
EU AI Act Enforcement Has Started: What U.S. Boards Must Do Before December
EU AI Act enforcement is live. U.S. boards have until December 2 to act—regardless of where your business is incorporated. Here's what you must do now.
Your company's AI products don't touch EU users? The European AI Office doesn't care where your lawyers say your business lives. As of August 2, 2026, the EU AI Act's full enforcement powers are live, the AI Office has authority to fine GPAI model providers, and the transparency clock is ticking toward a December 2 hard deadline that most U.S. boards haven't discussed yet. The companies getting this right are already building their action plans. The ones getting it wrong will be reading enforcement notices.
The urgency isn't theoretical.
In March 2026, the EU AI Office issued landmark fines totaling €85 million for opaque AI recruitment, unregistered biometric surveillance, and credit scoring without explanation rights.
Enforcement infrastructure is operational. The question boards need to ask isn't "does this law apply to us?" It's "can we prove we've done the work?"
The Act applies to providers, deployers, importers, and distributors of AI systems placed on the EU market or whose output is used in the EU, regardless of where the company is headquartered. This extraterritorial reach captures major U.S. and global tech firms.
If your SaaS platform serves European customers, your AI copilot processes data on behalf of EU employees, or your foundation model API routes requests to EU endpoints, you are in scope. Full stop.
The Regulatory Reality Your Board Needs to Understand
The EU AI Act classifies AI systems into four risk tiers: unacceptable, high, limited, and minimal, with fines up to €35 million or 7% of global annual turnover under Article 99.
To put that in board-level terms: a company generating $5 billion in global revenue faces a potential $350 million fine for a single enforcement action. That is a material event requiring SEC disclosure and triggering D&O scrutiny.
The penalty structure is genuinely punitive: up to 7% of global annual turnover exceeds even GDPR's maximum 4%.
U.S. boards that survived GDPR compliance cycles with minimal disruption should not assume the same playbook applies here. The AI Act's risk tiering, technical documentation requirements, and systemic risk obligations for GPAI models go significantly further.
Across all sectors, only 13% of companies have any formal AI governance framework at all.
That statistic explains why enforcement actions will find easy targets. Companies without documented AI inventories, risk classifications, or governance policies cannot demonstrate due diligence under any regulatory interpretation. The enforcement infrastructure is ready. Most companies are not.
Building AI governance after an enforcement notice is like buying insurance after the house burns down. The EU AI Office can request technical documentation, issue corrective measures, and impose fines. Your board needs documented evidence of governance maturity before that request arrives, not a sprint plan to create it afterward.
What "Full Enforcement" Actually Means Right Now
Three distinct enforcement tracks are running simultaneously, and each carries its own obligations and timeline.
The European Commission can now enforce the AI Act's general-purpose AI model obligations, including through fines. The underlying GPAI obligations started on August 2, 2025, while the Commission's full enforcement powers became applicable on August 2, 2026.
From August 2, 2026, the AI Office and authorities of Member States are responsible for implementing, supervising, and enforcing the AI Act. The AI Office holds enforcement powers over GPAI models. It can request technical documentation, evaluate models, require corrective measures, and issue fines for non-compliance.
Providers of GPAI models with systemic risk face additional duties covering model evaluations, systemic risk assessment and mitigation, serious incident reporting, and cybersecurity protection.
| Obligation Track | Who It Affects | Status as of Sept 2026 | December 2026 Action Required |
|---|
| GPAI Model Rules (Chapter V) | Foundation model providers and deployers | Enforceable since Aug 2025; fines active Aug 2026 | Systemic risk evaluation submission to AI Office |
| Article 50 Transparency Duties | All generative AI deployers serving EU users | Active Aug 2, 2026 | Machine-readable watermarking by Dec 2, 2026 |
| High-Risk AI (Annex III) | Hiring, credit, healthcare, critical infrastructure AI | Deferred to Dec 2, 2027 | Gap assessment and documentation now |
| Prohibited Practices (Article 5) | Social scoring, biometric surveillance, manipulation | Enforceable since Feb 2025 | Screen existing AI systems immediately |
| GPAI Systemic Risk Models | Models exceeding 10²⁵ FLOP training compute | Active; AI Office evaluating now | Adversarial testing, incident reporting protocols |
The December 2 Watermarking Deadline: A Hard Technical Cliff
This is the deadline most U.S. enterprises are ignoring, and it is the one most likely to produce early enforcement actions.
Article 50 of the EU AI Act may affect more organizations than almost any other provision. It introduces transparency obligations on providers and deployers of certain AI systems, under which users must be informed when they are interacting with an AI system or where content is AI-generated.
Under the Digital Omnibus, generative AI systems already on the market before August 2, 2026 have until December 2, 2026 to meet the Article 50(2) machine-readable marking requirement. Systems placed on the market from August 2, 2026 onward must comply from that date.
The compliance window is not generous.
The provisional agreement reduced the Article 50 compliance window from six months to three.
Most enterprises have not completed an inventory of where generative AI produces outputs touching EU users, let alone commissioned watermarking implementation and testing.
