AI Compliance · 11 min read · May 2026
The EU AI Act in 2026: What US Teams Must Do
By Thinklytics Partners, Governance & Trust Practice
The EU AI Act's high-risk obligations did not take effect in August 2026. The Digital Omnibus moved them to December 2027, and most published summaries still have the old date. Here is what actually applies now, what lands on 2 December 2026, and what it means for a US team.
For two years AI regulation was a slide in a strategy deck. In 2026 it has a date, a penalty, and reach into the United States. The EU AI Act's high-risk obligations now apply from 2 December 2027 for stand-alone systems and 2 August 2028 for systems embedded in regulated products, and the Colorado AI Act takes effect on 1 January 2027. Neither one cares where your company is headquartered. They care where your AI is used.
This is the milestone most mid-market teams have not planned for, because the earlier deadlines did not touch them. The 2025 dates covered banned practices and general-purpose model providers. The high-risk regime is the one that lands on ordinary companies running AI in hiring, credit, support, and operations, and it is now a 2027 and 2028 problem rather than a 2026 one.
- Dec 2, 2027 EU AI ACT , HIGH-RISK OBLIGATIONS TAKE EFFECT. Deferred from August 2026 by the Digital Omnibus. High-risk breaches carry up to 15 million euros or 3 percent of global turnover; the 7 percent tier applies to prohibited practices. The Act reaches any company whose AI systems, or their output, are used in the EU. Source: EU AI Act, Regulation 2024/1689, as amended by Regulation (EU) 2026/1744.
Does the EU AI Act actually apply to a US company?
It can, and the test is not your address. If you provide or deploy an AI system that is used in the EU, or whose output is used there, the Act can apply to you the same way GDPR did. A US lender scoring EU applicants, a US SaaS vendor whose AI feature is used by EU customers, a US employer screening candidates in the EU: all in scope.
The honest answer for any specific system is that applicability is a legal call. What you can do without a lawyer, and should do first, is build the inventory and classification that the legal call depends on. You cannot decide whether you are exposed until you know what AI you run and what it touches.
The compliance clock
The AI compliance clock, 2025 to 2027
The Act phases in. The 2 December 2026 transparency deadline is the one most mid-market teams have not noticed.
- Feb 2025 , prohibited practices banned. Unacceptable-risk uses such as social scoring and most real-time biometric identification became illegal across the EU.
- Aug 2025 , general-purpose AI model rules. Transparency and documentation obligations for general-purpose AI model providers began.
- Dec 2, 2027 , high-risk system obligations. Risk management, data governance, logging, human oversight, and conformity duties for high-risk AI. The milestone with teeth, deferred sixteen months.
- 2026 , Colorado AI Act takes effect. The first broad US state AI law, with duties around high-risk automated decisions. Confirm the current effective date with counsel.
- Aug 2027 , remaining high-risk rules. Obligations for high-risk AI embedded in regulated products phase in.
Source: EU AI Act (Regulation 2024/1689) and Colorado SB 24-205. Dates are directional; confirm applicability with legal counsel.
The pattern in that timeline is the trap. The early dates were narrow, so most companies correctly concluded they were not affected and moved on. The high-risk definition is broad, and the same companies have not revisited the question. The gap between "we looked once and were fine" and "the rule changed under us" is where the exposure sits.
The four tiers, and which one you are in
The Act sorts AI into four risk tiers, and your obligations follow the tier. Most of a normal company's AI sits in the bottom two: a chatbot that has to disclose it is a bot, an analytics model that needs no special treatment. The work is proving which of your systems are high-risk and documenting the rest so you can show your reasoning.
The four risk tiers, and what each requires
Most of a typical company's AI sits in the bottom two tiers. The work is proving which systems are high-risk and documenting the rest.
| Tier | What it covers | Your obligation |
|---|---|---|
| Unacceptable | Social scoring, manipulative or exploitative AI | Prohibited. Do not deploy. |
| High-risk | AI in hiring, credit, education, essential services, safety components | Risk management, data governance, logging, human oversight, conformity assessment. |
| Limited | Chatbots, generative content, emotion or biometric categorization | Transparency. Tell people they are dealing with AI or seeing AI output. |
| Minimal | Spam filters, recommendation engines, most analytics | No specific obligation, but inventory and document it anyway. |
Source: EU AI Act risk classification, Regulation 2024/1689. Classification of a specific system should be confirmed with counsel.
