The EU AI Act Playbook (1/3): Why It's the Global Baseline

Extraterritorial reach, GDPR overlap, and why regulators from California to Seoul are converging on this one law 

Key Takeaways

  • The EU AI Act reaches companies that have never set up an office in Europe. If your AI system’s output is used in the EU, or the system affects people located there, the obligations generally apply regardless of where you are incorporated.
  • Its real advantage is specificity. Most AI rules elsewhere state principles — be fair, be transparent, be accountable. The EU AI Act names the artefacts: a risk management system, data governance measures, technical documentation, automatic logging, human oversight, disclosure, content marking. Principles cannot be handed to an engineer. Requirements can.
  • It does not replace privacy law, it sits on top of it. GDPR governs what happens to personal data; the AI Act governs how the system itself is built, documented, and supervised — and it applies even when no personal data is involved.
  • Other jurisdictions are converging on the same shape rather than inventing new ones. South Korea’s AI Framework Act became fully operative in July 2026, imposing impact-assessment and documentation duties that track many of the same named categories as the EU’s approach.
  • The United States splits in two. Federally the direction is deregulatory — no comprehensive statute, and a preemption push Congress has so far declined to enact. But binding state duties are already in force in California, Texas, Illinois and Utah, and California deliberately moved its AI Transparency Act to 2 August 2026 to line up with the EU’s Article 50 date.
  • For a company building governance once and deploying globally, the EU AI Act is the most demanding specification available and therefore the most useful one to build against. Meeting it tends to satisfy the others; the reverse is rarely true.

1. The Question Behind the Question: Does This Even Apply to Us?

current AI regulation status in the EU, US, South Korea and Japan (illustrative summary, not an official classification)

Figure: current AI regulation status in the EU, US, South Korea and Japan
(illustrative summary, not an official classification)

When a US manufacturer, a Japanese logistics firm, or a Korean SaaS vendor first reads about the EU AI Act, the instinct is reasonable: this is European law, we are not European, next topic.

That instinct is wrong often enough to be expensive. The Act applies to providers who place AI systems on the EU market, to deployers established in the EU, and — critically — to providers and deployers located anywhere in the world where the output produced by the system is used in the EU. A recruitment screening tool run from Austin that evaluates candidates for a German subsidiary is in scope. A generative AI feature in a product sold to European customers is in scope. An internal AI assistant used by staff in your Amsterdam office is in scope.

The second reason to pay attention has nothing to do with jurisdiction. The EU AI Act has become the reference document that everyone else writes against — including your customers’ procurement teams, your enterprise buyers’ security questionnaires, and increasingly your own government. When a European client asks whether your product supports their Article 50 disclosure obligations or their Annex III documentation duties, the question arrives whether or not the law binds you directly.

This is the practical shape of what people call the Brussels effect. It is rarely a regulator that reaches you first. It is a customer contract, a vendor assessment questionnaire, or a partner asking you to warrant something you have never documented.

2. What the EU AI Act Actually Is

Regulation (EU) 2024/1689 is not a privacy law and not an ethics charter. Structurally it is closer to product safety legislation — the same family of thinking that governs medical devices and machinery — applied to software that makes or informs decisions.

It sorts AI systems into four tiers by the risk their use case presents. Unacceptable-risk practices such as social scoring are banned outright. High-risk systems — recruitment screening, credit scoring, education admissions, and the other Annex III domains — carry the full weight of obligations. Limited-risk systems, meaning anything that interacts with a person or generates content, carry transparency duties. Minimal-risk systems carry nothing beyond the general AI literacy duty.

The obligations arrive in stages. Prohibitions and the AI literacy duty applied from 2 February 2025. General-purpose AI model obligations from 2 August 2025. Article 50 transparency from 2 August 2026. High-risk obligations follow on 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for AI embedded in regulated products, after the Digital Omnibus deferral was adopted in mid-2026.

Our companion article walks through the classification exercise in detail, including the provider-versus-deployer distinction and the Article 6(3) exemption. This piece is about why the framework is worth building against in the first place.

