EU AI Act Fines, Deadlines & Compliance Guide
Everything you need to know about the EU AI Act. Scope, prohibited practices, non-compliance fines up to €35M, and the real compliance deadlines for 2026-2028.

A technology enthusiast's plain-English walk through what the Act actually asks of us.
Let me get one thing off my chest first. I am still not sure how I feel about the EU AI Act referring to us, the entire human race, as “natural persons.” There, I have said it. Now we can move on. 😅
I am not a lawyer, but I am a genuine technology enthusiast, and I have spent more hours than I would like to admit reading the Act and its addendums. So consider this your friendly shortcut. Let’s dig into what the EU AI Act means in real terms, and hopefully save you reading the 144 pages of the Act in the process!
What is the EU AI Act? What is the act really trying to do?
At its heart, the Act starts from a simple premise: AI should be a human-centric technology. It should serve as a tool for people, with the ultimate aim of increasing human well-being. That single idea shapes almost everything that follows.
From there, the rules are meant to be clear and robust in protecting fundamental rights, while still supporting new and innovative solutions. The ambition is to enable a European ecosystem of public and private organisations building AI systems in line with Union values, and to unlock the potential of digital transformation across every region of the Union. In other words, protect people first, but do not smother the innovation that AI accelerates..
There is also a deliberate focus on smaller players. The Act includes measures to support innovation with particular attention to small and medium enterprises and startups, part of Europe's stated goal of leading the world in secure, trustworthy and ethical AI use.
A quick observation: one of these measures is a “shared” yet logically isolated sandbox for SMEs and startups, offered for free. Sandbox as a Service as the new SaaS, if you like. It is a lovely idea, though it raises plenty of questions for me around data privacy, cost recovery, and the entry and exit criteria of sandbox use. I am skeptical, but genuinely interested to see how it plays out.
Prohibited AI practices under the EU AI Act
Some uses of AI are considered dangerous enough to be prohibited outright. Two stand out:
- Manipulation that causes harm. AI systems placed on the market, put into service, or used with the objective or effect of materially distorting human behaviour, where significant harm is likely, particularly serious adverse impacts on physical or psychological health or on financial interests.
- Social scoring. AI must not be used to score natural persons in ways that could produce discriminatory results.
Both come back to the same principle: people should not be quietly nudged, manipulated, or ranked in ways that damage them.
Who and what does the EU AI Act apply to?
A common misconception is that this is an EU-only concern. It is not. The Act applies to organisations outside the EU that interact and trade with organisations inside it. If your AI touches the EU market, it very likely touches you.
Beyond that reach, the Act pays special attention to a set of higher-risk domains, including:
- Remote biometric identification systems.
- AI used as a component in the management and operation of critical digital infrastructure, road traffic, or the supply of water, gas, heating or electricity.
- AI used to evaluate learning outcomes, including where those outcomes steer the learning process of people in education and vocational training.
- HR systems used for recruitment or selection, such as placing targeted job adverts, filtering applications, and evaluating candidates.
- Law enforcement and border control.
That phrase “critical digital infrastructure” is worth pausing on, because it is defined by cross-reference rather than in the Act itself. The Critical Entities Resilience (CER) Directive frames critical infrastructure across 11 sectors: energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, public administration, space, and food.
If your organisation sits anywhere in that list, the Act is not abstract. It is in your world.
EU AI Act Fines and Penalties
Rules are only as strong as their consequences, and here the Act does not hold back. Under Article 20, providers of high-risk AI systems who consider, or have reason to consider, that a system they have placed on the market is not compliant must immediately take corrective action: bring it into conformity, withdraw it, disable it, or recall it as appropriate. There is no quiet waiting-and-seeing.
What are the penalties for non compliance?
The financial penalties scale with the seriousness of the breach. Administrative fines can reach EUR 15,000,000 or, for an undertaking, up to 3 percent of total worldwide annual turnover for the preceding financial year, whichever is higher. Where the breach endangers the health or fundamental rights of EU natural persons (humans 😅), that ceiling rises to EUR 35,000,000 or 7 percent. These are numbers that reach the boardroom.
EU AI Act deadlines: What applies and when?
The Act entered into force on 1 August 2024, and some deadlines have since shifted. A few foundational dates have stayed put: the prohibited-practices and AI-literacy rules applied from 2 February 2025, and the general-purpose AI (GPAI) obligations from 2 August 2025. The high-risk timelines, however, have been pushed back:
The extra breathing room is welcome, but it is breathing room, not a reprieve. The direction of travel has not changed. The suggestion is to adopt and manage AI securely making compliance less of a heavy lift when the auditors arrive.
