US foundation-model providers have built their compliance posture on a voluntary baseline. The NIST AI Risk Management Framework sets out practices a developer may adopt; the federal approach has been set by executive action rather than statute; and the binding rules arrive state by state, in instruments such as the Colorado AI Act, itself rewritten before it ever took effect.1National Institute of Standards and Technology, 'Artificial Intelligence Risk Management Framework (AI RMF 1.0)' (NIST AI 100-1, January 2023); Colorado SB 24-205, 'Consumer Protections for Artificial Intelligence', its operative requirements deferred to 30 June 2026 by SB 25B-004 and repealed and reenacted before they took effect by SB 26-189 (signed 14 May 2026; requirements from 1 January 2027). The instinct that follows is reasonable: AI obligation is something a US developer opts into. The EU AI Act's rules for general-purpose AI models do not behave that way.2Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (AI Act) [2024] OJ L 2024/1689. They are not the voluntary baseline carried across the Atlantic. They are an enforceable, sanctions-backed set of duties that have bound model providers since 2 August 2025, and on 2 August 2026 the European Commission acquires the power to investigate those providers, order them to change course, and fine them. The headlines that announced a delay to the AI Act in late 2025 did not move that date.
1. The Delay That Did Not Touch GPAI
In November 2025 the Commission proposed the Digital Omnibus on AI, and the co-legislators reached provisional agreement on 7 May 2026 on a package that pushed the Act's high-risk timetable back. Stand-alone high-risk systems under Annex III, due on 2 August 2026, would move to 2 December 2027; high-risk AI embedded in regulated products under Annex I would move to 2 August 2028.3European Commission, 'Proposal for a Regulation amending Regulations (EU) 2024/1689 and (EU) 2018/1139 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI)' COM(2025) 836 final (19 November 2025); provisional inter-institutional agreement reached 7 May 2026, deferring the high-risk obligations without deferring the Chapter V obligations for general-purpose AI models or the 2 August 2026 enforcement date; not formally adopted as of publication. For a US company reading trade press, the message compressed to four words: the AI Act slipped.
The compression is where the exposure hides. The deferral reached the high-risk regime. It did not defer the obligations on providers of general-purpose AI models, and it did not move the two dates that decide a model provider's position. The obligations in Art. 53 and Art. 55 AI Act have applied since 2 August 2025. The Commission's supervision and enforcement powers over model providers, dormant through a one-year adjustment period, switch on 2 August 2026. Providers of models placed on the Union market before 2 August 2025 have until 2 August 2027 to bring those models into compliance.4AI Act (n 2): general-purpose AI obligations from 2 August 2025 (Art. 113(b)); enforcement powers and fines from 2 August 2026 (Art. 88–94, Art. 101); pre-2025 models compliant by 2 August 2027 (Art. 111(3)); systemic-risk designation ex officio from 2 August 2025 (Art. 51(1)(b), Art. 52(4)), the scientific-panel qualified-alert route sitting in Chapter IX (Art. 90(1)(a)); fines up to 3% of worldwide annual turnover or EUR 15 million. None of those three dates moved.
The distinction between an obligation and the power to enforce it is doing real work here. A model provider has been legally bound since August 2025; what it has not faced is a regulator able to compel compliance. From 2 August 2026 the Commission may request the technical documentation a provider was supposed to be keeping, conduct its own evaluations of the model, order mitigation measures, and require that a model be restricted, withdrawn, or recalled. It may impose a fine of up to 3% of total worldwide annual turnover or 15 million euros, whichever is higher. For a frontier developer, the percentage figure is the operative one, and the turnover it runs on is worldwide rather than European. Whether that turnover is the provider entity's alone or its group's is not settled on the face of Art. 101 AI Act, which omits the reference to an undertaking that Art. 99 AI Act carries.
A provider that reads the headlines and concludes it has until December 2027 has made a category error that the structure of the Act invites. The error is not merely a missed date. During the adjustment period the Commission is not wholly inert: the designation power in Art. 52 AI Act sits in Chapter V and has applied since 2 August 2025, so a model can be designated as one carrying systemic risk before August 2026, while the scientific-panel alert route that Art. 52(4) also names runs through Art. 90 AI Act, which sits in a chapter the Act's application provision does not bring forward. The Omnibus had not been formally adopted as of publication, and its final text could shift; what has been stable through each stage is the decision to leave the general-purpose AI timetable in place. Whether a US provider's existing governance documentation would survive a documentation request issued in the first weeks of enforcement is a question that depends on what was assembled while the obligation was, in practice, unpoliced.
