The EU AI Act for US and UK Companies: What Applies Now

The dates changed two weeks ago. The AI Omnibus entered into force on 27 July 2026 and pushed the high-risk deadlines back, while a different set of obligations started on 2 August. Here is what applies to a company outside the EU, and what does not.

Short answer

You are in scope if you place an AI system on the EU market or if the output of your AI system is used in the Union — being registered in Delaware or London does not exempt you. The high-risk deadlines everyone quotes were moved on 27 July 2026: Annex III now applies from 2 December 2027 and Annex I from 2 August 2028. What did start on 2 August 2026 is the transparency set: disclose the bot, mark the synthetic content, label the deepfake. For a company outside the EU that is not operating in one of the listed sensitive areas, that is the whole of it until December 2027.

This is a summary of published law, not legal advice, and the AI Act interacts with sector rules that differ by market. Where a decision turns on it, read the text or take advice on your specific system.

Whether you are in scope at all

Articles written for a US or UK audience tend to start with the risk pyramid. That is the wrong first question. The first question is territorial, and it is answered in Article 2, which extends the Regulation to three groups that matter here.

Providers “placing on the market or putting into service AI systems… in the Union, irrespective of whether those providers are established or located within the Union or in a third country”. Deployers “that have their place of establishment or are located within the Union”. And — the limb that surprises people — providers and deployers “located in a third country, where the output produced by the AI system is used in the Union”.

Read that third limb slowly. The system can run on US infrastructure, be built by a US team, and be sold under a US contract. If what it produces is used in the Union, the Regulation reaches it. The test is not where your company sits; it is where the market and the output are.

In practice that catches a lot of ordinary businesses: a SaaS product with European customers, an agency generating content for EU clients, a support tool whose answers reach EU users, a screening system used on candidates located in the Union. It does not catch a purely domestic US tool whose output never leaves the US, and it does not apply to systems used exclusively for military, defense or national security purposes.

What changed on 27 July 2026

If you have read anything about the AI Act — or asked an AI assistant about it — you have probably been told the high-risk obligations begin on 2 August 2026. That was true when it was written, and it is no longer true.

The simplification package known as the AI Omnibus was proposed on 19 November 2025, reached political agreement on 7 May 2026, and, in the Commission’s own words, “enters into force across the EU” on 27 July 2026 — six days before the deadline it moved. It extends the timelines rather than removing the obligations, adds a prohibition on nudification apps, permits processing special categories of personal data specifically to detect and correct bias, simplifies the AI literacy requirement, and extends certain simplified requirements to small mid-cap companies as well as SMEs.

Two things follow for anyone doing this research. First, the deadline you are planning against has probably moved. Second, and more usefully: any source that still says 2 August 2026 for high-risk systems is stale, and that includes a good deal of what a language model will tell you, because the change landed after most training data was collected. Check the date on the page before you act on what it says.

The dates, as they now stand

Verified against the Commission’s regulatory framework page on 10 August 2026.

EU AI Act application timeline after the Omnibus
ObligationApplies fromStatus today
Prohibited practices and AI literacy2 February 2025In force
General-purpose AI model obligations and governance rules2 August 2025In force
Remainder of the Act, including Article 50 transparency2 August 2026In force — enforcement announced
High-risk use cases in sensitive areas (Annex III)2 December 2027Extended by the Omnibus, previously 2 August 2026
High-risk AI embedded in regulated products (Annex I)2 August 2028Extended by the Omnibus

Annex III covers the sensitive areas: biometrics, critical infrastructure, education, employment, migration, asylum and border control. Annex I covers AI built into products already regulated for safety — lifts, toys, machinery. If your system sits in neither list, the high-risk chapter is not your problem at all, now or in 2027.

The obligation you most likely have

Article 50 is short, it is in force, and it is the part of the Act that touches ordinary companies. The Commission announced enforcement of these rules from 2 August 2026 and published guidelines on the transparency obligations on 20 July 2026.

