Loading...
The world's first comprehensive AI law is now enforceable, with penalties up to €35M or 7% of global turnover. Meeting it requires AI engineering and legal expertise together — a combination almost no one has.
The Regulatory Wave
The AI Act doesn't arrive on a single day — it lands in waves. Each deadline pulls more systems into scope, and the most demanding obligations hit in 2026.
Regulation (EU) 2024/1689 — the AI Act — enters into force 20 days after publication in the Official Journal. The compliance clock starts.
Unacceptable-risk practices (social scoring, manipulative systems, most real-time biometric ID) are banned. Providers and deployers must ensure staff AI literacy.
Obligations for general-purpose AI (GPAI) models apply. The governance structure (AI Office, national authorities) and the penalty regime become operative.
The bulk of the Act applies, including obligations for providers of high-risk AI systems listed in Annex III (employment, credit, education, critical infrastructure, law enforcement, and more).
Final phase: obligations apply to high-risk AI that is a safety component of products already covered by EU product-safety legislation (medical devices, machinery, vehicles, etc.).
Prohibited AI practices
Up to €35,000,000 or 7% of total worldwide annual turnover — whichever is higher (Art. 99).
Most other obligations
Up to €15,000,000 or 3% of global turnover for breaches by providers, deployers, importers and notified bodies.
Incorrect information
Up to €7,500,000 or 1% of global turnover for supplying incorrect, incomplete or misleading information to authorities.
Market Impact
The Commission expected 5–15% of AI systems to be high-risk. Enterprise reality is far higher — which turns compliance from a niche legal task into a recurring engineering cost across the whole AI estate.
of enterprise AI systems may be high-risk or unclear
An appliedAI study of 106 enterprise AI systems found 18% were high-risk and a further 40% had unclear classification — versus the Commission’s original 5–15% estimate.
estimated annual EU compliance cost
DIGITALEUROPE industry estimate of the recurring cost of complying with the AI Act across the EU.
maximum fine, or 7% of global turnover
Article 99 of Regulation (EU) 2024/1689 — higher than GDPR’s 4% ceiling.
Sources linked in the references below. Figures are third-party estimates and ranges, not guarantees.
The Gap
AI Act compliance sits exactly between two professions that rarely overlap. Each side owns half the answer.
Law firms can read Annex III and draft policy, but they cannot inspect a training pipeline, audit a model for bias, build the technical documentation in Annex IV, or implement the logging and human-oversight controls the Act actually requires. Their advice stops at the slide deck.
ML teams can build and ship models, but they routinely misclassify risk tiers, miss that their use case falls under Annex III, conflate GDPR with the AI Act, and treat conformity assessment as paperwork to bolt on later — when it is a design constraint from day one.
Enterprises end up coordinating between counsel and engineers who do not speak each other’s language. Requirements get lost in translation, timelines slip past the 2026 deadline, and the €35M exposure stays on the books.
The Unique Position
Łukasz Augustyniak sits in the rare overlap: a production AI engineer with formal legal training. The same person who can audit the model can read the regulation — and close the translation gap that derails most compliance efforts.
Product Vision
Compliance is not a one-off audit — it is a continuous state that has to survive every model change and every new piece of guidance. The path runs from hands-on advisory to repeatable tooling.
Map every AI system in your estate to its risk tier, flag Annex III exposure, and surface the unclassified middle that the appliedAI data shows is the real risk.
Build the technical documentation, logging, data governance and human-oversight controls into the system from the start — not as a retrofit weeks before the deadline.
Productize the assessment into tooling that re-evaluates systems as they change and as guidance evolves, so compliance is a living state rather than a one-off audit.
Conformity-by-design takes months, not weeks. If you have AI systems touching the EU market, now is the time to map your exposure.
Start the conversation