David Juilfs
I hope you enjoy reading this blog post. If you want my team to just do your marketing for you, click here.
Author: David Juilfs | Owner & CEO Gorilla Marketing
Published on June 9, 2026

You're probably already using AI in ways that feel routine. A chatbot on your website. Call summaries inside your phone system. Intake automation for new patients or new clients. Contract review, document analysis, ad copy drafts, review-response tools, maybe even synthetic voice or video in marketing.

That's exactly why the EU AI Act matters.

A lot of U.S. businesses still think this law is for model builders, Silicon Valley platforms, or multinational software companies with offices in Europe. That's the wrong frame. If your business uses AI and your services, content, or outputs reach people in the EU, this stops being a distant policy story and becomes an operating issue. The core question isn't whether you're an AI company. It's whether AI is now embedded in how you market, sell, serve, document, or communicate.

Understanding the EU AI Act for U.S. companies means getting practical fast. You need to know where your exposure sits, which tools create immediate transparency obligations, and where a more serious governance program is required. Waiting until a customer asks, a vendor changes terms, or a regulator's timeline catches up to your workflow is sloppy management.

The EU AI Act Is Here: Does Your U.S. Business Need to Pay Attention?

Your firm buys an AI intake tool, plugs it into the website, and lets it screen leads, answer questions, and draft follow-ups. Six months later, a vendor asks you to accept new contract terms because some of your users are in Europe. Now the issue is on your desk. That is how this law shows up for U.S. companies. Indirectly, through tools you did not build.

The mistake is treating the EU AI Act as a problem for model developers only. For medical practices, law firms, accounting firms, and other service businesses, the bigger exposure often sits in third-party software already embedded in daily operations. If those tools generate outputs used in the EU, support EU-based users, or affect decisions tied to EU individuals, your business can have compliance obligations even without a European office.

This catches companies that buy AI, not just companies that sell it.

That distinction matters because buyers tend to assume the vendor owns the risk. It does not work that way in practice. If your team uses AI in patient intake, legal document review, appointment triage, client messaging, marketing content, or internal decision support, you need your own inventory, your own review process, and your own record of why the tool is acceptable for that use.

The pressure is highest in firms handling sensitive information or professional judgment. Healthcare groups and law firms are obvious examples. They often use AI features inside scheduling platforms, transcription tools, CRMs, research products, and case or patient workflow systems without a clear map of where the output goes or how the vendor classifies the system. That is a management problem, not just a legal one.

A lot of companies also need to tighten the legal and operational side of AI use. This overview of why AI compliance is becoming a major legal practice area shows why contract review, procurement, governance, and workflow design now belong in the same conversation.

Use a simple rule. If AI touches customer service, patient or client communications, intake, documentation, or marketing claims, review it before you scale it.

Start with three questions:

  1. Which third-party AI tools are already active across the business?
  2. Do any of them touch EU users, EU data, or outputs that could be relied on in the EU?
  3. What controls do we have beyond the vendor's sales promises and boilerplate terms?

Answer those now. The compliance timeline is staggered, and that creates confusion, but it also gives you a clear priority. First, identify where AI is being used. Then sort the tools by risk and business impact. Companies that wait for 2026 to start will waste time cleaning up tool sprawl, weak contracts, and undocumented workflows they should already have under control.

Does the EU AI Act Apply to Your U.S. Company

A Boston law firm buys an AI contract review tool from a U.S. vendor. An Illinois clinic adds an AI chatbot to handle patient intake. Neither company writes models. Neither company thinks of itself as an AI company. Both can still fall within the EU AI Act if the tool, the users, or the output connects to the EU.

That is the mistake U.S. companies keep making. They assume the Act only matters if they build AI products or open an office in Europe. The trigger is much broader. If your company puts AI into services used in the EU, or if AI-generated output is relied on there, you need to assess your role and your exposure now.

A businessman in a suit holds a tablet showing a world map with the US and Europe highlighted.

Start with your role, not your headquarters

The smartest first question is not “Are we covered?” It is “How are we involved with the AI system?”

That answer drives your obligations.

