EU AI Act vs US AI policy 2026 compliance guide

EU AI Act vs US AI policy: 2026 compliance guide

A clear comparison of EU AI Act obligations and the new US AI policy landscape after EO 14110's revocation, with practical steps for compliance teams.

Two frameworks were supposed to define global AI governance: the European Union's AI Act and the United States' Executive Order 14110. That comparison made sense in early 2024. It doesn't anymore.

EO 14110 is dead. President Trump revoked it on his first day back in office, and what replaced it looks almost nothing like its predecessor - it trades mandatory reporting thresholds and civil rights enforcement for a policy of "removing barriers" to AI development. Meanwhile, the EU AI Act, which entered into force in August 2024, has kept marching through its own compliance calendar - though that calendar has now actually been rewritten, not just proposed. A package known as the Digital Omnibus on AI cleared its final legislative hurdle this summer and is now binding law.

In 2024, the US and EU sought comparable global AI governance. Today, they are charting fundamentally opposite paths.

So the real story in 2026 isn't a face-off between two comparable regimes. It's a story of divergence: one bloc doubling down on binding, risk-based regulation, and one country pulling back toward voluntary standards, state-level fragmentation, and a national security lens. For technical leaders and legal counsel operating on both sides of the Atlantic, understanding how that divergence happened matters just as much as knowing where things stand today - and, as the past few months have shown, both sides are still moving.

What happened to Executive Order 14110

EO 14110, signed by President Biden on October 30, 2023, was billed as the most comprehensive AI governance document the US government had produced. It directed agencies to lean on existing authorities - NIST, the Department of Commerce, DHS - rather than creating new regulatory machinery. It introduced a reporting threshold for "dual-use foundation models" trained above 10^26 floating-point operations, pushed federal adoption of the NIST AI Risk Management Framework, and directed agencies to use civil rights law against algorithmic discrimination in housing, credit, and employment.

None of that survived the transition. On January 20, 2025, President Trump rescinded EO 14110 outright. Three days later he signed a replacement, Removing Barriers to American Leadership in Artificial Intelligence, which explicitly criticized the Biden order as "dangerous" and "unnecessarily burdensome" and instructed agencies to identify and roll back anything issued under it that didn't align with a new mandate: sustaining America's AI dominance globally.

"State-by-State regulation creates a patchwork of 50 different regimes, making compliance more challenging, especially for start-ups."

That line, from a subsequent executive order, captures the throughline of everything that has followed. Since January 2025, the US approach has been built around three ideas: strip out what looks like a compliance burden, treat AI policy as a competitiveness and national security issue rather than a civil rights one, and push back against state-level rules that might recreate the patchwork Washington just tore down at the federal level.

The policy sequence since the revocation

The pace of executive action has been unusually fast, even by the standards of a technology this contested. Worth tracking in order:

  • January 2025 - EO 14110 revoked; replaced days later by an order directing agencies to develop a national AI Action Plan and strip "ideological bias" from federally-relevant AI systems.
  • April 2025 - OMB guidance directs agencies to appoint Chief AI Officers and adopt minimum risk-management practices for "high-impact" uses, while rescinding several Biden-era procurement safeguards.
  • July 2025 - The White House releases Winning the AI Race: America's AI Action Plan, cataloguing more than 90 federal policy actions across innovation, infrastructure, and international posture. A companion order, EO 14319, Preventing Woke AI in the Federal Government, directs agencies to procure only large language models that meet "unbiased AI principles."
  • December 2025 - EO 14365, Ensuring a National Policy Framework for Artificial Intelligence, pushes for a "minimally burdensome" national posture and directs the Department of Justice to stand up an AI Litigation Task Force to challenge state-level AI laws it considers "onerous" - an explicit preemption push, with Colorado's original AI Act named directly as a target.
  • June 2026 - EO 14409, Promoting Advanced Artificial Intelligence Innovation and Security, introduces cybersecurity mandates for federal and national-security systems and a voluntary framework under which frontier-model developers can share models with the government up to 30 days before wider release - while stating outright that it creates no licensing or preclearance requirement.

