Home
Blog
EU AI Act: How to Avoid a €35M Fine | Requirements and Checklist
Artificial intelligence
September 30, 2026

EU AI Act: How to Avoid a €35M Fine | Requirements and Checklist

Chief Technical Officer
Key Takeaways
  • The EU AI Act sorts AI into four risk levels. The higher the risk to people, the more rules you follow.
  • It applies to any company whose AI is used in the EU, even if the company is based in the US.
  • Bans have applied since 2 February 2025. Chatbot and AI content labels apply from 2 August 2026. After the AI Omnibus, high-risk rules start on 2 December 2027.
  • Fines go up to €35 million or 7% of global yearly revenue, whichever is higher, for banned AI practices.
  • The European Commission offers a free EU AI Act Compliance Checker. It is a good first step, but it is in beta and is not legal advice.

Think about the rules for cars. Before a new car can drive on public roads, it needs working brakes, seat belts, and lights. Nobody thinks these rules stop people from driving. They just make sure the car does not hurt anyone.

The EU AI Act does the same thing for artificial intelligence. If your company builds or uses AI and has users in Europe, this law is now part of your job. The good news: most of it is common sense, and most AI tools only need a few simple steps.

In this guide, we explain the law in plain words, show the dates that matter, and give you a checklist you can use today.

What Is the EU AI Act?

The EU AI Act is the first big law in the world made just for AI. Its official name is Regulation (EU) 2024/1689. It entered into force on 1 August 2024, and its rules switch on step by step until 2028.

The main idea is simple: the more an AI system can hurt people, the more rules it must follow. A spam filter gets almost no rules. An AI that decides who gets a loan or a job gets a lot of rules. Some AI uses are banned completely.

The law wants three things:

  • AI that is safe, so it does not harm people's health or safety.
  • AI that respects people's rights, so it does not treat anyone unfairly.
  • AI that is honest, so people know when they are talking to a machine or looking at fake content.

In July 2026, the EU updated the law with a package called the AI Omnibus. It gave companies more time for the strictest rules and added new bans. We use the updated dates everywhere in this article.

If you want the bigger picture of how to run AI safely inside a company, read our guide on why AI transformation is a problem of governance.

Who Has to Follow the EU AI Act?

Short answer: almost anyone whose AI touches people in the EU.

Your company does not need an office in Europe. If a US startup sells an AI tool to a company in Germany, or if the results of its AI are used in France, the law can apply.

The law gives different jobs to different players. The two you will meet most often are the provider and the deployer.

RoleWho it isSimple exampleMain job under the law
ProviderThe company that builds an AI system and puts it on the market under its own nameA software company that sells an AI tool for sorting job applicationsMake the system safe and well documented before anyone uses it
DeployerThe company that uses an AI system in its workA retail chain that uses that tool to screen candidatesUse the system the right way, keep a human in control, and tell people about it
Importer and distributorCompanies that bring AI into the EU or resell itA reseller of AI software in EuropeCheck that the provider did its job

One thing surprises many teams. A deployer can become a provider. This happens if you put your own name on someone else's high-risk AI system, change it in a big way, or use it for a new high-risk purpose. For example, if you take a general chatbot and turn it into a tool that scores loan applications, you now carry the provider's duties.

What about OpenAI, Anthropic, and other model makers? Big AI models like GPT or Claude are called general-purpose AI models. The companies behind them have their own rules, which started on 2 August 2025. If you build a product on top of these models, you still have your own duties for your product.

The Four Risk Levels, Explained Simply

The whole law is built like a pyramid. At the top are a few AI uses that are banned. At the bottom are the many everyday tools that have almost no rules.

