EU AI Act Compliance: GPAI Penalties in Force, High-Risk Rules From December 2027
An EU AI Act compliance diagnostic costs €4,500-9,000 and takes 2-3 weeks: you learn which AI systems you use, their risk level, and what you are missing. AI literacy and the bans have applied since 2025, Annex III high-risk AI must comply from 2 December 2027, and fines reach €35M or 7% of global turnover.
- €35M Maximum Fine (7% Turnover)
- 01 · Inventory Systems, data and risks
- 02 · Risk Classification and thresholds
- 03 · Controls Technical and organisational
- 04 · Evidence Records that prove it
- 05 · Audit Internal and external
- 06 · Accountable A person answers for it
- Every finding updates the controls
- ISO 27001 Information security
- ISO 42001 AI management system
- ENS Spanish National Security Framework
- 5.0 on Clutch · verified reviews
- Since 2009 Software and AI engineering
In numbers
The State of AI Regulation
Figures from the regulation that demand action now.
- €15M High-Risk & GPAI Or 3% of turnover for breaching high-risk or GPAI provider obligations
- 2 Feb 2025 Already in Force AI literacy measures (Art. 4) and prohibited practices
- 2 Dec 2027 High-Risk (Annex III) Date set by Regulation (EU) 2026/1744; previously 2 August 2026
Why
EU AI Act Timeline: Deadlines Already in Force
What already applies and what arrives up to 2028, including the changes made by Regulation (EU) 2026/1744.
2 February 2025 (IN FORCE): AI literacy for staff (Art. 4) and prohibition of unacceptable AI practices (subliminal manipulation, social scoring, mass biometric surveillance). 2 August 2025 (IN FORCE): obligations for general-purpose AI models (GPAI), the governance framework, and the general penalties regime. 2 August 2026 (IN FORCE): general application of the regulation, transparency obligations (Art. 50), and penalties for GPAI model providers. 2 December 2026 (NEXT DEADLINE): new prohibited practices (AI-generated non-consensual sexual content and child sexual abuse material) and marking of content generated by systems already on the market. 2 August 2027: GPAI models placed on the market before 2 August 2025. 2 December 2027: full requirements for high-risk AI systems under Annex III (risk management, data quality, transparency, human oversight, robustness). 2 August 2028: high-risk AI embedded in regulated products under Annex I (machinery, medical devices, toys). The high-risk dates are those set by Regulation (EU) 2026/1744, in force since 27 July 2026.
- 3 Deadlines in Force
- 2 Dec 2026 Next
- €35M Max Fine
What's included
What Our Service Includes
From inventory to documented compliance.
- AI literacy training: to meet the obligation to take AI literacy measures (Art. 4, as worded by Regulation 2026/1744) for staff who use or oversee AI systems
- AI system inventory and classification: mapping all AI uses and classifying by risk level (minimal, limited, high, unacceptable)
- Risk assessment: fundamental rights impact analysis for high-risk systems per Annex III
- Technical documentation: training data records, performance metrics, detected biases, and mitigation measures
- Conformity assessment preparation: getting your organization ready for notified body audits
- Chatbot and AI feature compliance: transparency, generated content identification, and user rights
Definition
What Is the EU AI Act?
The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive artificial intelligence regulation. It establishes a legal framework based on the risk level of each AI system: prohibited practices, obligations for high-risk AI, transparency requirements, and the obligation to take AI literacy measures (Art. 4, as worded by Regulation 2026/1744).
Why
Private AI: The Shortest Path to Compliance
Your data, your AI. Impossible to copy, easier to audit.
Complying with the EU AI Act is far simpler when you control the system. A private AI, with your data on your own infrastructure (private RAG, models under your control), gives you exactly what the law demands: decision traceability, data governance, transparency, and real human oversight. Relying on an opaque third-party SaaS leaves those obligations out of your reach, because you cannot see what data goes in, how decisions are made, or where processing happens. We build your enterprise RAG on data that never leaves your control and pair it with AI consulting so architecture and compliance move together.
- Your Control Data
- Full Traceability
- Simpler Audit
Summary
Executive Summary
What you need to know to take action.
The EU AI Act already has three deadlines in force: since 2 February 2025, organizations must take AI literacy measures (Art. 4) and unacceptable AI practices are prohibited; since 2 August 2025, GPAI models have transparency and governance obligations; and since 2 August 2026, the Art. 50 transparency rules and penalties for GPAI providers apply. The main deadline is now 2 December 2027: Regulation (EU) 2026/1744 moved the risk management, data quality, transparency, and human oversight requirements for Annex III high-risk AI to that date.
The fines exceed the GDPR: up to €35M or 7% of global turnover. The delay buys time, not an exemption: organizations that reach the deadline with their dossier ready avoid sanctions and gain an edge over competitors who have not moved yet. The starting point is the diagnostic: knowing which AI systems you run, their risk level, and what you are missing.
