Regulation

What US Companies Must Know About the EU AI Act’s Split Deadlines

The EU has delayed high-risk AI compliance to 2027 and 2028, but transparency rules are already in force—and fines reach 7% of global turnover.

Editorial·12 Sep 2026
What US Companies Must Know About the EU AI Act’s Split Deadlines

US companies selling or deploying artificial intelligence in the European Union received a partial reprieve this summer, but the relief is narrower than many compliance teams had hoped. On July 27, 2026, Regulation (EU) 2026/1744 entered into force, formally extending the EU AI Act’s core high-risk compliance deadlines. Yet the same legal package left the Act’s transparency rules on schedule, meaning that as of August 2, 2026, providers and deployers must already inform users when they are interacting with an AI system and label AI-generated content.

The stakes are global. The EU AI Act applies not only to companies based in the bloc but to any organization whose AI systems are used in the EU or whose outputs affect EU residents. With maximum penalties reaching €35 million or 7% of global annual turnover, whichever is higher, non-compliance is a balance-sheet risk for American firms even without a single European office. For many international businesses, the Act has become a de facto regulatory benchmark, shaping product roadmaps, procurement contracts, and risk governance far beyond Brussels.

A split compliance calendar after the Digital Omnibus

The original AI Act set August 2, 2026, as the deadline for most high-risk AI systems. That date has now been replaced by a two-tier schedule. Under Regulation (EU) 2026/1744, adopted as part of the EU’s “Digital Omnibus” package and published in the Official Journal on July 24, 2026, stand-alone high-risk systems listed in Annex III — including uses in employment, education, credit scoring, and law enforcement — must comply by December 2, 2027. That is a 16-month extension from the original date. High-risk AI systems embedded in regulated products covered by Annex I, such as medical devices and machinery, have until August 2, 2028.

  • February 2, 2025: Prohibitions on unacceptable-risk AI took effect.
  • August 2, 2026: Article 50 transparency obligations began to apply.
  • December 2, 2026: Watermarking grace period ends for legacy systems.
  • December 2, 2027: High-risk Annex III systems must comply.
  • August 2, 2028: High-risk Annex I embedded systems must comply.

The delay was not a technical accident. Industry pressure, including from the Trump Administration, and the recognition that necessary harmonised technical standards were not ready pushed EU lawmakers to revise the timeline. But the extension does not apply to every obligation. Article 50 transparency duties took effect on August 2, 2026, as originally scheduled. That means chatbots, emotion recognition systems, deepfake generators, and other AI applications must already disclose their nature to users. AI-generated content must be labelled. A narrow grace period applies only to the machine-readable marking, or watermarking, of content from systems already on the market before August 2, 2026; those providers have until December 2, 2026, to meet that specific technical requirement.

Meanwhile, prohibitions on unacceptable-risk AI have been in force since February 2, 2025. Social scoring, certain forms of biometric surveillance, and other banned practices are not affected by the new extension and remain illegal in the EU.

Penalties that reach across borders

The EU AI Act’s fine structure is one of the main reasons it has become a global compliance priority. Violations of the prohibitions on unacceptable-risk AI carry penalties of up to €35 million or 7% of global annual turnover, whichever is higher. Breaches of high-risk system obligations and Article 50 transparency rules can trigger fines of up to €15 million or 3% of global annual turnover. Supplying incorrect, incomplete, or misleading information to regulators is capped at €7.5 million or 1% of turnover.

These figures are calculated on worldwide turnover, not just EU revenue. Because the Act has extraterritorial reach, a US company with no legal entity in the EU can still be fined if its AI system is used in the bloc or its outputs affect EU residents. That makes the EU AI Act a de facto global standard, and it explains why many American compliance teams now treat Brussels as a primary regulatory risk alongside domestic state and federal rules.

What US companies should do now

The immediate priority is Article 50 transparency. Even if a company’s high-risk systems do not need full conformity assessments until December 2027 or August 2028, the obligation to inform users and label AI-generated content is already live. Companies should audit customer-facing chatbots, voice assistants, content generation tools, and any system that creates synthetic media. For systems already on the EU market before August 2, 2026, the watermarking requirement has a shorter grace period ending December 2, 2026, so technical teams have only months to implement machine-readable provenance markers.

At the same time, US companies should map their AI portfolio against the Act’s risk categories. The extension gives breathing room for high-risk systems, but it does not remove the need for documentation, risk management, human oversight, and data governance. Annex III systems in employment, education, credit scoring, and law enforcement will face the December 2, 2027 deadline, while Annex I embedded systems in medical devices and machinery have until August 2, 2028. Companies that wait until the final months risk finding that the harmonised standards are still incomplete or that their supply chain lacks the necessary conformity evidence.

It is also important to monitor the development of technical standards. The extension was granted partly because those standards were not ready. As standards bodies and the European Commission finalise them, US companies should track which standards apply to their systems and begin aligning internal processes early. Procurement teams should update vendor contracts to require AI Act compliance information, and legal teams should review whether any current or planned AI use falls under the prohibited categories that have been in force since February 2, 2025.

A strategic shift, not just a compliance exercise

For many US companies, the EU AI Act is no longer a distant European issue. It is shaping product design, data strategy, and market access decisions. The extended deadlines reduce immediate pressure, but they also create a longer runway for competitors to build compliant systems and for regulators to refine enforcement expectations. Companies that treat the delay as an opportunity to integrate AI governance into their core operations will be better positioned than those that simply postpone work.

The split calendar also means that compliance is not a single event. Transparency duties are already enforceable, prohibitions have been active for more than a year, and high-risk obligations will phase in over the next two years. US companies should therefore maintain a living inventory of AI systems, assign clear ownership for EU AI Act compliance, and prepare for the possibility that other jurisdictions may adopt similar rules. The EU’s approach has already influenced regulatory debates in other regions, and the Act’s extraterritorial scope means that even a company with no European office may need to demonstrate compliance to European customers, partners, or regulators.

Looking ahead, the next critical milestone for most US companies is December 2, 2026, when the watermarking grace period expires for legacy systems. After that, the focus shifts to the December 2, 2027, high-risk deadline for Annex III systems, followed by the August 2, 2028, deadline for Annex I embedded systems. The EU AI Act’s extension has bought time, but it has not reduced the legal exposure. For American firms operating globally, the practical question is no longer whether the EU rules apply to them, but how quickly they can build the governance, documentation, and technical capabilities to meet a standard that is fast becoming the global baseline for trustworthy AI.

#EU AI Act #compliance #US companies #AI regulation

Newsletter

Get the AI news that matters

One short brief with the day's most important AI stories — written for professionals.

We send a confirmation link. No spam. Unsubscribe anytime.

WhatsApp