AgenTomte

August 18, 2026 · 7 min read

Which AI Regulations Apply to Your Business in 2026

By Anna, co-founder, build and content

Two facts decide which AI rules bind you, and neither one is where your company is registered. The first is where the output of your AI system lands. The second is whether that output shapes a decision about a person: a hire, a loan, a rent application, a claim, a grade. Get those two answers and most of the map draws itself.

If your outputs reach the European Union, the EU AI Act reaches you with no EU entity, no EU office and no EU customer contract. Article 2(1)(c) of Regulation (EU) 2024/1689 covers providers and deployers established in a third country “where the output produced by the AI system is used in the Union”. That limb was not touched by Regulation (EU) 2026/1744, the Digital Omnibus on AI, which has been in force since 27 July 2026 and moved several other deadlines.

Does the EU AI Act apply to a company with no EU entity?

Yes, in two situations. You are in scope if you place an AI system or a general-purpose AI model on the EU market, and you are in scope if the output of your system is used in the Union, wherever you sit. An export desk in Colombo running a quoting agent for German buyers is caught by the second limb. So is a US agency generating campaign copy that its client publishes in France.

There is a real limit, and it matters for small exporters. The European Commission’s Article 50 guidelines, document C(2026) 5054 of 20 July 2026, say that “incidental, unforeseeable or unauthorised downstream use” does not on its own pull a third-country provider into scope. Third-country deployers are bound where they foresee dissemination in the Union, by directing or authorising distribution there, and not where content reaches an EU audience through channels outside their control. Selling to EU buyers is foreseeable. A stranger reposting your blog in Belgium is not.

Article 2 also carves out several things people worry about needlessly: purely personal non-professional use, systems built solely for scientific research and development, and research or testing before a system goes to market. That last exemption stops at testing in real world conditions. Free and open-source releases sit outside the Act unless they are high-risk or fall under Article 5 or Article 50.

What is actually binding on 18 August 2026?

Less than the compliance vendors implied, and more than most non-EU firms realise.

ObligationStatus todayDateSource
Prohibited practices, AI literacyBinding2 February 2025AI Act Art. 113(a)
General-purpose AI model duties, penalties chapterBinding2 August 2025AI Act Art. 113(b)
Article 50 transparency (four limbs)Binding2 August 2026AI Act Art. 113
Marking of pre-existing generative systemsGrandfathered2 December 2026Guidelines C(2026) 5054, para 153
High-risk under Annex IIIDeferred2 December 2027Reg (EU) 2026/1744, recital 40
High-risk embedded in regulated productsDeferred2 August 2028Reg (EU) 2026/1744, recital 40

One nuance gets reported wrong constantly. The 2 December 2026 date is not the deadline for machine-readable marking of AI-generated content in general. Article 50(2) has been binding since 2 August 2026. The December date is a transitional window for generative systems that were already on the EU market before 2 August 2026, and it covers the marking duty only. The Commission also states that content generated before 2 August 2026 needs no retroactive labelling, but text generated earlier and published on or after that date does need a label.

Fines for breaching Article 50 run to EUR 15,000,000 or 3% of total worldwide annual turnover, whichever is higher, under Article 99(4)(g). Small and medium enterprises, including startups, pay the lower of the two figures rather than the higher one, under Article 99(6). We wrote the full timeline in the EU AI Act as it stands in August 2026, so this post stays on the scope question.

Do the US state rules reach a company with no US entity?

Texas does, explicitly. The Texas Responsible AI Governance Act, HB 149, has been in force since 1 January 2026 and applies to anyone who “produces a product or service used by residents of this state”. No Texas entity required.

It is an intent-based statute rather than a risk-management regime: it bans AI developed or deployed with intent to incite self-harm or crime, to discriminate unlawfully against a protected class, or to produce sexual deepfakes. Curable violations carry USD 10,000 to 12,000 each, uncurable ones USD 80,000 to 200,000, and the Attorney General must give written notice and a 60-day cure period. There is no private right of action.

