For US companies to be in the clear, they would have to split their EU subsidiaries in such a way that the US branch could not access their EU operations or ship new patches, and would not have operational oversight.
But US law like cloud act is a broad overreach of US law into other countries.
Which puts them into a tough spot where there parent company has to comply with US law and give US access to their EU daughter company but their daughter company must not allow them such access at all and if they would use technical means to get it anyway it would be legally no different then a cyberattack....
But then came the CloudAct and the location doesn’t matter anymore.
You do business in the US, you have to provide the data.
In other words, if a US authority has any say on what's running/hosted in data centers in EU, it's a no go for more and more businesses and administrations.
US daughter companies have not means at all to direct their parent company to breach EU law, the other way around is more complicated
https://english.ncsc.nl/publications/publications/2022/augus...