Skip to main content
AI Governance

EU AI Act obligations for U.S. vendors: what is in force, what moved, and what to do

The high-risk deadline every roadmap was built around no longer exists. A regulation adopted in July 2026 pushed it out by sixteen months. Here is what is actually enforceable against a U.S. software company right now, and what is still phasing in.

The date everyone planned around is gone

For two years, every EU AI Act compliance plan we have read was anchored to one date: 2 August 2026. That was when Chapter III — the high-risk regime, with its conformity assessments, quality management systems, technical files and post-market monitoring — was supposed to bind. It did not. Regulation (EU) 2026/1744, adopted 8 July 2026 and published in the Official Journal on 24 July 2026, amends the AI Act and moves the high-risk application dates to 2 December 2027 for stand-alone systems and 2 August 2028 for systems embedded in already-regulated products. The amending regulation entered into force on 27 July 2026.

This matters for a practical reason beyond the calendar. A large share of the public trackers, vendor checklists and consultancy timelines still show the old schedule. We checked several while writing this, including one of the most widely cited community timelines, and found the pre-amendment dates presented as current. If a compliance plan on your desk says high-risk obligations bite on 2 August 2026, that plan was written against superseded law. Check the version before you spend money against it.

Verified — the amending instrument

Regulation (EU) 2026/1744, the "Digital Omnibus on AI"

Adopted 8 July 2026. Published in the Official Journal 24 July 2026. In force 27 July 2026. It amends the AI Act (Regulation (EU) 2024/1689) and two sectoral regulations — (EU) 2018/1139 on civil aviation and (EU) 2023/1230 on machinery. The stated driver was that harmonised standards and national competent authority designations were not ready in time to make the high-risk regime workable.

What is actually enforceable today

The deferral is narrow. It moved Chapter III, Sections 2 and 3 — the substantive high-risk requirements. It did not unwind the parts of the Act that have already been applying for a year and a half, and it did not move the obligation that reaches the largest number of ordinary software vendors.

The prohibitions in Article 5 have applied since 2 February 2025. So has the AI literacy duty in Article 4, which the amendment softened in substance: providers and deployers now must support the development of AI literacy among their staff rather than guarantee a defined level of it. The general-purpose AI model regime, the governance architecture, the notified-body framework and the penalty provisions have applied since 2 August 2025. And Article 50, the transparency chapter, applies from 2 August 2026 — that date survived the amendment intact.

DateWhat appliesStatus as of August 2026
1 Aug 2024AI Act enters into force. No operative duties yet.Done
2 Feb 2025Article 5 prohibitions; Article 4 AI literacy duty.In force
2 Aug 2025General-purpose AI model obligations; governance and notified bodies; Member State competent authorities; Article 99 penalties.In force
2 Aug 2026Article 50 transparency obligations.Applies — date unchanged by the amendment
2 Dec 2026Watermarking grace period ends for systems placed on the market before 2 Aug 2026. New prohibition on generating non-consensual intimate imagery and child sexual abuse material becomes applicable.Pending
2 Aug 2027Providers of general-purpose AI models placed on the market before 2 Aug 2025 must be compliant. Regulatory sandboxes operational.Pending
2 Dec 2027High-risk obligations for stand-alone Annex III systems. Moved from 2 Aug 2026.Deferred
2 Aug 2028High-risk obligations for systems embedded as safety components in products under existing sectoral law (Annex I). Moved from 2 Aug 2027.Deferred
2 Aug 2030Article 111(2) transitional deadline for high-risk systems intended for use by public authorities.Long horizon
31 Dec 2030AI components of the large-scale EU IT systems in Annex X placed on the market before 2 Aug 2027.Long horizon

Whether the Act reaches you at all

Start here, because most U.S. vendors get this wrong in one of two directions — either assuming they are outside a European regulation because they have no European entity, or assuming they are inside it because they have European users.

