Skip to main content
AdvisoryBy Rutvi VaderaAugust 27, 20269 min read

EU AI Act After the Digital Omnibus: What Applies to US Companies

EU AI Act After the Digital Omnibus: What Applies to US Companies

The direct answer: the EU AI Act applies to a US company only if its AI reaches the EU: you place an AI system on the EU market, your AI outputs are used in the EU, or your chatbot or generated content reaches EU users. If none of those are true, you are out of scope, and most US-only mid-market companies that deploy vendor AI tools are exactly that. For companies that are in scope, the deadlines changed in July 2026. The Digital Omnibus deferred the high-risk obligations to December 2, 2027 and August 2, 2028, but it did not touch Article 50 transparency or general-purpose AI enforcement, both of which went live on August 2, 2026.

Status verified August 27, 2026. This page is updated when the regulatory status changes.

One warning before the detail: most of what ranks in search for "EU AI Act deadline" was written before the Digital Omnibus passed and still describes August 2, 2026 as the high-risk compliance date. That is no longer the law. If you built a compliance timeline off an article from 2024 or 2025, rebuild it from the dates below.

What the Digital Omnibus actually changed

The Digital Omnibus on AI is enacted law, not a proposal. The European Parliament approved it on June 16, 2026, the Council on June 29, 2026, it was published in the Official Journal on July 24, 2026, and it entered into force on July 27, 2026. Law firm summaries from Gibson Dunn and a research note from the Cloud Security Alliance cover the mechanics in depth.

The headline change is the high-risk timeline. The original AI Act required high-risk systems to comply by August 2, 2026. The omnibus split and deferred that deadline. Standalone high-risk systems listed in Annex III, the category that covers AI used in employment, credit, insurance, and similar consequential decisions, now have until December 2, 2027. AI embedded in products already regulated under Annex I sectoral legislation, such as machinery and medical devices, has until August 2, 2028.

What was not delayed

Two obligations landed on schedule on August 2, 2026, and this is where the stale content does real damage, because a reader who hears "the AI Act was delayed" tends to assume everything moved.

First, Article 50 transparency obligations. If your chatbot faces EU users, it must disclose that the user is interacting with an AI system. AI-generated or manipulated content, including deepfakes, must be labeled. These duties applied on August 2, 2026 and the omnibus did not defer them.

Second, general-purpose AI enforcement. GPAI model provider obligations have applied since August 2, 2025, structured around the GPAI Code of Practice published in July 2025, as Latham & Watkins documented at the time. What changed on August 2, 2026 is that the Commission's enforcement powers activated, with fines of up to 3 percent of global annual turnover or EUR 15 million, whichever is higher. This mostly concerns model providers, not deployers, but if you fine-tune or rebrand a foundation model and offer it in the EU, you should get scoping advice before assuming you are just a deployer.

Obligation Original date Current date after the omnibus
Article 50 transparency (chatbot disclosure, content labeling)August 2, 2026August 2, 2026, unchanged and in force
GPAI model obligations and Commission finesObligations from August 2, 2025; enforcement August 2, 2026Unchanged, enforcement active since August 2, 2026
Standalone Annex III high-risk systemsAugust 2, 2026December 2, 2027
AI embedded in Annex I regulated productsAugust 2, 2026 onwardAugust 2, 2028

The scoping decision tree for US companies

Before any deadline matters, you have to be in scope at all. Walk these three questions in order. They mirror how the Act reaches beyond the EU: through systems placed on the EU market and through outputs used in the EU.

Question 1: do you sell or offer your AI-powered product to EU customers? If your SaaS product with AI features has EU customers, or you actively market into the EU, you are placing an AI system on the EU market and you are in scope. Move to classification: check whether any of your AI use cases fall under Annex III, and note your December 2, 2027 date if they do. If you have no EU customers, continue.

Question 2: are outputs of your AI used in the EU? This is the catch that surprises people. A US company running AI for HR screening, credit decisions, or insurance pricing can be in scope if those decisions affect persons in the EU, for example EU-based applicants to a US employer. If your AI outputs never touch EU persons, continue.

Question 3: does your chatbot or generated content reach EU users? A public-facing chatbot on your website that EU visitors can use, or AI-generated content you distribute to EU audiences, triggers Article 50 transparency duties, and those are live now. If the answer is no here too, you are out of scope.

Three no answers means no direct EU AI Act obligations today. That is not a hedge, it is the answer, and it describes most US-only mid-market deployers: companies using vendor AI tools internally, selling only to US customers, with no EU-facing AI surface. You do not need an EU AI Act compliance project. What you likely do need is covered in the next section, because the US landscape moved in the opposite direction this year, as we detailed in our roundup of what changed in AI regulation as of August 2026.

Not sure which side of the scoping line you are on?

