Module 4: EU AI Act Deep Dive
7. Timelines and Penalties
Capsule description
This capsule consolidates the practical planning information: when each obligation comes into force and how much non-compliance costs.
Without this information, you can't plan compliance. This capsule is the module's operational reference.
The complete timelines
February 2025: Prohibitions in effect
What applies:
- Art. 5 prohibitions are enforceable.
- Unacceptable Risk systems are prohibited.
Immediate action:
- Identify whether your system falls into the prohibited categories.
- If it does: stop the deploy, re-architect, or exit the EU market.
May 2025: Codes of Practice
What applies:
- Voluntary codes for GPAI.
- Best practices guidance published.
August 2025: GPAI obligations
What applies:
- Art. 51-55 are enforceable.
- GPAI providers must comply.
Action:
- Verify your provider's compliance.
- Update contracts if necessary.
August 2026: High-risk full obligations
What applies:
- Art. 9-15 are enforceable for new deployments.
- A conformity assessment is required.
- Registration is required.
Action (most critical):
- High-risk systems must comply by this date.
- The conformity assessment can take weeks/months — start early.
- Registration must be in place.
August 2027: Existing systems
What applies:
- High-risk systems deployed BEFORE Aug 2026 must also comply.
Action:
- Inventory your existing AI systems.
- Identify the high-risk ones.
- Plan the compliance retrofit.
Visualization: the planning timeline
2024 ──── 2025 ──────────────── 2026 ──────────── 2027
│ │ │
Feb: Prohibited Aug: High-risk Aug: Existing
systems full reqs systems comply
cannot deploy
Aug: GPAI rules
May: Codes of
Practice
For your team:
Today H1 2026 Aug 2026 2027+
│ │ │ │
Classify Build Deploy with Maintain
systems compliance compliance + retrofit
└─ ~1 month └─ ~6 months └─ Ongoing existing
Penalties in detail
Tier 1: Up to €35M or 7% of revenue
For:
- Violations of the prohibited practices (Art. 5).
- Non-compliance with a prohibition: deploying an unacceptable risk system.
Examples:
- Deploying a social scoring system in the EU.
- Deploying real-time biometric ID in public spaces (with no exception).
- Deploying manipulative AI that causes harm.
This is the most severe tier. Designed to deter the prohibitions.
Tier 2: Up to €15M or 3% of revenue
For:
- Violations of the obligations for high-risk systems (Art. 9-15, 16, 23-27, 39, 40, 43-45, 47-49).
Examples:
- Deploying a high-risk system with no risk management.
- Inadequate technical documentation.
- Insufficient human oversight.
- No conformity assessment.
This is the most likely penalty for typical violations.
Tier 3: Up to €15M or 3% of revenue
For:
- Violations of the GPAI obligations (Art. 53-55).
Examples:
- A GPAI provider not publishing the required docs.
- A missing copyright policy.
- Inadequate cybersecurity for systemic-risk models.
Tier 4: Up to €7.5M or 1.5% of revenue
For:
- Incorrect, incomplete, or misleading information given to authorities.
- Failing to respond to regulator queries.
Examples:
- Lying about your classification.
- Hiding documentation.
- Not responding to a regulator's request.
A note on percentage vs. absolute
For each tier, the fine is whichever is greater:
- A percentage of revenue.
- Or a fixed euro amount.
For startups with low revenue: the fixed amount applies. For large enterprises: the percentage is typically higher.
Examples:
- A startup with $1M in revenue, Tier 1 violation: €35M (fixed). Existential.
- A large company with $1B in revenue, Tier 1: 7% = $70M. Manageable but significant.
Penalty considerations
Factors that influence the penalty within the range
Regulators consider:
- The severity of the violation.
- The scope (number of people affected).
- Duration.
- Intent: willful vs. negligent.
- Mitigation efforts: remediation taken.
- Cooperation with the investigation.
- Previous violations.
- The company's financial situation.
Aggravating factors
- Hiding violations.
- Failing to remediate after notice.
- Multiple violations.
- High-impact harm.
Mitigating factors
- Self-disclosure of the issues.
- Prompt remediation.
- Demonstrated due diligence (the Phase 1 frameworks!).
- A first-time violation.
- Cooperation with authorities.
Why the Phase 1 work matters here
Doing an Ethics Impact Analysis (M1), Bias Audits (M2), and Privacy Assessments (M3) demonstrates due diligence. Even if a violation occurs, that mitigating factor reduces the penalty.
Conversely, no documentation = an aggravating factor.
The cost of compliance vs. the cost of non-compliance
The cost of compliance for a high-risk system
Estimated:
- Initial setup: 3-6 months of engineering work + legal review.
- Rough estimate: $200K-$1M depending on complexity.
- Ongoing: 10-15% of engineering capacity dedicated to compliance maintenance.
- Annual: $100K-$500K.
- Conformity assessment: $20K-$100K depending on scope.
- Registration and maintenance: nominal fees.
Total per high-risk system: $200K-$1M initial + $100K-$500K annual.
The cost of non-compliance
Direct fines:
- Tier 2 (most likely): up to 3% of revenue or €15M.
