The EU's artificial intelligence regulation entered into force in August 2024 and started applying in stages. According to the European Commission, prohibitions on practices considered an unacceptable risk took effect in February 2025; obligations for general-purpose models followed in August of the same year. The heaviest chapter, covering systems classified as high-risk, was set for August 2026 — but days before that deadline, the European Parliament and Council approved a package that pushed that specific chapter to December 2027.
Read from a distance, that sounds like relief. It is only partial relief: the prohibitions and the general-purpose obligations have been in force since 2025, and the regulation is explicit about who it reaches. Article 2 extends the rules to providers and deployers "established or located in a third country, where the output produced by the system is used in the Union" — regardless of where the company is headquartered.
In practice, that includes a large share of companies with no office in Europe at all. A Euronews report from July 2026 shows the scale: 47% of companies already citing the regulation in their disclosures are headquartered outside the EU, and American companies alone account for 35% of that group. It is the same dynamic that, a decade earlier, turned Europe's data-protection law into a global benchmark even for companies that never had a European customer.
A European law that already reaches companies that never went to Europe
The trigger is not where the company is based. It is where the system's output is used. A company that provides an AI-assisted service to a European client, keeps a subsidiary in the EU, or supplies a company operating there can fall within the regulation's reach even without a single employee on the other side of the ocean.
Its reach extends beyond the EU's own borders, applying to any organisation whose AI systems are used in the bloc or whose outputs affect EU citizens, businesses or public institutions.
Penalties match the scale of that reach: up to €35 million or 7% of global annual revenue for the most serious breaches, according to the same report — the ceiling applies equally to European and non-European companies.
Readiness lags far behind the risk. Research cited by Euronews found that only 13% of companies worldwide have any formal AI governance framework, and just 12.4% require a person to review individual AI-made decisions. Fewer than one in four assess whether their own AI use could affect the rights of the people who work there.
The pattern across these numbers is familiar: the law already exists, its reach is already international, but the internal structure to answer it has not been built at most companies — including ones that make AI-assisted decisions every day.
The delay that brought only half the relief

The 2026 delay is real and specific. According to an analysis by the law firm Gibson Dunn, obligations for stand-alone high-risk systems — the category covering most corporate AI use — moved from August 2026 to 2 December 2027; for AI embedded in already-regulated products, the new deadline is August 2028.
What did not change is the rest of the calendar. The February 2025 prohibitions still stand, and the general-purpose obligations in force since August 2025 remain untouched. The law was not suspended — only its heaviest chapter got more time.
The common mistake is treating December 2027 as the day this starts to matter. It does not. The work the regulation demands — finding out where AI is used across the company, for what, with what information, and under whose sign-off — cannot be assembled overnight. A company that only starts mapping this close to the new deadline will discover, too late, that the inventory never existed.
And "we don't have an office in Europe" remains the most dangerous assumption on the list, because Article 2 never depended on that.
What is actually at stake
Strip away the legal layer, and what the regulation asks for is concrete: a company needs to know where AI is used, classify that use by risk, make sure a person is accountable for its more sensitive decisions, and keep a record of what happened.
Those four things are exactly what is missing when AI use inside a company runs through personal tools each employee picks on their own, with no inventory and no owner. The problem stops being purely legal — without that mapping, the company also does not know which important decisions already lean on AI today, whether or not they fall under the European rules.
What Has to Be in Place

A governed corporate AI environment answers those demands by design, not by promise after an audit.
A live inventory of AI use. Every agent, prompt, or workflow created inside the company gets logged — who created it, for which area, with which knowledge connected. Without that record, "where is AI used here" has no verifiable answer.
Risk classification before a use is released. Not every AI task needs the same level of control; one touching a credit decision, a hiring call, or sensitive customer data needs more review than a summary of an internal meeting.
Human approval matched to risk. Sensitive actions pause and ask a person to confirm before proceeding, inside the conversation itself — and critical documents may require a two-step review and approval, with the person who writes separated from the person who approves.
An audit trail. Creating an agent, approving a piece of content, changing a permission: all logged. In an inspection or an incident investigation, that is the difference between reconstructing what happened in minutes and not being able to reconstruct it at all.
This is how Skyller was designed: identity coming from the company directory, approval and logging as the factory default, not a setting someone has to remember to turn on.
From fine risk to a head start
A company that only sees this regulation as fine risk misses the other half of the story. The same inventory the European law demands is also what lets a company answer, in any internal or customer audit, an increasingly common question: "how do you use AI in there?"
A company already running on corporate identity, risk-based approval, and logging by default reaches December 2027 with the heavy lifting done months earlier. One still relying on personal accounts and scattered spreadsheets will spend whatever time is left before then simply rebuilding what should already exist.
There is also a gain that shows up in no regulatory requirement: a company that already gathers its AI use in one place can answer "how many AI agents do we have, and for what" in minutes — instead of asking every department and waiting for replies to trickle in by email.
A checklist for the next meeting
Before treating this as a 2027 project, it is worth bringing these questions to the next conversation with legal, IT, and operations leadership:
- Does any AI use here touch a client, subsidiary, or supplier operating in the European Union? If the answer is "we don't know," that is the first gap to close — Article 2 does not require physical presence in Europe to reach a company.
- Is there an inventory today of where AI is used across the company, and by whom? Without that list, there is no way to classify risk or later prove that anything was reviewed.
- Who approves an AI-driven decision before it turns into an action on a client or a contract? If the answer is "no one, for now," that is the most expensive gap to leave for later.
- If a regulator or a client asked today for the company's AI usage history, would it exist? The answer to that question says more about real readiness than any date on a calendar.