Colorado is the one to re-check if you read about it last year. The 2024 Colorado AI Act was repealed and reenacted by SB 26-189, signed 14 May 2026, and the obligations now begin on 1 January 2027. It reaches developers and deployers “doing business in Colorado” whose automated decision-making technology materially influences a consequential decision in employment, lending, insurance, housing, health care, education or essential government services. Employees and Colorado-resident job applicants count as consumers. The signed text carries no employee-count exemption, whatever the summaries say.

California splits by size and product. AB 2013 has required training-data disclosure from generative AI developers since 1 January 2026. The California AI Transparency Act, SB 942, became operative on 2 August 2026 after AB 853 moved it, and it binds providers with over one million monthly users. The California Privacy Protection Agency’s automated decision-making rules took effect on 1 January 2026 with compliance required from 1 January 2027.

There is still no federal US AI statute. Your practical federal exposure is Section 5 of the FTC Act, which the FTC has already used against AI claims in its Operation AI Comply sweep of September 2024, plus the sector rules you already live under.

What about the UK, and everywhere else you ship?

The UK has no AI statute. What it has is SI 2026/425, the Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026, in force since 12 May 2026. Read it carefully and you will see it places a duty on the Information Commissioner to prepare a code, not a duty on you, and it sets no statutory deadline for doing so.

The binding UK change is elsewhere: section 80 of the Data (Use and Access) Act 2025 replaced UK GDPR Article 22 with Articles 22A to 22C on automated decisions, commenced in full on 5 February 2026.

Two more worth a line each if you ship beyond the Atlantic. China’s Measures for Labeling AI-Generated and Synthetic Content, issued by the Cyberspace Administration of China and published 14 March 2025, have applied since 1 September 2025 and require both visible labels and metadata markers. South Korea’s AI Basic Act took effect on 22 January 2026, reaches foreign operators serving Korean users, and requires a domestic representative above defined revenue and user thresholds.

Which rule do most non-EU companies actually trip first?

The GDPR, not the AI Act. Article 3(2) applies to a controller outside the Union processing the data of people in the Union where the processing relates to offering goods or services to them, or monitoring their behaviour in the Union. Targeting has to be deliberate: the European Data Protection Board’s Guidelines 3/2018 on territorial scope are clear that incidentally holding an EU person’s data is not enough on its own.

For AI specifically, EDPB Opinion 28/2024, adopted 17 December 2024, is still the governing guidance, and its central holding is that models trained on personal data cannot be assumed anonymous. Two newer texts were adopted at the EDPB’s plenary of 8 July 2026, Guidelines 02/2026 on anonymisation and Guidelines 03/2026 on web scraping for generative AI, both in public consultation until 30 October 2026. If you scrape training data, read the second one now rather than after it is final.

How to answer this for your own business in an afternoon

Write down every AI system in use, then answer three questions per row: where the output goes, whether it decides something about a person, and what data goes in. Where the output goes gives you your jurisdictions. Whether it decides about a person tells you if the deferred high-risk chapter and the Colorado rules will find you in 2027. What data goes in gives you the privacy answer, which is usually the urgent one.

That inventory is the first deliverable of our AI operations audit, and it is the same discipline we run on ourselves.

Every tomte we run, our word for one production agent with one defined job, has a written scope and a logged run history. As of July 2026 that fleet stood at 41 agents, with 5,450 runs and zero failures across one 13-day stretch, and the reason we can state that is the logging, not the luck. The agent fleet write-up shows how it is governed, and the guardrails post covers the gates that keep unattended agents inside their scope.

Two hours of inventory now beats a compliance retainer later. Almost nothing in the list above applies to a business that cannot say what its agents do.

Send us the list at /start and we will tell you in writing which of these regimes touch you and which do not. Written reply within one business day. No call, ever.

Tell us what you want automated

Describe the work in writing. You get a written reply within one business day: a fixed-price proposal, a scoping question, or an honest referral out.

Start at /start

▸ written reply within one business day · no call scheduled, ever

Doesn't fit a package? Tell us what you need anyway.

Questions? Ask in writing

no chatbot · a human replies

Ask us anything, in writing

A founder replies within one business day. That is the same promise clients get.