EU AI Act Articles Every AI Builder Should Know
If you actually design, ship, or operate high-risk AI, a handful of articles carry most of the day-to-day weight. Here is the short version:
- Article 9, Risk Management. High-risk systems must be tested against pre-defined metrics and probabilistic thresholds, throughout development and before going live, sometimes even in real-world conditions.
- Article 10, Data Governance. You must detect, prevent and mitigate bias, and handle any special categories of personal data with real care.
- Article 13, Transparency. Deployers need the full picture, intended purpose, accuracy, robustness, cybersecurity, data specifications, and logging mechanisms.
- Article 14, Human Oversight. Systems must be designed so people can genuinely oversee them, stay alert to automation bias, and step in, including a reliable way to stop the system safely.
- Article 15, Accuracy, Robustness and Cybersecurity. Systems must be accurate, robust, resilient to faults and feedback loops, and able to withstand attempts by unauthorised parties to alter their behaviour.
- Article 72, Post-market Monitoring. Providers must keep collecting and analysing performance data across a system's whole lifetime.
- Article 73, Serious Incidents. Serious incidents must be reported promptly once a causal link is established, and within tight windows, no later than 15 days, and as little as two days for major incidents.
- Article 74, Enforcement. Market surveillance authorities can, under specific and justified conditions, request access to a system's source code to assess conformity.
It is genuinely encouraging that the Act (see Article 79) specifies and enforces action where AI poses a threat to the life and fundamental rights of EU natural persons. That is the human-centric premise showing up in practice, not just in the preamble.
Final Thoughts
The EU AI Act was ahead of its time when it arrived in 2024, and while some timelines and implementation details have since been amended, its core intent has held firm. It holds organisations of every shape and size to account for both the direct and indirect use of AI, across a wide range of industries and state-level concerns.
For me, the practical takeaway is this. AI, and increasingly agentic AI, evolves in ways that are not deterministic, so continuous monitoring at the semantic layer is really the only way to keep pace. Red teaming ahead of your adversaries keeps you ahead of the curve. And an old but still fitting saying applies: you cannot protect what you cannot see. Automatic, wide, cross-platform discovery of where AI is actually being used is fast becoming a foundational requirement of AI security and governance, not a nice-to-have.
If you have read this far, thank you. The Act is long, occasionally dry, and fond of calling us “natural persons”, but underneath the legalese sits a genuine attempt to keep AI working securely for people and encourages innovation. That feels worth understanding, and worth getting right.
A technology enthusiast's plain-English walk through what the Act actually asks of us.
Let me get one thing off my chest first. I am still not sure how I feel about the EU AI Act referring to us, the entire human race, as “natural persons.” There, I have said it. Now we can move on. 😅
I am not a lawyer, but I am a genuine technology enthusiast, and I have spent more hours than I would like to admit reading the Act and its addendums. So consider this your friendly shortcut. Let’s dig into what the EU AI Act means in real terms, and hopefully save you reading the 144 pages of the Act in the process!
What is the EU AI Act? What is the act really trying to do?
At its heart, the Act starts from a simple premise: AI should be a human-centric technology. It should serve as a tool for people, with the ultimate aim of increasing human well-being. That single idea shapes almost everything that follows.
From there, the rules are meant to be clear and robust in protecting fundamental rights, while still supporting new and innovative solutions. The ambition is to enable a European ecosystem of public and private organisations building AI systems in line with Union values, and to unlock the potential of digital transformation across every region of the Union. In other words, protect people first, but do not smother the innovation that AI accelerates..
There is also a deliberate focus on smaller players. The Act includes measures to support innovation with particular attention to small and medium enterprises and startups, part of Europe's stated goal of leading the world in secure, trustworthy and ethical AI use.
A quick observation: one of these measures is a “shared” yet logically isolated sandbox for SMEs and startups, offered for free. Sandbox as a Service as the new SaaS, if you like. It is a lovely idea, though it raises plenty of questions for me around data privacy, cost recovery, and the entry and exit criteria of sandbox use. I am skeptical, but genuinely interested to see how it plays out.
Prohibited AI practices under the EU AI Act
Some uses of AI are considered dangerous enough to be prohibited outright. Two stand out:
- Manipulation that causes harm. AI systems placed on the market, put into service, or used with the objective or effect of materially distorting human behaviour, where significant harm is likely, particularly serious adverse impacts on physical or psychological health or on financial interests.
- Social scoring. AI must not be used to score natural persons in ways that could produce discriminatory results.
Both come back to the same principle: people should not be quietly nudged, manipulated, or ranked in ways that damage them.
Who and what does the EU AI Act apply to?