- €35M Maximum Fine (7% Turnover)
- 2 Dec 2027 High-Risk (Annex III)
- 2-3 wks Compliance Diagnostic
For the CTO
Summary for CTO / Technical Team
Technical requirements and compliance framework.
The EU AI Act mandates a continuous risk management system for high-risk AI: training dataset documentation (provenance, quality, biases), performance and fairness metrics, automated decision logging, human-in-the-loop oversight mechanisms, and robustness testing against adversarial attacks, ground we share with our cybersecurity service.
For chatbots and user-facing AI features, the law requires clear transparency: users must know they are interacting with AI, AI-generated content must be labeled as such (including deepfakes), and there must be a mechanism to request human intervention. GPAI models require complete technical documentation including model cards.
Technologies
- ISO 42001
- NIST AI RMF
- EU AI Act
- GDPR
- Model Cards
- AI Risk Registry
- Fairness Metrics
- MLflow
- Automated AI system inventory with risk classification
- Bias monitoring and fairness metrics pipeline
- Automated decision logging for traceability
- Human-in-the-loop for high-risk systems
- Model cards and technical documentation per Annex IV
Who it is for
Is It Right for You?
The EU AI Act affects every organization that uses or develops AI systems in the European market.
Who it's for
- Companies that use chatbots, virtual assistants, or generative AI in customer service.
- Organizations that use AI for HR decisions (recruiting, performance evaluation).
- Financial companies that use AI for credit scoring or fraud detection.
- Any organization using AI with an AI literacy obligation (Art. 4).
- Software providers that integrate AI models into their products.
- Healthcare companies that use AI for diagnosis, triage, or treatment.
Who it's not for
- AI systems used exclusively for scientific research (exempt).
- Open-source AI with minimal risk and no direct commercial use.
- Purely military or national defense AI systems (outside the EU AI Act scope).
Key points
EU AI Act Compliance Services
Packages tailored to each phase of the regulation.
- 01
AI Literacy Training
Obligation already in force (Art. 4). Training program tailored to each employee's role: what AI is, how it works, risks, ethical use, and legal obligations. Available as in-person workshop or e-learning. Participation certificate: documenting the training is not mandatory, but we recommend it so you can show the measures you have taken.
- 02
Inventory and Risk Classification
Complete mapping of all AI systems in use (in-house and third-party). Risk-level classification under the regulation: unacceptable, high, limited, or minimal. Compliance gap identification and prioritized roadmap.
- 03
Impact Assessment and Documentation
For high-risk systems: fundamental rights impact assessment, technical documentation per Annex IV (training data, metrics, biases, mitigation measures), and conformity dossier preparation.
- 04
AI Governance and Monitoring
Design and implementation of an AI governance program: internal policies, AI Risk Registry, AI ethics committee, approval workflows for new systems, and continuous performance and fairness monitoring.
- 05
Chatbot and AI Feature Compliance
Specific audit of chatbots, virtual assistants, and generative AI features: transparency, AI-generated content labeling, human intervention request mechanism, and compliance with limited-risk system obligations.
Deliverables
AI Compliance Diagnostic: What You Get
The starting point, delivered in 2-3 weeks.
- Complete inventory of AI systems (in-house and third-party)
- Risk-level classification of each system under the regulation
- Gap analysis against the EU AI Act
- Verification that no system falls under prohibited practices
- AI literacy status of your team (Art. 4)
- Prioritized action plan with owners and deadlines
- Results session with leadership and technical team
- Delivered in 2-3 weeks
Investment
Investment
From the diagnostic to the full compliance program.
Reference ranges based on the number of AI systems, their risk level, and the size of the organization. Always less than a fine of 7% of turnover.
- AI Compliance Diagnostic Start Here
€4,500-9,000
The starting point. In 2-3 weeks you know which systems you run, their risk, and what you are missing.
- Inventory of all AI systems (in-house and third-party)
- Risk classification under the regulation
- Gap analysis against the EU AI Act
- Prioritized action plan with deadlines
- Results session with your team
- AI Literacy Training
€3,000-6,000
The Art. 4 obligation, already in force. Program tailored to each role.
- Content by profile (leadership, technical, user)
- In-person workshop or e-learning
- Participation certification
- Material aligned with the European AI Office
- Full Compliance Program
€15,000-30,000
To reach the deadline with your dossier ready.
- Everything in the diagnostic
- Technical documentation (Annex IV)
- Impact assessment and AI governance
- Human oversight and decision logging
- Preparation for audit and certification
No lock-in. Cancel with 30 days notice.
How we work
Compliance Process
From inventory to documented conformity.
