Insights · AI Regulation

EU AI Act: What U.S. Businesses Actually Need to Know in 2026

EU AI Act in plain English for U.S. businesses with EU exposure. Updated August 2026: the Digital Omnibus is now law (Regulation 2026/1744), what applied on August 2, 2026, and the new high-risk dates.

By Matthew Bertram · President of ModalPoint, CEO of EWR Digital · 2026

The EU AI Act is the world’s first comprehensive AI law. It applies extraterritorially, which means a U.S. company can be on the hook for compliance even if it does not have an office, employee, or server inside the European Union. Most U.S. coverage of the law is months out of date. Here is what changed in July and August 2026 and what U.S. businesses should actually be paying attention to.

This guide is for U.S.-based executives, board members, and counsel who export to the EU, sell software used by EU customers, or operate in industries where EU customers might end up using your AI features. AI-curious audience, plain English on top, citation-dense legal layer at the bottom.

Update, August 2026: the Omnibus is law and August 2 has come and gone

Two things happened since the May version of this guide, and together they settle most of the open questions.

  • The Digital Omnibus on AI was adopted. It is now Regulation (EU) 2026/1744 of 8 July 2026, published in the Official Journal on 24 July 2026 and in force since 27 July 2026. The postponements that were only provisional in May are now binding law: Annex III high-risk obligations apply from December 2, 2027 and Annex I (AI in regulated products) from August 2, 2028. Text on EUR-Lex.
  • August 2, 2026 still happened for everything that was not postponed. On that date the AI Act's general application began: the Article 50 transparency rules (tell people when they are talking to an AI, mark AI-generated content in a machine-readable way, label deepfakes) now apply; the European Commission's AI Office and national authorities began enforcing the Act; and the Commission can now fine providers of general-purpose AI models (up to 3 percent of global turnover or EUR 15 million). Commission announcement.
  • Two transition dates to write down. Generative systems already on the market before August 2, 2026 have until December 2, 2026 to meet the machine-readable marking rule. The new prohibitions on AI systems that generate non-consensual intimate imagery or child sexual abuse material also apply from December 2, 2026. Member-state regulatory sandboxes must be operational by August 2, 2027.

What did not change: the prohibited-practices list and the AI literacy duty (binding since February 2, 2025) and the general-purpose AI model obligations (binding since August 2, 2025; models placed on the market before that date must comply by August 2, 2027). The rest of this guide has been updated to match.

The 60-second version

  • What it is: A regulation of the European Union, effective in tranches starting February 2, 2025. The world’s first comprehensive AI law.
  • Who it covers: Anyone placing an AI system on the EU market, deploying AI in the EU, or producing AI outputs used in the EU. A U.S. company with EU customers is in scope.
  • What is binding right now (as of August 2026): The prohibited practices list (Article 5) and the AI literacy obligation (Article 4), enforceable since February 2, 2025. The General Purpose AI (GPAI) model obligations, enforceable since August 2, 2025. The Article 50 transparency obligations and the Commission's enforcement powers, including fines on GPAI providers, since August 2, 2026.
  • What was postponed, now in law (Regulation (EU) 2026/1744, in force July 27, 2026): the high-risk system obligations (Annex III) move from August 2, 2026 to December 2, 2027. Annex I high-risk obligations move to August 2, 2028.
  • What is new: a prohibition on AI systems that generate child sexual abuse material or non-consensual intimate imagery, applying from December 2, 2026, and a December 2, 2026 transition for machine-readable marking by generative systems that were already on the market.
  • The penalties: Up to EUR 35 million or 7 percent of global annual turnover for the most serious violations. Up to EUR 15 million or 3 percent for non-compliance with high-risk obligations. Lower amounts for procedural failures.
  • What U.S. companies should do: Map your EU exposure, classify any high-risk uses you have, comply with prohibited practices and GPAI rules now, and use the additional 16 months Annex III postponement bought you to build the documentation that will be required when those obligations land.

That is the gist. The detail follows.

Why a U.S. business should care about an EU law

The EU AI Act follows the GDPR template. It applies based on the location of the customer and the use, not the location of the company. If your AI product is used by a person in the EU, or if your AI produces outputs used in the EU, you are in scope. This is the same extraterritorial reach that pulled thousands of U.S. companies under GDPR in 2018.

