EU AI Act in plain English for U.S. businesses with EU exposure. Updated August 2026: the Digital Omnibus is now law (Regulation 2026/1744), what applied on August 2, 2026, and the new high-risk dates.
By Matthew Bertram · President of ModalPoint, CEO of EWR Digital · 2026
The EU AI Act is the world’s first comprehensive AI law. It applies extraterritorially, which means a U.S. company can be on the hook for compliance even if it does not have an office, employee, or server inside the European Union. Most U.S. coverage of the law is months out of date. Here is what changed in July and August 2026 and what U.S. businesses should actually be paying attention to.
This guide is for U.S.-based executives, board members, and counsel who export to the EU, sell software used by EU customers, or operate in industries where EU customers might end up using your AI features. AI-curious audience, plain English on top, citation-dense legal layer at the bottom.
Two things happened since the May version of this guide, and together they settle most of the open questions.
What did not change: the prohibited-practices list and the AI literacy duty (binding since February 2, 2025) and the general-purpose AI model obligations (binding since August 2, 2025; models placed on the market before that date must comply by August 2, 2027). The rest of this guide has been updated to match.
That is the gist. The detail follows.
The EU AI Act follows the GDPR template. It applies based on the location of the customer and the use, not the location of the company. If your AI product is used by a person in the EU, or if your AI produces outputs used in the EU, you are in scope. This is the same extraterritorial reach that pulled thousands of U.S. companies under GDPR in 2018.
Three concrete examples of when U.S. companies are in scope:
If your business has zero EU customers, EU users, or EU outputs, the AI Act does not directly apply to you. But the trend is clear: the U.S. federal government, state governments (Texas, Colorado), and other jurisdictions are watching the EU AI Act closely. The compliance practices you build for EU exposure are the ones that will scale to whatever lands next at home.
On May 7, 2026, after months of negotiation and a first trilogue that collapsed at the end of April, the European Parliament and the Council reached a provisional agreement on the Digital Omnibus on AI. Both institutions then adopted it, and it was signed on July 8, 2026 as Regulation (EU) 2026/1744, published July 24 and in force July 27, 2026. It does several things at once.
The agreement was formally adopted: Council final vote June 29, 2026, signature July 8, 2026, Official Journal July 24, 2026, in force July 27, 2026. The dates above are now the law.
A Texas-based SaaS vendor sells customer-service AI to a Berlin retailer. Today, the vendor must already comply with the prohibited-practices list, the Article 50 transparency rules (since August 2, 2026), and GPAI model obligations if applicable. Under the adopted Omnibus, the vendor has until December 2, 2027 instead of August 2, 2026 to bring any high-risk Annex III uses into compliance. The vendor uses the additional time to build the technical documentation, conformity assessment, post-market monitoring, and EU database registration that high-risk obligations require.
A Houston medical device manufacturer ships an AI-enabled diagnostic tool to a hospital in Milan. The AI is a safety component. Annex I obligations apply. The Omnibus pushes Annex I to August 2, 2028. The manufacturer has the time to align the AI conformity assessment with the existing CE-marking process for the medical device, rather than running parallel compliance regimes.
A Texas C&I manufacturer with zero EU sales and no EU users. The AI Act does not apply. But the company should still pay attention because (a) the EU framework is the template U.S. states are starting to follow, (b) the practices it requires (inventory, classification, technical documentation, post-market monitoring) are exactly what NIST AI RMF, ISO 42001, and any future federal U.S. AI regime will also require. Building EU-grade documentation is overkill for U.S. operators today and table stakes by 2027.
The Omnibus does not move the prohibited-practices list, the AI literacy obligation, or the GPAI obligations. Those were already in force in 2025 and they remain in force.
Several categories of AI use are flatly prohibited in the EU. Subliminal manipulation, exploitation of vulnerabilities, social scoring by public authorities, certain real-time biometric identification in public spaces by law enforcement, and certain emotion-recognition uses in workplaces and schools. The new Omnibus prohibition on AI-generated CSAM and non-consensual intimate imagery joins this list with a December 2, 2026 deadline.
Providers and deployers must take measures to ensure a sufficient level of AI literacy among staff and any other persons dealing with AI systems on their behalf. This is not a heavy obligation but it is a real one. Document the training your team has received.
Providers of General Purpose AI models (the foundation models that power generative AI assistants and other broadly capable systems) must comply with technical documentation, training data summary disclosures, downstream provider information, and certain risk-mitigation requirements. A two-year grace period applies to GPAI models that were already on the market on August 2, 2025. Most U.S. operators are deployers of GPAI rather than providers, but if you fine-tune or substantially modify a GPAI model, you may inherit provider obligations.
If you run a U.S. industry association whose members export to the EU, sell software to EU customers, or have EU operations, your audience needs the current picture. Most legal commentary your members are reading predates the July 2026 adoption of the Omnibus. The new dates, the new prohibitions, and what U.S. companies actually have to do in 2026 versus 2027 versus 2028 is a useful 30-minute talk for an executive audience.
That is a more current and more practical talk than what most AI-regulation speakers are delivering this year. If you are programming an upcoming event, here is the speaking page. Back to the practical guidance.
Primary sources: the European Commission’s AI Act page (digital-strategy.ec.europa.eu) and the implementation timeline tracker maintained by the Future of Life Institute.
The next sections cover the formal regulatory framing for general counsel, compliance officers, and AI governance professionals. Skip ahead if you do not.
