Módulo 4: EU AI Act Deep Dive
7. Timelines y Penalties
Descripción de la cápsula
Esta cápsula consolida la información práctica de planning: cuándo cada obligation entra en vigor y cuánto cuesta non-compliance.
Sin esta info, no podés planificar compliance. Esta cápsula es la referencia operacional del módulo.
Timelines completas
Febrero 2025: Prohibitions in effect
Lo que aplica:
- Art. 5 prohibitions enforceable.
- Sistemas Unacceptable Risk prohibidos.
Acción inmediata:
- Identify si tu sistema cae en prohibited categories.
- Si sí: stop deploy, re-architect, o exit EU market.
Mayo 2025: Codes of Practice
Lo que aplica:
- Voluntary codes for GPAI.
- Best practices guidance published.
Agosto 2025: GPAI obligations
Lo que aplica:
- Art. 51-55 enforceable.
- GPAI providers must comply.
Acción:
- Verify provider compliance.
- Update contracts si necesario.
Agosto 2026: High-risk full obligations
Lo que aplica:
- Art. 9-15 enforceable for new deployments.
- Conformity assessment required.
- Registration required.
Acción (most critical):
- High-risk systems must comply by this date.
- Conformity assessment can take weeks/months — start early.
- Registration must be in place.
Agosto 2027: Existing systems
Lo que aplica:
- High-risk systems deployed BEFORE Aug 2026 must also comply.
Acción:
- Inventory existing AI systems.
- Identify high-risk ones.
- Plan retrofit compliance.
Visualización: planning timeline
2024 ──── 2025 ──────────────── 2026 ──────────── 2027
│ │ │
Feb: Prohibited Aug: High-risk Aug: Existing
systems full reqs systems comply
cannot deploy
Aug: GPAI rules
May: Codes of
Practice
For your team:
Today H1 2026 Aug 2026 2027+
│ │ │ │
Classify Build Deploy with Maintain
systems compliance compliance + retrofit
└─ ~1 month └─ ~6 months └─ Ongoing existing
Penalties detalladas
Tier 1: Hasta €35M o 7% revenue
Para:
- Violations of prohibited practices (Art. 5).
- Non-compliance with prohibition: deploying unacceptable risk system.
Examples:
- Deploying social scoring system in EU.
- Deploying real-time biometric ID en public spaces (without exception).
- Deploying manipulative AI causing harm.
This is most severe. Designed para deter prohibitions.
Tier 2: Hasta €15M o 3% revenue
Para:
- Violations of obligations for high-risk systems (Art. 9-15, 16, 23-27, 39, 40, 43-45, 47-49).
Examples:
- Deploying high-risk system without risk management.
- Inadequate technical documentation.
- Insufficient human oversight.
- No conformity assessment.
This is the most likely penalty for typical violations.
Tier 3: Hasta €15M o 3% revenue
Para:
- Violations of GPAI obligations (Art. 53-55).
Examples:
- GPAI provider not publishing required docs.
- Missing copyright policy.
- Inadequate cybersecurity for systemic risk models.
Tier 4: Hasta €7.5M o 1.5% revenue
Para:
- Incorrect, incomplete, or misleading information to authorities.
- Failure to respond to regulator queries.
Examples:
- Lying about classification.
- Hiding documentation.
- Not responding to regulator request.
Note on percentage vs absolute
For each tier, fine is lo que sea mayor:
- Percentage of revenue.
- Or fixed euro amount.
For startups con low revenue: fixed amount applies. For large enterprises: percentage typically higher.
Examples:
- Startup con $1M revenue, Tier 1 violation: €35M (fixed). Existential.
- Large company con $1B revenue, Tier 1: 7% = $70M. Manageable but significant.
Penalty considerations
Factors that influence penalty within range
Regulators consider:
- Severity of violation.
- Scope (number of people affected).
- Duration.
- Intent: willful vs negligent.
- Mitigation efforts: remediation taken.
- Cooperation with investigation.
- Previous violations.
- Financial situation of company.
Aggravating factors
- Hiding violations.
- Failure to remediate after notice.
- Multiple violations.
- High-impact harm.
Mitigating factors
- Self-disclosure of issues.
- Prompt remediation.
- Demonstrated due diligence (Phase 1 frameworks!).
- First-time violation.
- Cooperation with authorities.
Why Phase 1 work matters here
Doing Ethics Impact Analysis (M1), Bias Audits (M2), Privacy Assessments (M3) demonstrates due diligence. Even if violation occurs, mitigating factor reduces penalty.
Conversely, no documentation = aggravating factor.
Cost of compliance vs cost of non-compliance
Cost of compliance for high-risk system
Estimated:
- Initial setup: 3-6 months engineering work + legal review.
- Rough estimate: $200K-$1M depending on complexity.
- Ongoing: 10-15% engineering capacity dedicated to compliance maintenance.
- Annual: $100K-$500K.
- Conformity assessment: $20K-$100K depending on scope.
- Registration y maintenance: nominal fees.
Total per high-risk system: $200K-$1M initial + $100K-$500K annual.
Cost of non-compliance
Direct fines:
- Tier 2 (most likely): up to 3% revenue or €15M.