Three concrete examples of when U.S. companies are in scope:

  • A U.S. SaaS vendor selling to a German manufacturer. The manufacturer uses your AI features. You are placing an AI system on the EU market.
  • A U.S. medical device exporter shipping AI-equipped equipment to an Italian hospital. You are a provider of an AI system in scope.
  • A U.S. law firm using an AI tool to help advise an EU client on a transaction. The output is being used in the EU. You may be a deployer in scope.

If your business has zero EU customers, EU users, or EU outputs, the AI Act does not directly apply to you. But the trend is clear: the U.S. federal government, state governments (Texas, Colorado), and other jurisdictions are watching the EU AI Act closely. The compliance practices you build for EU exposure are the ones that will scale to whatever lands next at home.

What changed: the Digital Omnibus on AI (agreed May 7, 2026, adopted July 8, 2026)

On May 7, 2026, after months of negotiation and a first trilogue that collapsed at the end of April, the European Parliament and the Council reached a provisional agreement on the Digital Omnibus on AI. Both institutions then adopted it, and it was signed on July 8, 2026 as Regulation (EU) 2026/1744, published July 24 and in force July 27, 2026. It does several things at once.

  • Postpones high-risk obligations. Annex III high-risk uses (employment, education, credit scoring, biometric ID, critical infrastructure, law enforcement, migration, justice administration) move from August 2, 2026 to December 2, 2027. Annex I systems (AI in regulated products) move to August 2, 2028.
  • Adds a new prohibition. AI systems that generate child sexual abuse material or non-consensual intimate imagery are prohibited. The deadline is December 2, 2026. The prohibition covers both the supply side (placing such systems on the market) and the use side (deployer use).
  • Sets a marking transition. The Article 50(2) machine-readable marking duty for AI-generated and manipulated content applies from August 2, 2026; generative systems already on the market before that date have until December 2, 2026.
  • Resolves an Annex I dispute. The conformity assessment regime for AI components in regulated products (machinery, medical devices) shifts to sectoral primacy with an equivalence clause for safety levels.

The agreement was formally adopted: Council final vote June 29, 2026, signature July 8, 2026, Official Journal July 24, 2026, in force July 27, 2026. The dates above are now the law.

What this looks like for U.S. businesses

The U.S. SaaS company with EU customers

A Texas-based SaaS vendor sells customer-service AI to a Berlin retailer. Today, the vendor must already comply with the prohibited-practices list, the Article 50 transparency rules (since August 2, 2026), and GPAI model obligations if applicable. Under the adopted Omnibus, the vendor has until December 2, 2027 instead of August 2, 2026 to bring any high-risk Annex III uses into compliance. The vendor uses the additional time to build the technical documentation, conformity assessment, post-market monitoring, and EU database registration that high-risk obligations require.

The U.S. medical device exporter

A Houston medical device manufacturer ships an AI-enabled diagnostic tool to a hospital in Milan. The AI is a safety component. Annex I obligations apply. The Omnibus pushes Annex I to August 2, 2028. The manufacturer has the time to align the AI conformity assessment with the existing CE-marking process for the medical device, rather than running parallel compliance regimes.

The U.S. company with no EU customers

A Texas C&I manufacturer with zero EU sales and no EU users. The AI Act does not apply. But the company should still pay attention because (a) the EU framework is the template U.S. states are starting to follow, (b) the practices it requires (inventory, classification, technical documentation, post-market monitoring) are exactly what NIST AI RMF, ISO 42001, and any future federal U.S. AI regime will also require. Building EU-grade documentation is overkill for U.S. operators today and table stakes by 2027.

What stays binding right now (do not relax on these)

The Omnibus does not move the prohibited-practices list, the AI literacy obligation, or the GPAI obligations. Those were already in force in 2025 and they remain in force.

Article 5: prohibited practices (binding since February 2, 2025)

Several categories of AI use are flatly prohibited in the EU. Subliminal manipulation, exploitation of vulnerabilities, social scoring by public authorities, certain real-time biometric identification in public spaces by law enforcement, and certain emotion-recognition uses in workplaces and schools. The new Omnibus prohibition on AI-generated CSAM and non-consensual intimate imagery joins this list with a December 2, 2026 deadline.

Article 4: AI literacy (binding since February 2, 2025)

Providers and deployers must take measures to ensure a sufficient level of AI literacy among staff and any other persons dealing with AI systems on their behalf. This is not a heavy obligation but it is a real one. Document the training your team has received.

