Spending on AI governance platforms is projected to reach $492 million in 2026 and surpass $1 billion by 2030, according to a Gartner press release, and the EU AI Act is the single biggest reason why. The Regulation does not stop at the EU border. Article 2 reaches any US company whose AI system output is used inside the Union, whether or not that company has ever opened a European office.
For most US organizations, this shows up first as a line item in an EU customer’s procurement questionnaire, not as a letter from a regulator. By the time a security review asks which AI Act risk tier your product falls into, the honest answer needs to already exist in writing.
This piece lays out exactly who is in scope, what changed when the Digital Omnibus deferred the high-risk deadlines in mid-2026, and which records and controls your organization needs on file before an EU customer, auditor, or your own board asks for them.
Does the EU AI Act Apply to Your Company? Article 2 in Plain Terms
Start with the test that actually matters, not the one most US teams run first. The question is not “do we have an EU office,” it is “does our AI system’s output get used by anyone in the EU.” Article 2(1)(c) of Regulation (EU) 2024/1689 extends the Act to providers and deployers established in a third country wherever the output produced by their AI system is used in the Union.
That is a lower bar than GDPR. GDPR’s extraterritorial reach requires targeting or monitoring: you had to be offering goods or services to EU individuals, or watching their behavior. The AI Act requires neither. If a French employer runs candidate resumes through your Texas-built screening model, you are in scope the moment that employer starts using it, regardless of whether you ever marketed to Europe.
Three categories capture non-EU companies in practice: providers placing an AI system on the EU market under their own name, deployers with an EU place of establishment (including a US company’s own EU subsidiary or office), and third-country providers or deployers whose AI output is used in the Union. That third category is the one most compliance mapping exercises miss, because it does not depend on a sales contract at all. A US SaaS company whose recommendation engine is embedded, unmodified, into a European customer’s product can be caught even without direct billing to an EU entity.
| What most US compliance teams get wrong: Treating “we have no EU entity” as a complete answer. Under Article 2(1)(c), the trigger is where the output lands, not where the company is incorporated. A no-EU-presence answer only closes the question if you have also confirmed no EU-based deployer or end user is acting on your system’s output. |
The Two Compliance Clocks: What the Digital Omnibus Actually Changed
In May 2026, EU lawmakers reached political agreement on the Digital Omnibus on AI, deferring the compliance deadline for stand-alone high-risk systems under Annex III from 2 August 2026 to 2 December 2027, and for high-risk AI embedded in regulated products under Annex I to 2 August 2028. The European Parliament formally endorsed the text on 16 June 2026, and the Council of the EU gave its final approval on 29 June 2026. Publication in the Official Journal and formal entry into force were expected within weeks of that approval, ahead of the original 2 August 2026 deadline.
Here is the part a lot of relief-toned coverage buried: the deferral only touches Annex III and Annex I high-risk obligations. It does not touch general-purpose AI (GPAI) provider obligations, which have applied since 2 August 2025, and it does not touch Article 50 transparency duties, which remain scheduled for 2 August 2026 (with a narrower grace period, to 2 December 2026, for watermarking obligations on systems already on the market before the August deadline).
Run two separate clocks. Clock one governs high-risk conformity assessment and technical documentation, and you now have until late 2027 or 2028 depending on the annex. Clock two governs GPAI documentation and Article 50 labeling and disclosure duties, and it is due in weeks, not years, for any company whose product touches a chatbot interface, synthetic media, or an EU-facing generative feature. A compliance plan calibrated only to clock one will walk into August 2026 non-compliant on the obligations that were never delayed.
