EU AI Act Compliance for US Companies: What Texas AI Startups Must Do Now
The EU AI Act has extraterritorial reach — Texas startups selling AI to EU customers must comply. Prohibited practices, GPAI model obligations, and the August 2026 high-risk deadline explained.
If your Texas startup builds AI products and has even a single customer in the European Union, you are already subject to the EU AI Act — the world's first comprehensive AI regulation. Most founders we speak with assume that because they are incorporated in Delaware and headquartered in Austin, European law does not apply to them. That assumption is wrong, and it is expensive. The EU AI Act has explicit extraterritorial reach: any company whose AI system produces outputs that are used in the EU must comply, regardless of where the company is based.
Two deadlines have already passed, and a third is imminent. The prohibited practices ban took effect on February 2, 2025. General-purpose AI (GPAI) model obligations have been enforceable since August 2, 2025. On August 2, 2026, the full high-risk AI system requirements kick in for systems covered by Annex III. The European AI Office has already published a General-Purpose AI Code of Practice to help companies comply with the GPAI rules that are already in force. If your startup has not mapped its EU AI Act exposure, you are operating without a compliance framework that European regulators can enforce starting today.
This guide walks through what the EU AI Act requires of US companies, how those obligations overlap with Texas's own AI law (TRAIGA), and what founders must do now. For our analysis of Texas-specific AI governance, see our TDPSA compliance guide, which covers the TRAIGA intersection with Texas privacy law. For AI vendor contract provisions that flow EU AI Act obligations downstream, see our AI vendor contract terms guide.
What the EU AI Act Actually Covers: Extraterritorial Scope
The EU AI Act (Regulation (EU) 2024/1689) applies a risk-based framework to AI systems placed on the EU market, put into service in the EU, or whose outputs are used in the EU — regardless of where the provider or deployer is established. Article 2 makes this explicit: the Act covers providers and deployers of AI systems irrespective of whether they are established within the Union or in a third country, as long as the output of the system is used in the EU.
For a Texas startup, this means the following scenarios trigger EU AI Act jurisdiction:
- You sell an AI-powered SaaS product to EU customers. If a German company subscribes to your AI analytics platform, your system's outputs are being used in the EU.
- Your AI product is embedded in a platform that serves EU users. If your API is called by an application with EU users, even indirectly, the output is being used in the EU.
- You build a GPAI model (like an LLM) that downstream providers integrate into EU-facing products. Even if you never directly sell to EU customers, if someone uses your model in an EU product, you are a GPAI provider under the Act.
The practical consequence is that most AI startups with any international reach are already in scope. The question is not whether you are subject to the EU AI Act — it is whether you have done the compliance work the Act requires.
The Prohibited Practices Ban: Already in Effect Since February 2025
On February 2, 2025, Article 5 of the EU AI Act took effect, banning certain AI practices outright. These prohibitions apply to all companies whose AI systems produce outputs used in the EU — including US companies. The banned practices include:
- Social scoring: AI systems that evaluate or classify persons based on social behavior or personality characteristics over a period of time, leading to detrimental or unfavorable treatment.
- Manipulative and exploitative AI: AI that deploys subliminal techniques or purposefully manipulative or deceptive techniques designed to materially distort behavior, causing significant harm.
- Biometric categorization: AI that categorizes individuals based on biometric data to infer race, political opinions, trade union membership, religious beliefs, or sexual orientation.
- Untargeted facial scraping: AI that builds facial recognition databases by scraping images from the internet or CCTV footage.
- Emotion recognition in workplaces and schools: AI that infers emotions in the workplace or educational institutions, with limited exceptions.
For Texas startups, the prohibited practices ban is the most immediate compliance risk. If your AI product includes any feature that could be characterized as social scoring, manipulative personalization, or biometric categorization, you may already be non-compliant. The penalties for prohibited practice violations are severe: up to €35 million or 7% of global annual turnover, whichever is higher. Unlike TRAIGA, which provides a 60-day cure period, the EU AI Act's enforcement does not include a cure period for prohibited practices.
GPAI Model Obligations: In Effect Since August 2025
On August 2, 2025, Chapter V of the EU AI Act took effect, imposing obligations on providers of general-purpose AI models. As the European Commission's AI Office states, "The AI Act rules on GPAI apply from 2 August 2025." These rules have been enforceable for months — yet most US startups are unaware they exist.