Indirect costs:
- Forced compliance retroactively (typically 3-5x normal cost under time pressure).
- Reputational damage.
- Lost contracts.
- Legal fees.
- Stock impact (if public).
Conservative ratio: cost of non-compliance is 5-50x cost of compliance.
ROI calculation for compliance: extremely positive. Even ignoring fines, the indirect costs make compliance the rational choice.
Strategic planning
For new systems
Plan compliance from start:
- Pre-design: classify system. If unacceptable, stop. If high-risk, plan budget.
- Design: integrate compliance into architecture (Phase 1 frameworks).
- Development: build documentation continuously.
- Pre-deploy: conformity assessment, registration.
- Deploy: with full compliance posture.
- Operations: monitoring, periodic re-evaluation.
For existing systems (until Aug 2027)
Inventory:
## Existing AI Systems Inventory
| System | Use case | Classification | Status |
|--------|----------|----------------|--------|
| Hiring AI | Screening CVs | High-risk | Need compliance |
| Customer support chatbot | FAQ | Limited | Disclosure update |
| Internal analytics | BI tool | Minimal | Voluntary best practice |
| Loan approval | Credit decisions | High-risk | Need full retrofit |
Prioritize:
- Unacceptable: stop immediately.
- High-risk: plan retrofit. Aug 2027 deadline.
- Limited: update disclosures by Aug 2026.
- Minimal: voluntary improvements.
Resource allocation
For mid-size company con several AI systems:
Year 1 (now-2026):
- 1 FTE dedicated to AI compliance.
- Legal review budget: $50K.
- Audit / conformity assessment: $50K.
Year 2 (2026-2027):
- 0.5 FTE ongoing.
- Maintain documentation.
- Monitor regulatory updates.
For small company con 1-2 high-risk systems:
- Outside legal counsel: $20K-$50K initial.
- Engineering time: 2-3 person-months.
- External assessment: $20K.
Trampas comunes en planning
1. "We'll deal with it when fined"
Fine ≠ remediation. After fine, you still must comply. Plus reputational damage. Plus retroactive forced compliance under time pressure (3-5x cost). Plan ahead.
2. Underestimating conformity assessment time
Some conformity assessments take months. Last-minute is impossible. Plan 6 months ahead minimum.
3. Ignoring documentation
Engineers focus on code. Documentation is 70% of compliance work. Allocate accordingly.
4. Treating compliance as one-time
Compliance es ongoing process. Budget for maintenance, not just initial setup.
5. No escalation path
When regulator queries arrive, who responds? Established process needed before queries arrive.
Auto-verificación
1. ¿Cuándo deberías empezar high-risk compliance work?
Now (relative to Aug 2026 deadline).
Razones:
- Compliance work toma 3-6 months minimum.
- Conformity assessment can take weeks-months additional.
- Documentation debe ser comprehensive y vivir como artifact.
- Iteration: first attempts at compliance often need refinement.
- Buffer: regulators may have specific requirements you didn't anticipate.
Working backward from Aug 2026:
- Feb 2026: should be in conformity assessment.
- Q4 2025: should have draft documentation complete.
- Q3 2025: should be implementing technical requirements.
- Q2 2025: should be classifying y planning.
If today is May 2026, you're already late. Start immediately.
2. ¿Por qué Phase 1 work es factor mitigante en penalties?
Regulators distinguish:
- Negligent violations: company didn't try, didn't document.
- Inadvertent violations: company tried in good faith, documented effort.
Negligent violations get maximum penalties. Inadvertent get mitigated penalties (frequently substantial reductions, sometimes 50-80% lower).
Phase 1 frameworks (M1 Ethics Impact Analysis, M2 Bias Audit, M3 Privacy Assessment) document:
- You identified potential issues.
- You implemented mitigations.
- You monitored effectiveness.
- You updated based on findings.
This is due diligence evidence. Regulators reward it.
Conversely, no documentation:
- Suggests negligence.
- Doesn't show good faith.
- Maximum penalties applicable.
The frameworks aren't just "for compliance" — they're protective in case of compliance failure.
Resumen y siguiente paso
-
Timelines:
- Feb 2025: Prohibitions.
- Aug 2025: GPAI rules.
- Aug 2026: High-risk full obligations (new deployments).
- Aug 2027: High-risk obligations for pre-existing systems.
-
Penalties:
- Tier 1 (prohibited): €35M / 7%.
- Tier 2 (high-risk obligations): €15M / 3%.
- Tier 3 (GPAI): €15M / 3%.
- Tier 4 (incorrect info): €7.5M / 1.5%.
-
Cost of compliance is 5-50x lower than non-compliance.
-
Phase 1 work is mitigating factor in penalty reduction.
Puente: la cápsula 08 es el mini-proyecto: Risk Classification — aplicar todo lo aprendido a un sistema real.
Recursos
- EU AI Act Art. 99 — Penalties — texto.
- EU AI Office — Implementation timeline — official.
Siguiente: 08-mini-proyecto-risk-classification.md — Risk Classification de un sistema real.
Cápsula 07 de 08 — Módulo 4 — AI Ethics & Compliance Guide