- 01
Inventory
We map every AI system in your organization: chatbots, predictive models, HR tools, scoring, automations. We include third-party AI (OpenAI, Google, Azure AI APIs) that you use.
- 02
Classification
We classify each system by risk level under the regulation. We identify specific obligations: transparency for limited risk, full requirements for high risk, and verify that no system falls under prohibited practices. We close the diagnostic with the gap analysis and the action plan.
- 03
Remediation
We implement the required technical and organizational measures: technical documentation, impact assessment, governance policies, team training, human oversight mechanisms, and decision logging.
- 04
Documentation and Monitoring
We prepare the complete conformity dossier: technical documentation (Annex IV), impact assessment, EU database registration (for high-risk), and a continuous post-deployment monitoring system.
Risks and how we cover them
Risks We Mitigate
From regulatory exposure to verified conformity.
- 01
Non-compliance fines (up to €35M / 7% revenue)
MitigationFull compliance program: inventory, classification, documentation, and monitoring. Conformity dossier ready for regulatory inspection.
- 02
AI literacy non-compliance (obligation already in force)
MitigationRole-adapted training program with participation certification. Content updated per the European AI Office guidelines.
- 03
Undocumented high-risk AI systems
MitigationExhaustive inventory + Annex IV technical documentation: training data, performance metrics, bias analysis, and mitigation measures.
- 04
Chatbots and generative AI lacking transparency
MitigationAudit of all AI interfaces: clear AI interaction identification, generated content labeling, and human intervention request mechanism.
Technologies
Frameworks and Tools
International AI governance standards.
- ISO 42001
- NIST AI RMF
- EU AI Act
- GDPR
- Model Cards
- AI Risk Registry
- Bias Detection
- Fairness Metrics
- MLflow
- Weights & Biases
- AI Incident Database
- ALTAI
- EN 301 549
- ISO 27001
The proof
Real-World Experience in Applied AI and Compliance
At Kiwop, we've spent years building and integrating AI solutions for businesses: intelligent chatbots, enterprise RAG, AI agents, and LLM integration. This hands-on technical experience lets us understand the regulation from a developer's perspective, not just a legal consultant's. We know what compliance means because we build the systems that must comply.
- 30+ LLM Projects Since 2023
- 3 Regulation Deadlines in Force
- Dec 2026 Next Regulation Deadline
- 2-3 wks Compliance Diagnostic
Why
EU AI Act vs GDPR: What Changes and What Stacks
The EU AI Act doesn't replace the GDPR: it builds on top of it.
If your organization already complies with the GDPR, you have a foundation, but the EU AI Act adds AI-specific requirements the GDPR doesn't cover: risk classification, model technical documentation, algorithmic bias assessment, mandatory human oversight, and AI-specific transparency. EU AI Act fines exceed the GDPR: up to 7% of global turnover vs 4% under the GDPR. Both regulations apply simultaneously: a chatbot that processes personal data must comply with both. Our privacy engineering service covers the personal data front.
- 4% Max Fine GDPR
- 7% Max Fine EU AI Act
- €35M Prohibited Practices
- €15M High-Risk & GPAI
Sources
Sources for the Figures on This Page
Official EU texts and our own data. Accessed 26 September 2026.
- Regulation (EU) 2024/1689 on artificial intelligence, official text on EUR-Lex Fines under Art. 99 (€35M or 7% for prohibited practices; €15M or 3% for other obligations; €7.5M or 1% for incorrect information; the lower amount for SMEs) and Art. 101 (€15M or 3% for GPAI providers). Dates in Art. 113: entry into force on 1 August 2024 and application on 2 February 2025, 2 August 2025, and 2 August 2026. Art. 4 (AI literacy) and Annexes I, III, and IV.
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), official text on EUR-Lex In force since 27 July 2026. Moves Annex III high-risk AI to 2 December 2027 and Annex I high-risk AI to 2 August 2028, adds prohibited practices from 2 December 2026, and rewrites Art. 4 as a duty to take AI literacy measures.
- Council of the EU, press release of 29 June 2026 Final adoption of the Digital Omnibus on AI and the new high-risk dates: 2 December 2027 and 2 August 2028.
- Regulation (EU) 2016/679 (GDPR), official text on EUR-Lex Art. 83: fines up to €20M or 4% of global turnover, the figure the AI Act's 7% is compared with.
- Kiwop's published prices and timelines for this service (September 2026) Diagnostic €4,500-9,000 in 2-3 weeks, AI literacy training €3,000-6,000, and full programme €15,000-30,000.
- Kiwop experience in LLM projects (2023-2026) More than 30 LLM projects since 2023. Internal figure: no published case study breaks it down.
FAQ
Frequently Asked Questions
What companies ask about the EU AI Act.
What is the EU AI Act and when does it apply?
