently from a system whose output influences a decision of significant importance to a customer, employee, or other person.
Therefore, the mere fact that a product “uses artificial intelligence” is not sufficient to determine these obligations. It is necessary to analyze the specific function of the product and how it is offered on the EU market.
The AI Act also affects contracts
The impact of the AI Act may already be evident during the negotiation of a contract with a European client or technology provider. The contract should clearly define the roles of the parties, the scope of the documentation to be provided, and responsibility for the system’s compliance with EU requirements.
Contracts with European clients increasingly include requirements regarding the status of the AI system, documentation, security, and liability for legal compliance. If a U.S. company does not have guaranteed access to the necessary information from its technology provider, it may have difficulty demonstrating that the product it offers meets the requirements of the AI Act.
At the same time, an overly broad assurance of full compliance with the AI Act may shift liability to the U.S. supplier for how the customer uses the system or for aspects of the technology beyond its control.
For this reason, product analysis should be linked to contract analysis. Only by considering both of these elements can one determine which obligations actually apply to the company and how they should be allocated among the participants in the technological process.
Why is it worth conducting an analysis early on?
The AI Act is being implemented in phases, but it is already affecting product development and negotiations with customers in the EU. A European business partner may expect information about the system’s status, the supplier’s role, and how regulatory requirements will be met even before the contract is signed.
An early analysis helps determine whether a product is subject to the AI Act and whether the documentation and contracts align with the U.S. company’s actual business model. This allows risks to be addressed before sales begin, rather than being revealed only during an audit, contract negotiations, or expansion into other EU markets. KBiW assists U.S. companies in assessing whether their products are subject to the AI Act and in adapting their contracts to meet EU market requirements.