Teams should map every output type, including text, synthetic voice, audio, images, video, and edited media. Watermarking, labeling, and disclosure are separate controls, so each one needs its own owner, test, and documentation path. Watermarks need real workflow testing after compression, editing, re-encoding, cropping, paraphrasing, storage, and platform upload.
That is months of technical work, not weeks.
Framework Alignment: What Structured Governance Looks Like
The companies best positioned to demonstrate compliance are those that mapped their AI systems against established governance frameworks before enforcement arrived. Three frameworks create the credible evidence layer regulators expect.
The EU AI Act, NIST AI RMF, and ISO 42001 form a single governance stack: regulation providing legal requirements, a framework providing risk management methodology, and a standard providing certifiable evidence.
The NIST AI Risk Management Framework structures governance across four functions: Govern, Map, Measure, and Manage. Each function maps directly to EU AI Act obligations. The Map function produces the AI system inventory the Act requires. The Measure function supports the technical evaluations GPAI systemic risk obligations demand. The Govern function creates the board-level accountability documentation that market surveillance authorities will request first.
ISO/IEC 42001:2023 provides the certifiable management system layer.
While certification does not automatically satisfy EU AI Act requirements, it demonstrates management system maturity that regulators evaluate. The crosswalk shows ISO 42001 covers significant portions of EU AI Act obligations for high-risk systems.
CISA's AI security guidance addresses the cybersecurity dimension that the EU AI Act specifically requires for GPAI systemic risk models, connecting AI governance to existing security program frameworks boards already understand.
An AI system register serves triple duty: it satisfies ISO 42001's Clause 8 requirements for operational planning, supports NIST AI RMF's Map and Govern functions, and provides the system inventory required for EU AI Act compliance.
Emerging Obligations Boards Should Track Now
The Brussels Effect Accelerates U.S. State Legislation
The "Brussels Effect" describes how the EU's regulatory power shapes global standards.
Colorado, Texas, and California have each advanced AI governance legislation modeled in part on the EU Act's risk-tiering approach. A board that builds EU AI Act compliance infrastructure this year gains structural alignment with the U.S. state requirements arriving in 2027 and 2028. Compliance built for one jurisdiction transfers; compliance neglected for both compounds.
GPAI Code of Practice Signing Creates Competitive Differentiation
The AI Office is developing codes of practice for GPAI model providers. These codes provide detailed guidance on how to meet the Chapter V obligations in practice. While not legally binding in themselves, compliance with approved codes of practice creates a presumption of conformity with the underlying regulatory requirements.
Companies that sign the GPAI Code of Practice shift the evidentiary burden toward regulators rather than themselves. Non-signatories face more frequent information requests and must demonstrate compliance independently.
Cybersecurity Integration Is Now Mandatory, Not Optional
The European Commission published its Action Plan on Cybersecurity and Artificial Intelligence on July 7, 2026. The plan connects AI security work with the AI Act, NIS2, the Cyber Resilience Act, DORA, and the Cyber Solidarity Act.
For U.S. companies with EU market exposure, this means AI governance programs cannot operate in isolation from existing cybersecurity programs. A vCISO-level security architecture review now must explicitly address AI system access controls, model testing, and adversarial testing alongside traditional security controls.
Board Readiness Assessment: Where Does Your Company Stand?
Before your next board meeting, your leadership team should be able to answer every item on this checklist with documented evidence, not verbal assurance.
AI System Inventory and Risk Classification
GPAI and Transparency Obligations
Governance and Board Evidence
Prohibited Practices Screening
If your team cannot check more than half of these items with documented evidence today, your organization has a governance gap with a regulatory deadline attached.
How I Help
My Secure AI Deployment service is built specifically for this moment. I conduct a structured AI system inventory across your entire technology stack, apply EU AI Act risk tier classification and NIST AI RMF alignment, implement access and model controls, and assess every third-party and vendor AI integration your organization relies on. The deliverable your board receives is documented governance evidence aligned to both the EU AI Act and NIST AI RMF, ready to present to regulators, auditors, and enterprise customers asking for AI compliance proof. For organizations facing the December 2 watermarking deadline specifically, I build the implementation plan, coordinate technical testing, and produce the documentation trail that demonstrates due diligence.
For boards facing the first pointed questions from institutional investors or audit committees about AI risk posture, my Board Advisory service translates technical AI governance gaps into quantified regulatory exposure that directors can act on. If your broader compliance program needs to integrate EU AI Act obligations alongside existing ISO 27001, SOC 2, or GDPR frameworks, I address that through compliance program design. And for organizations standing up AI governance programs from scratch, a Fractional CISO engagement provides the ongoing leadership to make governance operational rather than performative.
Adil Karam
Security & AI Governance Advisor
Helping organizations navigate security leadership and AI governance challenges.
Related Articles
Shadow AI Is Now Your Biggest Breach Risk: What the IBM 2026 Report Means for the Board
The EU AI Act Is Now Enforced: What Every Board Needs to Know About Real Fines and Transparency Obligations
AI Agent Sprawl: The Board Governance Crisis Your Org Chart Isn't Ready For
Ready to Put These Insights Into Action?
Whether you need secure AI deployment, security leadership, or compliance guidance, we can apply these strategies to your organization.