Tomorrow the AI fines begin
August 2 is the date. That's when the EU begins hitting generative AI firms with fines for non-compliance with the AI Act. The most critical bit for anyone actually running a business is the chatbot disclosure rule hitting API builders this Sunday.
Here's the reality: your vendor cannot comply for you. If you've built a customer interface on someone else's API, you're the one responsible for telling the user they're talking to a machine. I see plenty of firms treating their API contracts like a magic shield. They aren't.
The EU just finalized eight compliance changes via the Digital Omnibus to tighten this further. If your control design assumes the "disclosure button" is a feature your provider will just toggle on for you, you've already failed.
Who pays for this? Not just the firms. The insurers writing the professional liability policies for these AI implementations are about to find out their risk models were based on fiction.
Then we have KT Corporation in South Korea. They just got slapped with a penalty of 54 billion won—just under $38 million—for a data breach involving femtocells.
I've seen this movie before. Back in the early days of SOX, we saw firms try to hide systemic failures behind "isolated incidents." KT didn't just have a breach; the regulator is targeting an alleged cover-up. This is where I judge a finding by what it costs you at year-end. A data breach is a cost of doing business in 2026; a cover-up is a choice to multiply that cost by ten.
When you move from a technical failure to a governance failure, the regulators stop looking for a fix and start looking for a pound of flesh.
It's an expensive lesson in evidence.
On the financial side, AiRWA INC provides a textbook example of how to break your reporting cycle. They filed a late 10-K notice after an AI acquisition. It's the classic "growth at all costs" trap: you buy a flashy new asset, ignore the integration of their internal controls into your GAAP framework, and suddenly you can't close your books on time.
A late filing is a massive red flag to the market that your house isn't in order. It suggests that the acquisition wasn't just an investment, but a disruption to the basic plumbing of the company's finance department.
I’ve spent two decades watching people mistake "complex" for "sophisticated." Buying an AI company doesn't excuse you from the basics of financial reporting. If you can't produce a 10-K because your new acquisition's data is a mess, you didn't buy a tool; you bought a liability.
Finally, look at Hims & Hers. The FTC and several states are suing them over deceptive health data sharing and subscription billing. This isn't a technical glitch. It's a design choice. When the business model relies on "dark patterns" to keep subscribers locked in or to move data quietly, you aren't managing risk—you're creating it.
The objection here is usually that these practices are "industry standard." That’s a useless argument when you're standing in front of a judge. "Everyone else does it" isn't a control; it's a confession.
The second-order effect here hits the broader telehealth sector. The FTC has shown it's bored with warnings and is now moving toward litigation. Every other firm using similar billing logic just became a target.
If you're wondering if your current controls are sufficient, ask yourself this: if an auditor asked for the evidence of your disclosure process tomorrow morning, would you show them a signed policy or a screenshot of a vendor's "Coming Soon" page?