GPAI obligations (binding since August 2, 2025)

Providers of General Purpose AI models (the foundation models that power generative AI assistants and other broadly capable systems) must comply with technical documentation, training data summary disclosures, downstream provider information, and certain risk-mitigation requirements. A two-year grace period applies to GPAI models that were already on the market on August 2, 2025. Most U.S. operators are deployers of GPAI rather than providers, but if you fine-tune or substantially modify a GPAI model, you may inherit provider obligations.

A short note on speaking events

If you run a U.S. industry association whose members export to the EU, sell software to EU customers, or have EU operations, your audience needs the current picture. Most legal commentary your members are reading predates the July 2026 adoption of the Omnibus. The new dates, the new prohibitions, and what U.S. companies actually have to do in 2026 versus 2027 versus 2028 is a useful 30-minute talk for an executive audience.

That is a more current and more practical talk than what most AI-regulation speakers are delivering this year. If you are programming an upcoming event, here is the speaking page. Back to the practical guidance.

The 2026 checklist for U.S. companies with EU exposure

This quarter

  • Map your EU exposure. Which products, which features, which customers, which countries.
  • Confirm none of your AI use falls into the Article 5 prohibited list. Subliminal manipulation, social scoring, certain biometric identification, certain emotion recognition. The new CSAM and non-consensual imagery prohibition lands December 2, 2026.
  • Document AI literacy training. Light obligation, written record matters.
  • If you fine-tune or substantially modify a GPAI model, get provider-side documentation in order.

By end of 2026

  • Mark AI-generated and manipulated content in a machine-readable way and disclose AI interactions and deepfakes (Article 50, in force since August 2, 2026; generative systems already on the market have until December 2, 2026 for marking).
  • Confirm CSAM and non-consensual intimate imagery prohibitions are baked into product safeguards.
  • Begin technical documentation work for any high-risk Annex III uses you have. The new December 2, 2027 deadline gives you time, do not waste it.

2027 and beyond

  • Conformity assessments and EU database registrations for any Annex III high-risk uses (deadline December 2, 2027).
  • Annex I high-risk obligations for AI in regulated products (deadline August 2, 2028).
  • Continuous post-market monitoring as a permanent operating discipline.

For the technical reader: the formal regulatory layer

Primary sources: the European Commission’s AI Act page (digital-strategy.ec.europa.eu) and the implementation timeline tracker maintained by the Future of Life Institute.

The next sections cover the formal regulatory framing for general counsel, compliance officers, and AI governance professionals. Skip ahead if you do not.

The risk-tier framework

The AI Act establishes four risk tiers. Unacceptable risk (prohibited under Article 5). High risk (Annex III standalone uses and Annex I AI components in regulated products; the heaviest compliance regime). Limited risk (transparency obligations, including the watermarking and AI-interaction disclosure requirements). Minimal risk (no specific obligations). General Purpose AI models are regulated as a separate category, with additional rules for systemic-risk GPAI.

Annex III standalone high-risk uses

Eight domains: biometric identification and categorization, critical infrastructure management, education and vocational training, employment and worker management, access to essential services (credit scoring, insurance), law enforcement, migration and border control, administration of justice and democratic processes. The Omnibus extends compliance to December 2, 2027.

Annex I AI components in regulated products

AI safety components in products subject to existing EU sectoral safety law (machinery, medical devices, toys, marine equipment, civil aviation, motor vehicles, agricultural vehicles, recreational craft, lifts). The Omnibus shifts to sectoral primacy with an equivalence clause and pushes compliance to August 2, 2028.

Penalty structure

Tiered. Most serious violations (prohibited practices): up to EUR 35 million or 7 percent of total worldwide annual turnover, whichever is higher. Non-compliance with high-risk system obligations: up to EUR 15 million or 3 percent of global turnover. Provision of incorrect, incomplete, or misleading information to authorities: up to EUR 7.5 million or 1 percent of global turnover. SMEs and startups face proportionally lower caps.

Enforcement architecture

National competent authorities in each member state enforce most of the AI Act for systems placed in their jurisdiction. The European AI Office (within the Commission) has direct enforcement authority over GPAI models. The European Artificial Intelligence Board coordinates among national authorities and provides guidance.

How EU AI Act fits inside the broader 2026 governance environment

The EU AI Act is one of four anchor standards capital-intensive and regulated-industry operators are tracking in 2026: NIST AI RMF (federal U.S. voluntary), ISO 42001 (international management standard, certifiable), the EU AI Act (statute, where applicable), and a growing patchwork of U.S. state laws including TRAIGA in Texas and Colorado’s AI Act. The four overlap. None substitutes for any other.

