US EU AI Act consultants
- The EU AI Act reaches US companies through market placement and through output used in the EU. There is no US establishment requirement.
- There is no comprehensive federal AI statute. Binding duties sit mostly in state law.
- Texas TRAIGA, California SB 53 and AB 2013, and Illinois HB 3773 took effect on 1 January 2026.
- Colorado repealed its 2024 AI Act and replaced it with SB 26-189, with core duties starting 1 January 2027. The original never took effect.
- One governance programme built to the EU standard generally covers the state duties as well, which is the practical reason to build once.
How a US company ends up in EU scope
US companies fall under the EU AI Act on the same two tests as anyone else: placing an AI system on the EU market, or being a provider or deployer outside the EU whose system output is used in the EU. Neither test requires an EU entity, an EU office or an EU contract.
For a US company that also faces a growing set of state AI laws, the practical question is not which regime to comply with. It is how to build one governance programme that answers all of them.
Selling software to EU customers, directly or through a reseller.
Serving a US customer whose own operations reach the EU, so your output is used there.
Employing, screening or assessing people located in the EU.
Offering a consumer product whose output reaches EU users, even where terms and billing sit in the US.
Being named as provider on a system built by someone else, through rebranding, substantial modification, or use for a purpose the original provider did not intend.
What applies in the US at the same time
There is no comprehensive federal AI statute. Federal activity has run through executive orders and agency guidance, and a preemption push has been live without a statute being enacted. The binding private-sector duties sit in state law.
| Jurisdiction | Instrument | Status |
|---|---|---|
| Texas | TRAIGA, HB 149 | In force since 1 January 2026. Substantial compliance with the NIST AI Risk Management Framework carries an enforcement safe harbour |
| California | SB 53, the Transparency in Frontier AI Act, and AB 2013 on training data | Both in force since 1 January 2026 |
| California | CCPA automated decision-making regulations | In force since 1 January 2026, with a phased compliance cascade |
| California | AI Transparency Act, SB 942 and AB 853 | Operative from 2 August 2026 |
| Illinois | HB 3773, AI in employment, amending the Human Rights Act | In force since 1 January 2026 |
| Utah | SB 149, AI Policy Act | In force since 2024 |
| New York City | Local Law 144, bias audits for automated employment decision tools | In force since 2023 |
| Colorado | SB 26-189, replacing the repealed 2024 AI Act | Core automated decision duties from 1 January 2027 |
| New York State | RAISE Act, frontier developers | From 1 January 2027 |
The Colorado position is the one most often reported incorrectly. The 2024 Colorado AI Act was delayed, then repealed and replaced in May 2026 by a narrower automated decision transparency regime whose duties begin on 1 January 2027. The original act never took effect, and the framework-based defence it contained did not survive into the successor.
State laws generally attach based on where the affected person is, not where the company is. That is the same logic the EU Act uses, and it means growth into a new state or a new market can create obligations silently.
Why one programme covers most of it
The regimes ask for different documents and largely the same substance.
An inventory of AI systems with named owners. A documented risk assessment. Evidence that consequential decisions involve meaningful human review. Notice to affected people. Bias and performance testing with results retained. A record of what was decided and why.
Building to the EU AI Act standard, which is the most prescriptive of them, generally produces the evidence the state laws want. The NIST AI Risk Management Framework is the useful common spine, and Texas gives substantial compliance with it explicit safe-harbour status. Our NIST AI RMF service page covers that framework, and the site carries a separate set of guides on US state AI laws.
What a US-facing consultant should cover
Both layers, mapped once. A consultant who scopes only the EU Act leaves your state duties unassessed, and one who scopes only state law leaves you exposed on any EU-facing system.
They should establish EU scope explicitly rather than assuming it away. The output limb catches more US companies than the market limb does, and it is the one most often overlooked.
They should be current on Colorado. A consultant still describing the 2024 Colorado AI Act as the operative regime has not updated since May 2026.
They should build to the NIST AI Risk Management Framework as the common structure, then layer the EU Act's per-system documentation on top for EU-facing systems.
And they should be clear on the EU dates: Article 50 transparency obligations since 2 August 2026, Article 50(2) for legacy systems and the new prohibitions on 2 December 2026, high-risk obligations on 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for AI embedded in Annex I regulated products.
Cost
| Component | Typical range |
|---|---|
| Inventory and classification | $7,000 to $20,000 |
| Gap assessment across EU and state duties | $8,000 to $30,000 |
| Full readiness and build | $20,000 to $70,000 |
| Annex IV technical file, per high-risk system | $10,000 to $35,000 |
| Day rate | $800 to $2,000 |
Cost scales with system count, how many are high risk, and how many jurisdictions you touch.
What to do next
Answer two questions. Does any output from your AI systems reach people in the EU? And which states do your users, employees and applicants sit in? Those two answers define the whole programme.
Our free AI impact assessment gives an immediate first view, and the EU AI Act service page sets out how we run the work.
References
FAQ
Does the EU AI Act apply to US companies?
Yes, where a system is placed on the EU market or its output is used in the EU. No EU entity is required.
Is there a federal US AI law?
No comprehensive federal statute. Federal activity runs through executive orders and agency guidance, with binding private-sector duties mostly in state law.
Is the Colorado AI Act in force?
No. The 2024 act was repealed and replaced by SB 26-189, signed in May 2026, with core automated decision duties beginning 1 January 2027. The original never took effect.
Can one programme cover both EU and state requirements?
Largely yes. Building to the EU standard, on a NIST AI Risk Management Framework spine, produces most of the evidence state laws require.
Which state laws are in force now?
Texas TRAIGA, California SB 53 and AB 2013, California's CCPA automated decision regulations, Illinois HB 3773, Utah's AI Policy Act, and New York City Local Law 144.
About Hael
Hael is an advisory firm specialising in AI governance and security compliance. We take companies through the EU AI Act, ISO/IEC 42001, the NIST AI Risk Management Framework, SOC 2 and ISO 27001, building one governance programme that answers multiple regimes rather than several parallel ones. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.
This guide is general information and is not legal advice on your particular circumstances.