Módulo 4: EU AI Act Deep Dive

7. Timelines y Penalties

Descripción de la cápsula

Esta cápsula consolida la información práctica de planning: cuándo cada obligation entra en vigor y cuánto cuesta non-compliance.

Sin esta info, no podés planificar compliance. Esta cápsula es la referencia operacional del módulo.


Timelines completas

Febrero 2025: Prohibitions in effect

Lo que aplica:

  • Art. 5 prohibitions enforceable.
  • Sistemas Unacceptable Risk prohibidos.

Acción inmediata:

  • Identify si tu sistema cae en prohibited categories.
  • Si sí: stop deploy, re-architect, o exit EU market.

Mayo 2025: Codes of Practice

Lo que aplica:

  • Voluntary codes for GPAI.
  • Best practices guidance published.

Agosto 2025: GPAI obligations

Lo que aplica:

  • Art. 51-55 enforceable.
  • GPAI providers must comply.

Acción:

  • Verify provider compliance.
  • Update contracts si necesario.

Agosto 2026: High-risk full obligations

Lo que aplica:

  • Art. 9-15 enforceable for new deployments.
  • Conformity assessment required.
  • Registration required.

Acción (most critical):

  • High-risk systems must comply by this date.
  • Conformity assessment can take weeks/months — start early.
  • Registration must be in place.

Agosto 2027: Existing systems

Lo que aplica:

  • High-risk systems deployed BEFORE Aug 2026 must also comply.

Acción:

  • Inventory existing AI systems.
  • Identify high-risk ones.
  • Plan retrofit compliance.

Visualización: planning timeline

2024 ──── 2025 ──────────────── 2026 ──────────── 2027
              │                  │                │
              Feb: Prohibited    Aug: High-risk   Aug: Existing
                  systems        full reqs        systems comply
                  cannot deploy
              
              Aug: GPAI rules    
              
              May: Codes of
              Practice

For your team:

Today                  H1 2026                Aug 2026             2027+
  │                       │                       │                  │
  Classify              Build                   Deploy with        Maintain
  systems              compliance               compliance         + retrofit
  └─ ~1 month          └─ ~6 months            └─ Ongoing         existing

Penalties detalladas

Tier 1: Hasta €35M o 7% revenue

Para:

  • Violations of prohibited practices (Art. 5).
  • Non-compliance with prohibition: deploying unacceptable risk system.

Examples:

  • Deploying social scoring system in EU.
  • Deploying real-time biometric ID en public spaces (without exception).
  • Deploying manipulative AI causing harm.

This is most severe. Designed para deter prohibitions.

Tier 2: Hasta €15M o 3% revenue

Para:

  • Violations of obligations for high-risk systems (Art. 9-15, 16, 23-27, 39, 40, 43-45, 47-49).

Examples:

  • Deploying high-risk system without risk management.
  • Inadequate technical documentation.
  • Insufficient human oversight.
  • No conformity assessment.

This is the most likely penalty for typical violations.

Tier 3: Hasta €15M o 3% revenue

Para:

  • Violations of GPAI obligations (Art. 53-55).

Examples:

  • GPAI provider not publishing required docs.
  • Missing copyright policy.
  • Inadequate cybersecurity for systemic risk models.

Tier 4: Hasta €7.5M o 1.5% revenue

Para:

  • Incorrect, incomplete, or misleading information to authorities.
  • Failure to respond to regulator queries.

Examples:

  • Lying about classification.
  • Hiding documentation.
  • Not responding to regulator request.

Note on percentage vs absolute

For each tier, fine is lo que sea mayor:

  • Percentage of revenue.
  • Or fixed euro amount.

For startups con low revenue: fixed amount applies. For large enterprises: percentage typically higher.

Examples:

  • Startup con $1M revenue, Tier 1 violation: €35M (fixed). Existential.
  • Large company con $1B revenue, Tier 1: 7% = $70M. Manageable but significant.

Penalty considerations

Factors that influence penalty within range

Regulators consider:

  • Severity of violation.
  • Scope (number of people affected).
  • Duration.
  • Intent: willful vs negligent.
  • Mitigation efforts: remediation taken.
  • Cooperation with investigation.
  • Previous violations.
  • Financial situation of company.

Aggravating factors

  • Hiding violations.
  • Failure to remediate after notice.
  • Multiple violations.
  • High-impact harm.

Mitigating factors

  • Self-disclosure of issues.
  • Prompt remediation.
  • Demonstrated due diligence (Phase 1 frameworks!).
  • First-time violation.
  • Cooperation with authorities.

Why Phase 1 work matters here

Doing Ethics Impact Analysis (M1), Bias Audits (M2), Privacy Assessments (M3) demonstrates due diligence. Even if violation occurs, mitigating factor reduces penalty.

Conversely, no documentation = aggravating factor.


Cost of compliance vs cost of non-compliance

Cost of compliance for high-risk system

Estimated:

  • Initial setup: 3-6 months engineering work + legal review.
    • Rough estimate: $200K-$1M depending on complexity.
  • Ongoing: 10-15% engineering capacity dedicated to compliance maintenance.
    • Annual: $100K-$500K.
  • Conformity assessment: $20K-$100K depending on scope.
  • Registration y maintenance: nominal fees.

Total per high-risk system: $200K-$1M initial + $100K-$500K annual.