Article 2(1) sets three hooks. The first covers providers placing an AI system on the market or putting it into service in the Union, or placing a general-purpose AI model on the Union market, "irrespective of whether those providers are established or located within the Union or in a third country." The second covers deployers established or located in the Union. The third is the one that catches people: providers and deployers located in a third country "where the output produced by the AI system is used in the Union."

Read the third hook carefully. It is about where the output lands, not where the servers sit and not where the company is incorporated. A Virginia company running inference in a U.S. region, with no EU subsidiary and no EU sales team, is inside the scope if the output of that system is used in the Union. That is a factual question about your customers' workflows, and it is answerable. It is also a question most vendors have never actually asked their account teams.

The exclusions are real but narrower than the marketing summaries suggest. Systems placed on the market, put into service or used "exclusively for military, defence or national security purposes" are outside the Act. The operative word is exclusively. A dual-use product with a commercial edition does not inherit the exclusion for the commercial edition, and the same is true of a defence-derived component sold into a civil market. Systems developed and put into service "for the sole purpose of scientific research and development" are outside as well, but real-world testing is inside. Free and open-source releases are outside — unless they are placed on the market or put into service as high-risk systems, or as systems falling under Article 5 or Article 50.

The third scope hook is about where the output lands, not where the servers sit and not where the company is incorporated. That is a factual question about your customers' workflows, and it is answerable.

Which role you are holding

Obligations attach to roles, not to companies, and one company routinely holds several roles across a product line. A firm can be the provider of its own model-backed feature, the deployer of a third-party system in its own hiring process, and — through the Act's value-chain rules — the provider of a system it merely rebranded. Getting the role map wrong is the most common structural error we see in vendor self-assessments, because it puts the duty on the wrong entity and produces documentation nobody is required to hold.

RoleWho holds itWhat it carries in 2026
ProviderDevelops an AI system or model and places it on the Union market or puts it into service under its own name or trademark.Article 50 provider duties on interaction disclosure and synthetic-content marking. High-risk duties from Dec 2027.
DeployerUses an AI system under its own authority in a professional capacity.Article 50 deployer duties: emotion-recognition and biometric-categorisation notice, deepfake disclosure, AI-generated public-interest text disclosure.
Importer / distributorPlaces or makes available on the Union market a system from a third-country provider.Verification and traceability duties that become operative with the high-risk regime; penalty exposure under Article 99 already exists.
Authorised representativeAn EU-established entity mandated in writing by a third-country provider.Required now for third-country providers of general-purpose AI models. Required for high-risk providers under Article 22 when that regime lands.
Rebrander / substantial modifierPuts its name on someone else's system, or materially changes its intended purpose.Assumes provider obligations. This is the trap for integrators and white-label resellers.

Article 50 is the obligation that reaches ordinary software vendors first

If your product does not do biometrics, credit scoring, hiring decisions or medical triage, the high-risk chapter probably never touches you. Article 50 does. It applies from 2 August 2026 to a very broad class of systems, and its trigger is not sensitivity of use — it is the fact that a machine is generating or presenting content to a human being.

  • Provider duty — interaction disclosure. Systems intended to interact directly with natural persons must inform the person that they are dealing with an AI system, unless that is obvious from the circumstances to a reasonably observant user.
  • Provider duty — synthetic content marking. Systems that generate synthetic audio, image, video or text must mark the output in a machine-readable format, detectable as artificially generated or manipulated. Solutions must be effective, interoperable, robust and reliable as far as technically feasible.
  • Deployer duty — emotion recognition and biometric categorisation. People exposed to such a system must be informed of its operation, and the processing must comply with EU data protection law.
  • Deployer duty — deepfake disclosure. Image, audio or video content that is artificially generated or manipulated and resembles real persons, objects, places or events must be disclosed as such. Artistic, creative, satirical and fictional works get a lighter form of this obligation.
  • Deployer duty — AI-generated text published to inform the public. Text published on matters of public interest must be disclosed as AI-generated, unless a human carried out editorial review and a person or organisation holds editorial responsibility.

