1
Nh
net human
Why Net Human Our work Insights
What we do
About Talk to us
Home Why Net Human Our work Insights FAQ
WHAT WE DO
Consultancy Certification The Atlas The Institute How certification works The Guardrails EU AI Act readiness
About Tamsin TALK TO US
← INSIGHTS
REGULATION · EU AI ACT

Does the EU AI Act apply to US companies? Usually, and Article 50 already bites

Two things get missed. The Act follows the deployment rather than the head office, and the delay everyone heard about in the Omnibus was not this part of it.

TAMSIN DEASEY-WEINSTEIN19 AUGUST 20266 MIN READ

The question comes up on most first calls, usually phrased as a hope: we are a US business, so this is a European problem. It is not. The EU AI Act applies to providers, deployers, importers and distributors that place AI on the EU market, and to those whose AI outputs are used inside the European Union. You can be in scope with no EU entity, no EU office and no EU subsidiary.

The practical test is not where you are incorporated. It is where the output lands. If your support assistant answers a customer in Dublin, if your recruitment screening reads a CV from Lisbon, if your internal copilot drafts a letter that a colleague in Amsterdam sends — the output landed in the EU.

Obligations follow the deployment, not the head office.

The delay you heard about was not this

In 2026 the Digital Omnibus package pushed the Annex III high-risk compliance timeline back to December 2027, and a lot of boards filed the whole Act under later. Article 50 was left out of that deferral. Its transparency duties applied on schedule from 2 August 2026, and national market surveillance authorities can enforce them from that date.

One narrow grace period does exist: providers of generative systems already on the EU market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking and detection obligation. That is the only runway, it is provider-side, and it does not postpone any deployer duty. Content generated before August does not have to be labelled retroactively, though the Commission encourages it.

What Article 50 actually requires

FOUR SITUATIONS, TWO ROLES
01
Systems that interact with people. Providers must make sure a person is told they are dealing with an AI system, unless it is already obvious. Chatbots, voice assistants, agents.
02
Synthetic content. Providers of systems generating audio, image, video or text must mark the output in a machine-readable format so it can be detected as AI-generated.
03
Deepfakes and public-interest text. Deployers must disclose manipulated media, and AI-generated text published to inform the public on matters of public interest.
04
Emotion recognition and biometric categorisation. Deployers must inform the people subject to them.

Two features of this article catch people out. The obligations are not limited to high-risk systems — they attach to the situation, not the risk tier, so an ordinary customer service bot is in scope while sitting nowhere near Annex III. And the disclosure has to be clear and given at the point of first interaction, not buried in terms of service that nobody opens.

The exposure is not nominal. Breaching the transparency rules carries fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher.

What to do in the next fortnight

  • Inventory every AI system that speaks to a human, generates content, or infers something about a person. Most organisations find more than they expected, because procurement bought some of them.
  • For each one, write down whether you are the provider or the deployer. The obligations differ, and the answer is often both.
  • Check the disclosure a real user sees at first contact — not the policy page, the actual first screen or first sentence.
  • Ask your vendors, in writing, whether their generative output is marked in a machine-readable format, and when. Their 2 December date is your problem too.

None of that requires a legal opinion to begin. It requires somebody to own the list.

The part that is not compliance

Guardrail 05 of the Net Human Standard says: you always know when it is a machine. It was written before the deadline and it is not a restatement of Article 50 — it goes further, and treats disclosure as a point of pride rather than a box. Nobody should have to guess whether the voice, the tutor, the carer or the colleague is human.

Which is the more useful way to run this project. If you approach Article 50 as paperwork, you will do it once, badly, and again next year. If you approach it as a statement about how you treat people, the paperwork falls out of the design — and you get to say something your competitors cannot.

This is general information about the EU AI Act, not legal advice on your specific deployments. Written 19 August 2026; the Commission adopted its Article 50 guidelines on 20 July 2026 and the Code of Practice on Transparency of AI-Generated Content remains a live document.

IF THIS IS YOUR PROBLEM

If you cannot say which of your systems talk to people in the EU, that is the audit.

READ NEXT