A Z Cyber advisor can walk your AI inventory through the EU and US scoping questions and brief you on which obligations actually apply.

Talk to an Advisor →

If you are in scope: sequencing, not panic

For US companies that answered yes to any of the three questions, the omnibus bought time on the hardest work but not on the visible work. The sequencing that follows from the dates: fix Article 50 exposure immediately, because chatbot disclosure and content labeling are enforceable now and are also the cheapest items to close. Then inventory your AI use cases against Annex III and build the high-risk program against December 2, 2027, which is real time to do conformity work properly rather than a reason to shelve it. If your AI ships inside Annex I regulated products, your date is August 2, 2028 and your compliance path runs through the product legislation you already know.

One more flow-down effect: even out-of-scope US deployers will feel the Act through vendors. AI vendors selling into the EU are building compliance postures now, and their documentation, model cards, and transparency commitments become the diligence baseline everyone inherits. Asking vendors where they stand on the AI Act is becoming a standard procurement question regardless of your own scope.

Out of scope in the EU does not mean unregulated

The uncomfortable symmetry: while Brussels deferred its high-risk regime, US state law arrived. Texas TRAIGA has been in effect since January 1, 2026, with civil penalties up to $200,000 per violation and a statutory safe harbor for companies that document compliance with the NIST AI Risk Management Framework. Illinois HB 3773 has applied to AI in hiring decisions since January 1, 2026. So the practical question for a US-only company is not "how do we comply with the EU AI Act" but "which framework anchors our AI governance so state law and customer diligence are covered." For most mid-market companies that answer is NIST AI RMF, and our comparison of the EU AI Act versus the NIST AI RMF covers why the framework travels well even for companies with future EU ambitions.

If you are starting from zero, the path is the same regardless of jurisdiction: inventory your AI use, assign ownership, set policy, and build the review cadence. We laid that sequence out in how to build an enterprise AI governance program. A structured starting point is an AI governance assessment, which maps your current AI footprint against the obligations that actually apply to you, and our AI security services cover the technical side: securing the models, data flows, and AI features your governance program is supposed to govern.

What to watch next

December 2, 2026: new prohibited-practice additions from the omnibus apply, along with Article 50(2) transparency obligations for legacy systems. December 2, 2027: the deferred compliance date for standalone Annex III high-risk systems. August 2, 2028: the deferred date for AI embedded in Annex I regulated products. Between now and then, expect Commission guidance and standards work to firm up what high-risk conformity looks like in practice; timelines beyond the statutory dates are not yet fixed. This page will be updated as the status changes.

Frequently Asked Questions

Does the EU AI Act apply to my US company?

Only if your AI reaches the EU. You are in scope if you place an AI system on the EU market, if your AI outputs are used in the EU, or if your chatbot or generated content reaches EU users. A US company with no EU customers, no EU users of its AI outputs, and no EU-facing chatbot is out of scope. Most US-only mid-market companies that merely deploy vendor AI tools fall in that category and have no direct EU AI Act obligations today.

Was the EU AI Act deadline delayed?

Partially. The Digital Omnibus, in force July 27, 2026, deferred the high-risk obligations that were due August 2, 2026. Standalone Annex III high-risk systems now comply by December 2, 2027, and AI embedded in Annex I regulated products by August 2, 2028. Two things were not delayed: Article 50 transparency obligations, which applied on August 2, 2026, and Commission enforcement of general-purpose AI model obligations, which also activated on August 2, 2026.

What EU AI Act obligations apply right now in 2026?

Two sets. Article 50 transparency obligations applied on August 2, 2026: chatbots that reach EU users must disclose that the user is interacting with AI, and AI-generated or manipulated content, including deepfakes, must be labeled. Separately, general-purpose AI model provider obligations have applied since August 2, 2025, and became fully enforceable by the Commission on August 2, 2026, with fines up to 3 percent of global turnover or EUR 15 million. High-risk obligations are deferred to 2027 and 2028.

What are the new EU AI Act high-risk compliance deadlines?

December 2, 2027 for standalone high-risk systems listed in Annex III, which covers uses such as employment, credit, and insurance decisions affecting EU persons. August 2, 2028 for AI embedded in products already regulated under Annex I sectoral legislation. Both dates come from the Digital Omnibus, which entered into force on July 27, 2026. Content published before mid-2026 that cites an August 2, 2026 high-risk deadline is out of date.

Do US companies face EU AI Act fines for chatbots?

They can, if the chatbot faces EU users. Article 50 transparency obligations applied on August 2, 2026 and were not deferred by the Digital Omnibus, so an EU-facing chatbot must disclose that users are interacting with AI, and generated content must be labeled. Separately, GPAI model provider fines of up to 3 percent of global turnover or EUR 15 million became enforceable the same day, though those target model providers rather than typical deployers.

Subscribe for Updates

Get cybersecurity insights delivered to your inbox.