EU AI Act compliance clocks for US companies, post-Omnibus
| Obligation | Applies From | Affected by Omnibus? |
|---|---|---|
| Prohibited practices & AI literacy (Ch. I-II) | 2 February 2025 | No already in force |
| GPAI provider obligations (Ch. V) | 2 August 2025 | No unaffected |
| Article 50 transparency (chatbots, synthetic content) | 2 August 2026 | Largely no; watermarking grace to 2 Dec 2026 for legacy systems |
| High-risk stand-alone systems (Annex III) | 2 December 2027 | Yes deferred from 2 August 2026 |
| High-risk embedded systems (Annex I) | 2 August 2028 | Yes deferred from 2 August 2027 |
What Actually Triggers High-Risk Classification
The Act sorts AI systems into four tiers: unacceptable (prohibited outright), high-risk, limited risk (transparency obligations only), and minimal risk (no new duties). Most US B2B SaaS products land in the bottom two tiers. High-risk status under Annex III attaches to specific use cases, not to AI generally: biometric identification and categorization, employment decisions (recruitment screening, performance evaluation, task allocation, promotion or termination), credit scoring and creditworthiness assessment, education and vocational training access, critical infrastructure safety components, law enforcement, migration and border control, and administration of justice.
A narrow-task carve-out matters here. If your system performs a purely procedural task, refines the output of a completed human decision, or detects patterns without influencing the substance of a human’s decision, it may fall outside Annex III even if it operates in one of those listed domains. The Digital Omnibus retained the registration requirement for systems that rely on this exemption, though with a lighter information burden than for full high-risk systems.
For a US employer using an AI tool to screen or evaluate candidates located in the EU, or a fintech scoring EU-based applicants, the honest self-assessment usually lands the system inside Annex III. The deferral changes when conformity obligations bite, not whether the system is high-risk at all.
Recordkeeping: What Documentation You Need, and When
Documentation obligations scale with risk tier, and the biggest operational failure point at every organization we have seen assess this is not a missing policy document, it is the absence of a reliable inventory of where AI systems live, what feeds them, and what they produce. You cannot label, document, or attest to an AI system your organization has never inventoried in the first place.
The following records apply regardless of whether your systems are ultimately classified high-risk, because the classification exercise itself has to be documented and defensible.
- AI system inventory. Every AI system in use, standalone or embedded, internally built or procured, with provider/deployer role assigned per system. (Article 3 definitions; supports Article 16 documentation duty)
- Risk classification record. A written rationale for why each system sits in its tier, including the narrow-task exemption analysis where relied on. (Article 6 classification; ISO 42001 Clause 6.1 risk assessment)
- Technical documentation file. Purpose, architecture, training data provenance, performance metrics, and known limitations for any Annex III system. (Article 11 & Annex IV; NIST AI RMF MAP function)
- Risk management system log. Ongoing identification, evaluation, and mitigation of foreseeable risks across the system lifecycle. (Article 9; NIST AI RMF MEASURE and MANAGE functions)
- Human oversight design record. Documented mechanism by which a human can understand, intervene in, and override system output. (Article 14; ISO 42001 Clause 8.2)
- Post-market monitoring plan. How the provider tracks performance and incidents after deployment, with a serious-incident reporting pathway. (Article 72)
- GPAI model documentation. Training content summary, capabilities and limitations, and downstream provider disclosures for any general-purpose model you provide or substantially modify. (Article 53; already due since August 2025)
- Article 50 transparency log. Evidence that users are told they are interacting with an AI system, and that synthetic content is labeled or watermarked. (Article 50; due 2 August 2026, watermarking grace to 2 December 2026 for legacy systems)
The Controls Auditors and EU Customers Actually Ask to See
Documentation proves a control exists on paper. Auditors, EU procurement teams, and eventually market surveillance authorities want evidence the control operates. That distinction is where most first-time reviews stall.
Four control areas come up repeatedly in EU customer security questionnaires already circulating in 2026: governance structure (who owns AI risk decisions and how escalation works), human oversight in practice (not just a documented mechanism, but logs showing a human actually reviewed or overrode output), data governance for training and fine-tuning data (lineage, bias testing, and representativeness), and incident response (a defined path from detected AI-caused harm to internal reporting and, where required, notification to a market surveillance authority).