Role What it means in practice U.S. business example
Provider You build an AI system, brand it as your own, or place it on the market under your name A software company selling an AI legal research feature
Deployer You use an AI system inside your business operations A law firm using a third-party document review tool
Importer You bring an AI system from outside the EU into the EU market A company arranging EU distribution of an external AI product
Distributor You make an AI system available without being the original provider A reseller offering an AI-enabled platform to EU customers

One company can sit in several roles at once. Your product team might be a provider. Your HR team might be a deployer. Your European sales channel might make you an importer or distributor. Treating the whole company as one category leads to bad decisions and missed obligations.

Deployers are the group that gets ignored

This matters most for U.S. companies that use third-party AI tools instead of building them.

Healthcare groups, law firms, insurers, consultancies, and multi-location service businesses often license AI through other software they already buy. The AI sits inside intake tools, call analytics, document review platforms, scheduling systems, client portals, and marketing software. Leaders assume the vendor owns the compliance burden. That is a lazy and expensive assumption.

If your team uses the tool in a regulated workflow, your company carries risk.

A few common examples:

  • A law firm uses outside AI software to summarize discovery, draft clauses, or rank contract issues. The firm is a deployer.
  • A medical practice uses an AI assistant for patient intake, scheduling triage, or documentation support. The practice is a deployer.
  • A service company uses AI to generate customer messages, recommend next actions, or summarize calls across locations. The company is a deployer.

Vendor compliance matters. Your own use still matters too. You need to know what the tool does, where the outputs go, who relies on them, and whether the use case touches regulated decisions or sensitive data.

The practical test for U.S. companies

Use a business test, not a theoretical one.

The EU AI Act deserves attention from your company if any of these are true:

  • EU users interact with your AI-enabled service
  • AI output is delivered to, reviewed by, or acted on in the EU
  • You rebrand or resell an AI feature under your company name
  • Different departments are using AI tools without central approval or documentation

If you answer yes to any one of those, stop treating this as a Europe-only issue for later. Put an owner on it. Map the tools. Confirm your role for each use case. Then check which systems create actual compliance work versus routine procurement oversight.

That is the difference between a manageable AI program and a cleanup project nobody wants in 2026.

Navigating the Four AI Risk Categories

A U.S. company can use ten AI tools and face four different levels of exposure under the EU AI Act. That is why broad statements like "we only use low-risk AI" usually signal weak internal review, not safety.

The Act sorts AI by use case and potential harm. Use that structure to review each tool your teams rely on, especially third-party products embedded in hiring, client intake, patient workflows, document review, and customer communications. If you need a plain-English primer on how regulators define AI-related legal duties, this overview of AI law and compliance basics is a useful starting point.

Unacceptable risk

This category is banned.

If a tool uses manipulation, exploitation of vulnerability, or other practices the Act prohibits, stop the project and remove it from consideration. Do not waste time drafting internal policies for a use case the law does not permit.

Many U.S. companies will never intentionally buy a system in this category. The primary problem is indirect exposure through vendors. Ask a hard question during procurement: does this product use biometric categorization, covert manipulation, or other features that create rights-based concerns in the EU? If your vendor cannot answer clearly, treat that as a procurement failure.

High risk

This category deserves immediate executive attention because it creates the primary compliance burden.

High-risk AI includes systems used in sensitive contexts where outputs can affect health, safety, legal position, employment, access to services, or similarly serious outcomes. U.S. companies often miss this because they focus on whether they built the model. That is the wrong test. If your business uses a third-party tool inside a high-stakes workflow, you still have work to do.

Healthcare and legal services should be especially careful here. An AI feature that supports patient triage, clinical prioritization, or medically relevant recommendations needs review before rollout. A law firm tool that only drafts first-pass language may sit lower on the scale, but a system that influences case assessment, client screening, or other consequential judgments deserves a much harder look.

Use this table to classify common use cases:

Risk level What it means Example in healthcare or law
High risk Strong governance, documentation, oversight, and control requirements AI used in medical decision support, employment screening, or other consequential determinations
Limited risk Transparency duties apply A chatbot handling intake or answering routine questions
Minimal risk Light direct obligations under the Act Internal summarization, drafting help, or low-stakes productivity support

Limited risk

Through this aspect, many U.S. service firms will first feel the Act.

Limited-risk systems usually trigger transparency duties. If people are interacting with AI, or receiving AI-generated content in a context where disclosure is required, your company needs clear notices and clean operating rules. That applies fast to firms using third-party chatbots, intake assistants, synthetic media, and automated messaging across EU-facing channels.

