Skip to main content
โ† Back to Blog

September 26, 2026

The EU AI Act Is Enforcing: What US SMBs Using AI Should Do

The EU AI Act reaches US businesses whose AI output is used in Europe. The risk tiers in plain terms, and the short list of what to actually do.

By Ian Phillips, Founder & CEO, Phillips Data Solutions

Most US small businesses assume the EU AI Act is a European problem. It isn't, entirely. The law reaches any company whose AI output is used in the EU, and its obligations are phasing in across 2026 and 2027. If you sell into Europe, or your software does, some of this lands on you. Here's the shape of it, minus the panic โ€” and this is orientation, not legal advice, so check specifics with counsel.

Why a US business is in scope at all

The Act applies based on where the AI's effect lands, not where the company sits. If you put an AI system on the EU market, or the output of your system is used by people in the EU, you can be covered even with no office there. That's the same extraterritorial logic that made GDPR everyone's problem a few years ago, and it's why "we're a US company" isn't the shield it sounds like.

For a lot of small businesses the practical exposure is modest. But "modest" isn't "zero," and the way to know which you are is to look at what your AI actually does.

The risk tiers, in plain terms

The law sorts AI by how much harm it could do, and the tier decides how much is required of you.

  • Prohibited. A short list of uses that are banned outright โ€” things like social scoring and certain manipulative or biometric practices. Most businesses aren't near this, but it's worth confirming you're not.
  • High-risk. AI used in consequential decisions โ€” hiring, credit, education, essential services, and similar. This tier carries the real weight: documentation, human oversight, risk management, record-keeping. If your AI helps decide who gets a job or a loan, assume you're here.
  • Limited-risk / transparency. This is where most SMB use lands. The core duty is disclosure: people should know when they're dealing with an AI, and AI-generated content should be identifiable. Your chatbot has to say it's a bot. Your synthetic media needs to be marked.
  • Minimal-risk. Everything else โ€” the bulk of ordinary automation โ€” carries no new obligations.

Knowing your tier is ninety percent of the work, because it tells you whether you're doing a little disclosure or a lot of documentation.

What to do about it

  • Inventory your AI. List every place AI touches a decision or a customer โ€” the chatbot, the screening tool, the content generator, the vendor features buried in software you already run. You can't classify what you haven't listed.
  • Classify each use by tier. Most will be minimal or transparency-level. Flag anything touching hiring, credit, or another consequential decision for a closer look with counsel.
  • Fix the transparency gaps first. They're cheap and they're the most common exposure. If an AI talks to your customers, it should say so. If you publish AI-generated media, it should be labeled. This is a config and copy change, not a project.
  • Get your documentation habit in place. Even below the high-risk line, being able to say what a system does, what data it uses, and who's accountable is the thing regulators and enterprise buyers ask for. If you've done SOC 2 or HIPAA work, you already have the muscle โ€” the compliance playbook we use is the same shape.

The overlap you can reuse

Here's the part that's good news. The controls the AI Act wants for a serious deployment โ€” an inventory of what AI you run, logging of what it does, a human in the loop for consequential outputs, clear data handling โ€” are the same controls that make an AI system trustworthy and sellable to a cautious enterprise buyer. We build them in by default, not because a regulator asked, but because an AI agent you can't explain is one nobody should deploy. The regulation is mostly formalizing the discipline a careful build already has.

The move

Don't buy a compliance product before you've done the inventory. Most SMBs will find they're in the transparency tier, where the work is disclosure and a bit of documentation โ€” a week, not a quarter. The ones with a high-risk use will know it from the inventory, and that's the case to bring to a lawyer, not a blog post.

If you're deploying AI into a regulated setting or a nervous enterprise buyer is asking questions you're not sure how to answer, that's a discovery call โ€” and the deeper controls work is on the custom apps and workflow consulting pages.

Free checklist

AI Agent Compliance Checklist (SOC 2 + HIPAA)

The controls checklist we build into every regulated AI agent deployment โ€” what auditors and enterprise security teams actually ask for.

Instant access โ€” no spam, unsubscribe anytime.

Talk through compliance-ready AI in a free discovery call

SOC 2, HIPAA, or a nervous enterprise buyer โ€” weโ€™ll walk your use case and show you the controls that get AI agents through review.

Book My Free Compliance Call