Two threads run through all of it. First, computational thresholds and mandatory reporting are gone - nothing in the current US framework resembles the 10^26-operations trigger from EO 14110. Second, the fight has moved from Washington-versus-industry to Washington-versus-states, and the first real test case has already played out in Colorado.

The Colorado test case

Colorado's original AI Act (SB 24-205) was the article everyone used to point to as America's answer to the EU's risk-tiered approach: developer and deployer duties, mandatory impact assessments, a duty of reasonable care against algorithmic discrimination. It never actually took effect.

The law's start date slipped repeatedly - first from February to June 30, 2026 - while xAI sued Colorado's Attorney General in April 2026 to have the statute declared unconstitutional. The Department of Justice, acting through the newly formed AI Litigation Task Force, intervened in support just weeks later, marking the first time the federal government moved directly to invalidate a state AI law. A federal court stayed enforcement before the law ever bit.

Rather than fight it out in court, Colorado's legislature rewrote the statute. On May 14, 2026, Governor Jared Polis signed SB 26-189, which repeals SB 24-205 entirely and replaces it with a narrower "Automated Decision-Making Technology" framework, effective January 1, 2027. Gone are the mandatory risk-management programs, the annual impact assessments, and - notably - the rebuttable presumption that let companies claim reasonable care simply by aligning with the NIST AI Risk Management Framework or ISO/IEC 42001. What's left is a lighter-touch regime built around consumer notice, post-decision explanation, correction rights, and human review.

It's a instructive case study for the rest of the country: federal pressure didn't preempt Colorado's law outright, since only Congress or a court can technically do that, but it reshaped the law anyway. Legal challenges to the broader preemption push are still working through the courts, other states including California, Texas, and Illinois have their own AI statutes already in force, and several state attorneys general have signaled they intend to keep defending their authority to regulate.

The US traded compute triggers for a national security lens, treating federal restraint as the ultimate policy goal.

What's left of the old NIST-centered approach

The National Institute of Standards and Technology hasn't disappeared from the picture, but its role has shifted, and shifted again. The AI Risk Management Framework remains voluntary, and it was never binding to begin with - yet its influence persists because federal agencies, from the FTC to the FDA to the SEC, keep referencing its structure, and because federal procurement increasingly expects vendors to show alignment with it.

Colorado's rewrite is a useful reminder of just how much that voluntary status matters in practice. Under the original AI Act, demonstrated NIST alignment functioned as an actual legal shield - a rebuttable presumption of reasonable care written directly into the statute. SB 26-189 didn't carry that provision forward. Framework alignment is still smart operational practice, and it still helps satisfy the documentation and human-oversight duties the new Colorado law expects, but it is no longer a codified legal defense anywhere in the country. That's a meaningful inversion of how EO 14110 imagined NIST's role in the first place: the 2023 order treated the RMF as a stepping stone toward more structured federal oversight, where today, in the absence of that oversight, the RMF functions more like an insurance policy companies adopt voluntarily to manage risk with regulators and litigants.

The EU AI Act - still the world's most prescriptive regime

While US policy has been rewritten five times in eighteen months, the EU AI Act has stayed put in its fundamentals. It remains a binding, horizontal regulation built on a tiered risk hierarchy - unacceptable, high, limited, and minimal risk - with the heaviest obligations falling on systems used in employment, credit scoring, biometric identification, critical infrastructure, education, and law enforcement.

High-risk obligations haven't gotten lighter, just later

Providers of high-risk systems are still required to build a risk management system spanning the full product lifecycle, not a one-time assessment filed away after launch. The core technical obligations include:

  • Quality management systems - documented policies and procedures ensuring consistent technical compliance.
  • Data governance - training, validation, and testing data must be relevant, representative, and as error-free as reasonably achievable, with documented bias mitigation and provenance tracking.
  • Technical documentation - the Annex IV file that lets regulators assess compliance without reverse-engineering the underlying model.
  • Automated logging - built-in traceability so outcomes can be audited after the fact.

Before a high-risk system reaches the EU market, it needs a conformity assessment. Most providers can self-assess through internal control procedures; systems embedded in already-regulated products, like medical devices or vehicles, require a third-party Notified Body review. Passing results in a formal declaration of conformity and the right to apply the CE marking.