Common examples include:

  • Website chatbots on healthcare, legal, and professional service sites
  • AI-generated intake or follow-up messages sent to prospects, clients, or patients
  • Synthetic voice or video used in marketing or service delivery
  • AI-assisted public content where users need to understand how it was produced

A simple rule works well here. If a reasonable user could mistake AI for a human, disclose it. If your team is publishing altered or generated media, label it. Do this now, not after someone in compliance raises it during contract review.

Minimal risk

Minimal risk does not mean no management.

Many internal tools will fall here: note summarizers, writing support, search assistants, meeting recaps, and basic workflow automation. The law places fewer direct obligations on these use cases, but business risk still builds if teams start using them in regulated processes without approval.

That is how small tools become bigger problems. A harmless summarizer gets plugged into HR screening. A drafting tool starts shaping legal advice. A scheduling assistant begins influencing patient triage. Reclassify tools when the use case changes, not once a year after the damage is done.

Classify the use case, not the vendor

One vendor can offer products across several risk categories. One company can use the same tool in both minimal-risk and high-risk ways depending on where it sits in the workflow.

Review AI at the task level. Identify who uses it, what decision it influences, whether EU users are affected, and whether the output touches health, employment, legal rights, or other sensitive matters. Then set priorities based on that reality.

That approach will keep your 2026 preparation focused. It will also stop your team from wasting time on low-stakes tools while a high-risk use case slips through procurement unchecked.

Core Compliance Obligations for High-Risk AI

A U.S. company can trigger high-risk obligations without building a model, writing code, or calling itself an AI company. If your team uses a third-party tool in an EU-facing workflow that affects health, employment, access to services, or legal rights, you need controls you can prove.

That is the part many buyers miss. The burden does not disappear because the vendor built the system. If your business deploys it inside a regulated decision path, regulators and counterparties will expect evidence that you chose it carefully, set it up correctly, and kept humans accountable.

A graphic infographic listing nine core compliance obligations for high-risk artificial intelligence systems.

Start with ownership, not paperwork

High-risk AI compliance fails when the tool has an enthusiastic buyer but no accountable operator. Assign ownership before the system spreads across teams.

At minimum, name owners for:

  • Business operations to define the use case and decision impact
  • Legal or compliance to review obligations, contracts, and disclosures
  • IT or security to manage integrations, access, logging, and technical controls
  • Department leadership to supervise day-to-day use and escalation

If internal stakeholders still need plain-language context, point them to this overview of what AI law covers in practice. Then bring the discussion back to workflows, approvals, and evidence.

The work you actually need to do

Treat these as operating requirements. If a vendor cannot support them, stop calling that a feature gap. It is a procurement failure.

Risk management system

Write down how the use case can go wrong, who reviews those risks, what mitigations are in place, and when reassessment happens. Cover predictable failures such as bad outputs, misuse by staff, hidden bias, workflow drift, and overreliance on automation.

This needs to be active. A one-time memo will not help when a client, regulator, or auditor asks what changed after deployment.

Human oversight

Put a real person in control of the outcome, not just the interface. That person needs authority to question outputs, override them, pause use, and escalate problems.

For U.S. companies using third-party tools, weak implementation usually manifests. Staff get a polished dashboard, but no training, no intervention rules, and no defined point where human judgment must take over.

Technical documentation

You need a usable record of what the system does, what inputs it relies on, what outputs it produces, where it sits in the workflow, and what systems it connects to. Keep that documentation current enough that another reviewer could understand the setup without chasing five departments for answers.

If the vendor will not provide meaningful documentation, reconsider the tool. High-risk use cases are the wrong place for black-box procurement.

Record-keeping

Keep logs that let you reconstruct what happened. That includes inputs, outputs, user actions, overrides, incidents, and material system changes.

Without records, you cannot defend your process. You also cannot spot recurring problems early enough to fix them.

Data governance

Check whether the data used in the workflow is relevant, appropriate, current, and handled lawfully. For companies using third-party AI, this often means reviewing what your staff uploads, what the vendor retains, and whether the tool was repurposed for a more sensitive task than originally approved.

Healthcare and legal workflows can quickly become risky. Intake notes, case summaries, triage details, and client communications can shift a tool from harmless convenience to serious compliance exposure.

Accuracy, reliability, and cybersecurity

These are operational controls. Poor performance, inconsistent results, and weak security create business risk long before an enforcement letter arrives.