A "general-purpose AI model" is defined as an AI model — including when trained with large amounts of data using self-supervision at scale — that displays significant generality and is capable of competently performing a wide range of distinct tasks. If your startup trains or fine-tunes a foundation model (even an open-weight model like Llama or Mistral) and makes it available to others, you may be a GPAI provider under the Act. Article 53 imposes three core obligations:
Transparency and Technical Documentation
GPAI providers must maintain and make available to the AI Office and downstream providers technical documentation of the model, including training data, computational resources used, and known capabilities and limitations. Annex XI specifies the detailed content requirements for this documentation, which must include:
- A general description of the model, including its architecture, parameter count, and training methodology
- A summary of the training data, including its provenance, scope, and processing methods
- Information about how the model was evaluated, including testing parameters and metrics
- Information that enables downstream providers to comply with their own obligations under the AI Act
For Texas startups that train or fine-tune models, this documentation requirement is not optional. If you build on Llama, Mistral, or Qwen and offer the model to customers — even through an API — you may need to produce and maintain Annex XI-compliant technical documentation. For a detailed analysis of the licensing and compliance implications of building on open-weight models, see our coverage of open-weight AI licensing risks for startups.
Copyright Policy
Article 53 also requires GPAI providers to put in place a policy to comply with EU copyright law, particularly regarding the text and data mining of copyrighted works used in training. For US companies, this means your training data pipeline must include a documented copyright compliance strategy — not just under US fair use doctrine, but under EU law, which has different exceptions and limitations for text and data mining.
Systemic Risk Assessment
Under Article 55, providers of GPAI models classified as presenting "systemic risk" face additional obligations. A model is classified as systemic risk if it has high-impact capabilities, determined by training compute exceeding 10^25 FLOPs (floating point operations). For frontier models — the kind being built by well-funded AI labs — this triggers obligations to conduct model evaluations, assess and mitigate systemic risks, and report serious incidents to the AI Office. Most early-stage Texas startups will not cross the systemic risk threshold, but companies building on or fine-tuning frontier models should understand where the line is drawn.
The GPAI Code of Practice
In July 2025, the European AI Office facilitated the publication of the first General-Purpose AI Code of Practice, a voluntary framework designed to help companies comply with the GPAI obligations that took effect on August 2, 2025. As Latham & Watkins noted in their analysis, the Code of Practice represents a practical compliance roadmap, but adherence to it does not automatically guarantee legal compliance — it is a risk mitigation tool, not a safe harbor.
For US companies, the Code of Practice is the closest thing to a compliance manual the EU has published. It details how to structure technical documentation, how to implement copyright policies, and how to approach systemic risk assessment. If your startup is building GPAI models, the Code of Practice should be your starting reference document.
The August 2026 Deadline: High-Risk AI System Obligations
While GPAI obligations have been in force since August 2025, the next major deadline is August 2, 2026, when the full requirements for high-risk AI systems under Annex III take effect. If your AI system is used for any of the following purposes and its outputs are used in the EU, it may be classified as high-risk:
- Biometric identification and categorization
- Management of critical infrastructure (water, energy, transport)
- Education and vocational training (admissions, evaluations, remote learning)
- Employment and worker management (recruitment, promotion, termination)
- Access to essential private and public services (credit scoring, insurance, public benefits)
- Law enforcement
- Migration and border control
- Administration of justice
High-risk AI system providers must conduct conformity assessments, implement risk management systems, ensure data governance standards, maintain technical documentation, provide transparency to deployers, and enable human oversight. The penalties for non-compliance with high-risk system obligations are up to €15 million or 3% of global annual turnover.
TRAIGA Meets the EU AI Act: Where They Overlap and Diverge
Texas's own AI law, the Texas Responsible Artificial Intelligence Governance Act (TRAIGA), was signed into law as House Bill 149 on June 22, 2025, with an effective date of January 1, 2026. TRAIGA applies to persons who develop or deploy AI systems in Texas, and it prohibits specific categories of harmful AI use, requires consumer disclosures, and provides a safe harbor for companies that substantially comply with the NIST AI Risk Management Framework.
For Texas startups, the question is how much TRAIGA compliance work can be repurposed for EU AI Act alignment — and where the two regimes diverge.
Where They Overlap
Both TRAIGA and the EU AI Act share certain principles: transparency, documentation of system capabilities and limitations, prohibitions on certain harmful uses, and risk management. If your startup has already built a TRAIGA compliance program, the following work product can be repurposed:
- AI system inventory: TRAIGA requires you to identify which AI systems you develop or deploy. The same inventory is the starting point for EU AI Act compliance.