Indirect costs:
- Forced compliance retroactively (typically 3-5x the normal cost under time pressure).
- Reputational damage.
- Lost contracts.
- Legal fees.
- Stock impact (if public).
A conservative ratio: the cost of non-compliance is 5-50x the cost of compliance.
The ROI calculation for compliance: extremely positive. Even ignoring the fines, the indirect costs make compliance the rational choice.
Strategic planning
For new systems
Plan compliance from the start:
- Pre-design: classify the system. If unacceptable, stop. If high-risk, plan the budget.
- Design: build compliance into the architecture (Phase 1 frameworks).
- Development: build the documentation continuously.
- Pre-deploy: conformity assessment, registration.
- Deploy: with a full compliance posture.
- Operations: monitoring, periodic re-evaluation.
For existing systems (until Aug 2027)
Inventory:
## Existing AI Systems Inventory
| System | Use case | Classification | Status |
|--------|----------|----------------|--------|
| Hiring AI | Screening CVs | High-risk | Need compliance |
| Customer support chatbot | FAQ | Limited | Disclosure update |
| Internal analytics | BI tool | Minimal | Voluntary best practice |
| Loan approval | Credit decisions | High-risk | Need full retrofit |
Prioritize:
- Unacceptable: stop immediately.
- High-risk: plan the retrofit. Aug 2027 deadline.
- Limited: update disclosures by Aug 2026.
- Minimal: voluntary improvements.
Resource allocation
For a mid-size company with several AI systems:
Year 1 (now-2026):
- 1 FTE dedicated to AI compliance.
- Legal review budget: $50K.
- Audit / conformity assessment: $50K.
Year 2 (2026-2027):
- 0.5 FTE ongoing.
- Maintain documentation.
- Monitor regulatory updates.
For a small company with 1-2 high-risk systems:
- Outside legal counsel: $20K-$50K initial.
- Engineering time: 2-3 person-months.
- External assessment: $20K.
Common planning traps
1. "We'll deal with it when we get fined"
A fine ≠ remediation. After the fine, you still have to comply. Plus the reputational damage. Plus retroactive forced compliance under time pressure (3-5x the cost). Plan ahead.
2. Underestimating conformity assessment time
Some conformity assessments take months. Last-minute is impossible. Plan 6 months ahead minimum.
3. Ignoring documentation
Engineers focus on code. Documentation is 70% of the compliance work. Allocate accordingly.
4. Treating compliance as one-time
Compliance is an ongoing process. Budget for maintenance, not just the initial setup.
5. No escalation path
When regulator queries arrive, who responds? You need an established process before the queries arrive.
Self-check
1. When should you start high-risk compliance work?
Now (relative to the Aug 2026 deadline).
Reasons:
- Compliance work takes 3-6 months minimum.
- The conformity assessment can take additional weeks-months.
- The documentation must be comprehensive and live as an artifact.
- Iteration: first attempts at compliance often need refinement.
- Buffer: regulators may have specific requirements you didn't anticipate.
Working backward from Aug 2026:
- Feb 2026: you should be in the conformity assessment.
- Q4 2025: your draft documentation should be complete.
- Q3 2025: you should be implementing the technical requirements.
- Q2 2025: you should be classifying and planning.
If today is May 2026, you're already late. Start immediately.
2. Why is the Phase 1 work a mitigating factor in penalties?
Regulators distinguish:
- Negligent violations: the company didn't try, didn't document.
- Inadvertent violations: the company tried in good faith, documented the effort.
Negligent violations get maximum penalties. Inadvertent ones get mitigated penalties (frequently substantial reductions, sometimes 50-80% lower).
The Phase 1 frameworks (M1 Ethics Impact Analysis, M2 Bias Audit, M3 Privacy Assessment) document:
- That you identified the potential issues.
- That you implemented mitigations.
- That you monitored their effectiveness.
- That you updated based on the findings.
That is due diligence evidence. Regulators reward it.
Conversely, no documentation:
- Suggests negligence.
- Doesn't show good faith.
- Maximum penalties apply.
The frameworks aren't just "for compliance" — they're protective in the event of a compliance failure.
Summary and next step
-
Timelines:
- Feb 2025: Prohibitions.
- Aug 2025: GPAI rules.
- Aug 2026: High-risk full obligations (new deployments).
- Aug 2027: High-risk obligations for pre-existing systems.
-
Penalties:
- Tier 1 (prohibited): €35M / 7%.
- Tier 2 (high-risk obligations): €15M / 3%.
- Tier 3 (GPAI): €15M / 3%.
- Tier 4 (incorrect information): €7.5M / 1.5%.
-
The cost of compliance is 5-50x lower than non-compliance.
-
The Phase 1 work is a mitigating factor in reducing penalties.
Bridge: capsule 08 is the mini-project: Risk Classification — applying everything you learned to a real system.
Resources
- EU AI Act Art. 99 — Penalties — the text.
- EU AI Office — Implementation timeline — official.
Next: 08-mini-project-risk-classification.md — Risk Classification of a real system.
Capsule 07 of 08 — Module 4 — AI Ethics & Compliance Guide