What EU AI Act non-compliance
actually costs
Enterprises with any EU exposure now carry material financial risk from AI systems, whether or not they built those systems in-house. Here's the penalty structure as written into the Act, and what's already enforceable today versus what phases in.
Three penalty tiers, Article 99
€35M or 7%
of global annual turnover, whichever is higher
Prohibited AI practices
In forceArticle 5 violations — the highest tier. These provisions have been in force since February 2025.
€15M or 3%
of global annual turnover, whichever is higher
High-risk system & GPAI provider obligations
Phasing inNon-compliance with the requirements for high-risk AI systems or general-purpose AI model obligations.
€7.5M or 1%
of global annual turnover, whichever is higher
Incorrect or incomplete information
Phasing inSupplying incorrect, incomplete, or misleading information to regulators or notified bodies.
Whichever figure is higher applies to large enterprises; SMEs and startups face the lower of the two amounts in each tier.
What's already live vs. what's coming
Prohibited-practice provisions and AI literacy obligations took effect — the €35M/7% tier is already enforceable.
General-purpose AI model provider obligations and governance-authority designations took effect.
Article 50 transparency requirements (AI-generated content disclosure, chatbot disclosure) and Article 4 AI-literacy obligations are already in effect and were not deferred by the Digital Omnibus below — this is the real, current exposure most mid-market enterprises still have open.
High-risk system obligations (Annex III — the category most enterprise AI agents in finance, HR, and CRM fall into) phase in. Originally Aug 2026; deferred to 2 December 2027 by Regulation (EU) 2026/1744 (the "Digital Omnibus on AI"), in force since 27 July 2026.
High-risk systems that are safety components of products already regulated under existing EU product-safety law (Annex I — machinery, medical devices, and similar). Originally Aug 2027; deferred one year by the same Digital Omnibus regulation.
Dates per the EU AI Act's official timeline as amended by Regulation (EU) 2026/1744; not legal advice. Confirm applicability for your specific system with counsel. Reviewed against Reg. (EU) 2026/1744, 2026-09-02.
Where ISO 42001 fits in
ISO 42001 certification isn't itself an EU AI Act requirement, but it's emerging as the proof point enterprise buyers use to screen whether a vendor's governance claims are real rather than self-reported — reason enough to build toward it even before certification is complete.
See how NIST AI RMF, ISO 42001, and the EU AI Act line up →Not sure which tier applies to you?
A quick, rules-based check — select what your AI system does, get the likely risk tier and penalty exposure.
Run the readiness calculator →Tioga AI's EU AI Act Conformity Program covers Article 50 / state-law readiness and full conformity documentation.
See the Conformity Program →