Red PicoLibrary

AI Governance & Risk

EU AI Act Compliance Is No Longer in the Observation Phase

Up to 35 million EUR or 7% of global turnover.

That is what non-compliance with the EU AI Act can now cost. And the phased rollout most boards have been watching is no longer ahead of us:

• Prohibited practices - banned since February 2025
• General-purpose AI obligations - in force since August 2025
• High-risk system requirements - landing through 2026 and 2027

If your organization sells into, operates in, or serves customers in the EU, the comfortable observation phase is over.

Here is what I tell leadership teams to do in the next two quarters:

  1. Inventory every AI system you run - including the ones vendors run for you.
  2. Classify each one against the Act's risk tiers. Guessing wrong here is expensive.
  3. Assign a named owner for each high-risk system. Not a committee. A person.
  4. Build the documentation habit now - conformity assessments are much harder to reconstruct after the fact.

The fines get the headlines.

The bigger risk is slower: losing enterprise customers who start asking for AI compliance evidence in procurement.

First shared on LinkedIn.

Related

Go deeper: AI Audit Checklist: What Auditors Will Ask For | NIST AI RMF Explained: Govern, Map, Measure, Manage

Get the next one first

Weekly thinking on data and AI governance from Ash Srivastava.