EUAIActCompliance:PenaltiesforGPAIProvidersApplyFrom2August2026
The EU AI Act (Regulation (EU) 2024/1689) is already binding. Since 2 February 2025, AI literacy training is mandatory (Article 4) and unacceptable AI practices are banned. Since 2 August 2025, obligations for GPAI models and the governance framework apply. On 2 August 2026, requirements for high-risk AI systems under Annex III kick in and penalties for GPAI model providers become applicable: up to €35M or 7% of global turnover. We diagnose your compliance in 2-3 weeks.
EU AI Act Timeline: Deadlines Already in Force
What applies now and what arrives on 2 August 2026.
2 February 2025 (IN FORCE): mandatory AI literacy for all staff (Art. 4) and prohibition of unacceptable AI practices (subliminal manipulation, social scoring, mass biometric surveillance). 2 August 2025 (IN FORCE): obligations for general-purpose AI models (GPAI), the governance framework, and the general penalties regime. 2 August 2026 (NEXT DEADLINE): full requirements for high-risk AI systems under Annex III (risk management, data quality, transparency, human oversight, robustness), and penalties for GPAI model providers become applicable. 2 August 2027: obligations for high-risk AI embedded in regulated products under Annex I (machinery, medical devices, toys) and for GPAI models placed on the market before 2 August 2025.
What Our Service Includes
From inventory to documented compliance.
Private AI: The Shortest Path to Compliance
Your data, your AI. Impossible to copy, easier to audit.
Complying with the EU AI Act is far simpler when you control the system. A private AI, with your data on your own infrastructure (private RAG, models under your control), gives you exactly what the law demands: decision traceability, data governance, transparency, and real human oversight. Relying on an opaque third-party SaaS leaves those obligations out of your reach, because you cannot see what data goes in, how decisions are made, or where processing happens. We build your enterprise RAG on data that never leaves your control and pair it with AI consulting so architecture and compliance move together.
Executive Summary
What you need to know to take action.
The EU AI Act already has two deadlines in force: since 2 February 2025, AI literacy training (Art. 4) is mandatory and unacceptable AI practices are prohibited. Since 2 August 2025, GPAI models have transparency and governance obligations. 2 August 2026 is the main deadline: high-risk AI systems must meet full requirements for risk management, data quality, transparency, and human oversight, and penalties for GPAI providers become applicable.
The fines exceed the GDPR: up to €35M or 7% of global turnover. This is a short window with budget behind it: organizations that reach the deadline with their dossier ready avoid sanctions and gain an edge over competitors who have not moved yet. The starting point is the diagnostic: knowing which AI systems you run, their risk level, and what you are missing.
Summary for CTO / Technical Team
Technical requirements and compliance framework.
The EU AI Act mandates a continuous risk management system for high-risk AI: training dataset documentation (provenance, quality, biases), performance and fairness metrics, automated decision logging, human-in-the-loop oversight mechanisms, and robustness testing against adversarial attacks, ground we share with our cybersecurity service.
For chatbots and user-facing AI features, the law requires clear transparency: users must know they are interacting with AI, AI-generated content must be labeled as such (including deepfakes), and there must be a mechanism to request human intervention. GPAI models require complete technical documentation including model cards.
Is It Right for You?
The EU AI Act affects every organization that uses or develops AI systems in the European market.
Who it's for
- Companies that use chatbots, virtual assistants, or generative AI in customer service.
- Organizations that use AI for HR decisions (recruiting, performance evaluation).
- Financial companies that use AI for credit scoring or fraud detection.
- Any organization using AI with an AI literacy obligation (Art. 4).
- Software providers that integrate AI models into their products.
- Healthcare companies that use AI for diagnosis, triage, or treatment.
Who it's not for
- AI systems used exclusively for scientific research (exempt).
- Open-source AI with minimal risk and no direct commercial use.
- Purely military or national defense AI systems (outside the EU AI Act scope).
EU AI Act Compliance Services
Packages tailored to each phase of the regulation.
AI Literacy Training
Obligation already in force (Art. 4). Training program tailored to each employee's role: what AI is, how it works, risks, ethical use, and legal obligations. Available as in-person workshop or e-learning. Participation certification for compliance documentation.
Inventory and Risk Classification
Complete mapping of all AI systems in use (in-house and third-party). Risk-level classification per Annex III: unacceptable, high, limited, or minimal. Compliance gap identification and prioritized roadmap.
