Operating internationally means that your local offices must operate within local regulations and laws. The EU AI Act adds another layer of compliance for U.S. companies whose AI systems or outputs are used in the European Union. Article 50, which took effect Aug. 2, 2026, establishes transparency requirements for certain AI systems and AI-generated or manipulated content.
Those requirements can affect more than a company's European offices. U.S.-based teams that develop, deploy or manage AI systems used in the EU may also need to comply with the Act's transparency obligations and demonstrate how those systems and their outputs are governed.
Let’s back up a little before you become overwhelmed and think every piece of paper needs to be verified, stamped and locked in a vault for a possible future inspection.
With AI weaving ever deeper into business operations and daily life, it makes sense that regulators are establishing guardrails and clearer accountability alongside the technology.
Earlier AI-governance frameworks offer some context. The Monetary Authority of Singapore (MAS), for example, introduced guidance intended to strengthen AI risk management in financial institutions after its Veritas Initiative worked to support financial institutions in incorporating principles of Fairness, Ethics, Accountability and Transparency (FEAT).
This was initiated in 2018, and without going into too much detail on the various steps taken after that, let’s focus on one of the big takeaways from that process: the “Named Executive,” which also shows up in the EU AI Act. This is the executive who will hold the ultimate responsibility for a decision made using AI, altered by AI or somehow created by AI, reviewed by a human and presumed signed off by an executive.
What does Article 50 of the EU AI Act require?
In researching this piece, I had the good fortune to speak with Warwick Hill, founder and CEO of Sigillum, the London-based system of proof for high-stakes records. He and his team have taken the time to tease out the details in Article 50 so they could build a system that will help businesses prepare to meet the regulation and avoid fines.
Warwick shared with me the following paragraph that explains his view of the practical impact on organizations:
“Article 50 is the AI Act obligation that catches most organizations, far beyond just high-risk AI providers. A company with no high-risk AI at all still has duties the moment it runs a chatbot or publishes AI-generated content. That means these sectors — media, tech, social, advertising — are in scope from 2 August 2026, while the high-risk regime most coverage focuses on was deferred. And under the final Code of Practice, non-signatories face heavier evidentiary burdens and more frequent information requests. Whichever route a company takes, the obligation resolves to producible evidence.
“In essence,” Warwick explained, “it’s about proving content is legal, created by the company.” A company is expected to demonstrate the validity of the content it produces, whether it was AI-generated or influenced by AI, and who is responsible for it.
Right now, only chatbots are impacted by this requirement.
If you imagine a conical or pyramid-shaped tech stack, showing what services were used, where they were used, who used them, and finally at the top, who managed that decision, then you can see how a “Named Executive” becomes the one responsible for a given decision that allowed the creation of the material under review. This “Named Executive” is then considered personally liable.
Accountability is moving from companies to named executives, and brings global penalties along with it.
How does Article 50 apply to U.S. companies?
Doing business in the EU will now become more regulated than it already was for foreign corporations. In the United States, globally operating corporations will need to make adjustments to how they produce, approve and store content. In particular, content tied to decisions. They can no longer rely on “We reviewed it.” This must now be demonstrable, per piece, by a named responsible person.
It will require an adjustment in moral and ethical governance and a shift in mentality for executives.
Not all data or content needs to meet the stringent accountability criteria. Ordinary data won’t need:
- Integrity — what a stranger can check: An outsider must be able to confirm a record is unchanged without just trusting you.
- Timing — that predates the contest: Evidence only settles a dispute if it demonstrably existed before the dispute began. It cannot be backdated by the owner.
- Attribution — that survives the challenge: Where a decision is at issue, it matters who was answerable. That binding can’t be quietly reassigned after the fact.
What should U.S. companies do to prepare for EU AI Act compliance?
There are different ways to prepare to meet the requirements of the EU AI Act, and Article 50 in particular. Note that everything before August 2, 2026 doesn’t apply, which means there’s still time to make sure all current data meets the requirements going back to August of this year.
Or take a risk and wait until someone asks you for proof. The value of the content/data is not realized when it’s created, but when someone asks you to prove it.
U.S. companies doing business in the EU have adjusted to GDPR (General Data Protection Regulation) and will adjust to this as well, but it will take planning and changes to the way executives operate, as they can now be held personally liable.
Helping businesses prepare to meet the EU AI Act regulations is why Warwick Hill founded Sigillum, which offers a system of proof — insurance, in essence. If, as stated, 57% of companies name AI errors as their leading risk and no platform says who, by name, answers for that agent, then that’s a big gaping hole that could cost you millions in fines.