ServicesLive DemosMCPEngineeringAboutProcessContactGet Started
Regulatory exposure

What EU AI Act non-compliance
actually costs

Enterprises with any EU exposure now carry material financial risk from AI systems, whether or not they built those systems in-house. Here's the penalty structure as written into the Act, and what's already enforceable today versus what phases in.

Three penalty tiers, Article 99

€35M or 7%

of global annual turnover, whichever is higher

Prohibited AI practices

In force

Article 5 violations — the highest tier. These provisions have been in force since February 2025.

€15M or 3%

of global annual turnover, whichever is higher

High-risk system & GPAI provider obligations

Phasing in

Non-compliance with the requirements for high-risk AI systems or general-purpose AI model obligations.

€7.5M or 1%

of global annual turnover, whichever is higher

Incorrect or incomplete information

Phasing in

Supplying incorrect, incomplete, or misleading information to regulators or notified bodies.

Whichever figure is higher applies to large enterprises; SMEs and startups face the lower of the two amounts in each tier.

What's already live vs. what's coming

Feb 2025

Prohibited-practice provisions and AI literacy obligations took effect — the €35M/7% tier is already enforceable.

Aug 2025

General-purpose AI model provider obligations and governance-authority designations took effect.

Aug 2026

High-risk system obligations (Annex III — the category most enterprise AI agents in finance, HR, and CRM fall into) and Article 50 transparency requirements (AI-generated content disclosure, chatbot disclosure) phase in — the deadline most mid-market enterprises still have open exposure against.

Aug 2027

High-risk systems that are safety components of products already regulated under existing EU product-safety law (Annex I — machinery, medical devices, and similar) get a one-year later deadline.

Dates per the EU AI Act's official timeline; not legal advice. Confirm applicability for your specific system with counsel. Reviewed 2026-07-27.

Where ISO 42001 fits in

ISO 42001 certification isn't itself an EU AI Act requirement, but it's emerging as the proof point enterprise buyers use to screen whether a vendor's governance claims are real rather than self-reported — reason enough to build toward it even before certification is complete.

See how NIST AI RMF, ISO 42001, and the EU AI Act line up →

Not sure which tier applies to you?

A quick, rules-based check — select what your AI system does, get the likely risk tier and penalty exposure.

Run the readiness calculator →

Tioga AI's EU AI Act Conformity Program covers Article 50 / state-law readiness and full conformity documentation.

See the Conformity Program →