
The European Union AI Act may be European law, but its reach extends far beyond the EU’s borders. Companies based in the United States that develop, deploy or sell AI systems may already fall within its scope, even if they do not consider themselves international businesses.
For risk managers and corporate leaders, the EU AI Act represents more than another compliance obligation. It introduces a new governance framework that treats AI systems much like regulated products, requiring organizations to evaluate risk, document intended uses, implement oversight controls and establish post-market monitoring systems to see how AI tools operate in the real world. It also establishes market surveillance authorities to investigate and identify non-compliance with the EU AI Act.
At the same time, companies must navigate an increasingly fragmented U.S. landscape of state privacy laws, sector-specific regulations and litigation exposure. The result is a growing governance gap between broad European regulation and narrower but highly prescriptive U.S. enforcement regimes.
The Compliance Clock Has Already Started
Parts of the EU AI Act are already in effect, including bans on certain prohibited AI activities and enforcement of new transparency requirements. Other obligations tied to “high-risk” AI systems were originally scheduled to take effect in August 2026 but have been postponed until December 2027. Companies should make use of this delay and take action now.
Most companies will need 12 to 24 months to build governance frameworks, conduct risk assessments, align documentation, update contracts and operationalize compliance processes across legal, cybersecurity, engineering and product teams. For organizations already integrating AI into customer-facing products, hiring tools, analytics systems or healthcare applications, the lead time may be longer.
Why “High-Risk” Classification Matters
The central question under the EU AI Act is whether an AI system qualifies as “high risk.” The law identifies two broad categories: AI systems tied to safety components in products or critical infrastructure; and AI systems used in specifically designated high-risk areas such as employment, education, healthcare, financial services, biometric processing and certain forms of behavioral or sentiment analysis.
If an AI system falls into one of these categories, the company faces significantly more extensive obligations. What makes the classification process especially important is that regulators will evaluate how a system can be used and how the company intends for it to be used. That difference has major implications for governance strategy.
For example, a company may develop an AI tool intended only for narrow internal workflow automation. However, if its marketing materials, customer documentation or sales practices suggest broader applications in healthcare, employment screening or financial decision-making, regulators may classify the system as high risk.
In practice, intended use is shaped by far more than technical design. Regulators are expected to evaluate product documentation, customer contracts, marketing and advertising materials, sales enablement language and demonstrated use cases. This means legal, compliance and product teams cannot operate independently. Governance decisions made in marketing or sales may directly affect regulatory exposure.
AI Governance is Becoming Operational Risk Management
One of the most important shifts introduced by the EU AI Act is that AI governance increasingly resembles product safety governance. For decades, manufacturers of products such as automobiles and medical devices have operated under structured risk management and quality management obligations. Companies assess foreseeable harms, test products, monitor performance, document safety controls and maintain oversight throughout the product lifecycle.
The EU AI Act applies many of those same principles to AI systems. For high-risk systems, organizations may be required to complete a conformity assessment evaluating whether they have implemented adequate governance controls. Depending on the system, assessments may be internal or involve third-party review. These assessments should examine whether organizations have implemented:
- Risk management systems
- High-quality training, validation and testing datasets
- Technical documentation
- Logging and recordkeeping capabilities
- Transparency mechanisms
- Human oversight controls
- Accuracy, robustness and cybersecurity safeguards
For many organizations, this represents a substantial operational shift. AI governance can no longer sit solely within legal or compliance departments. Product teams, cybersecurity personnel, data scientists, procurement groups and executives all become part of the governance process.
A Different Approach in the United States
Unlike the EU, the United States does not currently have a comprehensive federal AI law. Instead, companies face a growing patchwork of state privacy laws, sector-specific regulations and litigation exposure.
California comes closest to the EU model. Under the California Privacy Protection Agency (CPPA) regulations, businesses using automated decision-making technology for significant decisions affecting California consumers will face risk assessment obligations beginning January 1, 2027. Certification and direct reporting obligations to CPPA will follow, going into effect in 2028.
These rules apply to AI systems involved in areas such as:
- Employment or independent contracting opportunities or compensation
- Provision or denial of housing
- Provision or denial of healthcare
- Provision or denial of financial services or lending services
- Education enrollment or opportunities
While narrower than the EU AI Act, California’s approach requires operational requirements many companies will eventually need anyway, including risk assessments and governance documentation. Other states are taking more targeted approaches. Healthcare AI, insurance AI, companion chatbots and children’s safety are becoming major legislative focus areas. In some sectors, state requirements may be even more prescriptive than the EU framework because they regulate highly specific disclosures, design features or operational practices.
This creates a difficult governance problem for multinational organizations. Companies must simultaneously prepare for broad EU governance obligations while adapting products to narrower but highly detailed state-level rules in the United States.
Rapidly Expanding Transparency Requirements
One area where EU and U.S. approaches increasingly overlap is transparency. Article 50 of the EU AI Act imposes transparency obligations on general-purpose AI systems, including systems that generate synthetic text, images, audio or video. Users generally must be informed when they are interacting with AI-generated content. These transparency obligations also apply to emotion recognition or a biometric categorization system.
Similar requirements are emerging in the United States. California and New York are already considering or implementing laws governing AI chatbots, healthcare AI and companion bots, particularly those interacting with minors. These laws often require companies to clearly disclose that users are interacting with AI systems and may impose additional safeguards for vulnerable populations. Illinois and Colorado already have existing biometric legislation with significant transparency obligations for their residents, and these existing laws apply to AI systems that process biometric data.
Litigation Risk May Come Before Regulation
One critical difference between Europe and the United States is how enforcement risk develops. The EU AI Act follows a structured regulatory model. Companies can generally evaluate the law, assess their systems and implement compliance frameworks against defined standards. In the United States, businesses are increasingly encountering litigation and regulatory action before comprehensive regulation exists.
Companies deploying AI-powered chatbots, healthcare AI and customer service agents are already facing lawsuits under state wiretapping and recording statutes based on allegations that conversations were recorded or intercepted without adequate consent. In addition, state regulators in California, Texas and Florida have launched investigations into these companies based on existing state laws governing false and misleading advertising and unfair trade practices.
This risk is particularly significant for organizations rapidly implementing AI into customer-facing environments without fully evaluating state privacy and consent laws. As a result, U.S. organizations cannot afford to treat AI governance solely as a future compliance issue. In many cases, the litigation exposure is already present today.
Governance Cannot Wait for Regulatory Certainty
One of the biggest mistakes companies can make is waiting for perfect clarity before building governance programs. The EU AI Act remains in flux and U.S. state laws continue to evolve rapidly. Sector-specific requirements are emerging at different speeds across healthcare, insurance, education and consumer technology. But the absence of final regulatory certainty does not eliminate operational risk.
Companies integrating AI into products, workflows or customer interactions should already be building governance structures that include: cross-functional AI governance teams; risk assessment processes; privacy and security review; documentation standards; product-use restrictions; transparency protocols; vendor oversight procedures; litigation risk review and product lifecycle monitoring.
Organizations that begin building these governance programs now will likely be better positioned to adapt as regulations evolve. Those that wait may find themselves trying to retrofit governance into products already deployed globally. The EU AI Act is not simply a European compliance issue—it is an early indicator of how governments and regulators increasingly expect companies to manage AI risk at scale.
For U.S. businesses, the question is no longer whether AI governance obligations are coming. The question is whether governance frameworks are developing quickly enough to keep pace with how rapidly AI is already being deployed.