
Does the EU AI Act Apply to You
You are in Quebec or Ohio and you have no European office, so you assume this is somebody else's problem. The test is not where you are. It is where the output lands.

Most owners of small and mid sized companies have filed the EU AI Act under things that happen to other people. Usually that is correct. Sometimes it is not, and the difference is worth ten minutes.
What it is and when it started
The European Union’s Artificial Intelligence Act entered into force on 1 August 2024, with obligations phasing in rather than landing at once. The first tranche applied from 2 February 2025, covering prohibited practices and a requirement that staff dealing with AI systems have adequate AI literacy. Obligations for general purpose AI models followed from 2 August 2025.
It works by risk tier. A small set of uses is banned outright. A defined set is high risk and carries substantial documentation, oversight and record keeping duties. Most ordinary business use sits below both of those and carries little more than transparency, which is the important thing for most readers here.
The part people get wrong
The Act is not limited to companies established in Europe. It reaches providers and deployers outside the Union where the output of the system is used inside it.
Read that clause slowly, because it is the one that catches people. It is not about your address, your servers or your incorporation. It is about where the result of the system lands.
So a Montreal firm running an AI screening step over applicants, some of whom are in Europe, is inside the perimeter. A US agency whose AI system generates output delivered to a European client is potentially inside it. A Quebec manufacturer selling only in North America, with an internal automation nobody outside the building ever sees, is not.
The cases most likely to be high risk
If any of these describe something you already run, that is the moment to take advice rather than a view.
Employment. Screening applicants, ranking candidates, or anything feeding promotion and termination decisions.
Access to essential services. Creditworthiness and eligibility assessments, which catches parts of lending and insurance.
Education and training where the system affects admission or assessment.
Biometrics in almost any form.
Recruitment is the one that surprises people. A firm that added AI CV screening to speed up hiring has, without any particular intention, entered the most heavily regulated category in the Act.
What most businesses actually owe
For ordinary uses, and that is the overwhelming majority, the practical obligations are modest and mostly amount to being honest.
Tell people when they are dealing with an AI system rather than a person. Label synthetic content as synthetic. Make sure the staff operating these systems understand what they do and where they fail, which is the literacy requirement and is satisfied by an afternoon and a written note, not a certification programme.
None of that is burdensome. All of it is good practice regardless of jurisdiction, and every one of those items is something a prospective client may reasonably ask about.
Why this is worth doing even if it does not apply
Two reasons, and neither is about compliance.
The first is that the questions the Act asks are the questions a serious buyer will ask you within the next two years. What does this system do, what data does it use, what happens when it is wrong, and who is accountable. A company with written answers wins procurement conversations against a company that has to go away and find out.
The second is that maintaining an inventory of what you run is genuinely useful on its own terms. Most businesses cannot list their AI systems. That is a management problem before it is a legal one.
What it does not do
Worth saying plainly, because the coverage has been alarming and the reality for most companies is not.
It does not ban AI in business. It does not require you to register ordinary automation with anybody. It does not apply to systems used purely for internal operations with no output reaching the Union. And it does not treat drafting an email, summarising a document, routing an enquiry or reading an invoice as high risk activities.
The prohibited list is narrow and it is not a description of anything a normal business was going to build: social scoring by public authorities, untargeted scraping of facial images to build recognition databases, emotion inference in workplaces and schools, and manipulation causing significant harm.
If your reaction to that list is that none of it resembles what you do, that is the correct reaction and it is the position most companies are in.
Where AI Optimize sits on this
We build with the disclosure and the audit trail on by default, because retrofitting them is far more expensive than including them, and because the argument for AI in a business is stronger when it is documented rather than quiet.
The systems we deliver record what ran, on what input, what they decided, and where a person intervened. That exists to make the system debuggable, and it happens to be most of what any regulator or client is going to ask for.
The ten minute version
List the AI systems you run. Include the tools your team adopted without telling anybody.
For each one, ask where the output goes. If it never reaches Europe, the Act is not your concern and you can stop.
Flag anything touching hiring, credit or eligibility, wherever it operates. Those deserve a proper look.
Turn on disclosure wherever a person could mistake the system for a human.
This is not legal advice and the Act is long. But most businesses can answer the only question that matters in an afternoon, and the ones that cannot list what they are running have a bigger problem than Brussels.
Sources
European Commission, Regulatory framework for AI. In force 1 August 2024; first obligations applied 2 February 2025, general purpose AI obligations from 2 August 2025.
AI Optimize builds disclosure and a full audit trail into every system as standard, so the answer to a client questionnaire already exists. That work sits under Custom AI Integrations.
Related reading

Canada Has No AI Law. What Applies Instead.
The federal AI bill died in January 2025. That does not mean nothing governs how you use these systems, and the rules that do apply are the ones most businesses have not read.

What Your AI Policy Should Say About Client Work
A page your team will actually read, covering the four situations that come up. Most policies fail because they were written to satisfy a lawyer rather than to be used on a Friday afternoon.
WHAT WE BUILD





