TL;DR: Enterprises face fines of up to €35 million or 7% of global annual turnover under the EU AI Act, while high-risk systems must meet documentation, testing, transparency, and human oversight obligations, according to VirtueAI. The practical issue is less awareness than operationalising AI governance across models, data, and accountability paths before enforcement pressure hardens.
NHIMG editorial — based on content published by VirtueAI: EU AI Act: What Enterprises Need to Know and How Virtue Helps
By the numbers:
- Failure to comply with the Act can lead to fines of up to €35 million or 7% of global annual turnover, whichever is higher.
- Providing incorrect or misleading information can trigger fines of up to €7.5 million or 1% of global turnover.
- VirtueGuard says it covers 320+ safety and security categories, including EU AI Act compliance.
Questions worth separating out
Q: How should enterprises prepare for EU AI Act compliance in regulated AI programmes?
A: Start with a complete AI inventory, then classify systems by risk, owner, data use, and decision impact.
Q: Why do high-risk AI systems require stronger governance than ordinary AI tools?
A: High-risk systems can affect employment, finance, health, or other sensitive outcomes, so regulators expect traceability, transparency, and human intervention.
Q: What do organisations get wrong about human oversight in agentic AI?
A: They confuse a named reviewer with effective oversight.
Practitioner guidance
- Create a regulated AI inventory Catalog each AI system by use case, data sensitivity, decision impact, and likely EU AI Act risk category so teams can prove what must be controlled.
- Link approvals to human oversight paths Make model approval records, override procedures, and escalation contacts part of the same workflow so human intervention is demonstrable during audit.
- Align AI governance with access control ownership Assign named owners for models, datasets, and change rights so accountability is visible across IAM, PAM, and AI operations.
What's in the full article
VirtueAI's full article covers the operational detail this post intentionally leaves for the source:
- The tiered penalty structure and how fines differ for prohibited, high-risk, and misleading-information scenarios
- VirtueAI's descriptions of VirtueRed and VirtueGuard, including the control problems each product is intended to address
- The article's own compliance framing for AI leads and enterprise teams navigating EU AI Act obligations
- Examples of the safety and security categories VirtueAI says its tooling covers
👉 Read VirtueAI's analysis of EU AI Act compliance requirements and penalties →
EU AI Act compliance gaps: what enterprises need to do now?
Explore further
AI compliance debt is now a governance debt problem, not a legal afterthought. The EU AI Act does not just add a new checklist. It exposes whether enterprises have any real control plane for AI systems, from classification and documentation to ownership and review. Where AI programmes grew faster than governance, the result is compliance debt that will surface during procurement, audit, or enforcement. Practitioners should treat AI governance as an operating model issue, not a policy memo.
A question worth separating out:
Q: Who is accountable when an AI system misses EU AI Act requirements?
A: Accountability follows the role the organisation actually plays, not just the contract wording. A provider, deployer, importer, or distributor can each carry different duties, and some organisations occupy more than one role across different systems. Legal responsibility should be mapped to system ownership, operational control, and the evidence trail, not assumptions about who bought the tool.
👉 Read our full editorial: EU AI Act compliance gaps expose governance debt in enterprise AI