New Phase of EU AI Act Takes Effect: Compliance and Cost Challenges for U.S. CFOs
The EU AI Act begins a new phase of enforcement on August 2, 2025, requiring newly deployed AI systems (such as chatbots) targeting the EU market to be clearly labeled and disclosed. U.S. corporate CFOs need to focus on two major risks: fines of up to 35 million euros or 7% of global annual revenue (whichever is higher) per violation, and in extreme cases, AI platforms may be banned. The Act applies to both deployers and providers and has extraterritorial effect. Companies must prepare in advance in areas such as role identification, training, legal review, and documentation to control compliance costs and operational risks.

A U.S. company's chatbot, if made available to EU users, could soon pose significant compliance hurdles and additional costs for financial executives.
Starting August 2,the EU AI Actenters a new enforcement phase, requiring all AI systems newly deployed to the EU market, such as chatbots and other AI-generated content, to be clearly labeled and disclose their AI nature.
For CFOs of U.S. companies, this means new obligations, increased compliance workloads, and potentially additional expenses. Similar to theColorado AI Act, the EU regulation applies to both deployers (companies using AI systems) and providers (companies developing AI models).
CFOs need to be alert to two key risks: the company could face fines of up to €35 million or 7% of global annual revenue (whichever is higher) for a single violation; in some cases, its AI platform could even be ordered to be taken offline. This is according to Rohan Massey, head of the data, privacy, and cybersecurity practice at Ropes & Gray and managing partner of the firm's London office.
"If you have a system around which you've built your business operations and are suddenly told you can no longer use it—that's not just a bad day or week, but a direct halt to business," Massey said in an interview.
Providers of general-purpose AI models operating in the EU market, including broad AI systems like large language models, must begin meeting compliance requirements starting August 2, including submitting technical documentation, publishing summaries of training data, providing information to downstream users, and adopting copyright and risk mitigation policies if the model poses systemic risks. Models already on the EU market before August 2 benefit from a two-year transition period, with providers required to achieve compliance by 2027 at the latest.
For U.S. finance teams, the impact is broad: they need to clarify their roles, budget for training and legal reviews, and document decision-making processes under a legal framework with extraterritorial effect. Requirements related to training employees involved in handling AI systems took effect on February 2, 2025.
Many companies lacking internal capabilities may turn to external legal counsel—Massey notes that CFOs should factor this cost into their compliance planning.
Deployer or provider? The line is blurred
The challenge for many companies is determining whether they are deployers or providers under the law. AlthoughEU guidelinessuggest that substantial modifications (such as changing more than 33% of a model's training compute) could make a company a provider, the distinction remains unclear. Companies also need to assess whether, in the process of customizing foundation models, they have shifted from being a deployer to a provider—this could become a significant issue.
Massey points out that the law does not clearly define when that threshold is crossed, although this ambiguity may be clarified over the next five years through enforcement practices.
Certain "high-risk" AI systems, broadly defined by the regulation, may force companies to temporarily suspend systems to meet additional documentation and risk management requirements, thereby driving up costs. These systems include applications used in biometric identification, critical infrastructure, education, employment, essential services, law enforcement, immigration, and justice. These obligations do not take effect until mid-2026.
"Many organizations may find themselves classified as high-risk, and I think—especially from a U.S. perspective—this will be somewhat surprising," he said.
Meanwhile, the Act has already fully banned "unacceptable risk" AI systems since 2024, including applications used for social scoring, emotion recognition in schools or workplaces, and manipulative AI targeting vulnerable groups. Companies found using or providing such tools within the EU may face immediate enforcement actions, including being required to withdraw from the market.
Early preparation steps—including inventorying AI systems and assessing provider and deployer roles—can help control costs and reduce risks, but compliance may be a moving target.
"We will likely see more guidance by the end of this year or early next year—and the timing of guidance may be quite close to implementation deadlines, which may not leave ample preparation time," Massey said.