A high-risk classification is not a disaster. It is a defined set of duties: risk management, governed and documented training data, logging, human oversight, and a conformity assessment. Every one of those is something a well-run data governance program already does in part. The deadline just makes it mandatory and auditable.
Why most teams are not ready
The reason readiness is hard is not the legal text. It is that the obligations assume a data and governance foundation that most companies funding AI have not built yet.
The readiness gap behind the deadline
Adoption is near-universal. The governance and data foundations the rules require are not.
- Use AI in at least one function
- Have AI-ready data practices
- Have mature AI or agent governance
Source: McKinsey State of AI 2025 (adoption); Gartner data-management survey 2024 (inverse of the 63 percent without AI-ready practices); Deloitte State of AI in the Enterprise 2026 (governance maturity).
Nearly everyone uses AI. Far fewer have AI-ready data, and fewer still have mature governance over how AI makes decisions. The Act asks for exactly the things that gap describes: lineage, logging, oversight, and documentation. A company that cannot show how an AI decision was made today cannot produce the audit trail the rule expects. This is the same foundation problem that stalls AI value in general, which is why readiness for the regulation and readiness for AI are largely the same project.
What readiness actually takes
You do not need a year. You need a scoped assessment and a sequenced fix.
A 3 to 6 week readiness path
Technical and operational work that runs alongside your counsel, not in place of it.
- Inventory every AI and analytics system. What you run, who owns it, what data it touches, and what it decides.
- Classify each system against the tiers. Most land in limited or minimal. The few that are high-risk are where the obligations concentrate.
- Document the gaps and build the audit trail. Logging, model records, risk assessments, and the human-oversight design a regulator or customer can ask to see.
- Sequence the remediation. A prioritized roadmap mapped to NIST AI RMF and ISO 42001 so one body of work satisfies more than one obligation.
Source: Thinklytics AI governance practice, 2026.
The work is technical and operational, and it runs alongside your legal counsel rather than instead of them. Counsel owns the interpretation of whether a system is in scope and high-risk. We build the inventory, the classification, the audit trail, and the remediation plan that the interpretation rests on, and we map it to NIST AI RMF and ISO 42001 so the same effort answers more than one obligation. When the work is done it does not just satisfy a regulator. It is the governance layer that lets you keep scaling AI safely, which is why most teams fold it into AI governance and managed operations rather than treating it as a one-time scramble.
The move this quarter
Inventory your AI systems and classify them against the tiers before the summer. If you cannot answer "which of our AI systems are high-risk" or "could we show an examiner how this decision was made," that is your gap, and it is cheaper to close now than under a deadline. Our EU AI Act and AI compliance readiness engagement does exactly that, and the 30-day Analytics Truth Audit is where most teams start.
This article is research and analysis, not legal advice. Confirm how any regulation applies to your specific systems with qualified counsel.
Frequently asked questions
Does the EU AI Act apply to US companies?
It can. If you provide or deploy AI systems that are used in the EU, or whose output is used there, the EU AI Act may apply regardless of where your company is based. The safe first step is to inventory and classify your AI systems against the regulation's risk tiers, then confirm applicability with counsel.
When do the EU AI Act's high-risk obligations actually apply?
Not in 2026. The Digital Omnibus, Regulation (EU) 2026/1744, moved stand-alone high-risk obligations under Annex III to 2 December 2027, and high-risk AI embedded in regulated products under Annex I to 2 August 2028. What did apply on 2 August 2026 was the remainder of the Act, including the Article 50 transparency duties. The live date in front of most teams is 2 December 2026, when AI systems generating synthetic audio, image, video, or text that were already on the market before 2 August 2026 must meet Article 50(2).
How large are the penalties?
The 7 percent figure is real but narrower than most summaries suggest. Up to 35 million euros or 7 percent of total worldwide annual turnover, whichever is higher, applies to the prohibited practices in Article 5. High-risk obligations, deployer duties, and the Article 50 transparency rules sit one tier down, at up to 15 million euros or 3 percent. Supplying incorrect information to authorities carries up to 7.5 million euros or 1 percent. All of them are set against global turnover, not EU turnover.