The AI Act establishes four risk tiers. Unacceptable risk (prohibited under Article 5). High risk (Annex III standalone uses and Annex I AI components in regulated products; the heaviest compliance regime). Limited risk (transparency obligations, including the watermarking and AI-interaction disclosure requirements). Minimal risk (no specific obligations). General Purpose AI models are regulated as a separate category, with additional rules for systemic-risk GPAI.
Eight domains: biometric identification and categorization, critical infrastructure management, education and vocational training, employment and worker management, access to essential services (credit scoring, insurance), law enforcement, migration and border control, administration of justice and democratic processes. The Omnibus extends compliance to December 2, 2027.
AI safety components in products subject to existing EU sectoral safety law (machinery, medical devices, toys, marine equipment, civil aviation, motor vehicles, agricultural vehicles, recreational craft, lifts). The Omnibus shifts to sectoral primacy with an equivalence clause and pushes compliance to August 2, 2028.
Tiered. Most serious violations (prohibited practices): up to EUR 35 million or 7 percent of total worldwide annual turnover, whichever is higher. Non-compliance with high-risk system obligations: up to EUR 15 million or 3 percent of global turnover. Provision of incorrect, incomplete, or misleading information to authorities: up to EUR 7.5 million or 1 percent of global turnover. SMEs and startups face proportionally lower caps.
National competent authorities in each member state enforce most of the AI Act for systems placed in their jurisdiction. The European AI Office (within the Commission) has direct enforcement authority over GPAI models. The European Artificial Intelligence Board coordinates among national authorities and provides guidance.
The EU AI Act is one of four anchor standards capital-intensive and regulated-industry operators are tracking in 2026: NIST AI RMF (federal U.S. voluntary), ISO 42001 (international management standard, certifiable), the EU AI Act (statute, where applicable), and a growing patchwork of U.S. state laws including TRAIGA in Texas and Colorado’s AI Act. The four overlap. None substitutes for any other.
For the broader four-standard treatment, see the 2026 AI Governance Framework implementation guide. For the federal U.S. piece specifically, see the NIST AI RMF implementation guide. For the Texas state-law picture, see TRAIGA: What Texas Businesses Actually Have to Do.
The companion question most operators are not yet asking: how AI engines describe your company is also a governance surface. AI governance and AI visibility are a two-layer control system, and the visibility layer becomes evidence in the same regulatory inquiries.
The Act's general application date arrived. The Article 50 transparency obligations began to apply (disclosing AI interactions, machine-readable marking of AI-generated content, deepfake labeling), the Commission's AI Office and national authorities began enforcement, and the Commission gained the power to fine general-purpose AI model providers. The high-risk obligations did not apply on that date; the Digital Omnibus moved them to December 2, 2027 (Annex III) and August 2, 2028 (Annex I).
Partly. Regulation (EU) 2026/1744, the Digital Omnibus on AI, in force since July 27, 2026, postponed the high-risk obligations. It did not delay the prohibited practices, the AI literacy duty, the general-purpose AI rules, or the Article 50 transparency rules.
December 2, 2027 for Annex III high-risk systems (employment, education, credit, biometrics, critical infrastructure, law enforcement, migration, justice) and August 2, 2028 for Annex I AI components in regulated products. High-risk systems already in use by public authorities get until August 2, 2030.
Yes, if the model is placed on the EU market. The obligations have applied since August 2, 2025; models on the market before that date must comply by August 2, 2027; and since August 2, 2026 the Commission can fine providers up to EUR 15 million or 3 percent of worldwide turnover. Most U.S. businesses are deployers rather than providers, but fine-tuning or substantially modifying a model can create provider duties.
Up to EUR 35 million or 7 percent of worldwide annual turnover for prohibited practices, up to EUR 15 million or 3 percent for most other obligations, and up to EUR 7.5 million or 1 percent for supplying incorrect information to authorities, with lower caps for SMEs and startups.
Most U.S. legal commentary on the EU AI Act is six months out of date. The Digital Omnibus, now law, changed the operative dates and added a new prohibition, and the August 2, 2026 transparency and enforcement milestones are already in force. U.S. boards and association audiences need the current picture, told plainly, with examples from their industry and a clear map of what to do this year versus 2027 versus 2028.
That is the talk I deliver. Houston-based, working with U.S. companies that have EU exposure across C&I, medical, and energy. Plain English. Real industry examples. Honest about what the law actually requires now, what is coming, and what just got pushed back.
Matt Bertram is the owner and CEO of EWR Digital, a Houston marketing firm he bought outright, and President of ModalPoint, an AI decision-governance advisory for energy. He spoke at the Ericsson Enterprise Wireless executive reception in Houston during OTC week 2026, participates in the NIST Cyber AI Profile community of interest (public workshop series), and is a Goldman Sachs 10,000 Small Businesses graduate (Houston, April 2026). Texas A&M, Class of 2006.
This guide describes the EU AI Act as enacted in 2024 and amended by Regulation (EU) 2026/1744 (the Digital Omnibus on AI), in force since July 27, 2026. Last reviewed August 20, 2026. Statutory and regulatory text is the controlling authority; nothing on this page is legal advice. Consult qualified EU counsel for any specific compliance question.
EU AI Act Article 12 (automated logging) and Article 26(5) (human oversight by persons with the necessary authority) require a runtime discipline most U.S. companies have not yet built. For the framework, see Decision Integrity as the Article 12 substrate.
I have spent since 1999 on one question: how machines decide who gets found, trusted and chosen. The Omnibus is that question arriving as statute — the machine now decides, and someone has to be accountable for it. From SEO to AI Decision Governance traces the same job across three generations of machine.
Matthew brings this to mainstage keynotes and closed-door board briefings. matthewbertram.com/speaking · More insights