The 2026 deferral would move the AI Act's high-risk deadlines, not its general-purpose AI deadlines. A US foundation-model provider that reads "the AI Act was delayed" and recalculates its own runway has misread which part of the Act the agreement would postpone.
2. Who Answers for the Model
The first question is not how to comply but whether the obligations attach to the provider at all, and the Act answers it in a way that disregards where the provider sits. The rules apply to any provider that places a general-purpose AI model on the Union market, whether the provider is established in the EU or in a third country.5AI Act (n 2), Art. 2(1)(a) (application irrespective of place of establishment), Art. 3(63) (definition), Art. 54 (third-country authorized representative by written mandate; Art. 54(6) open-source exemption, unless systemic risk), recital 97; European Commission, 'Guidelines on the scope of the obligations for general-purpose AI models established by Regulation (EU) 2024/1689 (AI Act)' C(2025) 5045 final (18 July 2025) (indicative 1023 FLOP marker; one-third-compute downstream-modifier criterion). "Placing on the market" is read broadly: it captures the first making-available of a model in the course of commercial activity, and a provider that integrates its own model into its own system and offers that system in the Union has placed the model on the market just the same.
For a US provider, the cognitive anchor is the export-control or terms-of-service model: the company ships weights, or exposes an API, and treats EU availability as a downstream distribution fact. The Act does not track that intuition. A model offered to EU users through an API is on the Union market. A model that a US provider never directed at Europe, but that a downstream developer integrates into a system later placed on the EU market, may pull the original provider into scope, a reading the Commission's own materials support while acknowledging that it remains to be tested in practice. The threshold question of who counts as a provider of a general-purpose AI model is therefore not one a US company can answer from its own commercial intentions.
What counts as a general-purpose AI model is itself a moving boundary. The Act defines it by generality, a model that displays significant generality and can competently perform a wide range of distinct tasks (Art. 3(63) AI Act), and the Commission's July 2025 guidelines add an indicative marker: training compute above 1023 FLOP combined with the ability to generate language, text-to-image, or text-to-video. The marker is indicative, not dispositive, which means the line is administered rather than fixed. The boundary moves again downstream. A company that fine-tunes or otherwise modifies another provider's model can itself become the provider of a new model, with its own Art. 53 obligations, and the Commission's indicative test for when that happens, modification compute exceeding one third of the original model's training compute, is a number most US legal teams have never had reason to calculate. An enterprise that fine-tunes an open model for a regulated use may have assumed it was a customer. It may be a provider.
Even a provider that accepts it is in scope meets a structural requirement with no clean US analogue. A provider established outside the Union must, before placing its general-purpose AI model on the Union market, appoint an authorized representative in the EU by written mandate, and the mandate must satisfy a defined content standard (Art. 54 AI Act). The representative is not a mailing address. It is a designated point of accountability that the Commission can address directly, and the only escape from the requirement is the open-source route examined below, which carries its own limits. Who serves as that representative, and what the mandate exposes both the representative and the provider behind it to, is a question most US providers have not asked, because the role does not exist in their home framework.
3. Four Duties, and Four More at the Frontier
Every provider of a general-purpose AI model in scope carries four obligations, and they are not interchangeable with the documentation a US developer already keeps. The provider must draw up and maintain technical documentation of the model for the AI Office (the Commission's supervisor for these models) and national authorities (Art. 53(1)(a) AI Act); it must prepare documentation enabling downstream developers who integrate the model to understand it and to meet their own obligations (Art. 53(1)(b)); it must put in place a policy to comply with Union copyright law (Art. 53(1)(c)); and it must publish a sufficiently detailed summary of the content used to train the model, on a template provided by the AI Office (Art. 53(1)(d)).6AI Act (n 2), Art. 53(1)(a)-(d): technical documentation for the AI Office and national authorities; documentation for downstream providers; a policy to comply with Union copyright law; and a publicly available summary of training content.
