The EU AI Act, dated honestly.
What already applies, what is coming, what the penalties are, and which obligations actually land on a mid-market organisation that uses AI rather than builds it.
The timeline.
Penalties are ceilings, not tariffs, and they sit in three tiers under Article 99. Only breaches of the Article 5 prohibitions reach €35M or 7%. High-risk and transparency breaches sit at €15M or 3%.
The €35M / 7% figure is frequently attached to high-risk non-compliance. It does not apply there. Article 99(3) reserves it for the Article 5 prohibitions; Article 99(4) puts provider, deployer and Article 50 transparency breaches at €15M or 3%; Article 99(5) puts misleading information to an authority at €7.5M or 1%. And for SMEs and start-ups, Article 99(6) applies the lower of the fixed sum and the percentage, not the higher — the reverse of the rule for everyone else.
| Date | Obligation | Status |
|---|---|---|
| 2 Feb 2025 | Prohibited AI practices Social scoring, real-time biometric identification in public spaces, emotion recognition at work or school, manipulative techniques, untargeted facial scraping. Article 99(3): up to €35M or 7% of worldwide turnover. | IN FORCE |
| 2 Feb 2025 | AI literacy Staff working with AI must have a sufficient understanding of it, appropriate to their role. Applies to deployers, which means it applies to you. | IN FORCE |
| 2 Aug 2025 | General-purpose AI rules and governance Technical documentation, training transparency, copyright compliance. National authorities and the AI Office active from this date. | IN FORCE |
| 2 Aug 2026 | Transparency duty (Article 50) People must be told when they are interacting with AI. Synthetic media carries a machine-readable disclosure. Article 99(4): up to €15M or 3% of worldwide turnover. | IN FORCE |
| 2 Aug 2027 | GPAI transition ends Models placed on the market before August 2025 must be fully compliant by this date. | UPCOMING |
| 2 Dec 2027 | Full high-risk obligations Annex III: biometrics, critical infrastructure, education, HR and recruitment, essential services, law enforcement, migration. Article 99(4): up to €15M or 3% of worldwide turnover. | UPCOMING |
| 2 Aug 2028 | High-risk AI in regulated products Medical devices, machinery, vehicles. Governed by existing product legislation as well as the Act. | UPCOMING |
Full high-risk obligations for Annex III systems were deferred from 2 August 2026 to 2 December 2027 by the Digital Omnibus amendment, Regulation (EU) 2026/1744, in force 27 July 2026. High-risk AI in regulated products remains at 2 August 2028. The amendment package changed more than the dates, so check the consolidated text rather than a summary — but anyone still selling urgency on the original 2026 deadline is either out of date or hoping you are.
Provider or deployer? Almost everything turns on this.
Most mid-market organisations are deployers. The obligations are real but far lighter than the provider set, and a great deal of what gets sold as "AI Act compliance" is aimed at the wrong party.
If you build or substantially modify AI
You are a provider. Also a provider if you put your own name on someone else's high-risk system, or change what it's for.
- Risk management system across the lifecycle
- Data governance and training data quality
- Technical documentation and logging
- Conformity assessment and CE marking
- Registration in the EU database
- Post-market monitoring
If you use AI in your own operations
You are a deployer. This is where most organisations sit, including most that have been sold a provider-shaped programme.
- Use high-risk systems per the provider's instructions
- Assign human oversight to competent, trained, authorised people
- Ensure input data is relevant and representative
- Monitor operation and report serious incidents
- Keep logs where you control them
- Inform workers before high-risk AI is used at work
- AI literacy across staff who work with it
The deployer obligation that catches organisations out is human oversight by a named person with the competence, training and authority to act. Not a policy saying oversight exists. A person, per system, who can be identified.
Which obligations are likely to apply to you?
Three questions to orient yourself in the table above. This narrows down where to look. It does not determine your legal position — that turns on intended purpose, substantial modification and facts no web form can establish.
ISO/IEC 42001, and how it relates.
What it is, how it links to the Act, and what certification costs
What it is
A voluntary, certifiable AI management system standard — ISO 27001 for AI. Published December 2023. Structured the same way, so it maps onto an ISMS you already run.
How it links to the Act
Complementary, not equivalent. Certification gives no presumption of conformity with the Act. The evidence feeds AI Act documentation; it does not replace it.
What certification costs
Typically six to twelve months. Audit fees from around $5,000, with whole programmes commonly $10,000 to $100,000-plus. Three-year certificate with annual surveillance.
Anyone telling you that 42001 certification satisfies the AI Act is wrong, and it is the kind of wrong that is expensive to discover late.
Every obligation above assumes you know what you are running.
Read the deployer list again. Human oversight per high-risk system. Input data relevance per system. Incident reporting per system. Worker information per system. Logs per system.
None of it can be satisfied without a current inventory of what AI exists, what it is used for, and who is accountable for each one. That is the clause most organisations cannot currently satisfy — not because the requirement is hard, but because the register doesn't exist.
The boundary, stated plainly.
This page is a plain-English summary for orientation. It is not legal advice. Qualified counsel in your jurisdiction should be engaged for interpretation, and the position differs across EU, UK, Dutch and Swiss law.
Moustr does not certify compliance with the EU AI Act, ISO/IEC 42001 or any other framework, and does not provide legal advice. It provides the underlying evidence — a continuously current record of what AI exists, who owns it and what is known about it — that legal, compliance and audit teams need to assess and demonstrate their own position.
Sources: Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, consolidated text on EUR-Lex · Article 99 · European Commission AI Act overview. Reference page v1.2, last reviewed 6 September 2026. If a date on this page has moved and we haven't updated it, tell us and we will.