- NIST AI RMF alignment: TRAIGA's safe harbor for NIST AI RMF compliance maps well to the EU AI Act's risk management system requirements under Article 9.
- Consumer disclosure protocols: TRAIGA requires disclosure when AI interacts with consumers. The EU AI Act's Article 50 transparency obligations cover similar ground, though with different specifics.
Where They Diverge
The two regimes diverge in several critical areas:
- Scope of prohibited practices: The EU AI Act's Article 5 ban is broader and more specific than TRAIGA's prohibited-use list. The EU bans social scoring, manipulative AI, and certain biometric practices outright. TRAIGA prohibits AI that incites self-harm, crime, or violence, and bars government social scoring — a narrower set of prohibitions.
- GPAI model obligations: The EU AI Act's Chapter V imposes specific documentation, copyright, and systemic risk obligations on GPAI model providers. TRAIGA has no equivalent GPAI-specific requirements.
- High-risk system conformity assessments: The EU AI Act requires conformity assessments for high-risk systems — a process that may involve notified bodies and CE marking. TRAIGA has no conformity assessment mechanism.
- Enforcement and penalties: TRAIGA is enforced exclusively by the Texas AG with a 60-day cure period and penalties of $10,000–$200,000 per violation. The EU AI Act is enforced by the AI Office and national authorities with no cure period for prohibited practices and penalties reaching 7% of global turnover.
- Extraterritorial reach: TRAIGA applies to companies operating in Texas. The EU AI Act applies to any company whose AI outputs are used in the EU — regardless of where the company is based.
For Texas startups operating in both regulatory environments, the practical approach is to build compliance to the stricter standard — which in most cases is the EU AI Act — and then demonstrate that TRAIGA's requirements are satisfied by the same compliance work. For our analysis of multi-state AI compliance, see our Colorado AI Act compliance guide for Texas companies, which covers a parallel state-level framework.
Selling AI products to EU customers without an EU AI Act compliance plan? We help Texas startups map their GPAI and high-risk system obligations, repurpose TRAIGA compliance work, and build documentation that satisfies both regimes — before a European regulator or enterprise customer forces the issue.
Actionable Next Steps
- Determine whether your AI system's outputs are used in the EU. Map your customer base, API integrations, and distribution channels. If any output reaches an EU user — directly or indirectly — you are in scope of the EU AI Act.
- Audit your AI systems against the Article 5 prohibited practices list. Review every feature of your product for social scoring, manipulative personalization, biometric categorization, and emotion recognition in workplace or educational contexts. If any feature could be characterized as a prohibited practice, remediate immediately — there is no cure period.
- Determine whether you are a GPAI model provider. If you train, fine-tune, or make available a general-purpose AI model to others — even through an API — you likely are. Begin building the Article 53 documentation: technical documentation per Annex XI, a copyright compliance policy, and training data provenance records.
- Review the GPAI Code of Practice. The Code of Practice published by the EU AI Office is the closest thing to a compliance manual available. Use it as your starting framework for GPAI obligations.
- Assess whether your system qualifies as high-risk under Annex III. If your AI is used for biometric identification, critical infrastructure, education, employment, credit, law enforcement, migration, or justice, map your compliance timeline to August 2, 2026.
- Build your compliance program to the stricter standard. If you are subject to both TRAIGA and the EU AI Act, build to EU AI Act requirements. TRAIGA's obligations are generally narrower, and compliance with the EU framework will satisfy most TRAIGA requirements.
- Align with the NIST AI RMF. Both TRAIGA's safe harbor and the EU AI Act's risk management requirements (Article 9) map to the NIST AI Risk Management Framework. NIST alignment is the single highest-value compliance investment for multi-jurisdiction AI governance.
- Engage counsel for an EU AI Act compliance assessment. The penalties for non-compliance — up to 7% of global turnover for prohibited practices — make the cost of a proactive assessment trivial by comparison. We help Texas startups build AI compliance programs that satisfy TRAIGA, the EU AI Act, and the emerging multi-jurisdiction AI regulatory landscape simultaneously.
The EU AI Act is not a future risk for US companies. Its prohibited practices ban has been enforceable since February 2025. Its GPAI model obligations have been in force since August 2025. The August 2026 deadline for high-risk AI systems is the next checkpoint in an enforcement timeline that is already running. Texas startups that build their AI compliance programs now — grounded in NIST AI RMF alignment and designed to satisfy the strictest applicable standard — will navigate this landscape with confidence. Startups that wait for an enforcement letter from the AI Office will discover that the cost of building compliance under regulatory pressure is measured in penalties, not preparation time.