Two details carry practical weight. First, the marking obligation is on machine-readable output, not on a visible label. A watermark that a human can see in a corner of an image is not the same artifact as provenance metadata a downstream system can parse, and the text says machine-readable. Second, systems already on the market before 2 August 2026 got a grace period to 2 December 2026 on the marking requirement. New systems did not. If you shipped a generative feature in July 2026, you have until December on the marking; if you ship one in September 2026, you do not.

Information under Article 50 must be given at the latest at the time of first interaction or exposure, in a clear and accessible form. That is a product-design requirement, not a policy-page requirement. A disclosure buried three clicks into terms of service does not meet a rule that says "at the time of the first interaction."

General-purpose AI models: a narrower door than most vendors assume

Chapter V has applied since 2 August 2025, and it produces more anxiety in U.S. vendor meetings than it should. It binds providers of general-purpose AI models — the entity that trains and places the model on the Union market. If you fine-tune someone else's checkpoint for your own product, whether you become a provider of a new model is a fact-specific question, and the Act's guidance turns on the significance of what you changed. Most application vendors calling an API are downstream deployers of a system, not providers of a model.

For those who are providers, Article 53 requires four things: technical documentation of the model's development, testing and evaluation per Annex XI, kept available to authorities; information sufficient for downstream providers to understand capabilities and limitations and meet their own duties, per Annex XII; a policy to comply with EU copyright law, including honouring machine-readable reservations of rights over text and data mining; and a publicly available, sufficiently detailed summary of training content using the Commission's template. Models released under a free and open-source licence with publicly available parameters and architecture are exempt from documentation and downstream-information duties — but not if the model carries systemic risk.

Systemic risk is where the tier changes. Article 51 presumes high-impact capability when cumulative training compute exceeds 1025 floating-point operations. That presumption is rebuttable, and the Commission can designate a model as systemic-risk on other grounds via the Annex XIII criteria. Providers can demonstrate compliance through approved codes of practice until harmonised standards exist, at which point conformity with those standards carries a presumption of compliance.

Providers of general-purpose models placed on the Union market before 2 August 2025 have until 2 August 2027 to bring them into compliance. That is the single most useful date in Chapter V for a U.S. firm with an existing model in the field.

High-risk: deferred, not withdrawn

The sixteen-month deferral is not a reprieve from the requirement; it is a reprieve from the deadline, and the two behave differently. Annex III still lists eight areas of stand-alone high-risk use: biometrics, including remote identification, biometric categorisation by protected attributes, and emotion recognition; safety components in critical infrastructure; education and vocational training, including admissions, assessment and proctoring; employment and worker management, including recruitment screening, task allocation and performance monitoring; access to essential private and public services, which is where creditworthiness assessment, insurance risk pricing and emergency-call triage sit; law enforcement; migration, asylum and border control; and administration of justice and democratic processes.

The amendment did tighten classification in one useful direction. The definition of "safety component" was refined so that systems which assist a user or optimise performance, without creating a health or safety risk, no longer fall into the high-risk bucket by construction. And systems that qualify under the Article 6(3) derogation — where the provider self-assesses that a system does not pose significant risk — still have to be registered in the EU database, though through a simplified procedure. Self-assessment is not the same as invisibility.

Under Article 111, systems lawfully placed on the market before the relevant application date can continue in service as long as the design does not change materially. Ship a significant redesign and the transitional shelter ends. This is the mechanism that converts a compliance question into a product-roadmap question, and it is the reason "we will look at it in 2027" is a poor answer for anything already in the field with a two-year feature plan.

The authorised representative question

Two separate representative requirements exist, and U.S. firms conflate them. Article 54 requires a third-country provider of a general-purpose AI model to appoint, by written mandate, a representative established in the Union before placing the model on the market. That representative verifies documentation, keeps a copy for ten years after the model goes to market, responds to reasoned requests from the AI Office, and cooperates on compliance. It may be addressed by regulators in addition to or instead of the provider, and it must terminate the mandate and notify the AI Office if it believes the provider is in breach. Free and open-source models are exempt unless they carry systemic risk.