3. Why Specific Rules Are an Asset, Not a Burden

Most AI governance instruments in the world today are statements of principle. Be transparent. Be fair. Be accountable. Protect privacy. Nobody disagrees with any of it, and nobody can build from it. Hand a principle to an engineering team and you get a meeting; hand them a requirement and you get a system.

The EU AI Act is unusual in that it names the artefacts. For high-risk systems it specifies a risk management system running across the lifecycle, data governance covering training, validation and testing sets, technical documentation sufficient for an authority to assess compliance, automatic event logging with defined retention, human oversight designed into the system rather than promised in a policy, and standards for accuracy, robustness and cybersecurity. For systems that interact with people or generate content, Article 50 specifies who must be told what, and that generated content must carry a machine-readable marker.

That level of detail has three practical consequences worth more than the compliance itself:

  • It is auditable. You can point to a log, a document, a test result. "We take fairness seriously" is not evidence; a retained interaction record is.
  • It is procurable. Enterprise buyers can ask specific questions and get specific answers, which shortens sales cycles rather than lengthening them.
  • It is portable. A governance programme built to a named specification transfers across jurisdictions. A programme built to a principle has to be reinvented each time someone else states the principle differently.

The uncomfortable version of the argument: vague regulation is not lighter, it is just deferred. You still carry the risk, you simply do not know what discharging it looks like until a regulator or a plaintiff tells you afterwards.

4. How It Compares: GDPR, the US, Korea, Japan, and the Voluntary Standards

The table below is a summary, not legal advice, and every one of these frameworks has detail this compresses away.

Framework Status Approach What it actually tells you to build
EU AI Act In force. Prohibitions and AI literacy since Feb 2025; GPAI Aug 2025; Article 50 transparency Aug 2026; high-risk Dec 2027 / Aug 2028 Binding, risk-tiered, product-safety architecture with extraterritorial reach Named system-level requirements: risk management, data governance, technical documentation, automatic logging, human oversight, accuracy and robustness, plus disclosure and content marking
GDPR In force since 2018 Binding, rights- and outcome-based, scoped to personal data Lawful basis, DPIAs, data subject rights, safeguards on automated decisions. Tells you what must be true of the processing, not how to engineer the system
United States — federal No comprehensive statute. Executive Order 14365 (Dec 2025) and a March 2026 White House framework push preemption; the Great American AI Act is a June 2026 discussion draft Executive action and procurement policy, plus an active effort to preempt state law Little that binds ordinary private-sector AI use. Congress has twice declined to preempt, and no preemption had been enacted as of July 2026
United States — states Binding duties already in force in California, Texas, Illinois and Utah. Colorado’s replacement regime and New York’s RAISE Act both start January 2027 Fragmented patchwork trending toward disclosure, content provenance and consumer rights rather than EU-style risk management Varies by state: frontier-model safety frameworks and training-data disclosure (CA), content provenance and free detection tools (CA, from 2 August 2026), intent-based discrimination prohibitions (TX), employment notice duties (IL), ADMT pre-use notices and opt-outs (CA)
South Korea AI Framework Act in force Jan 2026; enforcement decree fully operative July 2026 Binding, hybrid promotion-and-regulation, built on "high-impact" rather than "high-risk" Impact assessments, safety and reliability documentation, generative content labelling. Substantially lighter penalties than the EU
Japan AI Promotion Act enacted 28 May 2025, fully in force 1 September 2025 Promotion-oriented, principles-based, no monetary penalties Voluntary alignment with government guidance. No product classification or conformity assessment; authorities may advise, request information, or publicly name non-compliance
ISO/IEC 42001, NIST AI RMF Voluntary standards Management-system and risk-framework guidance, certifiable in the case of 42001 Governance structure and process discipline. Useful scaffolding, but not a legal obligation and not sufficient on its own for EU compliance

binding force and specificity across frameworks (illustrative comparison based on this article's content, not an official rating)

Figure: binding force and specificity across frameworks
(illustrative comparison based on this article's content, not an official rating)

The United States is the outlier, but not in the way the headlines suggest. It is worth separating the two layers, because they are moving in opposite directions.

