Does GDPR or the EU AI Act apply to my US company?
A US SaaS company selling seats to a customer in Berlin, a Shopify store shipping to France, an HR-tech vendor whose scoring model is used by a Dutch employer — none of these have an EU office, an EU bank account, or an EU-registered entity. All three can still fall squarely inside GDPR, the EU AI Act, or both. The trigger isn't where your company is incorporated. It's where your customers are, where your marketing points, and where your AI system's output ends up being used. That's a different question than the one most US businesses actually ask, which is usually some version of "we're a US company, why would EU law apply to us at all."
The GDPR test: are you targeting or monitoring people in the EU
GDPR's territorial scope, Article 3(2) of Regulation (EU) 2016/679, doesn't care about incorporation. It applies to a non-EU company whenever it offers goods or services to people in the EU — even for free — or monitors their behavior. Regulators look at intent to target, not mere accessibility: does your site price in euros, offer language versions for EU markets, run ads aimed at EU audiences, reference EU customers or testimonials, ship physically to EU addresses, or use a country-code domain like .de or .fr? A US company whose website happens to be reachable from Brussels because the internet is global isn't automatically in scope. A US company running euro-priced checkout, French- and German-language pages, and ads geo-targeted at Paris and Berlin is a different story, regardless of where its servers or headquarters sit. "Monitoring behavior" catches a second group entirely: cookies, analytics, and ad pixels that track EU visitors, even on a site that never explicitly targets EU sales.
The AI Act test: it doesn't ask where your company is, only where the output lands
The EU AI Act, Regulation (EU) 2024/1689, sets an even wider net for US AI vendors. Article 2(1)(c) applies to providers and deployers located in a third country wherever the output produced by their AI system is used in the EU. That's an output-based test, not an establishment-based one, and it doesn't require an EU sale at all. A US-based HR-tech company whose candidate-scoring tool is used by a single Dutch employer is inside scope, even if the US company itself has no EU customer, EU contract, or EU marketing whatsoever. On 2 August 2026, the obligations for Annex III high-risk systems and the Article 50 transparency duties came into force for every provider and deployer whose output reaches the EU, third-country vendors included — a deadline that's now live, not theoretical.
The duty most US companies skip entirely: appointing an EU representative
If GDPR applies to you under Article 3(2), Article 27 requires you to designate a representative established in an EU member state — a formal point of contact for supervisory authorities and data subjects, distinct from any lawyer you might already retain. Skipping this isn't a paperwork oversight regulators ignore: Article 83 puts the fine for failing to appoint a representative at up to €10 million or 2% of global turnover, on top of whatever fine applies to the underlying processing. The AI Act carries a parallel duty for non-EU providers of high-risk systems, who must appoint their own EU-based authorised representative before placing that system on the EU market. Both duties exist specifically because the EU expects to deal with third-country companies that have no EU office, and both are commonly the first thing a US company's compliance review misses — "do we need a US lawyer" and "do we need an EU representative" don't feel like the same question until someone points out that they're not optional alternatives to each other.
Who can actually enforce this against a company with no assets in the EU
This is the part that gets a lot vaguer once you leave the statute and look at what actually happens. The clearest test case is Clearview AI: Dutch, French, Italian, and Greek data protection authorities have collectively fined the US facial-recognition company roughly €100 million for GDPR violations. Clearview has no EU office, no EU representative, and no EU assets, and it has stated it doesn't do business in the EU at all. There's no treaty mechanism compelling US courts to enforce an EU regulator's fine, and by most public reporting the DPAs have collected close to none of it.
That doesn't mean the exposure is theoretical for a US company that isn't Clearview. Three things bite even without a collectible fine. First, EU business customers increasingly run procurement due diligence that requires a signed Data Processing Agreement, Standard Contractual Clauses, or evidence of a completed risk assessment before they'll sign a contract at all — for a US SaaS company chasing EU enterprise revenue, losing the deal is a faster and larger cost than losing a fight a regulator can't collect on. Second, the AI Act's market surveillance authorities have the power to order a product withdrawn from the EU market outright, which doesn't require collecting anything, it just ends EU sales. Third, being publicly known as the company that ignored EU regulators, the way Clearview now is, is not a reference a serious EU-facing sales pipeline can survive.
The complication sitting on top of all of this right now: the EU-US Data Privacy Framework
If your company transfers EU customers' personal data to US servers, that transfer needs its own legal basis, separate from whether GDPR applies to your processing in the first place. Most US companies rely on the EU-US Data Privacy Framework, the adequacy decision the European Commission adopted in July 2023. That basis is under real strain as of this article: the US Supreme Court's June 2026 ruling in Trump v. Slaughter stripped the statutory independence of FTC commissioners, and the European Data Protection Board has formally asked the Commission to review whether the DPF's adequacy decision still holds, since that decision cited FTC independence as a pillar of its reasoning. A separate legal challenge is already pending before the Court of Justice of the EU. Nobody knows yet how either process resolves, but the pattern will look familiar to anyone who watched Privacy Shield fall in 2020: a US company that hasn't lined up Standard Contractual Clauses as a fallback is carrying a second, independent risk on top of whatever its substantive GDPR exposure already is.
What to check in your own business
- Does your marketing, pricing, or checkout specifically target EU customers — euro pricing, EU-language pages, geo-targeted ads — rather than just being reachable from the EU?
- Does any AI feature you build or use produce a score, decision, or recommendation used by someone based in the EU, regardless of whether you have a single EU customer?
- Have you appointed an EU representative under GDPR Article 27, or under the AI Act's equivalent duty for high-risk providers, or are you assuming a US privacy policy already covers it?
- If you transfer EU personal data to US servers, are you relying solely on the Data Privacy Framework, and do you have Standard Contractual Clauses ready if that adequacy decision doesn't survive its current legal challenges?
- Could you produce a GDPR risk assessment or an AI Act risk classification today if an EU enterprise customer's procurement team asked for one tomorrow?
- Have you checked whether your product falls into an AI Act Annex III high-risk category for any EU-based user of its output, separately from how it's classified for your US customers?
General information, not legal advice: whether GDPR or the AI Act reaches your specific business depends on facts about your marketing, your customers, and your AI systems that this article can't resolve for you. Where Komplya publishes guidance like this, we're clear about which layers have been legally reviewed and which remain draft material, so you can weigh it accordingly.
Can a compliance tool built for EU SMEs actually help a US company? The applicability logic is the same test either way: GDPR's Article 3(2) targeting and monitoring criteria, and the AI Act's Article 2(1)(c) output-based scope, don't change based on where your company is incorporated. Answer a short questionnaire about your EU-facing marketing, customers, and AI features, and Komplya maps exactly which obligations apply and generates an AI-drafted Privacy Policy, AI Usage Policy, or DPIA grounded in those specific obligations — documentation that also happens to be what an EU enterprise customer's procurement team is likely to ask for. What Komplya doesn't do is act as your Article 27 EU representative; that's a distinct legal appointment you'd still need to arrange separately.
Rather than guessing whether EU law reaches your business from three thousand miles away, the faster path is to walk through your actual EU-facing customers, marketing, and AI systems against both tests directly.