Two of these reach into territory US providers consider settled on US terms. The copyright policy is not a policy to comply with US law. It is a policy to comply with Union copyright law, which includes the text-and-data-mining regime of the Copyright in the Digital Single Market (CDSM) Directive and the right of rightsholders to reserve their works from mining.7Directive (EU) 2019/790 of the European Parliament and of the Council of 17 April 2019 on copyright and related rights in the Digital Single Market [2019] OJ L130/92 (CDSM Directive), Art. 4 and in particular Art. 4(3) (text-and-data-mining exception and rightsholder reservation), referenced by Art. 53(1)(c) AI Act. A US provider whose training posture rests on the US fair-use doctrine still has to adopt and operate a policy addressed to the EU reservation mechanism, and whether the EU expects that policy to govern training conducted entirely outside the Union is precisely the kind of extraterritorial question the text leaves open. The training-content summary compounds the exposure from a different direction. A public summary of training content, prepared on the AI Office's template,8European Commission (AI Office), 'Explanatory Notice and Template for the Public Summary of Training Content for General-Purpose AI Models' (24 July 2025), under Art. 53(1)(d) AI Act (n 2). is a document that plaintiffs in copyright litigation on both sides of the Atlantic will read with care, and the duty to publish it does not pause because litigation is pending.
For a small number of providers, the obligations roughly double. A model is presumed to carry systemic risk when the cumulative compute used to train it exceeds 1025 FLOP, a presumption that is rebuttable but that puts the burden on the provider to displace it, and the Commission may also designate a model as systemic on qualitative grounds set out in Annex XIII (Art. 51 AI Act).9AI Act (n 2), Art. 51 (systemic-risk classification; presumption above 1025 FLOP under Art. 51(1)(a) and (2); qualitative designation under Art. 51(1)(b) and Annex XIII), Art. 52(1) (notification within two weeks), Art. 52(2) and (3) (rebuttal of the presumption, and its rejection), Art. 55 (evaluation including adversarial testing, systemic-risk mitigation, serious-incident reporting, cybersecurity). A provider that meets, or expects to meet, the compute threshold must notify the Commission without delay and in any event within two weeks (Art. 52 AI Act), an obligation that bites during training, before release, because a provider knows its compute budget in advance. A model with systemic risk then carries the duties in Art. 55 AI Act: to evaluate the model, including through adversarial testing; to assess and mitigate systemic risks at Union level; to track, document, and report serious incidents to the AI Office; and to ensure an adequate level of cybersecurity for the model and its infrastructure. For a US lab, the notification duty is the one most likely to be missed, because it converts an internal engineering milestone, crossing a compute threshold, into a regulatory filing deadline measured in days.
4. Sign the Code, or Justify the Alternative
The Act offers model providers an instrument that looks, to a US reader, like a safe harbor and is not one. The General-Purpose AI Code of Practice, published on 10 July 2025 and assessed as adequate by the Commission and the AI Board, sets out in three chapters, transparency, copyright, and safety and security, how a provider may meet its obligations under Art. 53 and Art. 55 AI Act.10The General-Purpose AI Code of Practice (10 July 2025), drawn up under Art. 56 AI Act (n 2) and assessed adequate by the Commission and the AI Board; adherence is a means of demonstrating compliance, not a presumption of conformity, and commitments implemented in line with the Code are among the matters to be taken into account in fixing a fine under Art. 101(1); non-adherents must show adequate alternative means. The first two chapters address the duties every provider carries; the third addresses the systemic-risk duties. A provider may sign.
What signing buys is narrower than the US safe-harbor reflex assumes, and what declining costs is larger. Adherence to the Code is not a presumption of conformity with the Act. It is a means of demonstrating compliance, and the Commission has said that for a provider adhering to an adequate code, it will focus its enforcement on monitoring adherence rather than reconstructing compliance from first principles. Commitments implemented in line with the Code are expressly among the matters the Commission must take into account when it fixes a fine, which is not the same thing as the signature buying a discount (Art. 101(1) AI Act). A provider that declines does not thereby escape the obligations; it takes on the burden of showing that its alternative means of compliance are adequate, and the Commission's guidelines tell non-adherents to expect more requests for information and access, with the very Code the provider declined to sign as the practical yardstick.
