Regulatory exposure

What EU AI Act non-compliance
actually costs

Enterprises with any EU exposure now carry material financial risk from AI systems, whether or not they built those systems in-house. Here's the penalty structure as written into the Act, and what's already enforceable today versus what phases in.

Three penalty tiers, Article 99

€35M or 7%

of global annual turnover, whichever is higher

Prohibited AI practices

In force

Article 5 violations — the highest tier. These provisions have been in force since February 2025.

€15M or 3%

of global annual turnover, whichever is higher

High-risk system & GPAI provider obligations

Phasing in

Non-compliance with the requirements for high-risk AI systems or general-purpose AI model obligations.

€7.5M or 1%

of global annual turnover, whichever is higher

Incorrect or incomplete information

Phasing in

Supplying incorrect, incomplete, or misleading information to regulators or notified bodies.

Whichever figure is higher applies to large enterprises; SMEs and startups face the lower of the two amounts in each tier.

What's already live vs. what's coming

Feb 2025

Prohibited-practice provisions and AI literacy obligations took effect — the €35M/7% tier is already enforceable.

Aug 2025

General-purpose AI model provider obligations and governance-authority designations took effect.

Now

Article 50 transparency requirements (AI-generated content disclosure, chatbot disclosure) and Article 4 AI-literacy obligations are already in effect and were not deferred by the Digital Omnibus below — this is the real, current exposure most mid-market enterprises still have open.

Dec 2027

High-risk system obligations (Annex III — the category most enterprise AI agents in finance, HR, and CRM fall into) phase in. Originally Aug 2026; deferred to 2 December 2027 by Regulation (EU) 2026/1744 (the "Digital Omnibus on AI"), in force since 27 July 2026.

Aug 2028

High-risk systems that are safety components of products already regulated under existing EU product-safety law (Annex I — machinery, medical devices, and similar). Originally Aug 2027; deferred one year by the same Digital Omnibus regulation.

Dates per the EU AI Act's official timeline as amended by Regulation (EU) 2026/1744; not legal advice. Confirm applicability for your specific system with counsel. Reviewed against Reg. (EU) 2026/1744, 2026-09-02.

Where ISO 42001 fits in

ISO 42001 certification isn't itself an EU AI Act requirement, but it's emerging as the proof point enterprise buyers use to screen whether a vendor's governance claims are real rather than self-reported — reason enough to build toward it even before certification is complete.

See how NIST AI RMF, ISO 42001, and the EU AI Act line up →

Not sure which tier applies to you?

A quick, rules-based check — select what your AI system does, get the likely risk tier and penalty exposure.

Run the readiness calculator →

Tioga AI's EU AI Act Conformity Program covers Article 50 / state-law readiness and full conformity documentation.

See the Conformity Program →