What counts as a high-risk AI system?
AI used in areas like hiring, credit, education, essential services, and safety components is generally high-risk and carries the full obligations. Chatbots and generative content usually fall under limited-risk transparency rules. Most analytics and recommendation systems are minimal-risk. Classification of a specific system should be confirmed with counsel.
Is the Colorado AI Act similar?
Less than it was. Senate Bill 26-189, signed on 14 May 2026, repealed and re-enacted the law and moved the effective date to 1 January 2027. The duty of care on algorithmic discrimination, the deployer risk-management programmes, and the impact assessments came out. What remains is largely a disclosure regime: notice before a consequential decision, an explanation afterwards, and consumer rights to correct data and obtain human review. The Attorney General has exclusive enforcement, with a 60-day cure period until 1 January 2030.
How long does readiness take?
A scoped readiness assessment is typically 3 to 6 weeks: inventory your AI systems, classify them against the regulation, and produce a prioritized gap-and-remediation plan. Remediation timelines depend on what the assessment finds, and mapping the work to NIST AI RMF and ISO 42001 means one effort satisfies more than one obligation.
Is this legal advice?
No. This article is research and analysis, not legal advice. Thinklytics does the technical and operational readiness work and partners with your legal counsel, who owns the legal interpretation.
Topics covered
- eu ai act compliance
- high-risk ai obligations
- eu ai act august 2026
- eu ai act for us companies
- ai regulation readiness
Frequently asked questions
Does the EU AI Act apply to US companies?
It can. If you provide or deploy AI systems that are used in the EU, or whose output is used there, the EU AI Act may apply regardless of where your company is based. The safe first step is to inventory and classify your AI systems against the regulation's risk tiers, then confirm applicability with counsel.
When do the EU AI Act's high-risk obligations actually apply?
Not in 2026. The Digital Omnibus, Regulation (EU) 2026/1744, moved stand-alone high-risk obligations under Annex III to 2 December 2027, and high-risk AI embedded in regulated products under Annex I to 2 August 2028. What did apply on 2 August 2026 was the remainder of the Act, including the Article 50 transparency duties. The live date in front of most teams is 2 December 2026, when AI systems generating synthetic audio, image, video, or text that were already on the market before 2 August 2026 must meet Article 50(2).
How large are the penalties?
The 7 percent figure is real but narrower than most summaries suggest. Up to 35 million euros or 7 percent of total worldwide annual turnover, whichever is higher, applies to the prohibited practices in Article 5. High-risk obligations, deployer duties, and the Article 50 transparency rules sit one tier down, at up to 15 million euros or 3 percent. Supplying incorrect information to authorities carries up to 7.5 million euros or 1 percent. All of them are set against global turnover, not EU turnover.
What counts as a high-risk AI system?
AI used in areas like hiring, credit, education, essential services, and safety components is generally high-risk and carries the full obligations. Chatbots and generative content usually fall under limited-risk transparency rules. Most analytics and recommendation systems are minimal-risk. Classification of a specific system should be confirmed with counsel.
Is the Colorado AI Act similar?
Less than it was. Senate Bill 26-189, signed on 14 May 2026, repealed and re-enacted the law and moved the effective date to 1 January 2027. The duty of care on algorithmic discrimination, the deployer risk-management programmes, and the impact assessments came out. What remains is largely a disclosure regime: notice before a consequential decision, an explanation afterwards, and consumer rights to correct data and obtain human review. The Attorney General has exclusive enforcement, with a 60-day cure period until 1 January 2030.
How long does readiness take?
A scoped readiness assessment is typically 3 to 6 weeks: inventory your AI systems, classify them against the regulation, and produce a prioritized gap-and-remediation plan. Remediation timelines depend on what the assessment finds, and mapping the work to NIST AI RMF and ISO 42001 means one effort satisfies more than one obligation.
Is this legal advice?
No. This article is research and analysis, not legal advice. Thinklytics does the technical and operational readiness work and partners with your legal counsel, who owns the legal interpretation.