EU AI Act Compliance for US Companies: What In-House Counsel Must Do Now

The EU AI Act has extraterritorial reach under Article 2, meaning any US company whose AI outputs are used in the EU must comply with prohibited practices, GPAI transparency, conformity assessments, CE marking, and penalties before the deadlines hit.

EU AI Act Compliance for US Companies: What In-House Counsel Must Do Now
Loading AudioNative Player...

If your company builds, sells, or deploys AI systems and has any customers or users in the European Union, the EU AI Act applies to you — regardless of where you are headquartered. That is not a hypothetical. Regulation (EU) 2024/1689, formally known as the EU Artificial Intelligence Act, carries explicit extraterritorial reach under Article 2, which extends compliance obligations to providers and deployers established in third countries whenever the output of their AI systems is used in the EU.

For in-house counsel at US companies, this means the AI Act is not a European problem you can delegate to your EU subsidiary's outside counsel. The obligations are already in force for prohibited practices and general-purpose AI (GPAI) model transparency, and the high-risk system requirements — including conformity assessments and CE marking — are approaching faster than most legal teams realize. If you have been tracking Colorado's AI Act (SB 26-189) or Texas's TRAIGA, the EU AI Act is the regulation with the broadest cross-border impact of all — and the one most likely to reshape your product roadmap.

This guide breaks down what your company must do under each tier of the AI Act's risk-based framework, the enforcement timeline you need to plan against, and the penalties for getting it wrong.

Why Article 2 Matters: The Extraterritorial Reach Provision

Article 2 of the AI Act establishes three jurisdictional hooks, and at least two of them capture US companies directly. Article 2(1)(a) applies the Act to providers placing AI systems on the EU market or putting them into service in the EU, "irrespective of whether those providers are established or located within the Union or in a third country." Article 2(1)(c) extends the Act to providers and deployers of AI systems established in third countries where the output produced by the system is used in the EU — an output-based jurisdictional test that sweeps in US companies whose AI-generated results are consumed by EU-based users or entities, even if the system itself is never physically deployed in Europe.

As the law firm William Fry explains in its practical guide to the AI Act's extraterritorial reach, this output-based jurisdiction is "a key aspect of the AI Act's extraterritorial scope." The practical implication: if your US-built AI recruiting tool screens candidates for an EU client, or your credit-scoring model outputs decisions that affect EU consumers, you are subject to the AI Act.

Third-country providers of high-risk AI systems must also appoint an authorised representative established in the EU (Article 22), who is responsible for verifying the EU declaration of conformity, maintaining technical documentation for ten years, and cooperating with EU competent authorities. Similarly, providers of GPAI models established outside the EU must appoint an EU authorised representative under Article 54. There is no workaround: if you want EU market access, you need a compliance presence in the EU.

Prohibited AI Practices: Already in Force Since February 2, 2025

The first enforcement deadline has already passed. As of February 2, 2025, Article 5's ban on prohibited AI practices is fully applicable. The European Commission published its Guidelines on Prohibited AI Practices on February 4, 2025, providing legal explanations and practical examples to help stakeholders understand which AI uses are categorically banned.

The prohibited practices under Article 5 include:

  • Subliminal or manipulative techniques that materially distort behavior in a way likely to cause significant harm;
  • Exploitation of vulnerabilities of specific groups (age, disability, socioeconomic status) to distort behavior;
  • Social scoring by public authorities — evaluating or classifying people based on social behavior over time;
  • Real-time remote biometric identification in publicly accessible spaces, with narrow exceptions for law enforcement;
  • Untargeted facial scraping to build or expand facial recognition databases;
  • Emotion recognition in workplaces and educational institutions;
  • Biometric categorization inferring sensitive attributes (race, religion, sexual orientation);
  • Social scoring by private actors in certain contexts;
  • Predictive policing based solely on profiling;
  • Untargeted scraping of facial images from the internet or CCTV.

These prohibitions apply to both providers and deployers. If any AI system in your company's portfolio touches these use cases and reaches EU users, you must cease or modify that use immediately. The EU Commission's guidelines are non-binding but reflect the Commission's interpretation — and enforcement is already live.

