EU AI Act Compliance: GPAI Penalties in Force, High-Risk Rules From December 2027

An EU AI Act compliance diagnostic costs €4,500-9,000 and takes 2-3 weeks: you learn which AI systems you use, their risk level, and what you are missing. AI literacy and the bans have applied since 2025, Annex III high-risk AI must comply from 2 December 2027, and fines reach €35M or 7% of global turnover.

  • €35M Maximum Fine (7% Turnover)
How compliance works: inventory, risk, controls, evidence, audit and an accountable person Every finding updates the controls 01 · Inventory Systems, data andrisks 02 · Risk Classification andthresholds 03 · Controls Technical andorganisational 04 · Evidence Records that proveit 05 · Audit Internal andexternal 06 · Accountable A person answersfor it
  1. 01 · Inventory Systems, data and risks
  2. 02 · Risk Classification and thresholds
  3. 03 · Controls Technical and organisational
  4. 04 · Evidence Records that prove it
  5. 05 · Audit Internal and external
  6. 06 · Accountable A person answers for it
  7. Every finding updates the controls
Scroll

In numbers

The State of AI Regulation

Figures from the regulation that demand action now.

  • €15M High-Risk & GPAI Or 3% of turnover for breaching high-risk or GPAI provider obligations
  • 2 Feb 2025 Already in Force AI literacy measures (Art. 4) and prohibited practices
  • 2 Dec 2027 High-Risk (Annex III) Date set by Regulation (EU) 2026/1744; previously 2 August 2026

Why

EU AI Act Timeline: Deadlines Already in Force

What already applies and what arrives up to 2028, including the changes made by Regulation (EU) 2026/1744.

2 February 2025 (IN FORCE): AI literacy for staff (Art. 4) and prohibition of unacceptable AI practices (subliminal manipulation, social scoring, mass biometric surveillance). 2 August 2025 (IN FORCE): obligations for general-purpose AI models (GPAI), the governance framework, and the general penalties regime. 2 August 2026 (IN FORCE): general application of the regulation, transparency obligations (Art. 50), and penalties for GPAI model providers. 2 December 2026 (NEXT DEADLINE): new prohibited practices (AI-generated non-consensual sexual content and child sexual abuse material) and marking of content generated by systems already on the market. 2 August 2027: GPAI models placed on the market before 2 August 2025. 2 December 2027: full requirements for high-risk AI systems under Annex III (risk management, data quality, transparency, human oversight, robustness). 2 August 2028: high-risk AI embedded in regulated products under Annex I (machinery, medical devices, toys). The high-risk dates are those set by Regulation (EU) 2026/1744, in force since 27 July 2026.

compliance/eu-ai-act-timeline.yaml
# EU AI Act timeline (Regulation (EU) 2024/1689 + 2026/1744)
2025-02-02: # IN FORCE
- AI literacy (Art. 4)
- Prohibited practices
2025-08-02: # IN FORCE
- GPAI obligations + governance
2026-08-02: # IN FORCE
- Transparency (Art. 50) + GPAI penalties
2026-12-02: # NEXT DEADLINE
- New prohibited practices
2027-12-02:
- High-risk AI (Annex III)
2028-08-02:
- Embedded high-risk (Annex I)
  • 3 Deadlines in Force
  • 2 Dec 2026 Next
  • €35M Max Fine

What's included

What Our Service Includes

From inventory to documented compliance.

  • AI literacy training: to meet the obligation to take AI literacy measures (Art. 4, as worded by Regulation 2026/1744) for staff who use or oversee AI systems
  • AI system inventory and classification: mapping all AI uses and classifying by risk level (minimal, limited, high, unacceptable)
  • Risk assessment: fundamental rights impact analysis for high-risk systems per Annex III
  • Technical documentation: training data records, performance metrics, detected biases, and mitigation measures
  • Conformity assessment preparation: getting your organization ready for notified body audits
  • Chatbot and AI feature compliance: transparency, generated content identification, and user rights

Definition

What Is the EU AI Act?

The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive artificial intelligence regulation. It establishes a legal framework based on the risk level of each AI system: prohibited practices, obligations for high-risk AI, transparency requirements, and the obligation to take AI literacy measures (Art. 4, as worded by Regulation 2026/1744).