For the broader four-standard treatment, see the 2026 AI Governance Framework implementation guide. For the federal U.S. piece specifically, see the NIST AI RMF implementation guide. For the Texas state-law picture, see TRAIGA: What Texas Businesses Actually Have to Do.

The companion question most operators are not yet asking: how AI engines describe your company is also a governance surface. AI governance and AI visibility are a two-layer control system, and the visibility layer becomes evidence in the same regulatory inquiries.

Frequently asked questions

What happened on August 2, 2026 under the EU AI Act?

The Act's general application date arrived. The Article 50 transparency obligations began to apply (disclosing AI interactions, machine-readable marking of AI-generated content, deepfake labeling), the Commission's AI Office and national authorities began enforcement, and the Commission gained the power to fine general-purpose AI model providers. The high-risk obligations did not apply on that date; the Digital Omnibus moved them to December 2, 2027 (Annex III) and August 2, 2028 (Annex I).

Was the EU AI Act delayed?

Partly. Regulation (EU) 2026/1744, the Digital Omnibus on AI, in force since July 27, 2026, postponed the high-risk obligations. It did not delay the prohibited practices, the AI literacy duty, the general-purpose AI rules, or the Article 50 transparency rules.

When do the high-risk obligations apply now?

December 2, 2027 for Annex III high-risk systems (employment, education, credit, biometrics, critical infrastructure, law enforcement, migration, justice) and August 2, 2028 for Annex I AI components in regulated products. High-risk systems already in use by public authorities get until August 2, 2030.

Do the general-purpose AI obligations apply to U.S. companies?

Yes, if the model is placed on the EU market. The obligations have applied since August 2, 2025; models on the market before that date must comply by August 2, 2027; and since August 2, 2026 the Commission can fine providers up to EUR 15 million or 3 percent of worldwide turnover. Most U.S. businesses are deployers rather than providers, but fine-tuning or substantially modifying a model can create provider duties.

What are the penalties under the EU AI Act?

Up to EUR 35 million or 7 percent of worldwide annual turnover for prohibited practices, up to EUR 15 million or 3 percent for most other obligations, and up to EUR 7.5 million or 1 percent for supplying incorrect information to authorities, with lower caps for SMEs and startups.

Want a current EU AI Act briefing for your board or association?

Most U.S. legal commentary on the EU AI Act is six months out of date. The Digital Omnibus, now law, changed the operative dates and added a new prohibition, and the August 2, 2026 transparency and enforcement milestones are already in force. U.S. boards and association audiences need the current picture, told plainly, with examples from their industry and a clear map of what to do this year versus 2027 versus 2028.

That is the talk I deliver. Houston-based, working with U.S. companies that have EU exposure across C&I, medical, and energy. Plain English. Real industry examples. Honest about what the law actually requires now, what is coming, and what just got pushed back.

Matt Bertram is the owner and CEO of EWR Digital, a Houston marketing firm he bought outright, and President of ModalPoint, an AI decision-governance advisory for energy. He spoke at the Ericsson Enterprise Wireless executive reception in Houston during OTC week 2026, participates in the NIST Cyber AI Profile community of interest (public workshop series), and is a Goldman Sachs 10,000 Small Businesses graduate (Houston, April 2026). Texas A&M, Class of 2006.

This guide describes the EU AI Act as enacted in 2024 and amended by Regulation (EU) 2026/1744 (the Digital Omnibus on AI), in force since July 27, 2026. Last reviewed August 20, 2026. Statutory and regulatory text is the controlling authority; nothing on this page is legal advice. Consult qualified EU counsel for any specific compliance question.

EU AI Act Article 12 (automated logging) and Article 26(5) (human oversight by persons with the necessary authority) require a runtime discipline most U.S. companies have not yet built. For the framework, see Decision Integrity as the Article 12 substrate.

Why a search guy is writing about AI law

I have spent since 1999 on one question: how machines decide who gets found, trusted and chosen. The Omnibus is that question arriving as statute — the machine now decides, and someone has to be accountable for it. From SEO to AI Decision Governance traces the same job across three generations of machine.

This thinking is also a keynote.

Matthew brings this to mainstage keynotes and closed-door board briefings. matthewbertram.com/speaking  ·  More insights

Book a keynote →