Updated June 2026: The EU's Digital Omnibus on AI has deferred the high-risk AI obligations — Annex III systems now comply by December 2, 2027 and Annex I embedded systems by August 2, 2028. But this is a deferral, not a repeal: Article 50 transparency obligations still apply from August 2, 2026, and prohibited-practice penalties have been live since February 2025.

The penalty architecture of the EU AI Act is unchanged — only the high-risk applicability dates moved. Organizations that treat the deferral as a reason to pause are misreading it: conformity assessments, risk-management systems and documentation typically take 12–18 months of structured work.

And the penalties are severe. Up to €35 million or 7% of global annual revenue — whichever is higher. For context, that exceeds even the GDPR's maximum of €20 million or 4% of turnover.

If your organization deploys AI systems that serve EU customers, processes EU resident data, or operates within the EU — this applies to you. Here's what CISOs, CTOs, and compliance leaders need to know right now.

TL;DR — The Numbers That Matter

  • €35M or 7% of global revenue — Prohibited AI practices (social scoring, unauthorized biometrics, subliminal manipulation)
  • €15M or 3% of global revenue — Non-compliance with high-risk AI requirements (missing risk management, no documentation, inadequate human oversight)
  • €7.5M or 1.5% of global revenue — Providing incorrect or misleading information to regulators
  • August 2, 2026 — Article 50 transparency obligations apply (chatbots, deepfakes, synthetic content)
  • December 2, 2027 — Annex III high-risk obligations apply (deferred from Aug 2026 by the Omnibus)
  • August 2, 2028 — Annex I high-risk obligations apply (medical devices, machinery, vehicles — deferred from Aug 2027)

For a company with €500M in annual revenue, the maximum Tier 1 penalty would be €35M (7% = €35M). For a company with €1B in revenue, it jumps to €70M. The regulation applies whichever is higher.

The Enforcement Timeline

The EU AI Act entered into force on August 1, 2024 with a phased enforcement schedule:

DateWhat Takes EffectStatus
Feb 2, 2025Prohibited AI practices banned + AI literacy requirements✅ Already enforced
Aug 2, 2025General-Purpose AI model rules (Chapter V) + governance structure✅ Already enforced
Aug 2, 2026Article 50 transparency obligations — chatbots, deepfakes, AI-generated content disclosure⚠️ Weeks away
Dec 2, 2026Watermarking grace period ends for existing systems + new NCII/CSAM prohibition applies🔜 New (Omnibus)
Dec 2, 2027Annex III high-risk AI obligations (Chapter III) — deferred from Aug 2026🔜 Deferred
Aug 2, 2028Annex I high-risk — AI in regulated products (medical devices, machinery, vehicles) — deferred from Aug 2027🔜 Deferred

Key point: Prohibited AI practices are already enforceable as of February 2025. If you're using social scoring, unauthorized biometric identification, or emotion recognition in the workplace, you are already in violation — and already exposed to the €35M/7% penalty tier.

Three Penalty Tiers Explained

The EU AI Act establishes three tiers of administrative fines under Article 99, each corresponding to different categories of violations:

Tier 1 — €35 Million or 7% of Global Turnover

Reserved for the most serious violations: prohibited AI practices under Article 5.

  • Social scoring systems used by or on behalf of public authorities
  • Real-time remote biometric identification in public spaces (beyond narrow exceptions)
  • AI using subliminal manipulation techniques that cause harm
  • AI exploiting vulnerabilities of specific groups (children, elderly, disabled)
  • Emotion recognition in workplaces or educational institutions
  • Untargeted scraping of facial images from the internet or CCTV
  • Biometric categorization inferring sensitive attributes (race, religion, sexual orientation)
  • Predictive policing based solely on profiling

Tier 2 — €15 Million or 3% of Global Turnover

Covers the broadest range of violations — non-compliance with high-risk AI system requirements. This is where most organizations will face exposure once high-risk obligations apply (December 2, 2027 for Annex III systems) — and where transparency failures under Article 50 bite from August 2026:

