The EU AI Act became law back in 2024, but the date that actually matters for most businesses is August 2, 2026 — the point at which enforcement power fully activates for high-risk AI systems and transparency obligations. Until now, most of the Act's teeth have been limited to a narrow set of prohibited practices. That changes this summer, and it changes for any company doing business in Europe, not just companies headquartered there.
“High-risk” is a specific legal category, not a vibe — it covers AI used in critical infrastructure, employment and hiring decisions, education, essential services, law enforcement, and immigration. If a business uses an AI tool to screen resumes, score creditworthiness, or make decisions about access to a service, there's a real chance it qualifies. Penalties for noncompliance run up to €35 million or 7% of global annual revenue, whichever is larger.
The complicating factor is that individual EU member states are layering their own additional requirements on top of the Act, and the U.S. has taken the opposite approach entirely — no comprehensive federal AI law, an administration actively trying to preempt state-level rules, and in the meantime 48 different state laws creating their own patchwork. A business operating in both markets is, in practice, complying with two philosophies of AI regulation at once.
None of this requires panic if you're a small or midsize business without EU operations. But if any part of your AI usage touches European customers, employees, or markets, this is the summer to have someone competent classify your systems against the Act's risk tiers — not after a regulator asks first.
Sources
- Foley & Lardner, "Compliance and Enforcement in Global AI Regulation"
- Kiteworks, "AI Regulation 2026: 10 Critical Compliance Risks"
- Tredence, "EU AI Act 2026 Compliance Guide for US Companies"