Guide

EU AI Act Compliance: What U.S. Enterprises Need to Know in 2026

EU AI Act Compliance: What U.S. Enterprises Need to Know in 2026
The EU AI Act is the world's first comprehensive AI regulation. Its high-risk provisions have not yet applied: Regulation (EU) 2026/1744 moved them to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems. What took effect in August 2025 was the general-purpose AI model regime, the governance provisions and the penalty regime. U.S. enterprises deploying AI systems that affect European citizens are subject to its requirements regardless of where the AI system is hosted. This guide covers the key obligations, compliance gaps, and how Smartflow maps to specific requirements.

Who Is Subject to the EU AI Act

The EU AI Act applies to any organization that places an AI system on the EU market or whose AI system's output is used in the EU. This includes U.S. financial institutions serving European clients, U.S. healthcare companies processing European patient data, U.S. technology companies deploying AI products in European markets, and U.S. enterprises with European employees using AI tools.

High-Risk System Requirements

High-risk systems face the most stringent requirements. In financial services, this includes AI used for creditworthiness assessment, risk pricing, and fraud detection. In healthcare: diagnosis, treatment recommendations, and patient triage. Obligations include:

  • Risk management system: Continuous identification, analysis, and mitigation of risks
  • Data governance: Training and testing datasets must meet quality criteria
  • Technical documentation: Comprehensive documentation of design, capabilities, and limitations
  • Record-keeping: Automatic logging of events throughout the AI system lifecycle
  • Transparency: Clear instructions for use including capabilities and limitations
  • Human oversight: Mechanisms enabling human oversight of AI operation
  • Accuracy and robustness: Appropriate levels of accuracy and cybersecurity

How Smartflow Maps to EU AI Act Requirements

  • Article 12 (Record-Keeping): VAS audit logs provide automatic, immutable logging of every AI interaction
  • Article 13 (Transparency): Maestro dashboard provides complete visibility into AI system usage
  • Article 14 (Human Oversight): Policy engine enables human-defined constraints. A high-severity action can be held pending human approval, and agent credentials carry the identity of the person who authorized them. Enforcement of agent identity is a setting you turn on rather than a default.
  • Article 15 (Accuracy and Robustness): AI firewall protects against prompt injection and adversarial inputs
  • Article 72 (Post-Market Monitoring): monitoring draws on the runtime record rather than a parallel process, and the Regulatory Examination Suite assembles documentation from it
  • Article 73 (Serious Incident Reporting): the same record supports the reporting clock, which starts when you become aware

The Compliance Gap

Most U.S. enterprises have addressed GDPR data protection but have not evaluated AI systems against EU AI Act obligations. The penalty framework mirrors GDPR: up to 35 million euros or 7% of global annual turnover. Compliance requires demonstrable governance infrastructure, not just documentation.

Craig Alberino
Craig Alberino
Craig Alberino is the Founder and CEO of APERION, which builds the runtime governance layer for AI agents in regulated enterprises. Inline policy enforcement and identity-bound audit, deployable on premises.

Put this in the path of your own agents.

Policy enforced inline between your agents and every model and tool they reach, with a record bound to the human who owns it.

Request a Demo Read the docs