  • Missing or inadequate risk management system (Article 9)
  • Data governance failures (Article 10)
  • Insufficient technical documentation (Article 11)
  • Inadequate record-keeping and logging (Article 12)
  • Failure to provide transparency information to deployers (Article 13)
  • Insufficient human oversight design (Article 14)
  • Inadequate accuracy, robustness, or cybersecurity (Article 15)
  • Missing quality management system (Article 17)
  • Failure to conduct conformity assessment (Article 43)
  • Failure to register high-risk AI in the EU database (Article 49)
  • Non-compliance with deployer obligations (Article 26)
  • Failure to meet transparency obligations for limited-risk systems (Article 50)

Tier 3 — €7.5 Million or 1.5% of Global Turnover

Targets dishonesty and obstruction in regulatory interactions:

  • Providing false or incomplete data to national authorities
  • Misleading information in conformity assessment documentation
  • Inaccurate registration information in the EU database
  • Obstruction during market surveillance activities

How Exposed Is Your Organization?

Our free assessment calculates your estimated regulatory penalty exposure based on your actual governance maturity — with specific EU AI Act gap identification.

What Counts as High-Risk AI?

The December 2027 deadline targets high-risk AI systems as defined in Article 6 and Annex III. Your AI system is high-risk if it falls into any of these categories:

  • Biometrics — Remote biometric identification, categorization, emotion recognition
  • Critical infrastructure — AI managing road traffic, water, gas, heating, electricity supply
  • Education & vocational training — AI determining access to education, evaluating learning outcomes, detecting cheating
  • Employment & workers management — AI for recruitment, job advertising targeting, evaluating candidates, making promotion/termination decisions, monitoring performance
  • Essential services — AI assessing creditworthiness, setting insurance risk/pricing, evaluating emergency service calls
  • Law enforcement — AI assessing risk of criminal behavior, polygraph alternatives, evidence reliability
  • Migration & border control — AI for visa processing, asylum application assessment
  • Justice & democratic processes — AI assisting judicial interpretation, influencing elections

Critical for CISOs: If your organization uses AI for credit scoring, insurance underwriting, recruitment screening, employee performance evaluation, or customer service triage that affects access to essential services — you likely have high-risk AI systems under the Act.

Who Is Actually Affected?

The EU AI Act has extraterritorial reach — similar to the GDPR. It applies to:

  • Providers — Anyone placing AI systems on the EU market, regardless of where they are based
  • Deployers — Organizations using AI systems within the EU
  • Importers and distributors — Entities in the EU supply chain
  • Non-EU companies whose AI systems produce output used within the EU

This means: A U.S.-based SaaS company whose AI-powered credit scoring tool is used by European banks is subject to the Act. A Canadian HR tech platform whose AI screens job candidates for EU employers is subject to the Act. Geography of your headquarters is irrelevant — what matters is where your AI output is consumed.

The Penalty Math for Your Organization

Regulators consider multiple factors when calculating actual fines (Article 99(3)):

  • Nature, gravity, and duration of the violation — including how many people were affected
  • Intentional vs. negligent — Deliberate non-compliance attracts higher fines
  • Mitigation efforts — Steps taken to reduce harm to affected persons
  • Degree of responsibility — What technical and organizational measures were in place
  • Previous violations — Repeat offenders face escalation
  • Cooperation with authorities — Self-reporting and transparency are mitigating factors
  • Financial benefit gained from the violation

The lesson from GDPR enforcement: having a documented governance program — even an imperfect one — is significantly better than having nothing. Regulators consistently impose lighter penalties on organizations that demonstrate good-faith compliance efforts.

SME and Startup Rules

The Act includes proportionality provisions for smaller organizations. Under Article 99(6), for SMEs and startups, the fine is the lower of the two amounts (percentage vs. fixed cap) — not the higher.