A common misconception is that this is an EU-only concern. It is not. The Act applies to organisations outside the EU that interact and trade with organisations inside it. If your AI touches the EU market, it very likely touches you.
Beyond that reach, the Act pays special attention to a set of higher-risk domains, including:
- Remote biometric identification systems.
- AI used as a component in the management and operation of critical digital infrastructure, road traffic, or the supply of water, gas, heating or electricity.
- AI used to evaluate learning outcomes, including where those outcomes steer the learning process of people in education and vocational training.
- HR systems used for recruitment or selection, such as placing targeted job adverts, filtering applications, and evaluating candidates.
- Law enforcement and border control.
That phrase “critical digital infrastructure” is worth pausing on, because it is defined by cross-reference rather than in the Act itself. The Critical Entities Resilience (CER) Directive frames critical infrastructure across 11 sectors: energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, public administration, space, and food.
If your organisation sits anywhere in that list, the Act is not abstract. It is in your world.
EU AI Act Fines and Penalties
Rules are only as strong as their consequences, and here the Act does not hold back. Under Article 20, providers of high-risk AI systems who consider, or have reason to consider, that a system they have placed on the market is not compliant must immediately take corrective action: bring it into conformity, withdraw it, disable it, or recall it as appropriate. There is no quiet waiting-and-seeing.
What are the penalties for non compliance?
The financial penalties scale with the seriousness of the breach. Administrative fines can reach EUR 15,000,000 or, for an undertaking, up to 3 percent of total worldwide annual turnover for the preceding financial year, whichever is higher. Where the breach endangers the health or fundamental rights of EU natural persons (humans 😅), that ceiling rises to EUR 35,000,000 or 7 percent. These are numbers that reach the boardroom.
EU AI Act deadlines: What applies and when?
The Act entered into force on 1 August 2024, and some deadlines have since shifted. A few foundational dates have stayed put: the prohibited-practices and AI-literacy rules applied from 2 February 2025, and the general-purpose AI (GPAI) obligations from 2 August 2025. The high-risk timelines, however, have been pushed back:
The extra breathing room is welcome, but it is breathing room, not a reprieve. The direction of travel has not changed. The suggestion is to adopt and manage AI securely making compliance less of a heavy lift when the auditors arrive.
EU AI Act Articles Every AI Builder Should Know
If you actually design, ship, or operate high-risk AI, a handful of articles carry most of the day-to-day weight. Here is the short version:
- Article 9, Risk Management. High-risk systems must be tested against pre-defined metrics and probabilistic thresholds, throughout development and before going live, sometimes even in real-world conditions.
- Article 10, Data Governance. You must detect, prevent and mitigate bias, and handle any special categories of personal data with real care.
- Article 13, Transparency. Deployers need the full picture, intended purpose, accuracy, robustness, cybersecurity, data specifications, and logging mechanisms.
- Article 14, Human Oversight. Systems must be designed so people can genuinely oversee them, stay alert to automation bias, and step in, including a reliable way to stop the system safely.
- Article 15, Accuracy, Robustness and Cybersecurity. Systems must be accurate, robust, resilient to faults and feedback loops, and able to withstand attempts by unauthorised parties to alter their behaviour.
- Article 72, Post-market Monitoring. Providers must keep collecting and analysing performance data across a system's whole lifetime.
- Article 73, Serious Incidents. Serious incidents must be reported promptly once a causal link is established, and within tight windows, no later than 15 days, and as little as two days for major incidents.
- Article 74, Enforcement. Market surveillance authorities can, under specific and justified conditions, request access to a system's source code to assess conformity.
It is genuinely encouraging that the Act (see Article 79) specifies and enforces action where AI poses a threat to the life and fundamental rights of EU natural persons. That is the human-centric premise showing up in practice, not just in the preamble.
Final Thoughts
The EU AI Act was ahead of its time when it arrived in 2024, and while some timelines and implementation details have since been amended, its core intent has held firm. It holds organisations of every shape and size to account for both the direct and indirect use of AI, across a wide range of industries and state-level concerns.
For me, the practical takeaway is this. AI, and increasingly agentic AI, evolves in ways that are not deterministic, so continuous monitoring at the semantic layer is really the only way to keep pace. Red teaming ahead of your adversaries keeps you ahead of the curve. And an old but still fitting saying applies: you cannot protect what you cannot see. Automatic, wide, cross-platform discovery of where AI is actually being used is fast becoming a foundational requirement of AI security and governance, not a nice-to-have.
If you have read this far, thank you. The Act is long, occasionally dry, and fond of calling us “natural persons”, but underneath the legalese sits a genuine attempt to keep AI working securely for people and encourages innovation. That feels worth understanding, and worth getting right.









