Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

EU AI Act deadlines and fines: what do practitioners need to do now?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 13010
Topic starter  

TL;DR: The EU AI Act sets prohibited-practice rules from 2025, general-purpose AI obligations from 2025, and high-risk system deadlines that now extend into 2027 and 2028, with fines reaching €35 million or 7% of worldwide turnover, according to Straiker. The practical issue is not legal awareness but whether AI governance, logging, oversight, and post-market monitoring are already operating as control functions rather than documents.

NHIMG editorial — based on content published by Straiker: EU AI Act Fines, Deadlines & Compliance Guide

By the numbers:

  • The high-risk timelines, however, have been pushed back: Annex III high-risk systems now apply on 2 December 2027 and Annex I high-risk systems on 2 August 2028.

Questions worth separating out

Q: How do organisations prepare for the EU AI Act without slowing AI adoption?

A: They should start with visibility, then classify use cases, then enforce access and logging.

Q: Why does human oversight matter for AI governance?

A: Human oversight matters because AI outputs can look confident while still being wrong, biased, or incomplete.

Q: What do organisations get wrong about AI compliance deadlines?

A: They often treat deadline extensions as a signal to wait.

Practitioner guidance

  • Map AI systems to regulatory scope and risk tier Create a register that classifies each AI use case against prohibited, limited-risk, and high-risk categories, then assign an accountable owner for each system.
  • Operationalize human oversight controls Define who can pause, review, override, or disable high-risk AI systems, and verify that those rights are logged and periodically tested in production.
  • Tie AI governance to IAM and PAM Review the identities, service accounts, and privileged roles that support model training, deployment, and monitoring so access is auditable end to end.

What's in the full article

Straiker's full blog post covers the operational detail this post intentionally leaves for the source:

  • Article-level breakdown of prohibited practices, high-risk categories, and when each deadline now applies.
  • Plain-language explanations of Articles 9, 10, 13, 14, 15, 72, 73, 74, and 79 for teams mapping compliance work.
  • Deadline table and compliance timeline details that help legal, security, and AI governance teams plan remediation.
  • The article's interpretation of AI literacy, corrective action, and post-market obligations in one place.

👉 Read Straiker's guide to EU AI Act fines, deadlines, and compliance duties →

EU AI Act deadlines and fines: what do practitioners need to do now?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 12594
 

EU AI Act compliance is really a control maturity test, not a policy exercise. The article treats the Act as a deadline-driven guide, but the deeper issue is whether organisations can evidence oversight, monitoring, and intervention in live systems. That matters because the Act expects real operational controls across the AI lifecycle, not just governance paperwork. Practitioners should treat compliance as a test of whether AI systems are governable in production.

A question worth separating out:

Q: Who is accountable when AI output causes a compliance or legal issue?

A: Accountability sits with the organisation that deploys and governs the AI use case, not only with the vendor that hosts the model. If an employee or agent uses AI in a business context, the enterprise must be able to show policy, monitoring, and evidence of control. That is now a governance obligation, not optional hygiene.

👉 Read our full editorial: EU AI Act compliance deadlines sharpen the case for AI governance



   
ReplyQuote
Share: