Microsoft opened its new AI Compliance Center in Dublin in January 2026. The facility — a converted office building near Grand Canal Dock, housing about 80 staff — manages EU AI Act compliance across Microsoft’s European operations. The Irish location is not accidental. Ireland has long been the EU subsidiary home for major US tech companies, chosen for its corporate tax environment, English-language infrastructure, and membership in the EU’s single market. Microsoft Ireland Operations Limited is the legal entity that contracts with most European customers.

This matters for the EU AI Act because compliance obligations attach to the “provider” or “deployer” of an AI system — and the legal structure of who is providing or deploying what significantly affects the compliance picture. Microsoft’s EU AI Act compliance architecture is routed through a subsidiary structure that creates legal clarity about obligations while, not entirely coincidentally, allowing the parent company to maintain flexibility in how it structures its AI liability exposure in the EU.

None of this is illegal. All of it is deliberate. And it’s instructive about how large US technology companies are approaching the EU AI Act not as an obstacle to be fought but as a compliance engineering problem to be solved.

The Provider-Deployer Distinction

The Act creates a hierarchy of obligations that assigns different responsibilities to “providers” (those who develop AI systems and place them on the market), “deployers” (those who use AI systems within professional contexts), and the intermediaries between them. This hierarchy is sensible in principle and creates practical complexity when a cloud platform provides AI capabilities that customers then deploy in high-risk applications.

Microsoft Azure’s legal position, articulated in their EU AI Act compliance documentation published in March 2026, is that Microsoft is the provider of foundational AI infrastructure and models. When an Azure customer builds a high-risk application using Azure OpenAI Service, the customer becomes the deployer — responsible for the application-level conformity assessment, the transparency obligations to end users, and the registration in the EU AI database. Microsoft provides documentation and tooling to help customers meet their obligations but is not itself responsible for the conformity assessment of the customer’s application.

This position is defensible. The customer does make the meaningful decisions about how to use the AI capability — what data to feed it, what decisions to base on it, what human oversight to provide. But it also means that the company with the most resources and technical understanding — Microsoft — is not the entity bearing the primary compliance obligation for the actual deployment. That obligation falls on the customer, who may be a mid-sized European company with far less compliance capacity.

Google Cloud has adopted a similar posture. Their “Shared Responsibility Model for EU AI Act Compliance” — published in February 2026, clearly modeled on their existing shared responsibility model for cloud security — explicitly assigns provider-level obligations to Google for the underlying infrastructure and model, deployer-level obligations to customers for the applications they build, and joint responsibility for the deployment configuration.

Amazon’s approach is somewhat different. AWS has positioned itself as a “tool provider” rather than an AI model provider, emphasizing that customers using Amazon Bedrock or SageMaker are the ones making AI deployment decisions. This framing pushes compliance responsibility further toward the customer than the Microsoft or Google models, which both include more substantive assistance with customer compliance.

What “EU-Specific” Products Actually Look Like

The most visible change in how US tech companies are handling the EU AI Act is the proliferation of EU-specific product variants and configurations.

OpenAI’s EU deployment of ChatGPT and the GPT-4 API includes transparency disclosures and capability restrictions that don’t apply to the US version. The model isn’t meaningfully different, but the product wrapper is. EU API customers receive automatic documentation of training data provenance in a format aligned with the GPAI requirements. The system cards are more detailed. There are additional consent mechanisms for memory and personalization features.

Whether these modifications represent genuine product differentiation or sophisticated documentation layering is a matter of perspective. The EU AI Office’s initial assessment of OpenAI’s GPAI compliance — published in a technical summary in April 2026 — was cautiously positive: the documentation meets the technical requirements, though the Office noted that some aspects of training data transparency were harder to verify than the documentation suggested.

Microsoft’s Copilot products have undergone more substantive changes for EU deployment. Copilot for M365 in the EU operates with additional audit logging, data residency restrictions, and human review workflows for certain output categories. Azure AI Search has EU-specific configurations that limit the types of data sources that can be indexed when the search is used in employment or credit contexts. These aren’t cosmetic changes. They represent genuine engineering investment in EU-specific compliance.

The interesting question is what drives this investment. Is it genuine commitment to the regulation’s goals? Fear of enforcement? Competitive positioning against European rivals? Probably all three, in proportions that vary by company. What’s clear is that the companies with sufficient resources to make the investment are making it, which — as we’ve noted repeatedly — compounds the advantage they have over smaller competitors.

The Subsidiary Layer

The legal subsidiary architecture that governs EU operations for US tech companies adds another dimension to the compliance picture.