  • Tell people they are talking to a machine. Providers must design systems intended to interact directly with natural persons so that those persons are informed they are interacting with an AI system — unless it is obvious to a reasonably well-informed, observant and circumspect person. A chat widget that reads as human is the textbook failure.
  • Mark synthetic output machine-readably. Providers of systems generating synthetic audio, image, video or text must ensure outputs are marked in a machine-readable format and detectable as artificially generated. There is an explicit carve-out where the system performs an assistive function for standard editing or does not substantially alter the input data or its semantics.
  • Disclose deepfakes. Deployers generating or manipulating image, audio or video content constituting a deep fake must disclose it. For evidently artistic, creative, satirical or fictional work the obligation narrows to disclosing that such content exists, in a way that does not spoil the work.
  • Disclose AI-written text on matters of public interest. This one has a limit worth knowing: it does not apply where the content has undergone human review or editorial control and a person holds editorial responsibility for the publication. Ordinary marketing copy is not text “published with the purpose of informing the public on matters of public interest” in the first place.

All of it must reach the person clearly and distinguishably, at the latest at the time of first interaction or exposure. If you run an AI chatbot for customer service or an AI voice agent touching EU users, this is the paragraph to read twice.

What has been in force since 2025

Two things predate all of the above and are easy to overlook because nobody sent a reminder.

The prohibitions have applied since 2 February 2025. They are narrow — manipulative techniques that cause significant harm, exploitation of vulnerability, social scoring, certain biometric categorization and emotion inference at work, untargeted scraping of facial images to build recognition databases — and they carry the heaviest fines in the Act. Many companies are nowhere near them. That is a reason to check once and record the conclusion, not a reason to skip the check. The one worth a deliberate look is emotion inference in the workplace, because sentiment features arrive quietly inside HR and support products that were bought for something else.

AI literacy has applied since the same date, and the Omnibus simplified it, with the Commission and Member States taking a stronger role in promoting it. The practical reading has not changed much: the people operating your AI systems should understand what those systems do and where they fail. That is a training question rather than a filing question, and it overlaps almost entirely with AI training for your team.

Provider or deployer, and why it decides everything

The Act allocates obligations by role, not by size, and companies routinely assume the lighter one.

Which role you are in, and what it means
You areTypical situationWhat attaches
DeployerYou use a model or an off-the-shelf AI product inside your own operations.Deployer-side transparency duties, AI literacy, and the deployer obligations of the high-risk chapter if your use case is listed.
ProviderYou place an AI system on the market or put it into service — including building on a general-purpose model and selling it under your own name.The heavier set: design-side transparency, and the full high-risk regime if your system is in Annex I or III.
BothYou sell an AI product and also use AI internally.Both, assessed per system rather than per company.

The trap here is not misreading the definition. It is a company that built an internal tool, then made it available to clients, and never revisited which role it was in — the same drift that turns a prototype into production without review. It is the reason ownership, hosting and role belong in the contract before work starts, as set out in custom software development.

Fines, and the SME rule that draws far less attention

Article 99 sets three tiers, each expressed as a fixed amount or a percentage of total worldwide annual turnover for the preceding financial year, whichever is higher: up to EUR 35 000 000 or 7 % for breaching the prohibitions, up to EUR 15 000 000 or 3 % for non-compliance with other operator obligations, and up to EUR 7 500 000 or 1 % for supplying incorrect, incomplete or misleading information to notified bodies or national competent authorities.

Then paragraph 6, which draws far less attention and materially changes the exposure for a small company: “In the case of SMEs, including start-ups, each fine referred to in this Article shall be up to the percentages or amount referred to in paragraphs 3, 4 and 5, whichever thereof is lower.” The headline figures are calibrated for large undertakings. For a company with modest turnover the percentage, not the ceiling, is the operative number.

Note also the third tier. Answering a regulator carelessly is a separate, independently finable act — which is an argument for keeping a written record of what your systems do before anyone asks.