Federally, the direction is deregulatory. There is still no comprehensive federal AI statute. Executive Order 14365, signed in December 2025, established an AI Litigation Task Force in the Department of Justice to challenge state AI laws, and a White House policy framework in March 2026 recommended that Congress preempt state laws imposing undue burdens. In June 2026 a bipartisan 269-page discussion draft, the Great American Artificial Intelligence Act, proposed transparency mandates, third-party audits, and a three-year preemption of state AI development laws. None of that is law. Congress has declined to preempt twice — the Senate stripped a state AI moratorium from the 2025 reconciliation bill by 99 votes to 1, and a second attempt through the defence authorisation failed in December 2025 — and as of July 2026 no federal preemption had been enacted.

At state level, binding duties are already in force. California alone has four instruments live or landing this year: the Transparency in Frontier Artificial Intelligence Act (SB 53), effective January 2026, requiring frontier developers to publish safety frameworks and report critical incidents, with penalties up to one million dollars per violation; AB 2013, requiring generative AI developers to disclose training-data documentation; the California AI Transparency Act (SB 942 as amended by AB 853), operative 2 August 2026, requiring large generative AI providers to offer a free AI detection tool and to apply visible and latent provenance disclosures, with further phases in 2027 and 2028; and the CPPA automated decision-making technology rules, which by January 2027 require pre-use notices, opt-out rights, and access to decision logic for significant decisions in employment, housing, credit, healthcare and education. Texas has had its Responsible AI Governance Act in force since January 2026, prohibiting AI built for restricted purposes and offering an affirmative defence for alignment with the NIST AI Risk Management Framework. Illinois amended its Human Rights Act in the same month to make discriminatory AI in employment decisions a civil rights violation with a private right of action. New York’s RAISE Act follows in January 2027.

Colorado is the retreat, not the pattern. It passed the first comprehensive US state AI law in 2024, deliberately importing the EU’s risk-based architecture, then repealed it in May 2026 and replaced it with a narrower automated decision-making statute effective January 2027, dropping the duty of care, risk management programmes and impact assessments.

The most telling detail is a date. California pushed the operative date of its AI Transparency Act from January 2026 to 2 August 2026 — the same day the EU’s Article 50 obligations began to apply — explicitly to align with the EU timeline. That is the Brussels effect visible in a statute rather than as a theory about one. For a company selling into both markets the practical conclusion is unchanged but better founded: the US floor is lower, fragmented across fifty jurisdictions, and unstable while preemption is contested, so it cannot serve as the design target. But “the US has no AI law” is simply wrong, and acting on it will get you caught in California or Texas.

Asia is converging rather than diverging. South Korea’s AI Framework Act took effect in January 2026 and became fully operative with its enforcement decree in July 2026, imposing impact assessment and documentation duties on high-impact AI in credit, healthcare and hiring — recognisably the same domains as Annex III, with lighter penalties. Japan’s AI Promotion Act, fully in force since September 2025, points in the same direction while staying promotion-oriented: no product classification or conformity assessment yet, but voluntary alignment with government guidance that authorities can escalate through requests for information or public naming.

5. Data and Privacy: Where the AI Act Goes Further Than Privacy Law Alone

A common misreading is that the EU AI Act competes with GDPR, or that complying with one covers the other. It does not work that way, and the distinction is the most useful thing in this article for anyone whose privacy programme is already mature.

GDPR governs the data. It asks whether you have a lawful basis, whether the individual has rights you must honour, whether you have run an impact assessment where the processing is risky, and whether a decision made solely by automated means about a person can be contested. It is powerful, and on personal data specifically it remains the stronger instrument.

The AI Act governs the system. It asks whether the training, validation and test data were examined for bias and gaps. Whether the system logs its own operation automatically. Whether a human can meaningfully intervene, and whether the interface was actually designed to let them. Whether you can produce documentation reconstructing how the system was built and tested. Whether the person on the other end knows they are dealing with an AI.