Test the system in the specific workflow where you plan to use it. Do not rely on vendor marketing claims or generic benchmark sheets. A tool that performs acceptably in demos can still fail in patient intake, claims review, legal drafting, or eligibility screening.

High-risk AI compliance comes down to evidence. If you cannot explain the workflow, show the controls, identify the owner, and produce records, you are not ready to use the system in that context.

Focus on the deployment timeline that matters

Do not wait until 2026 to clean this up. If you already use AI in a function that could qualify as high-risk, start now with inventory, ownership, vendor documentation, and escalation rules.

Then sequence the harder work. Test oversight in live workflows. Tighten logging. Update contracts. Recheck whether teams are using general-purpose AI tools inside sensitive decisions without approval.

Companies that start early will spend 2026 refining controls. Companies that wait will spend it scrambling to explain systems they never really governed.

How the AI Act Impacts Healthcare Law and Service Firms

A U.S. clinic buys an intake chatbot from a vendor. A law firm adds an AI assistant to screen leads and answer questions on its website. A multi-location service business starts using synthetic voice and AI-written responses in customer communications. None of these companies sees itself as an AI developer. All of them can still create EU AI Act exposure.

That is the mistake to fix. U.S. companies that use third-party AI tools are often closer to the compliance line than the vendors selling those tools.

Healthcare firms need to treat patient-facing AI as a governed workflow

Healthcare organizations often start with tools that look harmless. Scheduling assistants, intake bots, symptom-screening prompts, marketing content generators, and call-routing systems are easy to approve because they sit inside familiar software. That does not make them low-risk in practice.

If an EU-based patient or prospective patient interacts with your system, transparency duties can apply. If your team publishes AI-generated or AI-manipulated content, public labeling issues can apply. If staff rely on AI outputs to route people, summarize medical information, or shape access to care, the risk moves out of marketing and into operations.

Do four things immediately:

  • Tell users when they are interacting with AI
  • Define when a human must take over
  • Review every patient-facing script, prompt, and escalation path
  • Check whether marketing uses synthetic images, audio, or video without disclosure

Do not leave this with IT alone. Compliance, operations, marketing, and the business owner for the workflow should all be involved.

Law firms have a vendor-use problem, not just a model-risk problem

Law firms usually focus on accuracy and confidentiality. They should. But the first failure point is often much simpler. The firm deploys AI in intake, lead qualification, website chat, document summaries, or public legal content without clear disclosure, review rules, or ownership.

A chatbot that suggests whether someone may have a claim is not just a marketing widget. It shapes expectations, captures sensitive facts, and can influence how a prospective client acts next. An AI-generated explainer on a practice-area page is not just content production. It is client communication published under your brand.

The practical question is straightforward. Who owns the risk when the vendor supplies the tool, marketing publishes the output, and lawyers rely on the result?

If the answer is unclear, fix governance before you expand usage.

The highest-risk gap in professional services is usually not model development. It is unmanaged deployment by business teams using third-party tools inside real client workflows.

Service firms should map use cases by customer impact

Accounting firms, consultancies, franchises, home service brands, and other service businesses should stop treating AI as one category. The law applies to use cases. Review each workflow based on what the tool does, who sees it, and whether people rely on it.

Workflow Common AI use What to review
Lead handling Chatbots and automated qualification AI disclosure, escalation, recordkeeping
Marketing content AI-written copy or synthetic media Labeling, approval process, source review
Call operations AI summaries and routing Accuracy checks, staff override, downstream use
Reputation management Review-generation and response tools Transparency, misleading output, publishing controls

The business recommendation is simple. Inventory every third-party AI tool your teams already use. Then review the workflow, not just the software contract. That is where healthcare groups, law firms, and service businesses are most likely to miss their real exposure.

Your Practical Readiness Checklist for 2026

A U.S. law firm buys an AI intake tool from a vendor. Marketing adds an AI chatbot to the website. Operations turns on automated call summaries inside the phone system. No one thinks of this as product development. Under the EU AI Act, that assumption can leave you exposed.

Your 2026 plan should focus on what your business is already using, especially third-party tools inside client-facing or regulated workflows. The timeline is staggered, so treat compliance as a phased operating plan. Some rules already apply. Other obligations are scheduled to apply later, depending on the use case and your role. Editor note: verify the currently scheduled 2 August 2028 date before publication and update phrasing if needed.