What to do this quarter

  • List the AI systems whose output reaches the EU. Not the ones you built — the ones whose output lands with people in the Union. Expect it to be longer than the one leadership has in mind: embedded features inside bought software rarely make it onto anyone’s inventory.
  • Assign a role to each. Provider or deployer, per system. Write it down with the reason. This takes an afternoon and settles most of the downstream questions.
  • Fix the disclosures. Bot identified at first interaction, deepfakes labeled, generated media marked. This is cheap, it is already in force, and it is the most visible thing a regulator or a complainant can check.
  • Check for Annex III exposure before December 2027. If anything you run touches employment, education, biometrics or credit-like decisions, you have roughly sixteen months rather than none — use them to prepare rather than to forget.
  • Date-stamp your compliance notes. The timeline has already moved once. A note that does not say when it was written cannot be trusted the next time it moves.

Where this sits against the rest of what you might do with AI this year is covered in our AI strategy roadmap, and the security-side questions that come up in the same conversation are in AI and cybersecurity. The wider picture of what AI can do inside a smaller company is in our guide to AI automation for small business.

Employment is one of the Annex III areas, and it is also the area with the most non-EU law attached to it already — AI in hiring: what the law actually requires, and the wider privacy picture in AI and data protection.

Frequently asked questions

Does the EU AI Act apply to a company with no office in the EU?

It can. Article 2 catches providers who place an AI system on the Union market irrespective of whether they are established in the Union or in a third country, and it also catches providers and deployers located in a third country where the output produced by the AI system is used in the Union. That second limb is the one most easily overlooked: a US firm running an AI tool entirely on US infrastructure can still be in scope if the output of that tool lands with people in the EU.

Did the high-risk rules start on 2 August 2026?

No, and this is among the most out-of-date facts still circulating. The AI Omnibus entered into force on 27 July 2026 and moved them: rules for high-risk systems in Annex III now apply from 2 December 2027, and for high-risk AI embedded in physical products under Annex I from 2 August 2028. Anything published before late July 2026 — including many AI-generated summaries — will still say 2 August 2026.

So what did start applying on 2 August 2026?

The remainder of the Act. For a company not operating in one of the listed sensitive areas, that means the transparency obligations in Article 50: telling people they are interacting with an AI system, marking synthetic content in a machine-readable format, disclosing deepfakes, and disclosing AI-generated text published to inform the public on matters of public interest. The Commission published guidelines on those obligations on 20 July 2026 and announced enforcement starting 2 August.

Are we a provider or a deployer?

A deployer, in most cases, if you use somebody else's model or product inside your own business. You become a provider when you place an AI system on the market or put it into service — including, in substance, when you build a product on top of a general-purpose model and sell it under your own name. The distinction decides which obligations attach to you, so it is worth settling early rather than assuming.

What are the fines?

Article 99 sets up to EUR 35 000 000 or 7 % of total worldwide annual turnover for breaching the prohibitions, up to EUR 15 000 000 or 3 % for other operator obligations, and up to EUR 7 500 000 or 1 % for supplying incorrect or misleading information to authorities, whichever is higher in each case. There is a provision that draws far less attention than the headline figures: for SMEs including start-ups, the fine is capped at whichever of the amount or the percentage is lower.

Is the UK covered by the AI Act?

Not as a matter of UK law — the UK is a third country for this purpose and has not enacted an equivalent statute. But a UK company selling into the EU is in exactly the same position as a US one: what matters is where the system is placed on the market and where its output is used, not where the company is registered.

If you sell into the EU and are unsure which of your systems the Regulation reaches, the useful first conversation is an inventory rather than a legal opinion. Book a call.

LYVIA

LYVIA Team

AI automation and SEO/GEO visibility

LYVIA builds custom AI tools for companies of 10 to 100 people, and gets them found on Google and inside AI answers.

Free offer

Get your free AI audit
in 30 minutes

A LYVIA expert reviews your workflows, pinpoints the 3 highest-ROI AI opportunities, and hands you a concrete roadmap. No commitment, no jargon.

  • Full diagnostic of your business processes
  • Automatable quick wins, identified
  • A personalized roadmap you keep
Book my free audit

30 min · Free · No commitment