Regulators have stopped treating AI regulation as a future agenda item. In 2026, the EU AI Act’s general-purpose AI (GPAI) rules are enforceable, and more than a dozen US states have passed or advanced their own AI laws. Fines, audit letters, and procurement checklists are now operational realities, not hypotheticals. Nadia Cross mapped the deadlines and duties for publishers and deployers, and the picture is clear: compliance is no longer a legal exercise. It is an engineering and product problem with a price tag.

The EU AI Act enforcement calendar entered its operational phase for GPAI models in 2026. The key dates: August 2, 2025, brought GPAI transparency duties for documentation, copyright policy, and training summaries. August 2, 2026, strengthens Commission enforcement powers for new GPAI models and activates Article 50 transparency rules for deployers. December 2, 2026, introduces watermarking expectations for generative outputs under Omnibus adjustments. Full GPAI enforcement for models on the market before August 2025 shifts to August 2, 2027.

Models above the 10^25 FLOPs systemic-risk threshold face additional assessment, incident reporting, and cybersecurity expectations. The European Commission published GPAI guidelines and, in early 2026, draft implementing rules describing how investigators may access code, weights, and infrastructure. These are signals that paper compliance will not suffice. The regulator wants to look at the model, not just the binder.

National market surveillance authorities remain the front line for most high-risk AI systems in hiring, credit, medical devices, and critical infrastructure. Providers must register systems, maintain risk management files, and ensure human oversight where the Act demands it. Penalties can reach 7% of global turnover for the worst violations. That number appears on quarterly earnings calls.

For deployers, Article 50 transparency obligations require informing users they interact with an AI system unless obvious, marking synthetic audio, image, or video that could be mistaken for real, and disclosing emotion or biometric categorization when used. Content platforms should align UX copy, metadata, and moderation pipelines now, not the week before an audit.

GPAI model providers must supply technical documentation, a policy summarizing training-data copyright compliance, and public summaries of training content for applicable releases. Systemic-risk models add evaluation, adversarial testing, and serious-incident reporting. Downstream deployers who fine-tune or chain models inherit traceability requirements. Teams building on open weights should document divergence from the upstream provider’s safety mitigations. Synthetic data strategies do not eliminate copyright or transparency duties. They shift where lawyers look.

The US picture is different. Congress has not passed comprehensive federal AI legislation as of May 2026. Instead, agencies use existing authorities: FTC scrutiny of deceptive AI claims, FDA pathways for AI-enabled devices, NIST frameworks for risk management. The executive branch continues executive orders on AI safety and infrastructure. State law is where most deployers feel contiguous change.

The Colorado AI Act enforces algorithmic discrimination duties for high-risk decisions in employment, housing, and healthcare-adjacent services, with impact assessments and appeal rights. California requires transparency on training data for large developers, has chatbot disclosure bills, and ongoing privacy rulemaking under CPRA that affects automated decision-making. Texas, Utah, and others have disclosure and government-use restrictions with lighter-touch frameworks.

Multistate operators face compliance stacking. A single chatbot may need EU Article 50 labels, Colorado impact assessments, and California consumer notices. Legal teams increasingly maintain a jurisdiction matrix per feature flag.

Compliance costs are not only legal fees. Engineering lines include governance tooling, model inventory, risk tiering, approval workflows, logging and retention with PII redaction, human review queues for high-risk model outputs, and red-teaming and evals before launching multimodal or generative features. Mid-market publishers quoted six-figure first-year programs to stand up EU and US baseline compliance. Enterprises run higher. Smaller teams should prioritize scope reduction over checkbox policies nobody operates.

Procurement now asks vendors for AI Act conformity declarations, SOC 2 AI addenda, and incident SLAs. If you sell B2B software, your customers will export their regulatory burden to you via questionnaires.

Practical product deltas are visible. Clear AI labels on chat and support widgets in the EU. Watermarking or metadata on generated media where technically feasible before December 2026 deadlines. Appeal paths when automated decisions affect jobs, credit, or benefits in covered US states. Slower feature launches while legal reviews catch up to multimodal and agentic capabilities.

Engineering leaders should pair regulatory work with mechanical debt paydown: centralized policy engines, kill switches per region, eval harnesses that prove disclosure strings render in every locale.

The through-line for 2026 is convergence. Europe centralized high-risk and GPAI rules. America fragmented by state. Both expect evidence, not blog posts, when something goes wrong. The audit trail is the product now.