As of August 2, 2026, most remaining provisions of the European Union's Artificial Intelligence Act are in force, and their reach extends well beyond Europe's borders. U.S.…
As of August 2, 2026, most remaining provisions of the European Union's Artificial Intelligence Act are in force, and their reach extends well beyond Europe's borders. U.S. companies whose high-risk AI systems impact EU residents are now subject to the Act's extraterritorial requirements, regardless of where the company is physically headquartered or where its infrastructure resides. For American businesses deploying artificial intelligence in EU-facing products or services, the compliance clock has already started running.
The Act's extraterritorial application is a defining feature of the new regime. A U.S. company need not have a European office, subsidiary, or server presence to fall within scope. If a high-risk AI system produces outputs that are used within the European Union, or otherwise impacts EU residents, the obligations attach. This marks a significant departure from the more territorially bounded approach that has historically shaped U.S. technology regulation, and it demands a fresh look at deployment maps and customer bases.
The categories designated as high-risk are broad and touch many common commercial use cases. They include biometric identification, critical infrastructure, education, employment, essential services, and law enforcement. Providers of systems in these categories must complete conformity assessments before placing systems on the EU market, maintain detailed technical documentation, register their systems in an EU database, and appoint an authorized representative established within the European Union. These are not paper exercises; each requirement carries substantive evidentiary and governance demands.
The financial stakes for non-compliance are considerable. Penalties for violations of the high-risk provisions can reach up to 15 million euros or 3% of global annual turnover, whichever is higher. For U.S. companies with meaningful international revenue, that turnover-based calculation can dwarf the fixed cap and expose the enterprise as a whole, not merely the EU-facing business line.
U.S. companies should promptly inventory AI systems that may be classified as high-risk, evaluate whether they touch EU residents, and assess readiness against the Act's documentation, registration, and representation requirements. Early gap analysis is often the most efficient path to managing exposure.
This alert is provided for general informational purposes only and does not constitute legal advice. Clients should seek tailored counsel regarding their specific circumstances and AI deployments.