‍

EU AI Act risk levels. Source: Akveo
Risk levelWhat it meansExamplesWhat you must do
Unacceptable riskAI that is a clear threat to people's safety or rightsSocial scoring, harmful manipulation, emotion recognition at work or school, scraping faces from the internet to build a face database, AI that makes non-consensual intimate imagesDo not build or use it. It is banned.
High riskAI that makes or shapes important decisions about people's livesCV-sorting software, credit scoring, exam scoring, AI in medical devices, AI in critical infrastructure like transportFollow strict rules before launch and while it runs
Transparency riskAI that talks to people or creates contentChatbots, AI voice assistants, AI-generated images, video, and deepfakesTell people they are dealing with AI and label AI-made content
Minimal riskEveryday AI with little riskSpam filters, AI in video games, product recommendationsNo new rules. Good practices are still smart.

Many everyday business tools land in the bottom two levels. A support chatbot, an internal assistant, or a tool that writes marketing drafts is usually transparency risk or minimal risk.

The tricky part is that risk depends on the use, not on the technology. The same language model can be minimal risk when it summarizes meeting notes and high risk when it ranks job candidates.

Key EU AI Act Dates You Should Know

The law does not switch on all at once. It works like a staircase, with a new step every few months. In July 2026, the AI Omnibus moved the high-risk steps further out.

‍

EU AI Act key dates after the AI Omnibus. Source: Akveo
DateStatus todayWhat startsWho it affects
1 August 2024In forceThe law enters into forceEveryone, but no duties yet
2 February 2025In forceBanned AI practices become illegal. AI literacy duties start.Anyone building or using AI
2 August 2025In forceRules for general-purpose AI models, EU governance, and the fines chapter startModel makers like OpenAI, Anthropic, Google, and every company that can now be fined
2 August 2026In forceTransparency rules start: tell users about chatbots, label deepfakes and AI content. The Commission can now fine model makers directly.Chatbots, voice agents, content generators, model makers
2 December 2026Coming soonBan on AI that makes non-consensual intimate images. End of the grace period for labeling content from systems already on the market.Content generators
2 December 2027PlannedHigh-risk rules start for stand-alone systems (hiring, credit, education, and similar)High-risk AI providers and deployers
2 August 2028PlannedHigh-risk rules start for AI inside regulated products (medical devices, machines, toys)Product makers

The delay for high-risk systems is not a reason to wait. Building documentation, logs, and human checks takes months, and it is easier to plan them from day one than to add them to a finished product.

What Happens If You Break the Rules?

The fines are big on purpose. Like GDPR, they are based on a company's worldwide yearly revenue, so they matter even for large companies.

Are the fines real today? Yes. The fines chapter has applied since 2 August 2025. That means a company using a banned AI practice or breaking the transparency rules can be fined right now. The high-risk rules are different: they are not in force yet, so nobody can be fined for them until December 2027 or August 2028.

Can you be fined for it today?Rule
YesUsing a banned AI practice
YesNot telling users they talk to a chatbot, or not labeling deepfakes and AI content
YesGiving wrong information to authorities
Not yetHigh-risk system duties (planned for 2 December 2027 and 2 August 2028)
Not yetBan on AI that makes non-consensual intimate images (starts 2 December 2026)

As of September 2026, we could not find an official public record of an EU AI Act fine against a named company. Each EU country is still setting up its AI regulator, and some are slower than others. So the rules are live, but enforcement is just getting started.

What went wrongMaximum fine
Using a banned AI practice€35 million or 7% of worldwide yearly revenue, whichever is higher
Breaking other duties, like high-risk or transparency rules€15 million or 3% of worldwide yearly revenue, whichever is higher
Giving wrong or misleading information to authorities€7.5 million or 1% of worldwide yearly revenue, whichever is higher

For small and medium companies, including startups, the law uses the lower of the two numbers. That is fair, but even the lower number can hurt a young company.

Fines are not the only risk. A regulator can also order you to take an AI system off the market. For many companies, losing a product or a big EU customer is worse than the fine itself.

EU AI Act Compliance Checklist

You do not need a legal team to start. Use this checklist like a pre-flight check. The first part is for every company that uses AI. The second part is only for high-risk systems.