When a French company buys Azure AI services, the contractual relationship is (typically) with Microsoft Ireland Operations Limited, not Microsoft Corporation in Redmond. The AI Act obligations attach to that Irish entity. Microsoft Ireland has its own legal team, its own compliance infrastructure, and — critically — its own liability exposure that is technically separate from the parent company.

This doesn’t mean Microsoft US is insulated from enforcement consequences. The parent company provides indemnification and controls the subsidiary’s operations. But the legal architecture means that enforcement actions against Microsoft in the EU require going through the Irish entity, with Irish courts having jurisdiction over disputes, with DACI (Ireland’s AI Competent Authority, a subset of the Data Protection Commission) as the primary national authority. This is the same structure that governed GDPR enforcement, and GDPR observers will recognize that the Irish DPC became notorious for slow enforcement of complaints against tech companies with Irish EU headquarters.

There is a reason Meta, Google, Apple, Microsoft, LinkedIn, and Twitter/X all chose Ireland as their EU headquarters and have maintained it through years of political pressure and DPC criticism. The Irish regulatory environment — for reasons that include resources, culture, and political economy — has historically been more congenial to large US tech companies than German, French, or Spanish regulatory environments. The AI Act enforcement architecture, largely replicating the GDPR structure, preserves this dynamic.

The EU AI Office has extraterritorial enforcement authority that operates above the national level for certain provisions — particularly GPAI models and prohibited practices. This is an attempt to address the Irish bottleneck that plagued GDPR enforcement. Whether it will be effective depends on the Office’s willingness to intervene aggressively in cases where national authorities are slow, and on the Court of Justice’s interpretation of how EU-level and national-level authority interact in enforcement disputes.

The Quiet Architecture of Regulatory Adaptation

What’s most striking about how US hyperscalers have adapted to the EU AI Act is how little drama accompanied it. There were no congressional hearings about regulatory overreach, no CEO op-eds denouncing Brussels, no coordinated industry campaigns. Instead: legal teams were hired, compliance frameworks were published, product variants were engineered, subsidiary structures were optimized.

This is the behavior of companies that have been through GDPR, DORA, the Digital Services Act, and the Digital Markets Act. They’ve learned that fighting European regulation publicly generates bad press and rarely succeeds. Adapting to it through compliance engineering while continuing to operate essentially as before is more effective and attracts less attention.

The result is that the EU AI Act is changing how Microsoft, Google, and Amazon document and structure their AI products for Europe without fundamentally changing what those products do or how they compete. The most powerful AI companies in the world will be in full regulatory compliance — their lawyers will ensure that — while the companies the regulation was most concerned about disrupting continue to dominate. This is, in a structural sense, what regulation often achieves. Not disruption of the powerful. Management of the disruption’s surface area.

The Lobbying Geometry

One dimension of US hyperscaler engagement with the EU AI Act that rarely gets adequate attention is the lobbying that shaped the regulation before it was finalized.

Between 2021 and 2024, while the Act was moving through Council and Parliament deliberations, US tech companies engaged in substantial EU lobbying. The Digital Europe lobbying disclosure database shows Microsoft, Google, Apple, Meta, and Amazon collectively spending over €25 million on EU lobbying in 2023 alone. Not all of this was AI Act related. But the GPAI provisions — the parts of the Act that most directly affect these companies — were among the most heavily lobbied sections of the text.

The lobbying achieved several things. The compute threshold for systemic risk designation (10^25 FLOPs) is widely understood to have been influenced by industry analysis suggesting that threshold would cover only a small number of models — specifically, fewer than ten globally at the time of writing. The self-assessment provision for GPAI providers under a certain threshold gives companies substantial flexibility. The authorized representative mechanism (rather than requiring direct EU establishment) preserved the existing subsidiary structure approach that US companies already used.

This is not evidence of captured regulation. The provisions are defensible on independent grounds. But it is a reminder that the regulation that emerges from a lengthy legislative process reflects the accumulated influence of everyone who participated in that process — and the participants with the most resources and the most at stake had disproportionate input. The US hyperscalers didn’t fight the EU AI Act. They helped design it. The compliance architecture that emerged — one where large players with sophisticated legal and technical capacity can navigate gracefully while smaller players struggle — is not an accident. It’s a negotiated outcome. And the negotiators with the best lawyers won the negotiation they appeared to be losing.

Get the next live webinar in your inbox

One email a month: the upcoming live event + free recording access for subscribers. No spam, unsubscribe anytime.