Does the EU AI Act apply to a business outside the EU? It can, and that surprises people. The Act reaches providers and deployers outside the EU where the system is placed on the EU market, or where its output is used in the EU. Selling to EU customers, or running a tool whose results land with someone in the EU, is enough to be in scope.
Where this actually stands
Most of the AI Act has been in application since 2 August 2026, and enforcement began on that date. The part everyone was bracing for — the obligations on high-risk AI systems — did not arrive with it. It was deferred, deliberately and formally, a week before it was due.
The dates
| Date | What applies |
|---|---|
| 1 August 2024 | The Act entered into force. |
| 2 February 2025 | Definitions, AI literacy duties, and the outright prohibitions. |
| 2 August 2025 | Rules for general-purpose AI models; national governance and competent authorities. |
| 2 August 2026 | The majority of the Act applies and enforcement starts, including the transparency rules. |
| 2 December 2026 | End of the four-month transition for marking synthetic content, for systems already on the market before 2 August 2026. The European Commission also places the new prohibitions on this date. See below. |
| 2 August 2027 | Each Member State should have at least one AI regulatory sandbox running. |
| 2 December 2027 | Obligations for stand-alone high-risk systems (Annex III). Moved from 2 August 2026. |
| 2 August 2028 | Obligations for high-risk AI embedded in regulated products (Annex I). Moved from 2 August 2026. |
What changed in July 2026
Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 — the instrument generally called the Digital Omnibus on AI — was published in the Official Journal, L series 2026/1744, on 24 July 2026 and entered into force on 27 July 2026. It amended the AI Act and moved the high-risk deadlines: stand-alone high-risk systems under Annex III went from 2 August 2026 to 2 December 2027, and high-risk AI embedded in regulated products under Annex I went from 2 August 2026 to 2 August 2028.
Two things are worth being clear about. Deferred is not cancelled. The obligations are unchanged in substance; only the date moved. And the rest of the Act was not deferred — the prohibitions, the general-purpose AI rules, the transparency duties and the enforcement machinery are all live now.
If you read guidance on the AI Act written before late July 2026 — and a great deal of what is currently online was — it will tell you high-risk obligations bite on 2 August 2026. That is no longer correct.
What arrives on 2 December 2026
Two things, and they reach that date differently. First, the Article 50(2) transition. The Digital Omnibus gives providers who had already placed a generative AI system on the market before 2 August 2026 a four-month transitional period to meet the synthetic-content marking obligations. Four months from 2 August 2026 is 2 December 2026. Anything placed on the market on or after 2 August 2026 had to comply from the outset. Note that the Regulation states the four-month period rather than the calendar date; the date is the arithmetic.
Second, two new prohibitions, added to Article 5 of the AI Act. One covers AI systems that generate or manipulate realistic intimate imagery of an identifiable person without their explicit consent. The other covers AI systems that generate or manipulate child sexual abuse material within the meaning of Directive 2011/93/EU. The European Commission's own implementation timeline places both at 2 December 2026. We have verified the prohibitions themselves in the Official Journal text; the 2 December date for them we take from the Commission timeline rather than from the Regulation, which does not state that calendar date.
In plain terms, if you run or resell a tool that generates images, audio, video or text, the machine-readable marking of that output is the obligation with a December date on it.
What a small business should actually do
- Work out whether you are in scope at all. Most small businesses outside the EU are not. Selling into the EU, or producing output that is used there, is what puts you in.
- Know whether you are a provider or a deployer. Building or rebranding an AI system carries far heavier duties than using one. Most small businesses are deployers.
- Do not start a high-risk compliance programme on the assumption it was due in August 2026. It was not; you have until December 2027 or August 2028 depending on the category. Use the time rather than the panic.
- Treat AI literacy as already live. That duty has applied since February 2025 and is the one most often missed, because it sounds soft and is not.
- If you generate synthetic content, look at marking now. That is the obligation with the nearest deadline.
Sources
- Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI). Official Journal, L series 2026/1744, 24 July 2026. Read directly on EUR-Lex.
- Regulation (EU) 2024/1689 (the AI Act), as amended.
- European Commission, AI Act Service Desk — implementation timeline. Used for the 2 December 2026 date attached to the new prohibitions, which the Regulation itself does not state as a calendar date.
- Verified against the Official Journal text on 27 August 2026. The application dates in this Act have already been amended once, in July 2026; we monitor the Commission timeline for further change.
This page describes a regulation, not your situation, and it is not legal advice. If you think you may be in scope, the question of provider versus deployer is the one worth paying a lawyer to answer.