A governance committee that spans legal, compliance, product, engineering, and an executive sponsor is now standard practice among multinational companies treating the Act as a strategic priority rather than a checkbox. The committee’s job is not to write policy once. It is to keep the AI inventory current as new systems ship, which is the part that breaks down first when ownership sits with a single compliance analyst instead of a cross-functional structure.
Product note: Govern365.ai‘s compliance dashboard gives a governance committee a single view of which systems have current human-oversight evidence logged and which are lapsing, instead of chasing spreadsheet owners for status updates before an audit.
Cross-Framework Mapping: EU AI Act, ISO/IEC 42001, and NIST AI RMF
Most US companies preparing for the EU AI Act are not starting from zero. If you have implemented ISO/IEC 42001:2023 or built a program around NIST AI RMF 1.0, a meaningful share of the underlying control work already exists; it simply needs to be re-labeled and cross-referenced against the Act’s specific articles. This is the single highest-leverage exercise for a US compliance team in 2026, and it is largely absent from public guidance, most of which treats the three frameworks in isolation.
| Why this matters practically An organization that has already achieved ISO/IEC 42001 certification typically needs to add EU AI Act-specific items (the Article 2 scope memo, the authorized representative appointment, Article 50 labeling evidence) rather than build a parallel governance program from scratch. |
Clause-level mapping: EU AI Act obligations to ISO/IEC 42001 and NIST AI RMF 1.0
| EU AI Act Obligation | ISO/IEC 42001:2023 | NIST AI RMF 1.0 |
|---|---|---|
| Article 9 Risk management system | Clause 6.1 Actions to address risks and opportunities [VERIFY sub-clause] | MAP + MEASURE functions |
| Article 10 Data and data governance | Annex A control on data quality and provenance [VERIFY sub-control] | MAP 2.3, MEASURE 2.7 (bias and data quality) |
| Article 11 & Annex IV Technical documentation | Clause 7.5 Documented information | MAP 1.1-1.6 (context documentation) |
| Article 14 Human oversight | Annex A control on human oversight measures [VERIFY sub-control] | MANAGE 2.2, GOVERN 3.2 |
| Article 17 Quality management system | Clause 4-10 (full AIMS structure) | GOVERN function (overall) |
| Article 72 Post-market monitoring | Clause 9.1 Monitoring, measurement, analysis | MEASURE 3.1-3.3, MANAGE 4.1 |
Implement the NIST AI Risk Management Framework to establish AI inventories, risk assessments, and continuous monitoring that support EU AI Act compliance.
Product note: Govern365.ai‘s AI model registry auto-tags each inventoried system against its applicable ISO 42001 clauses, NIST AI RMF functions, and EU AI Act risk category in a single record, so the mapping above updates itself as your inventory changes instead of living in a static spreadsheet.
Authorized Representatives and EU Database Registration
If your organization provides a high-risk AI system or a GPAI model and is established outside the EU, Article 22 requires appointing an authorized representative located in the Union before placing that system on the market. This is a distinct role from a GDPR representative; it requires AI Act-specific expertise and a written mandate covering the specific obligations and procedures the representative will carry out on the provider’s behalf.
Without an authorized representative in place, a non-EU provider cannot legally offer a high-risk AI product into Europe, full stop. This requirement did not move with the Digital Omnibus and applies on the same timeline as the underlying high-risk obligations, meaning most US providers now have until the relevant Annex III or Annex I deadline to have the appointment finalized, but the earlier a mandate is signed, the more runway there is to work through the technical file the representative will need to review.
High-risk systems also require registration in the EU’s public database before market placement, under Article 49. The Digital Omnibus preserved this registration duty even for systems relying on the narrow-task exemption, though with a reduced information requirement for those cases.
Penalties and Real Exposure for US Companies
The fine structure is tiered by violation severity. Prohibited-practice violations carry the steepest exposure: up to €35 million or 7% of global annual turnover, whichever is higher. High-risk and GPAI non-compliance, along with Article 50 breaches, carry exposure of up to €15 million or 3% of global turnover. Supplying incorrect or misleading information to authorities can trigger fines up to €7.5 million or 1% of global turnover.