GPAI rules are already live, and enforcement starts this month

Rules for general-purpose AI models became legally applicable on August 2, 2025. Every GPAI provider must maintain technical documentation, publish a summary of training data, and demonstrate copyright compliance - including honoring rightsholder opt-out signals for future training runs. Models classified as posing systemic risk, typically the most computationally intensive or widely-used systems, face heavier obligations still: structured safety and security frameworks, adversarial red-teaming, incident reporting, and enhanced cybersecurity protections.

The European AI Office published a GPAI Code of Practice in July 2025, developed with input from more than a thousand stakeholders across three drafting rounds. Signing it isn't mandatory, but it functions as a practical safe harbor - providers who adopt it and show good-faith implementation get a more collaborative relationship with regulators during the transition, plus a documented mitigating factor if fines ever come into play. Providers who skip it must build an equivalent compliance case from scratch, which is a considerably heavier lift.

The dates that matter here: enforcement powers, including fines, activate for GPAI models placed on the market after August 2, 2025, starting this month - August 2, 2026 - while legacy models already on the market before that date get an extra year, until August 2, 2027, to come into compliance. Fines under Article 99 reach the greater of €15 million or 3% of global annual turnover for GPAI-specific violations, and up to €35 million or 7% of global annual turnover for the most serious breaches elsewhere in the Act.

Fines up to €35M prove the EU isn't bluffing. Its mandatory data governance bar remains the highest standard globally.

The Digital Omnibus is now law, not a proposal

Here's the development that most compliance guides published even a few weeks ago got wrong by necessity, simply because it hadn't happened yet: on July 24, 2026, the Digital Omnibus on AI - formally Regulation (EU) 2026/1744 - was published in the EU's Official Journal. It entered into force on July 27, 2026, five days ahead of the original high-risk deadline it was designed to replace. This is no longer a "provisional deal." It is binding EU law.

The revised timeline now reads as follows:

  • August 2, 2026 - Article 50 transparency obligations (AI-interaction disclosure, generative-content labeling) apply on schedule, as originally planned.
  • December 2, 2026 - Those same transparency obligations extend to systems already on the market before August 2026, and the Act's new prohibited-practices additions take effect.
  • December 2, 2027 - The main event: standalone high-risk systems under Annex III, covering employment, education, credit scoring, and access to essential services, must comply. This replaces the original August 2, 2026 date.
  • August 2, 2028 - High-risk AI embedded in already-regulated products, like medical devices or machinery under Annex I, gets the longest runway.

The Omnibus didn't just move dates. It also folded a new prohibition into Article 5 targeting AI-generated non-consensual intimate imagery, sometimes called "nudifier" tools, and child sexual abuse material - a provision that arrived with strong cross-party support and sits alongside the existing bans on practices like social scoring and manipulative AI. It reinstated a registration requirement for providers who consider their systems exempt from high-risk classification, giving the AI Office visibility it would otherwise lack. And it expanded the AI Office's enforcement toolkit, including the power to seal premises and impose daily penalty payments during active investigations.

What hasn't moved, and never was on the table: the ban on prohibited practices already in force since February 2025, the AI literacy obligations, and the GPAI rules described above. Those tracks were live before the Omnibus and remain live now that it's finalized.

Comparing what's actually left to compare

With EO 14110 gone, a fair comparison isn't "EU risk tiers versus US compute thresholds" anymore. It's a comparison between a mandatory legal regime and a voluntary-plus-preemption approach that treats federal restraint as the policy goal itself.

Nature of regulation and enforcement

The EU AI Act is horizontal, legally binding, and enforced through the AI Office and national competent authorities, with penalties that outscale even GDPR's. The current US posture has no equivalent enforcement body and, by design, avoids creating one. Compliance in the US context is now demonstrated through voluntary standards adoption, federal procurement requirements, or defensive positioning against state law - not through anything resembling a conformity assessment.

