There are three AI Act fine tiers. Most people only know one of them.
Everyone knows
the headline number. Almost nobody plans for the other two.
That gap tells
you exactly how most organisations are preparing, and why so many will still be
caught.
The
three tiers
Prohibited
practices cost up to 35 million euros or 7% of worldwide annual turnover,
whichever is higher.
Breaching
operator or general-purpose model duties runs to 15 million euros or 3%.
Giving an
authority incorrect, incomplete or misleading information costs up to 7.5
million euros or 1%.
Small and
medium companies are capped at the lower of the two figures rather than the
higher.
Read the third
tier twice. It does not punish reckless AI. It punishes an inaccurate answer.
You can act in
good faith, answer a regulator from a spreadsheet nobody updated, and land
inside it.
Which is the
cheapest tier to avoid, and the only one that is purely an admin problem.
Why that tier is a governance failure, not a legal one
AI compliance
means proving your AI meets rules somebody else wrote. It arrives with a date
and a penalty.
AI governance
means the rules you write for yourself, and the records that keep them honest.
Who may build
AI. What data they may use. Who approves it. Who reviews it later. Who switches
it off.
Nobody fines
you for skipping governance, which is precisely why it gets skipped and why the
records go stale.
There is a
sharper version of this in the source article: an AI system can be fully
compliant and still produce biased outcomes.
Compliance
checked the rule. Nothing checked whether the rule covered what you actually
built.
The full comparison of AI governance and AI compliance
sets out where each one carries the weight.
What
changed on 27 July and 2 August
The AI Omnibus
came into force on 27 July 2026 and moved several deadlines:
•
High-risk systems in biometrics, critical
infrastructure, education, employment, migration, asylum and border control now
apply from 2 December 2027.
•
High-risk AI built into products such as lifts, toys
and machinery applies from 2 August 2028.
•
Rules on non-consensual intimate imagery and child
sexual abuse material apply from 2 December 2026.
•
Small mid-cap companies picked up simplifications once
reserved for small businesses.
Then on 2
August 2026 the AI Office and national authorities became responsible for
supervising and enforcing the Act.
The homework is
due later. The inspector arrived early. Most coverage reported only the first
half.
Building
the framework, in the order that works
Start with
principles. Fairness, transparency, accountability and safety, written down as
approved use cases and clear boundaries.
Those
principles become the thing your compliance obligations map onto later. Without
them, each new law starts from nothing.
Second, set up
cross-functional oversight. AI governance cannot sit with one department.
A working
committee needs leadership, legal, data science, IT security and business
operations in the same room.
Third, monitor
continuously. Model performance, data quality and decision outputs, checked on
a schedule.
Regular audits
catch drift and bias while they are still cheap to fix, which is the whole
point of running a cycle.
Where
the tooling actually helps
Every step
above assumes you know which AI systems you run. Most organisations do not, and
a questionnaire will not tell them.
Seers AI Governance was built
for that specific gap. It runs in five steps and requires no self-reporting.
It scans your
website, pages, scripts, integrations and third-party embeds and detects every
AI system operating there.
It assigns each
one an EU AI Act risk tier, from prohibited through to minimal, so you know
what is urgent.
It generates a
compliance score from 0 to 100 based on tier, documentation and what your
policy pages disclose.
It crawls your
privacy policy, terms and cookie policy for AI mentions, then flags what is
missing and what contradicts reality.
It maps every
system to the articles it must satisfy, including Article 22 on automated
decisions and Articles 13 and 14 on transparency.
Then it returns
a prioritised remediation plan naming what to change, where to change it, and
which regulation each fix closes.
The score rises
as you work through it, which turns an open-ended legal worry into a number
your board can follow.
Seers reports
12,000+ policy gaps identified and 1,400+ enterprise clients governed to date.
It sits inside
the wider privacy platform at Seers,
used by 50,000+ organisations and covering 150+ privacy laws.
Both start
free, so finding out how exposed you are costs nothing but the scan.
Comments
Post a Comment