What EU AI Act non-compliance
actually costs
Enterprises with any EU exposure now carry material financial risk from AI systems, whether or not they built those systems in-house. Here's the penalty structure as written into the Act, and what's already enforceable today versus what phases in.
Three penalty tiers, Article 99
€35M or 7%
of global annual turnover, whichever is higher
Prohibited AI practices
In forceArticle 5 violations — the highest tier. These provisions have been in force since February 2025.
€15M or 3%
of global annual turnover, whichever is higher
High-risk system & GPAI provider obligations
Phasing inNon-compliance with the requirements for high-risk AI systems or general-purpose AI model obligations.
€7.5M or 1%
of global annual turnover, whichever is higher
Incorrect or incomplete information
Phasing inSupplying incorrect, incomplete, or misleading information to regulators or notified bodies.
Whichever figure is higher applies to large enterprises; SMEs and startups face the lower of the two amounts in each tier.
What's already live vs. what's coming
Prohibited-practice provisions and AI literacy obligations took effect — the €35M/7% tier is already enforceable.
General-purpose AI model provider obligations and governance-authority designations took effect.
High-risk system obligations (Annex III — the category most enterprise AI agents in finance, HR, and CRM fall into) and Article 50 transparency requirements (AI-generated content disclosure, chatbot disclosure) phase in — the deadline most mid-market enterprises still have open exposure against.
High-risk systems that are safety components of products already regulated under existing EU product-safety law (Annex I — machinery, medical devices, and similar) get a one-year later deadline.
Dates per the EU AI Act's official timeline; not legal advice. Confirm applicability for your specific system with counsel. Reviewed 2026-07-27.
Where ISO 42001 fits in
ISO 42001 certification isn't itself an EU AI Act requirement, but it's emerging as the proof point enterprise buyers use to screen whether a vendor's governance claims are real rather than self-reported — reason enough to build toward it even before certification is complete.
See how NIST AI RMF, ISO 42001, and the EU AI Act line up →Not sure which tier applies to you?
A quick, rules-based check — select what your AI system does, get the likely risk tier and penalty exposure.
Run the readiness calculator →Tioga AI's EU AI Act Conformity Program covers Article 50 / state-law readiness and full conformity documentation.
See the Conformity Program →