Article 22 imposes the parallel duty on third-country providers of high-risk systems: appoint an EU representative before making the system available, empower it to verify the EU declaration of conformity and technical documentation, keep records for ten years, hand over information and system logs to authorities, and handle registration. That one follows the deferred high-risk timeline.

The practical point is that appointing a representative is a contract with a real party who takes on personal regulatory exposure and can walk away. Firms that treat it as a mailbox service discover late that the representative has its own compliance incentives.

Penalties, and who actually brings them

Article 99 has applied since 2 August 2025. Breach of the Article 5 prohibitions carries up to €35,000,000 or 7% of total worldwide annual turnover, whichever is higher. Breach of most other operator obligations — including Article 50 transparency and the Article 22 representative duty — carries up to €15,000,000 or 3%. Supplying incorrect, incomplete or misleading information to authorities carries up to €7,500,000 or 1%. For SMEs and start-ups, the fine is capped at whichever of the percentage or the fixed amount is lower, which meaningfully changes the ceiling for a smaller vendor.

The amendment also extended some administrative relief to small mid-cap enterprises as defined in Commission Recommendation (EU) 2025/1099, widening the class that gets lighter documentation handling beyond the traditional SME definition.

Enforcement runs through Member State market surveillance authorities for AI systems and through the Commission's AI Office for general-purpose models. Practically, this means a U.S. vendor's first contact is likely to be an inquiry routed through a customer, a distributor, or a national authority in whichever Member State the output is being used. It is worth knowing in advance which entity in your structure would receive that letter.

A scoping sequence that produces an answer

Nothing above requires a consulting engagement to start. The first pass is an inventory question, and a technically literate team can run it internally.

First-pass EU AI Act scoping

1
Inventory every feature that uses a model. Include vendor-embedded features you did not build.
Week 1
2
Ask sales and support where the output is used, by named account and country. This is the Article 2 test.
Week 2
3
Assign a role per feature: provider, deployer, importer, distributor, rebrander.
Week 3
4
Flag anything that generates content or interacts directly with a person. That is the Article 50 set.
Week 4
5
Check each flagged feature against Annex III. Record the reasoning, not just the verdict.
Weeks 5-6
6
Fix the disclosure and machine-readable marking gaps. Ship before the December 2026 grace period closes.
Weeks 7-12

Step 5 is the one teams skip, and it is the one that pays. A written record of why a system was assessed as not high-risk is the artifact an authority will ask for, and it is also the artifact your enterprise customers will ask for during procurement diligence long before any regulator does. We have watched EU AI Act questionnaires appear in commercial security reviews for products that are nowhere near Annex III, simply because the buyer's counsel added the question to a standard form. Being able to answer it in one page is a sales asset.

Firms already running a NIST AI RMF program have most of the raw material. The control vocabularies differ and the legal effect differs — one is voluntary guidance, the other is directly applicable law with turnover-based fines — but the underlying evidence of intended purpose, evaluation, data governance and monitoring is largely the same evidence. The same is true of federal model documentation practice, which maps onto the Annex XI and Annex XII expectations more closely than most teams expect.

Where the picture is genuinely unsettled

Does fine-tuning make you a provider of a general-purpose AI model?

The Act attaches provider status to placing a model on the market, and modification can create a new provider, but the line between adaptation and creation has not been settled by enforcement practice. A light adapter on a hosted model and a substantial continued pre-training run sit at opposite ends of a spectrum with no bright line in the middle. Document what you changed and how much compute it took; that record is what the question will eventually be decided on.

What counts as "output used in the Union"?

