Skip to content
Home / EU AI Act Compliance
Pillar Guide

EU AI Act compliance: deadlines, penalties, and the evidence regulators expect.

“We’re not in Europe” is the most expensive assumption in AI right now. If your AI outputs reach EU users, the Act reaches you — and the high-risk obligations land on August 2, 2026.

⏱ High-risk obligations apply from August 2, 2026 — the audit window opens the day each system enters service.

Does the EU AI Act apply to you?

The Act is extraterritorial by design. It applies to providers placing AI systems on the EU market, to deployers established in the EU — and, critically, to providers and deployers outside the EU when the output of their AI system is used in the Union. A North American SaaS product with EU customers, a bank whose models score EU residents, a manufacturer whose AI-assisted product ships to Europe: all in scope.

The question is not whether you have an EU office. It is whether any AI system you run produces output that touches EU users — and whether you could prove, with records, how that system behaves.

The enforcement timeline

DateWhat becomes enforceable
February 2, 2025Prohibited practices banned (social scoring, manipulative systems, most real-time biometric ID); AI literacy obligations begin.
August 2, 2025Obligations for general-purpose AI models; governance structures live; penalties become applicable.
August 2, 2026The big one: high-risk system obligations (Annex III) and transparency requirements apply — risk management, data governance, logging, human oversight, post-market monitoring, all with documented evidence.
August 2, 2027High-risk AI embedded in regulated products; deadline for legacy general-purpose models.

What non-compliance costs

ViolationMaximum penalty
Prohibited AI practices (Article 5)€35M or 7% of global annual turnover — whichever is higher
Most other obligations (incl. high-risk requirements)€15M or 3% — whichever is higher
Supplying incorrect or misleading information to authorities€7.5M or 1% — whichever is higher
€35M / 7%

Article 99 penalties apply when contemporaneous evidence is absent — not only when systems fail. A policy document written after the letter arrives is not evidence. Records generated while the system runs are.

What compliance actually requires

Strip away the legal prose and the Act asks six operational questions. Regulators on three continents are converging on the same list:

  • Inventory: Do you know every AI system you run, and its risk classification?
  • Governance: Is there a named owner, a risk-management system, and documented data governance for each?
  • Logging & records: Does each high-risk system keep automatic logs a regulator could inspect?
  • Human oversight: Can a person understand, intervene in, and override the system — provably?
  • Independent validation: Has anyone outside the build team tested the system’s claims? (This is where AI security testing and conformity overlap.)
  • A kill switch: Can you stop the system — and show that you can?

Notice what all six have in common: they are answered with evidence, not intentions. That is HANDVANTAGE’s entire thesis — policies don’t pass audits; evidence does.

How HANDVANTAGE gets you there

Start: know your exposure (free, 15 minutes)

The EU AI Act exposure check classifies every AI system you run, gives you your risk tier, your binding deadline, and your maximum penalty exposure in dollars — then a personalised action plan. No lawyer required.

Then: stand up the six controls with evidence

We implement governance, logging, oversight and validation mapped simultaneously to the EU AI Act, ISO 42001, NIST AI RMF and SOC 2 — one audit trail, eleven frameworks, continuously maintained. The ISO 42001 gap assessment shows how far you are from the world’s first certifiable AI management standard.

Architecture, when it is the answer

For agentic AI, the cleanest path to compliant logging and oversight is running AI inside your own boundary: Vantage Workspace signs every AI action to a named person and ships with the assessment module’s EU AI Act template active. For what agent-specific risk looks like, read the agentic AI security guide.

Frequently asked questions

Does the EU AI Act apply to companies outside the EU?
Yes. It applies to providers and deployers located outside the EU when the output of their AI systems is used in the Union — the same extraterritorial logic as GDPR. An EU office is not required for you to be in scope.
What deadline matters in 2026?
August 2, 2026: obligations for high-risk AI systems under Annex III and transparency requirements become enforceable — risk management, data governance, automatic logging, human oversight and post-market monitoring, all with documentation. Penalties have already been applicable since August 2025.
What counts as a high-risk AI system?
Annex III lists the categories: AI used in employment and HR decisions, credit scoring and essential services, education, critical infrastructure, law enforcement, migration, justice, and biometric systems, among others. Many ordinary business uses — CV screening, loan decisioning — are high-risk.
What are the maximum fines?
€35M or 7% of global annual turnover (whichever is higher) for prohibited practices; €15M or 3% for most other violations including high-risk obligations; €7.5M or 1% for misleading regulators. For SMEs the lower of the two amounts applies.
What evidence do regulators actually expect?
Contemporaneous records: automatic logs from the running system, a maintained risk-management file, documented human oversight, and proof the controls were operating — not policy documents written after an inquiry begins. The audit window opens the day each system enters service.
Where do I start with EU AI Act compliance?
Inventory and classify your AI systems first — that determines everything else. The free 15-minute exposure check at SecVantages does exactly this and returns your risk tier, deadline and penalty exposure with an action plan.

Fifteen minutes to know your exposure.

Your risk tier, your binding deadline, your penalty exposure in dollars — and a plan. Free, no lawyer required.

Handvantage

AI security testing and governance evidence for regulated work.

hello@handvantage.com

Canada

HANDVANTAGE SERVICES LTD
329 Howe Street #1589
Vancouver, BC V6C 3N2
Canada

United States

Handvantage LLC
1111B S Governors Ave STE 39797
Dover, DE 19904
United States

© 2026 Handvantage. Registered in Canada and the United States.