There are three AI Act fine tiers. Most people only know one of them.

Everyone knows the headline number. Almost nobody plans for the other two.

That gap tells you exactly how most organisations are preparing, and why so many will still be caught.

The three tiers

Prohibited practices cost up to 35 million euros or 7% of worldwide annual turnover, whichever is higher.

Breaching operator or general-purpose model duties runs to 15 million euros or 3%.

Giving an authority incorrect, incomplete or misleading information costs up to 7.5 million euros or 1%.

Small and medium companies are capped at the lower of the two figures rather than the higher.

Read the third tier twice. It does not punish reckless AI. It punishes an inaccurate answer.

You can act in good faith, answer a regulator from a spreadsheet nobody updated, and land inside it.

Which is the cheapest tier to avoid, and the only one that is purely an admin problem.

Why that tier is a governance failure, not a legal one

AI compliance means proving your AI meets rules somebody else wrote. It arrives with a date and a penalty.

AI governance means the rules you write for yourself, and the records that keep them honest.

Who may build AI. What data they may use. Who approves it. Who reviews it later. Who switches it off.

Nobody fines you for skipping governance, which is precisely why it gets skipped and why the records go stale.

There is a sharper version of this in the source article: an AI system can be fully compliant and still produce biased outcomes.

Compliance checked the rule. Nothing checked whether the rule covered what you actually built.

The full comparison of AI governance and AI compliance sets out where each one carries the weight.

What changed on 27 July and 2 August

The AI Omnibus came into force on 27 July 2026 and moved several deadlines:

     High-risk systems in biometrics, critical infrastructure, education, employment, migration, asylum and border control now apply from 2 December 2027.

     High-risk AI built into products such as lifts, toys and machinery applies from 2 August 2028.

     Rules on non-consensual intimate imagery and child sexual abuse material apply from 2 December 2026.

     Small mid-cap companies picked up simplifications once reserved for small businesses.

Then on 2 August 2026 the AI Office and national authorities became responsible for supervising and enforcing the Act.

The homework is due later. The inspector arrived early. Most coverage reported only the first half.

Building the framework, in the order that works

Start with principles. Fairness, transparency, accountability and safety, written down as approved use cases and clear boundaries.

Those principles become the thing your compliance obligations map onto later. Without them, each new law starts from nothing.

Second, set up cross-functional oversight. AI governance cannot sit with one department.

A working committee needs leadership, legal, data science, IT security and business operations in the same room.

Third, monitor continuously. Model performance, data quality and decision outputs, checked on a schedule.

Regular audits catch drift and bias while they are still cheap to fix, which is the whole point of running a cycle.

Where the tooling actually helps

Every step above assumes you know which AI systems you run. Most organisations do not, and a questionnaire will not tell them.

Seers AI Governance was built for that specific gap. It runs in five steps and requires no self-reporting.

It scans your website, pages, scripts, integrations and third-party embeds and detects every AI system operating there.

It assigns each one an EU AI Act risk tier, from prohibited through to minimal, so you know what is urgent.

It generates a compliance score from 0 to 100 based on tier, documentation and what your policy pages disclose.

It crawls your privacy policy, terms and cookie policy for AI mentions, then flags what is missing and what contradicts reality.

It maps every system to the articles it must satisfy, including Article 22 on automated decisions and Articles 13 and 14 on transparency.

Then it returns a prioritised remediation plan naming what to change, where to change it, and which regulation each fix closes.

The score rises as you work through it, which turns an open-ended legal worry into a number your board can follow.

Seers reports 12,000+ policy gaps identified and 1,400+ enterprise clients governed to date.

It sits inside the wider privacy platform at Seers, used by 50,000+ organisations and covering 150+ privacy laws.

Both start free, so finding out how exposed you are costs nothing but the scan.


Comments

Popular posts from this blog

Common Cookie Errors on WordPress & Shopify

What are the best privacy tools for Shopify stores in 2025/2026?

Why Amazon Ad Reports Stopped Matching Real Sales