In force since 1 August 2024 and applied in stages, the EU AI Act classifies AI systems into four risk tiers: unacceptable (prohibited: social scoring, subliminal manipulation), high (strictly regulated: AI in HR, credit, justice, healthcare), limited (transparency obligations: chatbots, deepfakes), and minimal (no specific obligations). It applies to any provider or deployer of AI systems operating in the EU market, regardless of where they are headquartered. It complements the GDPR on data protection and establishes specific requirements for general-purpose AI models (GPAI) from providers like OpenAI, Anthropic and Google.

Why

Private AI: The Shortest Path to Compliance

Your data, your AI. Impossible to copy, easier to audit.

Complying with the EU AI Act is far simpler when you control the system. A private AI, with your data on your own infrastructure (private RAG, models under your control), gives you exactly what the law demands: decision traceability, data governance, transparency, and real human oversight. Relying on an opaque third-party SaaS leaves those obligations out of your reach, because you cannot see what data goes in, how decisions are made, or where processing happens. We build your enterprise RAG on data that never leaves your control and pair it with AI consulting so architecture and compliance move together.

compliance/private-ai-vs-saas.md
# Control the EU AI Act requires
Private AI (RAG + own models):
data_residency: your infrastructure
traceability: decision logs
data_governance: under your control
human_oversight: built in
Opaque third-party SaaS:
data_residency: unknown
traceability: limited
data_governance: the vendor's
  • Your Control Data
  • Full Traceability
  • Simpler Audit

Summary

Executive Summary

What you need to know to take action.

The EU AI Act already has three deadlines in force: since 2 February 2025, organizations must take AI literacy measures (Art. 4) and unacceptable AI practices are prohibited; since 2 August 2025, GPAI models have transparency and governance obligations; and since 2 August 2026, the Art. 50 transparency rules and penalties for GPAI providers apply. The main deadline is now 2 December 2027: Regulation (EU) 2026/1744 moved the risk management, data quality, transparency, and human oversight requirements for Annex III high-risk AI to that date.

The fines exceed the GDPR: up to €35M or 7% of global turnover. The delay buys time, not an exemption: organizations that reach the deadline with their dossier ready avoid sanctions and gain an edge over competitors who have not moved yet. The starting point is the diagnostic: knowing which AI systems you run, their risk level, and what you are missing.

  • €35M Maximum Fine (7% Turnover)
  • 2 Dec 2027 High-Risk (Annex III)
  • 2-3 wks Compliance Diagnostic

For the CTO

Summary for CTO / Technical Team

Technical requirements and compliance framework.

The EU AI Act mandates a continuous risk management system for high-risk AI: training dataset documentation (provenance, quality, biases), performance and fairness metrics, automated decision logging, human-in-the-loop oversight mechanisms, and robustness testing against adversarial attacks, ground we share with our cybersecurity service.

For chatbots and user-facing AI features, the law requires clear transparency: users must know they are interacting with AI, AI-generated content must be labeled as such (including deepfakes), and there must be a mechanism to request human intervention. GPAI models require complete technical documentation including model cards.

Technologies

  • ISO 42001
  • NIST AI RMF
  • EU AI Act
  • GDPR
  • Model Cards
  • AI Risk Registry
  • Fairness Metrics
  • MLflow
  • Automated AI system inventory with risk classification
  • Bias monitoring and fairness metrics pipeline
  • Automated decision logging for traceability
  • Human-in-the-loop for high-risk systems
  • Model cards and technical documentation per Annex IV

Who it is for

Is It Right for You?

The EU AI Act affects every organization that uses or develops AI systems in the European market.

Who it's for

  • Companies that use chatbots, virtual assistants, or generative AI in customer service.
  • Organizations that use AI for HR decisions (recruiting, performance evaluation).
  • Financial companies that use AI for credit scoring or fraud detection.
  • Any organization using AI with an AI literacy obligation (Art. 4).
  • Software providers that integrate AI models into their products.
  • Healthcare companies that use AI for diagnosis, triage, or treatment.

Who it's not for

  • AI systems used exclusively for scientific research (exempt).
  • Open-source AI with minimal risk and no direct commercial use.
  • Purely military or national defense AI systems (outside the EU AI Act scope).

Key points

EU AI Act Compliance Services

Packages tailored to each phase of the regulation.