Risk-based versus preemption-based logic

The EU still classifies systems by what they do: an AI tool used to grade exams is high-risk regardless of how large or small the underlying model is. The US, having abandoned its own compute-based trigger along with EO 14110, has replaced it with a federalism argument - the claim that a single national posture, even a light one, beats fifty different state regimes. The Colorado episode shows how that argument plays out in practice: not a clean federal knockout, but sustained pressure that pushes a state to legislate a narrower rule voluntarily. Whether the same pattern repeats in California, Texas, or Illinois is one of the more consequential open questions in US tech policy this year, and it's a natural companion question to how algorithmic sentencing tools are regulated at the state level more broadly, since both fights turn on the same underlying tension between federal uniformity and local accountability.

Data governance and documentation

The EU's data governance bar - complete, representative, statistically validated training data - remains the highest globally, and nothing in the current US executive-order sequence approaches it. A company already meeting EU AI Act data governance requirements will, in practice, clear any US regulatory expectation without much additional work. That asymmetry alone is why many multinational compliance teams still build to the EU standard first and treat US alignment as a byproduct.

Extraterritoriality

This is the one place where the comparison hasn't changed at all. The EU AI Act's extraterritorial reach means a US company serving a bank in Paris or a hospital in Warsaw is in scope, headquarters location notwithstanding. It remains the clearest example of the "Brussels Effect" in AI policy - a phenomenon worth understanding in its own right if you're weighing how far EU rules will shape practice outside the bloc.

The Brussels Effect is real: extraterritorial reach means US firms serving European clients cannot escape the anvil.

Strategic recommendations for multinational compliance

For any organization operating across both markets, chasing each executive order as it lands is not a strategy - it's whiplash. The more durable approach is building to the strictest applicable standard and treating everything looser as a subset of that work.

ISO/IEC 42001 as the connective layer

ISO/IEC 42001, the international standard for AI Management Systems, has become the practical bridge between "mandatory EU law" and "voluntary US guidance." It shares its structure with ISO 27001, which means organizations with existing information security certifications can extend rather than rebuild. NIST has published an official crosswalk mapping every AI RMF subcategory to a corresponding ISO 42001 clause - Govern maps broadly to leadership and planning controls, Map to impact assessment, Measure to monitoring, Manage to operational controls - so a single certified management system can serve as evidence across both regimes at once.

It's worth being precise about what ISO 42001 does and doesn't do. Certification demonstrates governance maturity; it doesn't discharge EU AI Act obligations outright. Conformity assessments, database registration, and fundamental rights impact assessments for high-risk systems are legal requirements the standard doesn't replace. And as Colorado's rewrite makes clear, it's no longer a guaranteed legal shield in the US either - treat ISO 42001 as the audit-ready wrapper around your compliance work, not a substitute for it, and don't assume framework alignment buys you a statutory defense unless the specific law you're relying on still says so.

Building one documentation vault, not three

Firms still splitting compliance work into separate EU, US, and internal governance files are duplicating a large share of the same effort - the same risk assessments, the same data lineage records, reformatted three different ways for three different audiences. A single modular repository should include:

  • Data provenance records - sources, cleaning steps, and documented bias mitigation.
  • Model cards and transparency reports - standardized summaries that double as GPAI documentation in the EU and as red-teaming evidence in the US.
  • Lifecycle risk assessments - a living record tracking risk from design through post-market monitoring, mapped once against EU AI Act articles, NIST RMF functions, and ISO 42001 clauses simultaneously.

Human oversight isn't optional in either framework

Whatever else has diverged, both regimes still converge on one point: humans need a real ability to intervene in AI-driven decisions. In the EU, that's a binding requirement for high-risk systems under Article 14. In the US, it survives as a core principle of the NIST RMF's Govern and Manage functions, and it's precisely the kind of obligation that survived Colorado's rewrite even as the mandatory impact assessments didn't - the new ADMT law still expects meaningful human review before a consequential decision goes final. Architecting for human-in-the-loop oversight and explainable outputs from the start avoids an expensive retrofit later, regardless of which framework ends up mattering most for a given deployment. This matters especially for AI-assisted hiring, screening, and credit-scoring tools, which now sit squarely inside the EU's high-risk category and deserve their own dedicated compliance review well before the December 2027 Annex III deadline arrives.

Chasing shifting orders is whiplash. Build to the strict EU standard, wrap it in ISO 42001, and survive both regimes.