Example: A startup with €2M in annual revenue faces a maximum Tier 1 fine of €140,000 (7% of €2M) rather than €35M. Still significant — potentially existential for an early-stage company — but proportionate.

However, SME status does not exempt you from compliance requirements. You still need risk management systems, documentation, and human oversight for high-risk AI — the fines are just capped lower.

What Regulators Will Check First

Based on GDPR enforcement patterns and the AI Act's emphasis, expect national market surveillance authorities to prioritize:

  1. AI system inventory and registration — Do you know which of your AI systems are high-risk? Are they registered in the EU database?
  2. Risk management system — Is there a documented, ongoing process for identifying, analyzing, estimating, and evaluating AI risks?
  3. Technical documentation — Can you demonstrate how your AI system was designed, developed, tested, and validated?
  4. Human oversight — Are qualified humans empowered to override or shut down AI decisions?
  5. Data governance — Can you demonstrate the quality, relevance, and representativeness of training and validation data?
  6. Conformity assessment — Has your high-risk AI undergone the required assessment procedure?

Get Your AI Governance Maturity Score

Evaluate all 6 regulatory checkpoints above — plus 2 more governance domains — in our free 10-minute assessment. Instant results with penalty exposure estimate.

Your 4-Month Compliance Roadmap

The deferral to December 2027 is breathing room, not a pass — transparency obligations land in weeks and conformity work takes 12–18 months. Here's a realistic 4-month plan to get ahead:

Month 1: Inventory and Classification

  • Conduct a complete AI system inventory — catalog every AI system in use
  • Classify each system against Annex III risk categories
  • Identify which systems qualify as high-risk
  • Map data flows and determine EU exposure

Month 2: Gap Assessment

  • Take an AI Governance Assessment to baseline your maturity
  • Conduct an ISO 42001 gap assessment for framework alignment
  • Document existing controls and identify gaps against Articles 9–17
  • Prioritize gaps by penalty exposure and implementation difficulty

Month 3: Control Implementation

  • Establish or formalize your risk management system (Article 9)
  • Create technical documentation packages for each high-risk system (Article 11)
  • Implement human oversight mechanisms (Article 14)
  • Deploy monitoring and logging capabilities (Article 12)

Month 4: Validation and Registration

  • Complete conformity assessments for high-risk systems (Article 43)
  • Register high-risk AI systems in the EU database (Article 49)
  • Conduct internal audit of compliance program
  • Brief the board and document governance accountability

Beyond Fines: The Real Cost of Non-Compliance

Financial penalties are only part of the picture. The EU AI Act gives national authorities power to:

  • Order withdrawal from market — Your AI system could be forced offline in the EU
  • Require corrective measures — Mandated redesign or reconfiguration
  • Issue public warnings — Reputational damage with customers and partners
  • Demand access to source code — For investigation purposes

And beyond regulatory action, non-compliance creates commercial risk. Enterprise procurement teams in the EU are already adding AI Act compliance to vendor questionnaires. If you can't demonstrate compliance, you lose deals. ISO 42001 certification is emerging as the de facto proof of compliance — organizations with certification will have a competitive advantage.

Next Steps

The transparency deadline of August 2, 2026 is weeks away, and December 2027 arrives faster than a conformity assessment does. Here's how to start today:

  1. Take the free assessment — Our AI Governance Assessment gives you a maturity score, penalty exposure estimate, and prioritized gap list in 10 minutes
  2. Build your AI inventory — Use our AI Inventory Builder to catalog and classify your systems against EU AI Act risk categories
  3. Evaluate ISO 42001 — ISO 42001 is being considered as a harmonized standard under the Act. Certification could create a legal presumption of conformity. Start with our pre-certification gap assessment
  4. Brief your leadership — Share this article and your assessment results with your board. The penalty exposure numbers will accelerate budget approval

Organizations that invest in governance now will be positioned as trusted partners. Organizations that wait will be scrambling — or paying regulators.