Cost of non-compliance

Direct fines:

  • Tier 2 (most likely): up to 3% revenue or €15M.

Indirect costs:

  • Forced compliance retroactively (typically 3-5x normal cost under time pressure).
  • Reputational damage.
  • Lost contracts.
  • Legal fees.
  • Stock impact (if public).

Conservative ratio: cost of non-compliance is 5-50x cost of compliance.

ROI calculation for compliance: extremely positive. Even ignoring fines, the indirect costs make compliance the rational choice.


Strategic planning

For new systems

Plan compliance from start:

  1. Pre-design: classify system. If unacceptable, stop. If high-risk, plan budget.
  2. Design: integrate compliance into architecture (Phase 1 frameworks).
  3. Development: build documentation continuously.
  4. Pre-deploy: conformity assessment, registration.
  5. Deploy: with full compliance posture.
  6. Operations: monitoring, periodic re-evaluation.

For existing systems (until Aug 2027)

Inventory:

## Existing AI Systems Inventory

| System | Use case | Classification | Status |
|--------|----------|----------------|--------|
| Hiring AI | Screening CVs | High-risk | Need compliance |
| Customer support chatbot | FAQ | Limited | Disclosure update |
| Internal analytics | BI tool | Minimal | Voluntary best practice |
| Loan approval | Credit decisions | High-risk | Need full retrofit |

Prioritize:

  1. Unacceptable: stop immediately.
  2. High-risk: plan retrofit. Aug 2027 deadline.
  3. Limited: update disclosures by Aug 2026.
  4. Minimal: voluntary improvements.

Resource allocation

For mid-size company con several AI systems:

Year 1 (now-2026):
- 1 FTE dedicated to AI compliance.
- Legal review budget: $50K.
- Audit / conformity assessment: $50K.

Year 2 (2026-2027):
- 0.5 FTE ongoing.
- Maintain documentation.
- Monitor regulatory updates.

For small company con 1-2 high-risk systems:

- Outside legal counsel: $20K-$50K initial.
- Engineering time: 2-3 person-months.
- External assessment: $20K.

Trampas comunes en planning

1. "We'll deal with it when fined"

Fine ≠ remediation. After fine, you still must comply. Plus reputational damage. Plus retroactive forced compliance under time pressure (3-5x cost). Plan ahead.

2. Underestimating conformity assessment time

Some conformity assessments take months. Last-minute is impossible. Plan 6 months ahead minimum.

3. Ignoring documentation

Engineers focus on code. Documentation is 70% of compliance work. Allocate accordingly.

4. Treating compliance as one-time

Compliance es ongoing process. Budget for maintenance, not just initial setup.

5. No escalation path

When regulator queries arrive, who responds? Established process needed before queries arrive.


Auto-verificación

1. ¿Cuándo deberías empezar high-risk compliance work?

Now (relative to Aug 2026 deadline).

Razones:

  1. Compliance work toma 3-6 months minimum.
  2. Conformity assessment can take weeks-months additional.
  3. Documentation debe ser comprehensive y vivir como artifact.
  4. Iteration: first attempts at compliance often need refinement.
  5. Buffer: regulators may have specific requirements you didn't anticipate.

Working backward from Aug 2026:

  • Feb 2026: should be in conformity assessment.
  • Q4 2025: should have draft documentation complete.
  • Q3 2025: should be implementing technical requirements.
  • Q2 2025: should be classifying y planning.

If today is May 2026, you're already late. Start immediately.

2. ¿Por qué Phase 1 work es factor mitigante en penalties?

Regulators distinguish:

  • Negligent violations: company didn't try, didn't document.
  • Inadvertent violations: company tried in good faith, documented effort.

Negligent violations get maximum penalties. Inadvertent get mitigated penalties (frequently substantial reductions, sometimes 50-80% lower).

Phase 1 frameworks (M1 Ethics Impact Analysis, M2 Bias Audit, M3 Privacy Assessment) document:

  • You identified potential issues.
  • You implemented mitigations.
  • You monitored effectiveness.
  • You updated based on findings.

This is due diligence evidence. Regulators reward it.

Conversely, no documentation:

  • Suggests negligence.
  • Doesn't show good faith.
  • Maximum penalties applicable.

The frameworks aren't just "for compliance" — they're protective in case of compliance failure.


Resumen y siguiente paso

  • Timelines:

    • Feb 2025: Prohibitions.
    • Aug 2025: GPAI rules.
    • Aug 2026: High-risk full obligations (new deployments).
    • Aug 2027: High-risk obligations for pre-existing systems.
  • Penalties:

    • Tier 1 (prohibited): €35M / 7%.
    • Tier 2 (high-risk obligations): €15M / 3%.
    • Tier 3 (GPAI): €15M / 3%.
    • Tier 4 (incorrect info): €7.5M / 1.5%.
  • Cost of compliance is 5-50x lower than non-compliance.

  • Phase 1 work is mitigating factor in penalty reduction.

Puente: la cápsula 08 es el mini-proyecto: Risk Classification — aplicar todo lo aprendido a un sistema real.


Recursos

  1. EU AI Act Art. 99 — Penalties — texto.
  2. EU AI Office — Implementation timeline — official.

Siguiente: 08-mini-proyecto-risk-classification.md — Risk Classification de un sistema real.

Cápsula 07 de 08 — Módulo 4 — AI Ethics & Compliance Guide