A quick note on frontier-model security

One thread that didn't exist in this comparison two years ago is starting to matter: both jurisdictions are now treating the most capable frontier models as a distinct category with its own security expectations, separate from ordinary consumer-facing AI compliance. The EU's GPAI systemic-risk tier and the US's voluntary frontier-model review framework under EO 14409 are structured very differently - one is a binding classification with mandatory red-teaming, the other a voluntary pre-release arrangement - but both signal that regulators on both sides of the Atlantic now see frontier capability, rather than deployment context alone, as something worth watching on its own terms.

What comes next

Two very different governance philosophies are now running in parallel rather than in dialogue. The EU has locked in its delay while holding firm on GPAI enforcement and prohibited practices - a regime maturing under real legal weight, not a moving target anymore. The US has spent eighteen months systematically dismantling federal oversight infrastructure while quietly building cybersecurity-specific mandates and a preemption fight that, in Colorado at least, has already produced a concrete result.

Neither trajectory is finished. Other states are watching Colorado's rewrite closely, and it's an open question whether California, Texas, or Illinois follow the same path or hold their ground in court. Congress still hasn't produced a comprehensive federal AI law - something that still doesn't exist even after three years of executive maneuvering - and whether it ever will remains genuinely uncertain, especially heading into a midterm election year.

For companies operating across both jurisdictions, that uncertainty isn't a reason to wait. It's a reason to build governance infrastructure sturdy enough to absorb whichever direction either side turns next.

Key takeaways

  • EO 14110 no longer exists. President Trump revoked it on January 20, 2025, and replaced it days later with an order titled Removing Barriers to American Leadership in Artificial Intelligence.
  • The EU AI Act remains a legally binding regulation, in force since August 2024, unaffected by the US policy reversal.
  • The US has abandoned its compute-based reporting trigger - the old 10^26 floating-point-operations threshold for "dual-use foundation models" no longer applies to anything.
  • December 2025's EO 14365 directs a DOJ AI Litigation Task Force to challenge "onerous" state AI laws; it named Colorado's original AI Act directly.
  • Colorado's original AI Act (SB 24-205) never took effect. After a federal court stayed it amid an xAI lawsuit joined by the DOJ, Colorado repealed and replaced it with SB 26-189, a narrower ADMT law effective January 1, 2027 - the first concrete outcome of the federal preemption push.
  • That rewrite eliminated Colorado's NIST/ISO 42001 safe harbor: demonstrated framework alignment is no longer a codified legal defense anywhere in the US.
  • A June 2026 executive order (EO 14409) adds voluntary cybersecurity mandates and a pre-release review framework for "frontier" AI models but explicitly creates no licensing or preclearance requirement.
  • EU GPAI obligations have applied since August 2, 2025; European Commission enforcement powers, including fines, activate August 2, 2026.
  • The Digital Omnibus on AI is now binding EU law (Regulation (EU) 2026/1744), in force since July 27, 2026 - not a pending proposal. It pushes the main high-risk deadline to December 2, 2027 for standalone Annex III systems and August 2, 2028 for high-risk AI embedded in regulated products.
  • The same Omnibus adds a new Article 5 prohibition on AI-generated non-consensual intimate imagery ("nudifiers") and CSAM, alongside the Act's existing banned practices.
  • GPAI-specific fines reach the greater of €15 million or 3% of global turnover; the Act's most serious violations can reach €35 million or 7% of global annual turnover.
  • ISO/IEC 42001, backed by an official NIST crosswalk mapping RMF functions to ISO clauses, remains the practical bridge between mandatory EU compliance and voluntary US standards - though it's a documentation aid, not an automatic legal shield in either jurisdiction.

Sources

 avatar
@wiktoria
  • Redaction badge
    Redaction
Wiktoria Wysocka
Digital Rights & Policy Analyst
Wiktoria Wysocka is a legal consultant who navigates the rapidly evolving terrain where digital technology collides with civil rights, data privacy, and corporate accountability. With a sharp instinct for regulatory complexity, she deciphers the dense legal frameworks governing AI liability, platform regulation, and surveillance capitalism, translating them into practical knowledge for developers, businesses, and everyday users. She believes most people are not confused by technology - they are confused by the law that governs it - and she writes to close that gap with precision and clarity.

Latest articles by Wiktoria Wysocka

No posts yet