The European Union’s Artificial Intelligence Act has moved from planning to enforcement. On August 2, 2026, the European Commission’s AI Office and national authorities began enforcing key provisions of Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744. These include transparency duties and obligations for providers of general-purpose AI models.
U.S. technology companies should not assume that operating outside Europe removes them from the Act. Coverage can depend on where a product is offered, where an AI system’s output is used, what role the company performs, and what the system is intended to do.
Why Does the August 2026 Milestone Matter?
The AI Act took effect in stages. Some provisions applied before August 2026. August 2, 2026, is nevertheless central because Article 50 transparency requirements became applicable and the Commission began fully enforcing the general-purpose AI model obligations.
Regulation (EU) 2026/1744, effective July 27, 2026, preserved the August transparency and enforcement date but postponed core requirements for many high-risk systems. Relevant Chapter III rules for stand-alone high-risk systems under Article 6(2) and Annex III are scheduled for December 2, 2027. Corresponding rules for certain regulated-product systems under Article 6(1) are scheduled for August 2, 2028. The amendment created preparation time, not a general moratorium.
When Can the EU AI Act Reach a U.S. Company?
Article 2 gives the Act significant territorial reach. It can apply to a provider that places an AI system or general-purpose AI model on the EU market or puts an AI system into service there, regardless of whether the provider is established in the EU. It also applies to deployers located in the EU and to certain importers, distributors, product manufacturers, and authorized representatives.
A provider or deployer outside the EU may also be covered when its AI system’s output is used in the EU. Examples include licensing a model to an EU integrator, supplying an AI assistant to European customers, or producing decisions for an EU business process. The absence of an EU subsidiary is not conclusive.
Role classification also matters. A provider develops, or has developed, a system or model and markets it or puts the system into service under its name or trademark. A deployer uses an AI system under its authority for a nonpersonal purpose. One company can occupy several roles, regardless of contractual labels.
What Transparency Rules Apply to Chatbots and AI-Generated Content?
Article 50 requires providers of certain systems that interact directly with people to disclose that they are communicating with AI, unless that fact is obvious in context. The European Commission’s 2026 guidance states that notice should appear from the start of the first interaction and be clear, distinguishable, and accessible. The rule can reach chatbots, AI agents, avatars, and similar systems.
Provider duties also address synthetic audio, images, video, and text. Covered systems generally must produce machine-readable markings that allow AI-generated or manipulated output to be detected. Limited exceptions include standard editing and systems that do not substantially alter supplied input or its meaning. Providers of systems placed on the market before August 2, 2026, have until December 2, 2026, to satisfy this specific duty; the transition does not postpone the rest of Article 50.
Deployers have separate disclosure obligations for deepfakes. They also generally must disclose AI-generated or manipulated text published to inform the public on matters of public interest. An exception may apply when the text has undergone human review or editorial control and a person or organization accepts editorial responsibility. The analysis is fact specific; a human merely clicking “publish” may not demonstrate meaningful review.
What Rules Apply to General-Purpose and High-Risk AI?
General-purpose AI model providers generally must maintain technical documentation, inform downstream providers, adopt an EU copyright-compliance policy, and publish a sufficiently detailed training-content summary. A non-EU provider generally must appoint an authorized representative before placing a covered model on the EU market. Models presenting systemic risk carry additional evaluation, risk-management, incident-reporting, and cybersecurity duties.
The substantive general-purpose AI obligations began applying on August 2, 2025, and became fully enforceable by the Commission on August 2, 2026. Providers of models placed on the market before August 2, 2025, generally have until August 2, 2027, to comply.
Although core high-risk requirements were postponed, companies should classify their systems now. Annex III identifies specified uses involving areas such as biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and justice. Classification turns on intended purpose and statutory criteria; not every AI application in a regulated industry is automatically high-risk.
What Penalties Can Apply?
The Act authorizes substantial administrative fines. Penalties can reach €35 million or 7 percent of worldwide annual turnover for prohibited practices, and €15 million or 3 percent for other covered violations, including certain transparency and general-purpose AI breaches. Incorrect, incomplete, or misleading information can trigger additional penalties. The calculation depends on the offender and violation, and authorities consider gravity, duration, and intent.
What Should U.S. Technology Companies Do Now?
- Map EU connections. Identify EU customers, distributors, users, websites, and business processes in which AI output is used.
- Assign legal roles. Determine whether the company is acting as a provider, deployer, downstream provider, importer, distributor, product manufacturer, or authorized representative.
- Classify each system and model. Document whether it presents prohibited, transparency, general-purpose, systemic, or potential high-risk issues.
- Test disclosures and markings. Confirm that notices appear at the correct time and that content marking and labeling work across products, devices, and languages.
- Collect compliance evidence. Preserve technical documentation, testing records, model information, copyright policies, training summaries, and publication-review records.
- Update governance and contracts. Allocate documentation, cooperation, change-notification, audit, incident-response, and disclosure responsibilities across the AI supply chain.
What Is the Practical Takeaway?
The EU AI Act is now an active enforcement regime, but its application depends on the specific provision, product, role, and territorial connection. For many U.S. technology companies, the immediate priorities are Article 50 transparency, general-purpose AI compliance, and documentation showing how the company reached its conclusions. The delayed high-risk dates should be used to build controls before those requirements become enforceable.
Our law firm provides legal counsel regarding internet law, artificial intelligence, data privacy, cybersecurity, technology transactions, and regulatory compliance. Businesses developing or deploying AI should consult qualified counsel regarding their technologies, markets, and legal roles. This article is provided for informational purposes only and does not constitute legal advice.
Internet Lawyer Blog

