Prompt and Model
Models

EU AI Act Penalties Start, Target Data Teams

The EU AI Act began assessing penalties on August 2, placing compliance responsibility on data teams. Organizations face fines up to €15M or 3% of global turnover for governance failures, with a Gartner survey indicating nearly 90% lack formal AI governance programs.

Models: The EU AI Act began assessing penalties on August 2, placing compliance responsibility on data teams

The EU AI Act began assessing penalties for AI oversights from poor data management on August 2. The Act places compliance responsibility squarely on data teams in any organization interacting with EU residents.

A clear problem is that most organizations did not build their data infrastructure with the required documentation in mind. Now that obligations for transparency, general purpose AI (GPAI) models, and AI literacy are in force, a divide exists between what the Act penalizes and the state of most data governance programs. Jelani Harper, a data industry analyst, reports on these gaps for TechTarget.

Data Management Requisites

Originally, the AI Act mandated high-risk Annex III systems be fully compliant by August 2, 2026. A May 2026 Digital Omnibus agreement delayed many requirements until December 2027. However, components effective from August 2 still demand rigorous data management.

Under Article 50's transparency rules, data teams must label AI-manipulated depictions of real people and deepfakes as AI-generated. Chatbots must inform users they are interacting with AI, unless it is obvious. Users must also be told when biometric categorization or emotion recognition systems are in use.

GPAI model providers, including teams that substantially tailor foundation models or build heavily reliant applications, must keep technical documentation under Annex XI. They must provide training data summaries and confirm data adheres to EU copyright law via a documented policy. AI literacy is required for all users and operators of AI systems.

Governance Shortcomings

For data teams, the biggest compliance obstacle is AI governance itself. A 2025 Gartner survey on cybersecurity risk handling found nearly 90% of organizations lacked AI governance programs. This indicates how immature AI governance remains. Many organizations run AI governance tied to specific employees or projects. Formalizing, documenting, and spreading roles and rules throughout the enterprise makes meeting the Act's mandates far easier.

Many users know their own tooling but not what runs in other departments. Compliance with GPAI and transparency requirements necessitates a comprehensive inventory of organizational AI systems, their data dependencies, and formal documentation. This demand falls hardest on GPAI model providers.

Penalty TypeFine Amount
Noncompliance for GPAI models€15M or 3% of global turnover (whichever is higher)
Noncompliance for transparency failures€7.5M or 1.5% of global turnover (whichever is higher)

Systemic risk GPAI models are defined as those trained with 10²⁵ FLOPs of compute. They require adversarial testing like red teaming, cybersecurity protections, and energy consumption data disclosures. Data teams without complete AI asset inventories cannot meet this requirement.

Siloed governance undermines transparency more directly for labeling model outputs. When only individual employees hold knowledge, it rarely reaches end users. The Act requires that knowledge be readily available to the public and internal users.

Remediation Steps

Applying data governance fundamentals to AI instances lets teams close gaps. The first step is to fully classify AI assets: the models, their use and users, training data, data models, taxonomies, and data sources. This inventory is what the Act's obligations assume exists. Without it, a team cannot show which systems are in scope.

Typically, only a few key employees hold this institutional knowledge. Data teams can formalize it through enterprise architecture to map systems, and use regex, machine learning, and other statistical methods to discover, classify, and tag them.

Next, teams should categorize AI assets by the EU AI Act risk tier: minimal risk, limited risk with transparency requirements, high risk, and prohibited. The tier determines which obligations attach. A limited-risk chatbot triggers Article 50's disclosure rules, while a systemic GPAI model pulls in adversarial testing and energy reporting.

The tiers require teams to update existing governance policies or write new ones. Splitting policies into two distinct sets helps: one for public interactions with AI systems, another for internal work like red teaming. Legal counsel can determine if an organization's use of GPAI models classifies it as a model provider, even if it did not build the model.

In many cases, deployments of dynamic agents can automate parts of transparency requirements. This includes watermarking content as AI-generated or triggering workflows to inform end users they are interacting with AI.

Related coverage

More from Models