The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive AI regulation. It entered into force on 1 August 2024 and applies in stages: 2 February 2025 (AI literacy + prohibited practices), 2 August 2025 (GPAI obligations + governance), 2 August 2026 (general application, transparency, and penalties for GPAI providers), 2 December 2027 (Annex III high-risk AI), and 2 August 2028 (high-risk AI embedded in Annex I products). The last two dates were set by Regulation (EU) 2026/1744. It applies to any organization that provides or uses AI in the EU market.
Who does the EU AI Act apply to?
It applies to any organization that develops, provides, or uses AI systems in the EU market, whether or not it is headquartered in Europe. It does not distinguish by sector or size: an SME using a chatbot, a bank running credit scoring, or a US company with European customers are all in scope. Specific obligations vary by your role (provider or deployer) and the system's risk level, but AI literacy (Art. 4) applies across the board.
What Changed on 2 August 2026, and What Was Postponed?
On 2 August 2026, penalties for providers of GPAI models became applicable (their obligations have applied since 2 August 2025), along with the Art. 50 transparency obligations, such as telling people they are talking to an AI. The requirements for Annex III high-risk AI (risk management, data quality, technical documentation, human oversight, and robustness), originally due on that date, were postponed to 2 December 2027 by Regulation (EU) 2026/1744. High-risk AI embedded in Annex I products moves to 2 August 2028.
How much are the fines for breaching the EU AI Act?
The fines exceed the GDPR: up to €35M or 7% of global annual turnover (whichever is higher) for prohibited practices. For most other violations, including high-risk and GPAI provider obligations: up to €15M or 3%. For supplying incorrect or misleading information to authorities: up to €7.5M or 1%. For SMEs and start-ups, the lower of the two amounts applies.
What is a high-risk AI system?
It is an AI system that, under Annex III, may affect people's safety or fundamental rights. This includes AI in HR recruitment and management (CV filtering, performance evaluation), credit and insurance scoring, administration of justice, border control, critical infrastructure, education (admissions, assessments), and healthcare (diagnosis, triage). If your AI influences decisions that affect people's rights, it is likely high-risk.
What is a general-purpose AI (GPAI) model?
A general-purpose AI (GPAI) model is a large-scale model trained to perform many different tasks, such as GPT, Claude, or Gemini. Their providers have had obligations since 2 August 2025 (technical documentation, transparency, copyright compliance), and the associated penalties have applied since 2 August 2026. If your company integrates one of these models via API, you are a deployer and have your own obligations, even though you are not the model provider.
My SME uses AI but doesn't develop it. What are my obligations?
Even if you only use third-party AI (ChatGPT, Copilot, a chatbot, an HR tool), you are a deployer and already have obligations. Since 2 February 2025 you must take AI literacy measures for your team (Art. 4) and avoid prohibited practices. If the system is high-risk, you add human oversight, transparency, and impact assessment. These obligations cannot be delegated to the model provider. Check which ones apply to you in two minutes with our EU AI Act self-assessment.
What does Art. 4 require on AI literacy?
It is the obligation, in force since 2 February 2025, for every organization that uses or oversees AI systems to take measures so its staff understand AI: what it is, how it works, its risks, and its responsible use. Since Regulation (EU) 2026/1744 it is an obligation of means: it does not require a specific level for each person, nor does it require documentation. Even so, we recommend tailoring the training to each role and keeping a record of it so you can prove it. It is the first obligation that affects virtually every company, whether it develops AI or not.
How do I start complying with the EU AI Act?
Start by knowing what you have: our EU AI Act self-assessment places you in two minutes, free. For the full inventory, our AI Compliance Diagnostic inventories all your AI systems, classifies them by risk level under the regulation, detects the gaps against the regulation, and delivers a prioritized action plan in 2-3 weeks. From there you know exactly what to do and in what order, without spending ahead of time. If you want to go deeper into architecture, we pair it with AI consulting.
Where can I read more about the AI Act?
This page has the up-to-date timeline, with the dates set by Regulation (EU) 2026/1744, and links to the official texts on EUR-Lex. To see which obligations apply to you, take our EU AI Act self-assessment: ten questions and an indicative result. If you prefer something applied to your own case, the AI Compliance Diagnostic gives you your organization's real status against the regulation.
Next step
High-Risk AI Deadline on 2 December 2027: Get There With Your Dossier Ready
AI literacy measures are already mandatory and GPAI penalties already apply. Start with the AI Compliance Diagnostic: in 2-3 weeks you know which systems you run, their risk, and what you are missing.
- No commitment
- Response in 24h
- Custom proposal
Let's talk.
Initial technical consultation
AI, security and performance. Diagnosis with phased proposal.
- NDA available
- Response <24h
- Phased proposal
Your first meeting is with a Solutions Architect, not a salesperson.
Talk to an architect