  1. 01

    AI Literacy Training

    Obligation already in force (Art. 4). Training program tailored to each employee's role: what AI is, how it works, risks, ethical use, and legal obligations. Available as in-person workshop or e-learning. Participation certificate: documenting the training is not mandatory, but we recommend it so you can show the measures you have taken.

  2. 02

    Inventory and Risk Classification

    Complete mapping of all AI systems in use (in-house and third-party). Risk-level classification under the regulation: unacceptable, high, limited, or minimal. Compliance gap identification and prioritized roadmap.

  3. 03

    Impact Assessment and Documentation

    For high-risk systems: fundamental rights impact assessment, technical documentation per Annex IV (training data, metrics, biases, mitigation measures), and conformity dossier preparation.

  4. 04

    AI Governance and Monitoring

    Design and implementation of an AI governance program: internal policies, AI Risk Registry, AI ethics committee, approval workflows for new systems, and continuous performance and fairness monitoring.

  5. 05

    Chatbot and AI Feature Compliance

    Specific audit of chatbots, virtual assistants, and generative AI features: transparency, AI-generated content labeling, human intervention request mechanism, and compliance with limited-risk system obligations.

Deliverables

AI Compliance Diagnostic: What You Get

The starting point, delivered in 2-3 weeks.

  • Complete inventory of AI systems (in-house and third-party)
  • Risk-level classification of each system under the regulation
  • Gap analysis against the EU AI Act
  • Verification that no system falls under prohibited practices
  • AI literacy status of your team (Art. 4)
  • Prioritized action plan with owners and deadlines
  • Results session with leadership and technical team
  • Delivered in 2-3 weeks

Investment

Investment

From the diagnostic to the full compliance program.

Reference ranges based on the number of AI systems, their risk level, and the size of the organization. Always less than a fine of 7% of turnover.

  • AI Compliance Diagnostic Start Here

    €4,500-9,000

    The starting point. In 2-3 weeks you know which systems you run, their risk, and what you are missing.

    • Inventory of all AI systems (in-house and third-party)
    • Risk classification under the regulation
    • Gap analysis against the EU AI Act
    • Prioritized action plan with deadlines
    • Results session with your team
    Talk to an architect
  • AI Literacy Training

    €3,000-6,000

    The Art. 4 obligation, already in force. Program tailored to each role.

    • Content by profile (leadership, technical, user)
    • In-person workshop or e-learning
    • Participation certification
    • Material aligned with the European AI Office
    Talk to an architect
  • Full Compliance Program

    €15,000-30,000

    To reach the deadline with your dossier ready.

    • Everything in the diagnostic
    • Technical documentation (Annex IV)
    • Impact assessment and AI governance
    • Human oversight and decision logging
    • Preparation for audit and certification
    Talk to an architect

No lock-in. Cancel with 30 days notice.

How we work

Compliance Process

From inventory to documented conformity.

  1. 01

    Inventory

    We map every AI system in your organization: chatbots, predictive models, HR tools, scoring, automations. We include third-party AI (OpenAI, Google, Azure AI APIs) that you use.

    Week 1
  2. 02

    Classification

    We classify each system by risk level under the regulation. We identify specific obligations: transparency for limited risk, full requirements for high risk, and verify that no system falls under prohibited practices. We close the diagnostic with the gap analysis and the action plan.

    Week 2-3
  3. 03

    Remediation

    We implement the required technical and organizational measures: technical documentation, impact assessment, governance policies, team training, human oversight mechanisms, and decision logging.

    Week 4-12
  4. 04

    Documentation and Monitoring

    We prepare the complete conformity dossier: technical documentation (Annex IV), impact assessment, EU database registration (for high-risk), and a continuous post-deployment monitoring system.

    Ongoing

Risks and how we cover them

Risks We Mitigate

From regulatory exposure to verified conformity.

  1. 01

    Non-compliance fines (up to €35M / 7% revenue)

    Mitigation

    Full compliance program: inventory, classification, documentation, and monitoring. Conformity dossier ready for regulatory inspection.

  2. 02

    AI literacy non-compliance (obligation already in force)

    Mitigation

    Role-adapted training program with participation certification. Content updated per the European AI Office guidelines.

  3. 03

    Undocumented high-risk AI systems

    Mitigation

    Exhaustive inventory + Annex IV technical documentation: training data, performance metrics, bias analysis, and mitigation measures.