Impact Assessment and Documentation
For high-risk systems: fundamental rights impact assessment, technical documentation per Annex IV (training data, metrics, biases, mitigation measures), and conformity dossier preparation.
AI Governance and Monitoring
Design and implementation of an AI governance program: internal policies, AI Risk Registry, AI ethics committee, approval workflows for new systems, and continuous performance and fairness monitoring.
Chatbot and AI Feature Compliance
Specific audit of chatbots, virtual assistants, and generative AI features: transparency, AI-generated content labeling, human intervention request mechanism, and compliance with limited-risk system obligations.
AI Compliance Diagnostic: What You Get
The starting point, delivered in 2-3 weeks.
- Complete inventory of AI systems (in-house and third-party)
- Risk-level classification of each system (Annex III)
- Gap analysis against the EU AI Act
- Verification that no system falls under prohibited practices
- AI literacy status of your team (Art. 4)
- Prioritized action plan with owners and deadlines
- Results session with leadership and technical team
- Delivered in 2-3 weeks
Investment
From the diagnostic to the full compliance program.
Reference ranges based on the number of AI systems, their risk level, and the size of the organization. Always less than a fine of 7% of turnover.
AI Compliance Diagnostic
The starting point. In 2-3 weeks you know which systems you run, their risk, and what you are missing.
- Inventory of all AI systems (in-house and third-party)
- Risk classification per Annex III
- Gap analysis against the EU AI Act
- Prioritized action plan with deadlines
- Results session with your team
AI Literacy Training
The Art. 4 obligation, already in force. Program tailored to each role.
- Content by profile (leadership, technical, user)
- In-person workshop or e-learning
- Participation certification
- Material aligned with the European AI Office
Full Compliance Program
To reach the deadline with your dossier ready.
- Everything in the diagnostic
- Technical documentation (Annex IV)
- Impact assessment and AI governance
- Human oversight and decision logging
- Preparation for audit and certification
No lock-in. Cancel with 30 days notice.
Compliance Process
From inventory to documented conformity.
Inventory
We map every AI system in your organization: chatbots, predictive models, HR tools, scoring, automations. We include third-party AI (OpenAI, Google, Azure AI APIs) that you use.
Classification
We classify each system by risk level per Annex III. We identify specific obligations: transparency for limited risk, full requirements for high risk, and verify that no system falls under prohibited practices.
Remediation
We implement the required technical and organizational measures: technical documentation, impact assessment, governance policies, team training, human oversight mechanisms, and decision logging.
Documentation and Monitoring
We prepare the complete conformity dossier: technical documentation (Annex IV), impact assessment, EU database registration (for high-risk), and a continuous post-deployment monitoring system.
Risks We Mitigate
From regulatory exposure to verified conformity.
Non-compliance fines (up to €35M / 7% revenue)
Full compliance program: inventory, classification, documentation, and monitoring. Conformity dossier ready for regulatory inspection.
AI literacy non-compliance (obligation already in force)
Role-adapted training program with participation certification. Content updated per the European AI Office guidelines.
Undocumented high-risk AI systems
Exhaustive inventory + Annex IV technical documentation: training data, performance metrics, bias analysis, and mitigation measures.
Chatbots and generative AI lacking transparency
Audit of all AI interfaces: clear AI interaction identification, generated content labeling, and human intervention request mechanism.
Real-World Experience in Applied AI and Compliance
At Kiwop, we've spent years building and integrating AI solutions for businesses: intelligent chatbots, enterprise RAG, AI agents, and LLM integration. This hands-on technical experience lets us understand the regulation from a developer's perspective, not just a legal consultant's. We know what compliance means because we build the systems that must comply.
EU AI Act vs GDPR: What Changes and What Stacks
The EU AI Act doesn't replace the GDPR: it builds on top of it.
If your organization already complies with the GDPR, you have a foundation, but the EU AI Act adds AI-specific requirements the GDPR doesn't cover: risk classification, model technical documentation, algorithmic bias assessment, mandatory human oversight, and AI-specific transparency. EU AI Act fines exceed the GDPR: up to 7% of global turnover vs 4% under the GDPR. Both regulations apply simultaneously: a chatbot that processes personal data must comply with both. Our privacy engineering service covers the personal data front.
Frequently Asked Questions
What companies ask about the EU AI Act.