Dimension GDPR EU AI Act
What it regulates How personal data is processed How the AI system itself is built, logged and supervised
Core questions Is there a lawful basis; are data-subject rights honoured; is a DPIA required? Were training/test data checked for bias and gaps; does the system log itself; can a human meaningfully intervene; can you reconstruct how it was built?
Applies with no personal data involved? No — without personal data processing it generally does not apply Yes — if the use case falls under Annex III, it applies even to models trained entirely on synthetic or industrial data
GDPR governs the “data”, the EU AI Act governs the “system” — the two stack rather than replace each other

Figure: GDPR governs the “data”, the EU AI Act governs the “system”
— the two stack rather than replace each other

The practical difference: the AI Act’s obligations apply even where no personal data is processed at all, and they attach to engineering decisions that privacy law never reaches. A model trained entirely on synthetic or industrial data sits outside most of GDPR and squarely inside the AI Act if its use case is in Annex III.

The two stack rather than substitute. Running an Article 35 DPIA does not discharge the Article 9 risk management obligation, and a complete technical documentation file does not establish a lawful basis. Companies that treat one as covering the other usually discover the gap during a customer audit.

One live caveat worth tracking: the Digital Omnibus is two separate tracks. The AI track, amending the AI Act, was adopted in mid-2026 and is in force. The data track, which proposes amendments to GDPR including a clearer legitimate-interest basis for AI training and a narrow allowance for incidental special-category data, remains in negotiation and has drawn a critical joint opinion from the EDPB and EDPS. Until that track is adopted, current GDPR rules apply unchanged. Do not plan against proposals.

6. Being Honest About Where the Act Falls Short

A page that only argues one side is not useful to anyone making a decision, so three genuine weaknesses:

The standards were late, and that is why the deadlines moved. The high-risk deferral to December 2027 happened in large part because the harmonised technical standards that turn the Act’s requirements into testable criteria were not ready. Specificity in the legislation does not automatically mean clarity in implementation.

Marking technology has not caught up with the marking obligation. Article 50(2) requires machine-readable markers on generated content, and robust solutions — particularly for text — remain limited. The Code of Practice helps, but it does not make the underlying problem disappear.

Compliance cost is real and falls unevenly. For a small vendor, a full high-risk programme is a material investment. The Act includes some SME accommodation, but nobody should pretend the burden is trivial.

None of that changes the strategic conclusion. If you have to build a governance programme anyway, building it to the most demanding specification available is cheaper than building it three times to three weaker ones.

7. What This Means If You Are Not Based in the EU

Take a US-headquartered company as the clearest case. Federal AI policy is moving in a deregulatory direction and no comprehensive federal statute exists — but that does not mean no rules apply: binding duties are already in force in California, Texas, Illinois and Utah, the patchwork is expanding state by state, and your European customers are already asking Article 50 and Annex III questions today regardless of what Washington eventually decides.

Building to the EU specification is the fastest way to answer all of that from one programme instead of assembling a separate response for every state and every customer questionnaire. The same logic holds, with different local detail, for companies headquartered elsewhere outside the EU: a South-Korea-headquartered company, for example, is already subject to a binding AI Framework Act that became fully operative in July 2026, with impact-assessment and documentation duties recognisably close to the EU’s own. Companies that wait for their domestic framework to be finalised end up doing the same work later, under more time pressure, and without the commercial benefit of being able to answer a European buyer today.

8. Where to Start

  1. Inventory every AI system and agent in use or planned, internal and external alike. Most companies discover more than they expected, usually in HR, finance, and customer support.
  2. For each one, record who built it, who operates it, whether it touches EU users or produces output used in the EU, and what decision it influences.
  3. Classify against the four tiers. Check limited risk first — those obligations are already live — then work through Annex III.
  4. Identify the gap between what you can currently prove and what the tier requires. In practice the gap is almost always evidence: logging, documentation, and demonstrable oversight rather than policy.
  5. Fix the disclosure gaps first. They are the cheapest to close and the most visible externally.

The recurring theme in that list is that governance obligations are ultimately evidence obligations. Policies are necessary and insufficient; what a regulator or an enterprise customer asks for is a record. That is the problem AnyInsight is built to solve — complete interaction logging between users, AI systems and agents, and external systems, sensitive-data monitoring on inbound and outbound flows, and access control at the agent layer, with architecture currently being built toward high-risk-level standards so that moving up a tier later does not mean starting over.

