Application timeline and penalties
The Application timeline and penalties framework establishes a phased rollout of legal obligations based on AI risk levels and defines severe financial sanctions for non-compliance. Organizations must align their compliance roadmaps with specific deadlines to avoid fines that can reach up to 7% of total worldwide annual turnover or €35 million, whichever is higher.
What it means
The EU AI Act does not apply all rules at once; instead, it uses a staggered implementation timeline. Certain "prohibited" AI practices have the shortest grace period (typically six months after entry into force), while requirements for General Purpose AI (GPAI) and high-risk systems follow in subsequent phases (generally 12 to 36 months).
From a compliance perspective, this means an organization cannot treat the Act as a single project with one deadline. Implementation must be tiered: first removing prohibited systems, then governing GPAI models, and finally implementing full quality management systems for high-risk AI.
The penalty regime is designed to be "effective, proportionate, and dissuasive." Fines are scaled based on the type of infringement—with the highest penalties reserved for using prohibited AI practices—and are calculated relative to the company's global turnover to ensure they impact large enterprises as well as SMEs.
How to meet it
- Conduct a comprehensive inventory of all AI systems currently in use or under development within the organization.
- Classify every identified system into the Act’s risk categories (Prohibited, High-Risk, Limited Risk, or Minimal Risk).
- Create a compliance calendar that maps specific legal deadlines to each category of AI asset found in your inventory.
- Immediately decommission or pivot any systems that fall under "Prohibited AI Practices" to meet the earliest deadline.
- Establish a governance budget and resource allocation plan specifically for the high-risk system requirements (e.g., data governance, technical documentation) before their specific deadlines hit.
- Implement an internal monitoring mechanism to track new AI deployments against the phased timeline to ensure no "shadow AI" bypasses these dates.
Evidence an auditor asks for
- An AI Asset Register that includes risk classifications and corresponding compliance target dates.
- A documented Compliance Roadmap or Project Plan showing milestones aligned with the EU AI Act's phased entry into force.
- Records of decommissioning or modification for systems identified as prohibited.
- Board-level or executive meeting minutes demonstrating awareness of the penalty risks and approval of the implementation budget.
Common pitfalls
- Assuming a single "go-live" date for all requirements rather than managing the staggered timeline by risk category.
- Overlooking the immediate urgency of the ban on prohibited practices while focusing too heavily on long-term high-risk documentation.
- Calculating potential financial exposure based only on fixed Euro amounts rather than the percentage of total worldwide annual turnover.