Part 1: For every AI system

StepWhat to doWhy it matters
Make an AI listWrite down every AI tool you build or use, including chatbots, internal assistants, and AI features inside other softwareYou cannot check what you do not know about
Find your roleFor each tool, decide if you are the provider, the deployer, or bothYour duties depend on your role
Sort by riskPut each tool into one of the four risk levelsThe risk level tells you which rules apply
Check the banned listMake sure nothing you do is on the banned listThese fines are the biggest, and they apply today
Tell people it is AIShow a clear note when users talk to a chatbot or voice agent, and label AI-made images, video, and deepfakesTransparency rules apply since 2 August 2026
Train your teamTeach the people who use or build AI what it can and cannot doAI literacy duties apply since 2 February 2025
Know where your data goesCheck which AI vendors see your data, if they train on it, and how long they keep itThis protects you under both the AI Act and GDPR
Keep a human in the loopMake sure a person can check and stop important AI decisionsIt is required for high-risk AI and smart for everything else

Part 2: Extra steps for high-risk systems

StepWhat to doWho does it
Risk managementFind, test, and reduce risks for the whole life of the systemProvider
Good dataUse training and test data that is relevant, complete, and checked for biasProvider
Technical documentsDescribe how the system works, what it is for, and its limitsProvider
Automatic logsRecord what the system does so problems can be traced. Deployers keep logs for at least six months.Provider and deployer
Accuracy and securityMake the system reliable and protected against attacksProvider
Conformity check and registrationPass a conformity assessment, add the CE mark, and register the system in the EU database before launchProvider
Watch it after launchMonitor how the system works in real life, report serious incidents, and tell affected workers and people that AI is usedProvider and deployer

How to Run a Quick EU AI Act Self-Audit

An audit sounds scary, but the first round can take an afternoon. Here is a simple way to do it.

  1. Open your AI list. Take the list from the checklist above.
  2. Run each tool through the EU AI Act Compliance Checker. The European Commission made a free online tool for this: the EU AI Act Compliance Checker. You answer short questions about your AI system, and it shows which rules may apply to you and what your duties could be as a provider, deployer, or other player.
  3. Mark the gaps. For each tool, note what is missing: a chatbot notice, a content label, a training session, a vendor contract, a log.
  4. Fix the easy things first. Transparency notices and team training are quick wins, and they are already required.
  5. Plan the big things. If a tool is high risk, plan documentation, logging, and human oversight now, before the December 2027 deadline.
  6. Repeat every time something changes. A new feature or a new use case can move a tool to a higher risk level.
EU AI Act Compliance Checker. Source: ai-act-service-desk.ec.europa.eu

A quick note: the Compliance Checker is in beta, and it is not legal advice. It is a great way to see where you stand, but for high-risk systems you will still need a proper review with legal and technical experts.

How Akveo Builds Compliance-Safe AI Software

At Akveo, we build AI products like AI agents and conversational AI assistants for our clients. For us, safe data and safe models are not an extra feature. They are the starting point of every project.

Here is how our CTO, Evgeny Lupanov, describes our approach to AI data governance:

We build on providers like OpenAI and Anthropic, which offer enterprise-grade no-training policies and Zero Data Retention options, ensuring your data isn't used to train foundation models.
‍
When stricter compliance is required, we deploy the same AI models through AWS Bedrock or Microsoft Azure AI. AWS and Microsoft host the models within their own cloud infrastructure, so your data stays inside your existing cloud environment and compliance perimeter, while delivering the same model capabilities.
‍
Evgeny Lupanov, CTO at Akveo

In simple words: your data is not used to teach public AI models, and when you need extra protection, the AI runs inside the cloud you already trust.