For example, a company selling a recruitment screening tool into the EU market used to face an audit question like "how do you make sure this feature is not discriminatory" with little more than a verbal assurance from HR or engineering that "we care about fairness" — with no evidence they could pull up on demand. After adopting AnyInsight, every AI scoring decision generates an exportable interaction record automatically, and inbound and outbound sensitive data is masked and monitored in real time; when an auditor asks which application was rejected by the AI and on what basis, the company can produce the full record and access-control trail within minutes, instead of assembling policy documents under time pressure.

9. FAQ

Q1: We have no EU entity and no EU customers. Can we ignore this entirely?

For direct legal exposure today, possibly. But check three things before concluding that: whether any output your systems produce is used in the EU, whether any employee or contractor of yours is located there, and whether any of your customers resell or deploy your product into Europe. Also weigh the indirect route — enterprise procurement questionnaires increasingly track the AI Act regardless of the buyer’s own jurisdiction.

Q2: We are already GDPR compliant. Does that cover us?

No. GDPR governs personal data processing; the AI Act governs how the AI system is built, documented, logged and supervised, and it applies even where no personal data is involved. The two overlap in places, particularly around bias and automated decisions, but neither discharges the other. Section 5 sets out the split.

Q3: Would it not be easier to build to our own country’s law and adjust later?

Easier in the short term, usually more expensive overall. Frameworks in Korea and elsewhere are converging on the EU’s structure rather than replacing it, and the EU requirements are the strictest of the set. A programme built to the EU specification generally satisfies the others; one built to a lighter framework normally has to be rebuilt.

Q4: The US is deregulating. Does that not suggest the EU approach is losing?

Only the federal layer is deregulating, and it has not actually changed the law: Congress has twice declined to preempt state AI rules, and none had been preempted as of July 2026. Meanwhile California, Texas and Illinois all have binding duties in force right now, and California moved its AI Transparency Act to 2 August 2026 specifically to align with the EU. So the US is not converging on a lighter standard — it is fragmenting, which is worse for planning. Fifty variable regimes under a contested federal layer is a stronger argument for building to one strict specification, not a weaker one.

Q5: What is the single highest-value thing to do this quarter?

The inventory. Almost every failure mode we see — missed disclosure deadlines, unclassified HR tools, an auditor asking a question nobody can answer — traces back to a company not knowing what AI it was running. It is an afternoon of work and it determines everything downstream.

Conclusion

The EU AI Act is not important because Europe passed it. It is important because it is currently the only major framework that translates AI governance principles into requirements an engineering team can actually build, and because enough of the world is converging on its structure that building to it once is cheaper than building to four things later.

For companies outside Europe, the honest question is not whether the Act applies — it usually does, through output, staff, customers, or contract. The question is whether you can currently prove what you would need to prove if someone asked this week.

The Series, Start to Finish

This was Part 1 of The EU AI Act Playbook.

지금 Trusted AI로 구축을 시작하세요

AnyInsight.ai 계정을 만들고 모든 기능에 완전히 접근할 수 있는 14일 무료 체험을 이용해 보세요.
무료 체험 시작

AnyInsight.ai 소개

AnyInsight.ai는 기업이 코딩 없이 AI Agents를 구축, 배포, 관리할 수 있도록 돕는 안전한 AI workforce 플랫폼입니다. Zero-trust 아키텍처를 기반으로 내장형 접근 제어, prompt injection protection, governance 및 compliance를 제공하여 기업이 AI를 신뢰 기반으로 확장할 수 있도록 지원합니다.

Disclaimer

The insights and information shared in this article regarding the EU AI Act are for informational purposes only and do not constitute professional legal advice. We do not provide legal consulting services and assume no legal liability for any decisions made based on the content of this publication. As the interpretation and application of laws can vary depending on specific circumstances, we strongly recommend consulting a qualified legal advisor or attorney before making any compliance assessments or business decisions.

Reference

계속 살펴보기

관련 글

모든 글 보기