A seven-step checklist infographic outlining a practical roadmap for businesses to achieve EU AI Act compliance by 2026.

Step one through three

Start by finding the actual exposure.

  1. Inventory every AI system in use
    Include stand-alone tools, AI features embedded in existing software, website chat, drafting assistants, call tools, search tools, and workflow automation. Do not accept, "it is just a vendor feature" as a reason to skip review.

  2. Classify each use case by business impact
    Review the workflow, not the brand name of the tool. An internal note-summarization feature does not raise the same issues as a patient-facing chatbot, a legal intake assistant, or a system that influences eligibility, triage, or case handling.

  3. Assign your role for each use case
    Determine whether you act as a provider, deployer, importer, distributor, or authorized representative in that specific context. U.S. companies often get this wrong because they assume the vendor carries all responsibility. If your team uses the tool in a live workflow, your obligations do not disappear.

Step four through six

Then fix the gaps that create the fastest risk.

Review high-risk and customer-facing uses first

Prioritize healthcare, legal, HR, finance, and any workflow that affects access, rights, advice, or important decisions. If your business uses a third-party AI tool in one of these areas, review oversight, documentation, logging, and escalation now. Do not wait until procurement asks questions or a customer files a complaint.

Fix transparency on websites, chat, and published content

This is the quickest cleanup item for many U.S. companies. Check whether users can tell when they are interacting with AI. Review chatbot disclosures, synthetic media labels, AI-assisted intake flows, and public content approval rules. For service firms, these front-end controls usually matter sooner than technical model documentation.

Put one owner in charge and train the people actually using the tools

Compliance fails when AI decisions are spread across marketing, operations, IT, and practice leaders with no single owner. Assign authority. Then train staff on approved tools, prohibited uses, disclosure rules, human review points, and escalation triggers. A short policy people follow beats a long policy no one reads.

Priority call: Fix visible transparency gaps and undocumented high-impact uses first. That gives you the fastest risk reduction.

Step seven

Build repeatable oversight.

  • Review vendors on a schedule
  • Update the AI inventory when tools, features, or workflows change
  • Reassess risk before expanding a use case into client, patient, or public interactions
  • Keep records of decisions, policy changes, approvals, and training
  • Treat AI governance as an operating process, not a one-time legal project

If you want a practical framework for setting ownership, policies, and review processes, use this guide to AI governance strategies for businesses.

The companies that will be ready for 2026 are not the ones waiting for a final date circled on a calendar. They are the ones cleaning up tool sprawl, tightening customer-facing transparency, and putting controls around third-party AI now.

Partnering for AI Readiness and Growth

The EU AI Act isn't just another legal burden to hand off and forget. It's now part of the digital operating environment. It affects trust, procurement, customer experience, internal controls, and the way businesses deploy marketing and service technology.

That's why a narrow legal-only response won't be enough.

Healthcare groups, law firms, and service businesses need a practical blend of governance and execution. Someone has to identify the AI tools already sitting in the marketing stack. Someone has to review whether website chat, intake flows, and public content meet transparency expectations. Someone has to make sure performance goals don't outrun compliance basics.

That work connects directly to digital maturity. Firms that clean up AI usage usually end up with better vendor discipline, clearer content standards, tighter workflow design, and fewer surprises across teams. They also put themselves in a stronger position when discerning buyers, partners, or internal stakeholders start asking hard questions.

For businesses trying to get ahead of that shift, this guide on AI governance strategies for businesses is a strong next step.

The companies that handle this well won't be the ones that memorized legal terms. They'll be the ones that treated AI governance like a business capability.


If your team needs help auditing AI tools across your website, content, lead intake, and marketing operations, schedule a strategy call with Gorilla. Gorilla helps healthcare organizations, law firms, and service businesses build digital systems that perform well and hold up under growing compliance pressure.

David Juilfs
About the author:
David Juilfs
Owner & CEO Gorilla Marketing
David has 15+ years in marketing experience ranging from traditional print, radio and tv advertising to modern day digital marketing for law firms and lead generation software. He is a multi-award winning marketer and has also volunteers his time with SCORE as a business coach/consultant to help businesses get better leads, more business and higher ROI. You can contact him at [email protected].
Follow the expert: