Skip to main content
CISSP-ISSAP · 20+ Years · #10 OnCon Icon, 2022
Back to BlogAI Governance
EU AI Act Enforcement Has Started: What U.S. Boards Must Do Before December

EU AI Act Enforcement Has Started: What U.S. Boards Must Do Before December

EU AI Act enforcement is live. U.S. boards have until December 2 to act—regardless of where your business is incorporated. Here's what you must do now.

September 12, 202610 min readBy Adil Karam

Your company's AI products don't touch EU users? The European AI Office doesn't care where your lawyers say your business lives. As of August 2, 2026, the EU AI Act's full enforcement powers are live, the AI Office has authority to fine GPAI model providers, and the transparency clock is ticking toward a December 2 hard deadline that most U.S. boards haven't discussed yet. The companies getting this right are already building their action plans. The ones getting it wrong will be reading enforcement notices.

The urgency isn't theoretical.

In March 2026, the EU AI Office issued landmark fines totaling €85 million for opaque AI recruitment, unregistered biometric surveillance, and credit scoring without explanation rights.

Enforcement infrastructure is operational. The question boards need to ask isn't "does this law apply to us?" It's "can we prove we've done the work?"

The Act applies to providers, deployers, importers, and distributors of AI systems placed on the EU market or whose output is used in the EU, regardless of where the company is headquartered. This extraterritorial reach captures major U.S. and global tech firms.

If your SaaS platform serves European customers, your AI copilot processes data on behalf of EU employees, or your foundation model API routes requests to EU endpoints, you are in scope. Full stop.

The Regulatory Reality Your Board Needs to Understand

The EU AI Act classifies AI systems into four risk tiers: unacceptable, high, limited, and minimal, with fines up to €35 million or 7% of global annual turnover under Article 99.

To put that in board-level terms: a company generating $5 billion in global revenue faces a potential $350 million fine for a single enforcement action. That is a material event requiring SEC disclosure and triggering D&O scrutiny.

The penalty structure is genuinely punitive: up to 7% of global annual turnover exceeds even GDPR's maximum 4%.

U.S. boards that survived GDPR compliance cycles with minimal disruption should not assume the same playbook applies here. The AI Act's risk tiering, technical documentation requirements, and systemic risk obligations for GPAI models go significantly further.

Across all sectors, only 13% of companies have any formal AI governance framework at all.

That statistic explains why enforcement actions will find easy targets. Companies without documented AI inventories, risk classifications, or governance policies cannot demonstrate due diligence under any regulatory interpretation. The enforcement infrastructure is ready. Most companies are not.

Building AI governance after an enforcement notice is like buying insurance after the house burns down. The EU AI Office can request technical documentation, issue corrective measures, and impose fines. Your board needs documented evidence of governance maturity before that request arrives, not a sprint plan to create it afterward.

What "Full Enforcement" Actually Means Right Now

Three distinct enforcement tracks are running simultaneously, and each carries its own obligations and timeline.

The European Commission can now enforce the AI Act's general-purpose AI model obligations, including through fines. The underlying GPAI obligations started on August 2, 2025, while the Commission's full enforcement powers became applicable on August 2, 2026.

From August 2, 2026, the AI Office and authorities of Member States are responsible for implementing, supervising, and enforcing the AI Act. The AI Office holds enforcement powers over GPAI models. It can request technical documentation, evaluate models, require corrective measures, and issue fines for non-compliance.

Providers of GPAI models with systemic risk face additional duties covering model evaluations, systemic risk assessment and mitigation, serious incident reporting, and cybersecurity protection.

Obligation TrackWho It AffectsStatus as of Sept 2026December 2026 Action Required
GPAI Model Rules (Chapter V)Foundation model providers and deployersEnforceable since Aug 2025; fines active Aug 2026Systemic risk evaluation submission to AI Office
Article 50 Transparency DutiesAll generative AI deployers serving EU usersActive Aug 2, 2026Machine-readable watermarking by Dec 2, 2026
High-Risk AI (Annex III)Hiring, credit, healthcare, critical infrastructure AIDeferred to Dec 2, 2027Gap assessment and documentation now
Prohibited Practices (Article 5)Social scoring, biometric surveillance, manipulationEnforceable since Feb 2025Screen existing AI systems immediately
GPAI Systemic Risk ModelsModels exceeding 10²⁵ FLOP training computeActive; AI Office evaluating nowAdversarial testing, incident reporting protocols

The December 2 Watermarking Deadline: A Hard Technical Cliff

This is the deadline most U.S. enterprises are ignoring, and it is the one most likely to produce early enforcement actions.

Article 50 of the EU AI Act may affect more organizations than almost any other provision. It introduces transparency obligations on providers and deployers of certain AI systems, under which users must be informed when they are interacting with an AI system or where content is AI-generated.

Under the Digital Omnibus, generative AI systems already on the market before August 2, 2026 have until December 2, 2026 to meet the Article 50(2) machine-readable marking requirement. Systems placed on the market from August 2, 2026 onward must comply from that date.

The compliance window is not generous.

The provisional agreement reduced the Article 50 compliance window from six months to three.

Most enterprises have not completed an inventory of where generative AI produces outputs touching EU users, let alone commissioned watermarking implementation and testing.

Teams should map every output type, including text, synthetic voice, audio, images, video, and edited media. Watermarking, labeling, and disclosure are separate controls, so each one needs its own owner, test, and documentation path. Watermarks need real workflow testing after compression, editing, re-encoding, cropping, paraphrasing, storage, and platform upload.

That is months of technical work, not weeks.

Framework Alignment: What Structured Governance Looks Like

The companies best positioned to demonstrate compliance are those that mapped their AI systems against established governance frameworks before enforcement arrived. Three frameworks create the credible evidence layer regulators expect.

The EU AI Act, NIST AI RMF, and ISO 42001 form a single governance stack: regulation providing legal requirements, a framework providing risk management methodology, and a standard providing certifiable evidence.

The NIST AI Risk Management Framework structures governance across four functions: Govern, Map, Measure, and Manage. Each function maps directly to EU AI Act obligations. The Map function produces the AI system inventory the Act requires. The Measure function supports the technical evaluations GPAI systemic risk obligations demand. The Govern function creates the board-level accountability documentation that market surveillance authorities will request first.

ISO/IEC 42001:2023 provides the certifiable management system layer.

While certification does not automatically satisfy EU AI Act requirements, it demonstrates management system maturity that regulators evaluate. The crosswalk shows ISO 42001 covers significant portions of EU AI Act obligations for high-risk systems.

CISA's AI security guidance addresses the cybersecurity dimension that the EU AI Act specifically requires for GPAI systemic risk models, connecting AI governance to existing security program frameworks boards already understand.

An AI system register serves triple duty: it satisfies ISO 42001's Clause 8 requirements for operational planning, supports NIST AI RMF's Map and Govern functions, and provides the system inventory required for EU AI Act compliance.

Emerging Obligations Boards Should Track Now

The Brussels Effect Accelerates U.S. State Legislation

The "Brussels Effect" describes how the EU's regulatory power shapes global standards.

Colorado, Texas, and California have each advanced AI governance legislation modeled in part on the EU Act's risk-tiering approach. A board that builds EU AI Act compliance infrastructure this year gains structural alignment with the U.S. state requirements arriving in 2027 and 2028. Compliance built for one jurisdiction transfers; compliance neglected for both compounds.

GPAI Code of Practice Signing Creates Competitive Differentiation

The AI Office is developing codes of practice for GPAI model providers. These codes provide detailed guidance on how to meet the Chapter V obligations in practice. While not legally binding in themselves, compliance with approved codes of practice creates a presumption of conformity with the underlying regulatory requirements.