For small and medium enterprises, and under the Digital Omnibus’s extension of SME-style relief to small mid-cap companies, fines are calculated as the lower of the fixed amount or the percentage, not the higher, which meaningfully changes exposure for smaller US organizations selling into the EU.
For a US enterprise with material global revenue, the percentage-of-turnover exposure is not a rounding error; it is calculated against worldwide turnover, not EU-derived revenue. That detail alone is why several multinational companies have already stood up cross-functional AI Act governance structures well ahead of the enforcement dates that did not move.
A Practical 2026-2027 Compliance Roadmap
The sequence that works, in order: inventory every AI system regardless of risk tier, since nothing downstream is possible without it; classify each system against Annex III and document the rationale, including any narrow-task exemption reasoning; close the clock-two gaps first, meaning GPAI documentation and Article 50 transparency, since those deadlines did not move; build or extend a risk management system and human oversight design for any system trending toward high-risk; appoint an authorized representative early if you provide high-risk systems or GPAI models into the EU; and map existing ISO 42001 or NIST AI RMF work against the Act’s specific articles rather than starting a parallel program.
Boards and audit committees are increasingly asking for this roadmap in writing, with owners and dates attached, well before any regulator asks the same question. Treating the Omnibus deferral as permission to deprioritize AI governance is the most common and most expensive misread of the 2026 update.
Organizations using AI in employment should also understand AI hiring tools compliance, including bias audits, recordkeeping, and evidence requirements
Frequently Asked Questions
Does the EU AI Act apply to a US company with no office in Europe?
Yes, if your AI system’s output is used in the EU. Article 2(1)(c) applies to third-country providers and deployers whenever output produced by their AI system is used in the Union, with no requirement for an EU entity, EU staff, or EU-based servers.
Is being GDPR-compliant enough to satisfy the EU AI Act?
No. GDPR governs personal data handling; the AI Act governs the AI system’s risk classification, documentation, human oversight, and transparency duties. The two regimes overlap in places, particularly around data governance, but neither substitutes for the other’s specific obligations.
Did the Digital Omnibus delay the entire EU AI Act?
No. It deferred only the high-risk obligations under Annex III (to 2 December 2027) and Annex I (to 2 August 2028). GPAI provider obligations and Article 50 transparency duties remain on their original 2025 and 2026 dates.
What is Article 2(1)(c) of the EU AI Act?
It is the provision extending the Act to providers and deployers established in a third country, such as the United States, wherever the output produced by their AI system is used in the European Union, regardless of where the company itself is located.
Do US companies need an EU authorized representative?
Only if you provide a high-risk AI system or a GPAI model into the EU market and are established outside the Union. Article 22 requires a written mandate to a representative located in the EU before the system is placed on the market.
What are the penalties for EU AI Act non-compliance?
Fines scale by violation type: up to €35 million or 7% of global turnover for prohibited practices, up to €15 million or 3% for high-risk and GPAI or Article 50 violations, and up to €7.5 million or 1% for supplying incorrect information to authorities.
Can ISO/IEC 42001 certification help with EU AI Act compliance?
It can substantially reduce the build effort. ISO/IEC 42001’s AI management system structure overlaps with the Act’s risk management, documentation, and human oversight requirements, though EU AI Act-specific items like scope analysis and authorized representative appointment still need to be added separately.
Conclusion
The EU AI Act does not ask where your company is headquartered. It asks where your AI system’s output ends up. That single fact, more than any single deadline, is why the Digital Omnibus’s deferral of high-risk obligations to December 2027 and August 2028 is relief on one clock and no relief at all on the other. GPAI documentation and Article 50 transparency duties are due on the original schedule regardless.
The one action worth taking this week: confirm your AI system inventory is complete and current, because every other record and control in this piece depends on it existing first.
Govern365.ai‘s AI model registry, risk assessment, and compliance dashboard were built by the Global AI Certification Council to keep that inventory current automatically. Start your 14-day free trial of Govern365.ai, by the Global AI Certification Council