GPAI Model Transparency Duties: In Force Since August 2, 2025

For companies that develop or fine-tune large language models or other general-purpose AI models, the second enforcement milestone has also passed. Since August 2, 2025, Chapter V of the AI Act imposes obligations on all GPAI model providers under Article 53. These obligations apply regardless of where the model was trained or where the provider is headquartered — a point reinforced by Recital 106, which stipulates that GPAI providers must comply with EU copyright law no matter where training takes place.

Under Article 53, all GPAI model providers must:

  • Maintain technical documentation about the model, including training methodology, data sources, and testing results;
  • Provide information and documentation to downstream AI system providers who intend to integrate the GPAI model, so those providers can comply with their own AI Act obligations;
  • Comply with EU copyright law, including respecting text and data mining opt-outs under EU law;
  • Publish a publicly available summary of the content used to train the model.

For models classified as having systemic risk — defined under Article 51 as models trained with more than 10²⁵ FLOPs of compute — additional obligations apply under Article 55, including adversarial testing, incident reporting, and cybersecurity measures. The AI Office within the European Commission oversees GPAI compliance and can request documentation, conduct evaluations, and impose corrective measures.

Additionally, Article 50's transparency obligations for AI-generated content have been in force since August 2, 2025. Providers of GPAI systems that generate synthetic audio, video, images, or text must ensure their outputs are marked as AI-generated. Deployers of these systems must disclose when content is AI-generated to the people exposed to it.

High-Risk AI Systems: Conformity Assessments and CE Marking

The most resource-intensive obligations under the AI Act apply to high-risk AI systems — those listed in Annex III (standalone systems) and Annex I (AI components embedded in regulated products). These include AI systems used in recruitment and hiring, creditworthiness assessment, biometric identification, critical infrastructure management, education and vocational training, law enforcement, migration and border control, and the administration of justice.

If your company develops AI in any of these areas, you will need to complete a conformity assessment, implement a quality management system (QMS), compile technical documentation, register in the EU AI database, and affix CE marking before placing the system on the EU market. For a detailed walkthrough of which systems qualify as high-risk, see our companion article on classifying high-risk AI systems under the EU AI Act.

The High-Risk Requirements (Articles 9–15)

High-risk AI system providers must satisfy a bundle of technical and governance requirements:

  • Risk management system (Article 9) — a continuous, iterative process to identify, estimate, and evaluate risks, then deploy mitigation measures;
  • Data and data governance (Article 10) — training, validation, and testing datasets must meet quality criteria, including relevance, representativeness, and freedom from errors;
  • Technical documentation (Article 11) — maintained before the system enters the market and kept current throughout its lifecycle;
  • Record-keeping and logging (Article 12) — automatic event logs sufficient to ensure traceability;
  • Transparency to deployers (Article 13) — instructions for use covering system capabilities, limitations, and human oversight measures;
  • Human oversight (Article 14) — designed to be overseen by natural persons during the system's use;
  • Accuracy, robustness, and cybersecurity (Article 15) — systems must achieve appropriate performance levels and be resilient to errors, faults, and attacks.

Conformity Assessment and CE Marking (Articles 43 and 48)

Before placing a high-risk AI system on the EU market, the provider must complete a conformity assessment. For most Annex III systems, this involves an internal control procedure combined with a quality management system assessment. However, systems used for biometric identification or those falling under certain safety legislation require assessment by a notified body — an independent, EU-accredited conformity assessment body. Once conformity is demonstrated, the provider draws up an EU declaration of conformity (Article 47) and affixes the CE marking (Article 48), signaling compliance with the Act's requirements.

Updated Timeline: The 2026 Digital Omnibus Extension

Originally, the high-risk AI system obligations were set to apply on August 2, 2026. However, the 2026 Digital Omnibus package extended these deadlines. According to the EU AI Act compliance deadline tracker, the revised timeline is:

  • December 2, 2027 — High-risk AI systems under Annex III (standalone systems such as recruitment AI, credit scoring, and biometric categorization);
  • August 2, 2028 — High-risk AI components embedded in Annex I regulated products (medical devices, machinery, aviation, toys).

