EU and UK Startups Expanding to the US: What AI Compliance Actually Costs You

American AI regulation is a live patchwork of state laws under federal challenge. What a European or British startup needs to prepare before selling into the US, and what it can safely ignore.

By Rafal Skucha

A founder asked me recently whether their EU AI Act work would help or hinder a US launch. It is the right question, and the answer is counter-intuitive: it helps commercially, it does not transfer legally, and the thing that will actually slow them down is neither regulation.

Here is what a European or British startup planning a US expansion needs to know, and - more usefully - what it can ignore.

The American position is genuinely unsettled

There is no federal AI statute. What exists is a patchwork of state laws, most of them very new, and a federal administration actively trying to stop them.

Since 1 January 2026, Texas, California and Illinois have had AI laws in force. Texas prohibits developing or deploying AI with intent to manipulate, discriminate unlawfully or infringe rights. California’s SB 53 targets the largest frontier developers, but AB 2013 applies far more broadly: any developer of a generative AI system offered in California must publish a summary of its training data. Illinois restricts AI in employment decisions.

Colorado repealed its original AI Act and replaced it with a new automated decision-making law, signed in May 2026, whose obligations start on 1 January 2027. Worth noting for anyone who read about the original: the provision that gave you a defence for following a recognised framework did not survive into the replacement. New York’s RAISE Act, aimed at frontier developers, also starts on 1 January 2027.

Against that, the December 2025 executive order created a Department of Justice task force to challenge state AI laws as inconsistent with national policy, alongside funding conditions and preemption efforts.1 An executive order cannot repeal state law - that takes Congress or the courts - so the practical position is that these obligations are simultaneously in force and under attack.

For a startup, that means planning for volatility rather than for a rulebook.

What actually bites a European startup selling into the US

Three things, in order of likelihood.

AB 2013, if you ship generative AI features. Publishing a training-data summary is a real obligation with a low threshold, and it catches companies that think of themselves as application builders rather than model developers. If you fine-tune anything, check this one properly.

Employment and hiring use cases. Illinois, New York City’s bias audit rule and Colorado’s incoming regime all converge here. If your product touches hiring, promotion or performance, you are in the most regulated corner of the US landscape.

Sector rules that have nothing to do with AI. Healthcare, financial services and insurance regulators apply existing law to AI-driven decisions. For most startups this matters more than any AI-specific statute, and it is the one they research last.

Everything else - frontier model rules, compute thresholds, safety frameworks - is aimed at companies orders of magnitude larger than you.

Does EU AI Act work transfer?

Legally, no. The regimes are built on different logic. Europe triggers on use case and risk to people. The US triggers on sector, on the size of the developer, and increasingly on specific practices. Compliance with one is not compliance with the other, and no certificate bridges them.

Commercially, yes, and more than founders expect. The artefacts the EU forces you to produce - documented data provenance, a written risk assessment, a governance policy, structured logging, a stated position on human oversight - are exactly what a US enterprise procurement team asks for. You will not present them as AI Act compliance. You will present them as answers to a vendor questionnaire, and you will answer in a day rather than a month.

There is also a concrete legal asymmetry worth exploiting. Texas grants protection from enforcement to organisations substantially complying with the NIST AI Risk Management Framework.2 NIST is voluntary and free. If you are already doing EU-driven governance work, mapping it onto NIST is a small increment that buys you a defensible position in at least one large state.

My advice to European founders is therefore: build to NIST as your US-facing framework, keep the EU documentation as your evidence base, and stop looking for a single global standard. There isn’t one.

What investors will ask, which is not the same question

Here is the part founders underestimate. In practice, your US expansion is gated by investors and enterprise customers, not by regulators.

US investors are asking AI questions in diligence now: what your training data is and whether you have the rights to it, whether AI-generated code is in your codebase and how it was reviewed, whether your AI claims in marketing match what the product does, and whether any of your use cases sit in a regulated category. Warranty schedules increasingly include AI-specific representations - training data ownership, output IP, absence of unauthorised AI usage by staff.

None of that is regulation. All of it can cost you a term sheet or a discount. We have written about it from the investor’s side in should AI compliance be part of technical due diligence.

The claims point deserves special attention. The FTC has been active on AI marketing claims that outrun the product. For a European startup used to a regulator that polices process, an American regulator that polices what you said in a press release is a different discipline.

What to do, and in what order

Before you sell anything in the US. Write down every AI feature, what it does, what data trained it and where that data came from. If you cannot answer the provenance question, that is your first project and it is not a compliance project - it is an engineering one.

Before your first enterprise deal. Produce a one-page AI governance policy and a security position you can send with a questionnaire. Map what you already have to NIST. This is days of work, not weeks, and it removes the most common source of procurement delay.

Before you raise. Get an independent read on the AI risk in your codebase and your claims. Investors will find it; finding it first is cheaper.

Not yet. Do not buy a compliance platform. Do not pursue ISO/IEC 42001 certification unless a named customer has asked for it in writing.3 Do not build a compliance function. At your stage these consume the runway that should be going into the product, and none of them close deals on their own.

The thing that will actually slow you down

It will not be AI regulation. It will be data residency and security review.

US enterprise buyers ask where data is processed, who can access it, what your sub-processors are, and whether you can support their own obligations. European startups usually have good answers because GDPR forced them. Where they come unstuck is having built an architecture that assumes EU processing and cannot easily offer a US region.

That is an architectural decision, and it is far more expensive to change later than any policy document. If US expansion is on the roadmap within two years, design for regional separation now. We cover the general shape of that question in is it safe to put company data into AI, and it applies equally to your customers’ data in your systems.

If you are planning a US launch and want a straight read on what genuinely applies to you, book a free half-hour. Most of the startups we talk to are carrying about a third of the compliance anxiety they should be, and worrying about the wrong third.

References

  1. The White House - Ensuring a National Policy Framework for Artificial Intelligence, December 2025.
  2. NIST - AI Risk Management Framework.
  3. ISO - ISO/IEC 42001:2023, AI management systems. Certification is voluntary.
← Back to Blog