What is the EU AI Act and when does it apply?
The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive AI regulation. It entered into force on 1 August 2024 and applies in stages: 2 February 2025 (AI literacy + prohibited practices), 2 August 2025 (GPAI obligations + governance), 2 August 2026 (Annex III high-risk AI and penalties for GPAI providers), and 2 August 2027 (high-risk AI embedded in Annex I products). It applies to any organization that provides or uses AI in the EU market.
Who does the EU AI Act apply to?
It applies to any organization that develops, provides, or uses AI systems in the EU market, whether or not it is headquartered in Europe. It does not distinguish by sector or size: an SME using a chatbot, a bank running credit scoring, or a US company with European customers are all in scope. Specific obligations vary by your role (provider or deployer) and the system's risk level, but AI literacy (Art. 4) applies across the board.
What changes on 2 August 2026?
The full requirements for Annex III high-risk AI systems apply: risk management, data quality, technical documentation, human oversight, and robustness. On the same date, penalties for providers of GPAI models become applicable; their obligations have applied since 2 August 2025. For high-risk AI embedded in regulated products under Annex I, the deadline is 2 August 2027.
How much are the fines for breaching the EU AI Act?
The fines exceed the GDPR: up to €35M or 7% of global annual turnover (whichever is higher) for prohibited practices. For most other violations, including high-risk and GPAI provider obligations: up to €15M or 3%. For supplying incorrect or misleading information to authorities: up to €7.5M or 1%. For SMEs and start-ups, the lower of the two amounts applies.
What is a high-risk AI system?
It is an AI system that, under Annex III, may affect people's safety or fundamental rights. This includes AI in HR recruitment and management (CV filtering, performance evaluation), credit and insurance scoring, administration of justice, border control, critical infrastructure, education (admissions, assessments), and healthcare (diagnosis, triage). If your AI influences decisions that affect people's rights, it is likely high-risk.
What is a general-purpose AI (GPAI) model?
A general-purpose AI (GPAI) model is a large-scale model trained to perform many different tasks, such as GPT, Claude, or Gemini. Their providers have had obligations since 2 August 2025 (technical documentation, transparency, copyright compliance), and the associated penalties become applicable on 2 August 2026. If your company integrates one of these models via API, you are a deployer and have your own obligations, even though you are not the model provider.
My SME uses AI but doesn't develop it. What are my obligations?
Even if you only use third-party AI (ChatGPT, Copilot, a chatbot, an HR tool), you are a deployer and already have obligations. Since 2 February 2025 you must ensure your team's AI literacy (Art. 4) and avoid prohibited practices. If the system is high-risk, you add human oversight, transparency, and impact assessment. These obligations cannot be delegated to the model provider. Check which ones apply to you in two minutes with our EU AI Act self-assessment.
What is the mandatory AI literacy obligation (Art. 4)?
It is the obligation, in force since 2 February 2025, for every organization that uses or oversees AI systems to ensure its staff have sufficient knowledge of AI: what it is, how it works, its risks, and its responsible use. A generic talk is not enough: it must be tailored to each person's role and documented. It is the first obligation that affects virtually every company, whether it develops AI or not.
How do I start complying with the EU AI Act?
Start by knowing what you have: our EU AI Act self-assessment places you in two minutes, free. For the full inventory, our AI Compliance Diagnostic inventories all your AI systems, classifies them by risk level (Annex III), detects the gaps against the regulation, and delivers a prioritized action plan in 2-3 weeks. From there you know exactly what to do and in what order, without spending ahead of time. If you want to go deeper into architecture, we pair it with AI consulting.
Where can I read more about the AI Act?
We have published a complete guide to the EU AI Act for businesses covering the application timeline, the risk tiers, obligations by role, and the concrete steps to get ready. If you prefer something applied to your own case, the AI Compliance Diagnostic gives you your organization's real status against the regulation.
Penalties for GPAI Providers Apply From 2 August 2026: Reach the Deadline Ready
AI literacy is already mandatory and the high-risk deadline is around the corner. Start with the AI Compliance Diagnostic: in 2-3 weeks you know which systems you run, their risk, and what you are missing.
Request a compliance diagnostic Initial technical
consultation.
AI, security and performance. Diagnosis with phased proposal.
Your first meeting is with a Solutions Architect, not a salesperson.
Request diagnosis