If your team was planning around the original August 2026 date, you should read our earlier analysis of the deadline extension — but do not treat the extension as breathing room. The conformity assessment, QMS implementation, technical documentation, and EU database registration typically require 12–24 months of preparation, meaning organizations targeting the December 2027 deadline should have begun scoping and gap assessment in 2026.

Enforcement and Penalties: What Non-Compliance Costs

The AI Act's penalty regime under Article 99 is modeled on GDPR but is arguably more severe in its maximum exposure. The fines are calculated as the greater of a fixed amount or a percentage of the company's global annual turnover for the preceding financial year:

  • Prohibited practice violations (Article 5) — up to €35 million or 7% of global annual turnover, whichever is higher;
  • Other obligations violations (including high-risk system requirements, GPAI model obligations, and transparency duties) — up to €15 million or 3% of global annual turnover, whichever is higher;
  • Supplying incorrect, incomplete, or misleading information to notified bodies or competent authorities — up to €7.5 million or 1% of global annual turnover, whichever is higher.

For SMEs and startups, the fines are capped at the lower of the fixed amount or the applicable percentage. Market surveillance authorities in each EU member state are responsible for enforcement, with the AI Office handling GPAI model oversight directly. Companies can also face temporary or permanent bans on placing non-compliant AI systems on the EU market, and withdrawal of CE marking.

Practical Compliance Steps for In-House Counsel

Given the phased enforcement timeline, in-house counsel should prioritize compliance work in the following order:

1. Conduct a Prohibited-Practice Audit Now

Article 5 is already in force. Review every AI system your company provides or deploys — including those used internally — against the ten prohibited practice categories. If any use case touches social scoring, untargeted facial scraping, emotion recognition in workplaces, or real-time biometric identification, you need to remediate immediately.

2. Inventory Your GPAI Model Obligations

If your company develops or fine-tunes foundation models, confirm you have technical documentation, a training data summary, and a copyright compliance review in place. If you integrate third-party GPAI models (for example, through API calls to large language models), verify that your upstream providers have published their training data summaries and that you have the information you need to fulfill your own downstream obligations as a system provider.

3. Classify Your AI Systems Against Annex III

Map every AI system in your portfolio against the Annex III high-risk categories. For systems that qualify, begin the conformity assessment process immediately — it involves risk management documentation, data governance reviews, technical documentation, and potentially notified body engagement. The December 2027 deadline for standalone Annex III systems will arrive quickly for organizations that have not started.

4. Appoint an EU Authorised Representative

If you are a third-country provider of high-risk AI systems or GPAI models, you must appoint an authorised representative established in the EU before placing your products on the EU market. This is a legal requirement, not a best practice, and your authorised representative will be the primary point of contact for EU enforcement authorities.

5. Build a Cross-Border Compliance Strategy

The EU AI Act is not the only AI regulation your company faces. US state laws like Colorado SB 26-189 and Texas TRAIGA impose their own transparency, risk assessment, and governance requirements. Rather than building separate compliance programs for each jurisdiction, design a unified framework that satisfies the strictest applicable standard — which, for most US companies with EU exposure, will be the AI Act.

Actionable Next Steps

The prohibited practice ban is enforceable today. GPAI model transparency rules are enforceable today. The high-risk system obligations, while extended to December 2027 for Annex III systems, require lead time measured in years, not months. Here is what in-house counsel should do this quarter:

  • Run a prohibited-practice gap analysis across your entire AI inventory, including vendor-provided systems;
  • Document your GPAI model compliance posture — technical documentation, training data summaries, and copyright compliance reviews;
  • Begin Annex III classification for all customer-facing AI systems, and scope the conformity assessment workload;
  • Identify and retain an EU authorised representative if you are a provider of high-risk systems or GPAI models;
  • Brief your board and product leadership on the AI Act's extraterritorial reach and the financial exposure under Article 99's penalty regime.

The EU AI Act is not a regulation you can wait out. Its obligations are already binding, its penalties are among the most severe in any technology regulation worldwide, and its reach extends to any US company whose AI outputs touch the EU market. The companies that start compliance work now will avoid the scramble — and the fines — that await those that do not.

Need help building an EU AI Act compliance program tailored to your company's AI portfolio? Our team works with in-house counsel to map obligations, scope conformity assessments, and design cross-border compliance frameworks.

Book a consultation