Companies that sign the GPAI Code of Practice shift the evidentiary burden toward regulators rather than themselves. Non-signatories face more frequent information requests and must demonstrate compliance independently.

Cybersecurity Integration Is Now Mandatory, Not Optional

The European Commission published its Action Plan on Cybersecurity and Artificial Intelligence on July 7, 2026. The plan connects AI security work with the AI Act, NIS2, the Cyber Resilience Act, DORA, and the Cyber Solidarity Act.

For U.S. companies with EU market exposure, this means AI governance programs cannot operate in isolation from existing cybersecurity programs. A vCISO-level security architecture review now must explicitly address AI system access controls, model testing, and adversarial testing alongside traditional security controls.

Board Readiness Assessment: Where Does Your Company Stand?

Before your next board meeting, your leadership team should be able to answer every item on this checklist with documented evidence, not verbal assurance.

AI System Inventory and Risk Classification

  • [ ] Complete inventory of all AI systems in production, including third-party and embedded AI
  • [ ] Risk tier classification for each system against EU AI Act Annex I and Annex III categories
  • [ ] Identification of all GPAI models used via API, fine-tuning, or integration (GPT, Claude, Gemini, Llama, etc.)
  • [ ] Assessment of which systems produce outputs reaching EU users
  • GPAI and Transparency Obligations

  • [ ] Technical documentation maintained for all GPAI model deployments
  • [ ] Training data summary published or in preparation for applicable systems
  • [ ] Article 50 disclosure obligations implemented for AI-interaction and AI-generated content
  • [ ] Watermarking or machine-readable marking implementation plan with December 2, 2026 target date
  • [ ] Testing plan for watermark persistence across compression, cropping, and format conversion
  • Governance and Board Evidence

  • [ ] AI governance policy documented and board-approved
  • [ ] Named accountability roles for each AI system in inventory
  • [ ] NIST AI RMF alignment documented across Govern, Map, Measure, Manage functions
  • [ ] EU authorized representative appointed if required
  • [ ] Incident response protocol for AI-related serious incidents to AI Office
  • [ ] Board AI risk reporting cadence established, at minimum quarterly
  • Prohibited Practices Screening

  • [ ] All existing AI applications screened against Article 5 prohibited practices list
  • [ ] Social scoring, real-time biometric identification, and subliminal manipulation use cases formally excluded or documented
  • If your team cannot check more than half of these items with documented evidence today, your organization has a governance gap with a regulatory deadline attached.

    How I Help

    My Secure AI Deployment service is built specifically for this moment. I conduct a structured AI system inventory across your entire technology stack, apply EU AI Act risk tier classification and NIST AI RMF alignment, implement access and model controls, and assess every third-party and vendor AI integration your organization relies on. The deliverable your board receives is documented governance evidence aligned to both the EU AI Act and NIST AI RMF, ready to present to regulators, auditors, and enterprise customers asking for AI compliance proof. For organizations facing the December 2 watermarking deadline specifically, I build the implementation plan, coordinate technical testing, and produce the documentation trail that demonstrates due diligence.

    For boards facing the first pointed questions from institutional investors or audit committees about AI risk posture, my Board Advisory service translates technical AI governance gaps into quantified regulatory exposure that directors can act on. If your broader compliance program needs to integrate EU AI Act obligations alongside existing ISO 27001, SOC 2, or GDPR frameworks, I address that through compliance program design. And for organizations standing up AI governance programs from scratch, a Fractional CISO engagement provides the ongoing leadership to make governance operational rather than performative.

    See if I should be in the room

    #EU AI Act#AI Governance#Regulatory Compliance#GPAI#Board Oversight#AI Office
    PDFShare:

    Adil Karam

    Security & AI Governance Advisor

    Helping organizations navigate security leadership and AI governance challenges.

    Ready to Put These Insights Into Action?

    Whether you need secure AI deployment, security leadership, or compliance guidance, we can apply these strategies to your organization.