The European Union's AI Act reached a major milestone on August 2, 2026. The Annex III high-risk provisions became binding, moving the regulation from a planning exercise into an active compliance obligation. For companies that assumed this was a European problem, the timing is a good reason to reconsider. The Act reaches well beyond EU borders, and US subsidiaries of French-owned businesses are squarely inside its scope.
The EU AI Act applies based on where an AI system's output is used, not where the system was built, hosted, or trained. If a US entity runs an AI tool that affects EU residents in any way, the Act applies. There is no requirement for a European office, European staff, or even an intentional targeting of EU customers.
This catches companies off guard because most US compliance planning treats European law as relevant only to European entities. A US-based hiring platform that screens candidates who happen to include EU nationals falls under this law. So does a credit scoring model that processes applications from EU-based customers, or an insurance underwriting tool that touches EU policyholders through a group structure. Businesses that operate as the US arm of a French parent company are especially exposed, since data, staff, and customers often move across both sides of the relationship.
Before this date, the EU AI Act's prohibited practices provisions and AI literacy requirements were already active, dating back to February 2025. What changed on August 2, 2026 is the enforcement of high-risk system obligations under Annex III. These cover AI used in employment decisions, credit and insurance access, education, biometric identification, and several other categories tied to essential services.
Companies operating high-risk systems in these categories must now complete a conformity assessment, prepare detailed technical documentation, maintain a risk management system for the AI system's full lifecycle, and register the system in the EU AI Act database. None of these are one-time tasks. They require ongoing monitoring and updated records as the system changes.
The penalties are designed to get attention. Noncompliance can bring fines of up to 35 million euros or 7 percent of global annual turnover, whichever is higher. Regulators are not waiting for a grace period to pass before acting. Market surveillance authorities in EU member states now have the standing to investigate and penalize noncompliant systems.
One of the harder parts of this law is not the penalty structure. It is figuring out which systems actually qualify as high-risk in the first place. Some categories are explicit: credit scoring, patient triage tools, and employment screening are named directly in Annex III. Others are excluded just as clearly, such as fraud detection and algorithmic trading systems used purely for internal risk management.
A meaningful share of enterprise AI systems fall into neither category cleanly. When a system's classification is ambiguous, the safer and often cheaper path is to build to the higher compliance standard rather than spend resources arguing for an exemption that may not hold up under review.
The most useful first step is an honest inventory. List every AI system currently in production, note what decisions it makes or influences, and identify whether any output could plausibly reach an EU resident through customers, employees, applicants, or partners. This inventory becomes the foundation for everything else.
From there, prioritize systems that touch employment, credit, insurance, or biometric data, since these carry the clearest high-risk designation. For each one, confirm whether the company is acting as a provider or a deployer under the Act. A company that builds and sells an AI system is typically a provider. A company that licenses a third-party AI tool and uses it internally without significant modification is usually a deployer, though it still carries real obligations around monitoring and incident reporting.
Documentation should not be treated as an afterthought created for a future audit. Technical files, risk assessments, and monitoring records are easier to produce when they are built alongside the system rather than reconstructed after the fact. Companies that wait until a regulator asks are usually the ones that struggle most.
The EU AI Act has moved past the stage where companies could treat it as a future item on a roadmap. The high-risk obligations are enforceable now, and the extraterritorial reach of the law means a US office is not a shield. For French-owned businesses running operations in the United States, this is one of the clearest cases where compliance in one jurisdiction cannot be separated from the other. The businesses that treat this as connected, rather than as two separate regulatory environments, will spend far less time firefighting later.
If your company needs help mapping which AI systems in your US operations may fall under EU AI Act obligations, LENET can walk through the inventory and documentation process with you.