The split among developers is instructive. Within weeks of publication the majority of frontier model developers signed; Meta publicly declined, framing the Code as reaching beyond the Act; and one developer signed only the safety and security chapter. For a US provider, the decision is recognizable as a litigating posture rather than a compliance task: whether to accept a documented, Commission-endorsed route and the deference that travels with it, or to preserve room to argue that the Code overreaches while accepting the evidentiary burden that refusal transfers. Either choice can be defensible. Neither is free, and the instinct to decline a voluntary instrument on principle imports a US free-speech and over-delegation frame that does not change where the burden of proof sits under the Act. The more exposed position is the one a provider reaches without deciding: neither signing the Code nor assembling the alternative-means record that declining requires. Whether a US provider's existing model documentation, written for internal governance or for the NIST framework, amounts to adequate alternative means is not a question that answers itself, and not one a provider will want to confront for the first time inside a Commission documentation request.
5. The Open-Source Exemption, and Where It Closes
The Act carves out open models, and the carve-out is narrower than the US "open weights, no obligations" assumption. A provider that releases a model under a free and open-source license, with the parameters, including the weights, the architecture, and information on usage made publicly available, is relieved of the technical-documentation and downstream-documentation duties in Art. 53(1)(a) and (b) AI Act.11AI Act (n 2), Art. 53(2) (open-source relief from Art. 53(1)(a) and (b) only, unavailable to models with systemic risk) and recitals 102–104 and 112; Commission Guidelines (n 5), section 4 (narrow reading of "free and open-source"). Open release also lifts the Art. 54 AI Act duty to appoint an authorized representative in the Union, and there the relief stops; two limits define what is left standing.
The first limit is that the copyright policy and the training-content summary survive. Releasing a model openly does not remove the duty to operate a policy addressed to Union copyright law or to publish the training-content summary; those obligations apply to open and closed models alike. A US developer that open-sources a model to shed regulatory weight sheds the documentation duties and keeps the two obligations most entangled with copyright litigation. The second limit is that the carve-out disappears at the frontier. The exemption does not apply to a general-purpose AI model with systemic risk. A model trained above the 1025 FLOP threshold carries the full Art. 55 load, evaluation, systemic-risk mitigation, incident reporting, and cybersecurity, whether or not it is open, and the Act's recitals acknowledge that mitigations are harder to implement once a model is openly released, which leaves the systemic-risk question sitting upstream of a release decision that is difficult to unwind. What counts as a genuinely free and open-source license is also administered rather than assumed: the Commission's guidelines read the concept narrowly, and monetization or gated access can take a release outside it.
For a US provider whose open-source strategy rests on the premise that publishing weights ends the regulatory conversation, the EU sequence inverts the intuition: openness is a partial exemption from two of four model-documentation duties, it never touches copyright, and it vanishes precisely for the models the provider is most likely to consider strategically important.
6. Strategic Considerations
The questions that determine a US provider's exposure are not the ones the compliance calendar surfaces. The threshold question is status: is the company a provider of a general-purpose AI model at all, and if so, as of when, given that a model on the Union market before 2 August 2025 runs to the 2 August 2027 deadline while a model placed after that date was bound at once? The answer may turn on a downstream integration the provider did not control and a compute-share calculation its lawyers have never run. A second question follows: has anyone mapped which of the company's models approach or cross the 1025 FLOP threshold, and if one does, was the two-week notification to the Commission made when the compute budget was set rather than when the model shipped? The duty runs during training, and a notification that should have been made months earlier is not cured by making it late.
The Code decision compounds both. Whether to sign the Code of Practice or to justify an alternative is not a one-time election; it is a posture that has to be documented, owned, and defended, and the provider that has neither signed nor built the gap-analysis record that declining requires occupies the weakest of the three positions. Who inside the organization owns that decision, and whether the model documentation already in hand would satisfy a regulator applying the Code as its yardstick, are questions that precede any filing. Then there are the loops that carry an EU exposure back into US law. A published training-content summary is discoverable, and it will be read against positions the company has taken in US copyright litigation. A Commission fine, or a model restriction, is the kind of event that can mature into a US securities-disclosure question for a company with public reporting obligations, and standard directors-and-officers coverage does not always reach foreign regulatory action. The authorized representative the Act requires a non-EU provider to appoint is a named accountability point, and what the mandate exposes that representative, and the provider behind it, to is a matter of drafting the Act specifies only in part.
None of these questions resolves on the face of the regulation. Each depends on facts the company holds and has not yet assembled: its training-compute ledger, its release history, its downstream contracts, its litigation posture, and its tolerance for arguing with a regulator that, from August 2026, has the power to argue back. The date is fixed. What it will mean for any particular provider is not.