  4. 04

    Chatbots and generative AI lacking transparency

    Mitigation

    Audit of all AI interfaces: clear AI interaction identification, generated content labeling, and human intervention request mechanism.

Technologies

Frameworks and Tools

International AI governance standards.

  • ISO 42001
  • NIST AI RMF
  • EU AI Act
  • GDPR
  • Model Cards
  • AI Risk Registry
  • Bias Detection
  • Fairness Metrics
  • MLflow
  • Weights & Biases
  • AI Incident Database
  • ALTAI
  • EN 301 549
  • ISO 27001

The proof

Real-World Experience in Applied AI and Compliance

At Kiwop, we've spent years building and integrating AI solutions for businesses: intelligent chatbots, enterprise RAG, AI agents, and LLM integration. This hands-on technical experience lets us understand the regulation from a developer's perspective, not just a legal consultant's. We know what compliance means because we build the systems that must comply.

  • 30+ LLM Projects Since 2023
  • 3 Regulation Deadlines in Force
  • Dec 2026 Next Regulation Deadline
  • 2-3 wks Compliance Diagnostic

Why

EU AI Act vs GDPR: What Changes and What Stacks

The EU AI Act doesn't replace the GDPR: it builds on top of it.

If your organization already complies with the GDPR, you have a foundation, but the EU AI Act adds AI-specific requirements the GDPR doesn't cover: risk classification, model technical documentation, algorithmic bias assessment, mandatory human oversight, and AI-specific transparency. EU AI Act fines exceed the GDPR: up to 7% of global turnover vs 4% under the GDPR. Both regulations apply simultaneously: a chatbot that processes personal data must comply with both. Our privacy engineering service covers the personal data front.

  • 4% Max Fine GDPR
  • 7% Max Fine EU AI Act
  • €35M Prohibited Practices
  • €15M High-Risk & GPAI

Sources

Sources for the Figures on This Page

Official EU texts and our own data. Accessed 26 September 2026.

  1. Regulation (EU) 2024/1689 on artificial intelligence, official text on EUR-Lex Fines under Art. 99 (€35M or 7% for prohibited practices; €15M or 3% for other obligations; €7.5M or 1% for incorrect information; the lower amount for SMEs) and Art. 101 (€15M or 3% for GPAI providers). Dates in Art. 113: entry into force on 1 August 2024 and application on 2 February 2025, 2 August 2025, and 2 August 2026. Art. 4 (AI literacy) and Annexes I, III, and IV.
  2. Regulation (EU) 2026/1744 (Digital Omnibus on AI), official text on EUR-Lex In force since 27 July 2026. Moves Annex III high-risk AI to 2 December 2027 and Annex I high-risk AI to 2 August 2028, adds prohibited practices from 2 December 2026, and rewrites Art. 4 as a duty to take AI literacy measures.
  3. Council of the EU, press release of 29 June 2026 Final adoption of the Digital Omnibus on AI and the new high-risk dates: 2 December 2027 and 2 August 2028.
  4. Regulation (EU) 2016/679 (GDPR), official text on EUR-Lex Art. 83: fines up to €20M or 4% of global turnover, the figure the AI Act's 7% is compared with.
  5. Kiwop's published prices and timelines for this service (September 2026) Diagnostic €4,500-9,000 in 2-3 weeks, AI literacy training €3,000-6,000, and full programme €15,000-30,000.
  6. Kiwop experience in LLM projects (2023-2026) More than 30 LLM projects since 2023. Internal figure: no published case study breaks it down.

FAQ

Frequently Asked Questions

What companies ask about the EU AI Act.

What is the EU AI Act and when does it apply?

The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive AI regulation. It entered into force on 1 August 2024 and applies in stages: 2 February 2025 (AI literacy + prohibited practices), 2 August 2025 (GPAI obligations + governance), 2 August 2026 (general application, transparency, and penalties for GPAI providers), 2 December 2027 (Annex III high-risk AI), and 2 August 2028 (high-risk AI embedded in Annex I products). The last two dates were set by Regulation (EU) 2026/1744. It applies to any organization that provides or uses AI in the EU market.

Who does the EU AI Act apply to?