Here is what this looks like in a real project. For a smart manufacturing client in Germany, we built Factory Copilot, an AI chatbot that lets plant operators and managers ask questions about factory data in plain language. It pulls answers from SQL databases, PDF manuals, REST APIs, Azure IoT Hub telemetry, Power BI reports, and SAP ERP. The AI runs on Azure OpenAI (GPT-4) inside the Microsoft Azure environment, and role-based access control and encryption make sure users only see the data they are allowed to see. The result: 50% faster data retrieval, delivered in 5 months, with no trade-off on data protection.

We also build AI products for other European companies, like an AI-powered language learning platform in Czechia built on OpenAI, and a virtual car mechanic app in Sweden built on Anthropic Claude and launched in 1 month.

Compliance also gets easier when the engineers who build the AI work right next to the people who use it. Questions about data, users, and risk then come up early, not after launch. We explain this way of working in our guide to forward deployed engineering.

If you want to see how we bring AI into software delivery in general, take a look at our free AI-Enabled Software Delivery playbook.

Common EU AI Act Mistakes to Avoid

MistakeWhy it is a problemWhat to do instead
"We are not in the EU, so it does not apply to us"The law covers AI used in the EU, not only EU companiesCheck where your users and your AI's results are
"The high-risk rules are delayed, so we can wait"Bans, transparency rules, and AI literacy already apply, and fines are liveFix what applies today, then plan for 2027
"OpenAI or Anthropic handles compliance for us"Model makers cover their models, not your product or how you use itCheck your own role and duties for each AI tool
"It is just a chatbot, there are no rules"Chatbots must tell users they are AIAdd a clear AI notice to every chat and voice interface
"We checked once, we are done"A new feature or use case can change the risk levelReview your AI list every time something changes
"Compliance is only a legal task"Many duties, like logs, data quality, and human oversight, are built into the softwareBring engineers into the process from the start

Wrapping Up

The EU AI Act can look huge, but the core idea fits in one sentence: the more your AI can affect people's lives, the more care you must show. For most teams, that means knowing which AI they use, being honest with users, training their people, and protecting their data.

Some rules and fines are already live, and the strictest rules arrive in December 2027 and August 2028. The best time to prepare is while you are still building, not after a regulator or a big customer asks questions.

This article is for general information only and is not legal advice. For decisions about a specific AI system, talk to a qualified legal expert.

‍

{{cta}}

‍

FAQ

Is the EU AI Act already in force?

Yes. The law entered into force on 1 August 2024. Bans on certain AI practices and AI literacy duties apply since 2 February 2025, the fines chapter since 2 August 2025, and transparency rules since 2 August 2026. High-risk rules start on 2 December 2027 and 2 August 2028.

Does the EU AI Act apply to US companies?

Yes, if their AI systems are used in the EU or their AI results are used there. Having no office in Europe does not change that.

What is the EU AI Act Compliance Checker?

It is a free online tool from the European Commission. You answer questions about your AI system, and it shows which rules may apply to you. It is in beta and is not legal advice, so use it as a first step.

What are the fines under the EU AI Act?

Up to €35 million or 7% of worldwide yearly revenue for banned AI practices, up to €15 million or 3% for most other violations, and up to €7.5 million or 1% for giving wrong information to authorities. For small and medium companies, the lower number applies.

Did the AI Omnibus cancel the high-risk rules?

No. It only moved the start dates. Stand-alone high-risk systems now have until 2 December 2027, and AI inside regulated products has until 2 August 2028.

Article Sources
Chief Technical Officer

Chief Technical Officer at Akveo, with over 15 years of software engineering experience and a specialisation in AI development, data analysis, and scalable system architecture.

Build AI Your Customers Can Trust

From AI agents to conversational assistants, we build AI software with secure data handling and trusted model providers.

Get in Touch

Have a Project in Mind?

Let's discuss your goals and how we can help you reach them.
Clutch Bage 5.0 rating
Dmitry Klim
Head of Growth
5900 Balcones Drive #21729, Austin, TX 78731
[email protected]
+1 (512) 921-9631