The statutory text is clear that third-country providers and deployers are covered when output produced by the system is used in the Union. What is not settled is how attenuated the use can be before the hook releases — an EU employee reading a U.S.-generated summary is a different case from an EU-facing product feature, and neither has been tested. Treat direct, foreseeable EU use as in scope and record the analysis for the marginal cases.

Will the December 2027 date hold?

The stated reason for the deferral was that harmonised standards and national competent authority designations were not ready. Those are the same conditions that would justify a further deferral if they are still unmet. We would not build a plan that assumes another slip, and we would not build one that assumes the current date is immovable either. Build the evidence base, which is useful under any schedule, and keep the deadline-specific work loosely coupled.

Does an EU-facing product change our U.S. federal posture?

Not directly. The Act excludes systems used exclusively for military, defence or national security purposes, and U.S. federal delivery generally produces no output used in the Union. The interaction appears when a commercial edition of the same codebase ships to European customers, because the exclusion is edition-specific rather than codebase-specific. That is a product-line question, and it is worth answering deliberately rather than by default.

Bottom line

As of August 2026, a U.S. vendor's live exposure under the EU AI Act is the Article 5 prohibitions, the Article 4 literacy duty, the general-purpose model regime if it trains models, and — from 2 August 2026 — the Article 50 transparency obligations, which reach almost any product that generates content or talks to a person. The high-risk regime that dominated the planning conversation for two years now lands on 2 December 2027 for stand-alone systems and 2 August 2028 for embedded ones.

The correct response to a deferral is not to stop. It is to move the effort from deadline-driven paperwork toward the evidence that holds its value under any schedule: a feature inventory, an honest map of where output is used, a role assignment per feature, and a written classification rationale. That work makes the December 2027 date manageable, closes the Article 50 gaps that are live right now, and answers the procurement questionnaire that is going to arrive from a European customer well before any authority calls.

Frequently asked questions

Does the EU AI Act apply to a U.S. company with no European entity?

It can. Article 2(1) covers providers and deployers located in a third country where the output produced by the AI system is used in the Union, in addition to anyone placing a system or general-purpose model on the Union market. Incorporation and server location are not the test.

Which EU AI Act obligations are in force in 2026?

The Article 5 prohibitions and the Article 4 AI literacy duty since 2 February 2025; the general-purpose AI model regime, governance provisions and Article 99 penalties since 2 August 2025; and the Article 50 transparency obligations from 2 August 2026. High-risk obligations were deferred to 2 December 2027 and 2 August 2028.

What did the Digital Omnibus on AI change?

Regulation (EU) 2026/1744, in force 27 July 2026, moved stand-alone high-risk obligations from 2 August 2026 to 2 December 2027 and embedded high-risk from 2 August 2027 to 2 August 2028. It also softened the AI literacy duty, refined the "safety component" definition, gave a grace period to 2 December 2026 on watermarking for systems already on the market, and added a prohibition on generating non-consensual intimate imagery and child sexual abuse material.

Do we need to label AI-generated content?

From 2 August 2026, providers of systems that generate synthetic audio, image, video or text must mark output in a machine-readable format detectable as artificially generated. Deployers separately must disclose deepfake content and AI-generated text published to inform the public on matters of public interest, unless a human held editorial responsibility. Systems already on the market before 2 August 2026 have until 2 December 2026 for the marking duty.

What are the fines under the EU AI Act?

Up to €35,000,000 or 7% of worldwide annual turnover for prohibited practices; up to €15,000,000 or 3% for most other operator obligations, including transparency; up to €7,500,000 or 1% for supplying incorrect or misleading information. For SMEs and start-ups, the applicable cap is whichever figure is lower rather than higher.

1 business day response

Need to know where your product stands?

We map AI features to roles and obligations, close the transparency gaps in the product itself, and leave you with a written classification rationale your customers and counsel can read.

CapabilitiesMore insights →Start a conversation
UEI Y2JVCZXT9HP5CAGE 1AYQ0NAICS 541512SAM.GOV ACTIVE