It applies to any organization that develops, provides, or uses AI systems in the EU market, whether or not it is headquartered in Europe. It does not distinguish by sector or size: an SME using a chatbot, a bank running credit scoring, or a US company with European customers are all in scope. Specific obligations vary by your role (provider or deployer) and the system's risk level, but AI literacy (Art. 4) applies across the board.

What Changed on 2 August 2026, and What Was Postponed?

On 2 August 2026, penalties for providers of GPAI models became applicable (their obligations have applied since 2 August 2025), along with the Art. 50 transparency obligations, such as telling people they are talking to an AI. The requirements for Annex III high-risk AI (risk management, data quality, technical documentation, human oversight, and robustness), originally due on that date, were postponed to 2 December 2027 by Regulation (EU) 2026/1744. High-risk AI embedded in Annex I products moves to 2 August 2028.

How much are the fines for breaching the EU AI Act?

The fines exceed the GDPR: up to €35M or 7% of global annual turnover (whichever is higher) for prohibited practices. For most other violations, including high-risk and GPAI provider obligations: up to €15M or 3%. For supplying incorrect or misleading information to authorities: up to €7.5M or 1%. For SMEs and start-ups, the lower of the two amounts applies.

What is a high-risk AI system?

It is an AI system that, under Annex III, may affect people's safety or fundamental rights. This includes AI in HR recruitment and management (CV filtering, performance evaluation), credit and insurance scoring, administration of justice, border control, critical infrastructure, education (admissions, assessments), and healthcare (diagnosis, triage). If your AI influences decisions that affect people's rights, it is likely high-risk.

What is a general-purpose AI (GPAI) model?

A general-purpose AI (GPAI) model is a large-scale model trained to perform many different tasks, such as GPT, Claude, or Gemini. Their providers have had obligations since 2 August 2025 (technical documentation, transparency, copyright compliance), and the associated penalties have applied since 2 August 2026. If your company integrates one of these models via API, you are a deployer and have your own obligations, even though you are not the model provider.

My SME uses AI but doesn't develop it. What are my obligations?

Even if you only use third-party AI (ChatGPT, Copilot, a chatbot, an HR tool), you are a deployer and already have obligations. Since 2 February 2025 you must take AI literacy measures for your team (Art. 4) and avoid prohibited practices. If the system is high-risk, you add human oversight, transparency, and impact assessment. These obligations cannot be delegated to the model provider. Check which ones apply to you in two minutes with our EU AI Act self-assessment.

What does Art. 4 require on AI literacy?

It is the obligation, in force since 2 February 2025, for every organization that uses or oversees AI systems to take measures so its staff understand AI: what it is, how it works, its risks, and its responsible use. Since Regulation (EU) 2026/1744 it is an obligation of means: it does not require a specific level for each person, nor does it require documentation. Even so, we recommend tailoring the training to each role and keeping a record of it so you can prove it. It is the first obligation that affects virtually every company, whether it develops AI or not.

How do I start complying with the EU AI Act?

Start by knowing what you have: our EU AI Act self-assessment places you in two minutes, free. For the full inventory, our AI Compliance Diagnostic inventories all your AI systems, classifies them by risk level under the regulation, detects the gaps against the regulation, and delivers a prioritized action plan in 2-3 weeks. From there you know exactly what to do and in what order, without spending ahead of time. If you want to go deeper into architecture, we pair it with AI consulting.

Where can I read more about the AI Act?

This page has the up-to-date timeline, with the dates set by Regulation (EU) 2026/1744, and links to the official texts on EUR-Lex. To see which obligations apply to you, take our EU AI Act self-assessment: ten questions and an indicative result. If you prefer something applied to your own case, the AI Compliance Diagnostic gives you your organization's real status against the regulation.

Next step

High-Risk AI Deadline on 2 December 2027: Get There With Your Dossier Ready

AI literacy measures are already mandatory and GPAI penalties already apply. Start with the AI Compliance Diagnostic: in 2-3 weeks you know which systems you run, their risk, and what you are missing.

  • No commitment
  • Response in 24h
  • Custom proposal
Last updated: September 2026

Let's talk.

Initial technical consultation

AI, security and performance. Diagnosis with phased proposal.

  • NDA available
  • Response <24h
  • Phased proposal

Your first meeting is with a Solutions Architect, not a salesperson.

Talk to an architect