What does the EU AI Act require of businesses in 2027?
Published Jun 14, 2026 · Updated Jun 14, 2026
By 2027 the EU AI Act is largely in force on a risk-based model: prohibited uses have been banned since February 2025, general-purpose AI obligations since August 2025, and high-risk system obligations since August 2026 — with penalties reaching €35 million or 7% of global turnover, which makes it the AI equivalent of GDPR for any business serving the EU. The Act phases in between August 2024 and August 2027, classifying AI by risk tier and attaching heavier duties to riskier uses. Prohibited practices applied from 2 February 2025; GPAI (general-purpose AI) obligations from 2 August 2025; high-risk system obligations from 2 August 2026; and full application from 2 August 2027 — though high-risk AI embedded in regulated products got an extended transition to 2 August 2028 under the AI omnibus agreement. High-risk deployers must maintain detailed technical documentation, robust risk management, and effective human oversight, and pass formal conformity assessments by Notified Bodies leading to CE marking. The penalties are severe: GPAI breaches draw up to €15 million or 3% of global turnover, and broader violations up to €35 million or 7% — a percentage of worldwide revenue, not EU revenue. GPAI providers must also deliver transparency, post-market monitoring, and systemic-risk mitigation.
For operators, the EU AI Act is a clean lesson in why AI now carries GDPR-scale compliance — classify your systems by risk, build the documentation and human oversight early, and remember the fine is a slice of your global revenue.
1. The Risk-Based Structure
Duties scale with risk
The Act's core design is risk-based: AI is sorted into tiers, and the obligations scale with the risk of the use. Unacceptable uses are banned outright; high-risk uses carry heavy compliance duties; limited and minimal risk uses carry light or no obligations. The framework targets the highest-risk uses rather than regulating all AI equally.
A phased rollout
The rules phase in between August 2024 and August 2027 (with some extensions), so the obligations arrived in waves rather than all at once. That staging gave businesses time to prepare for each tier — but by 2027, the prohibited, GPAI, and high-risk layers are all live.
2. The Compliance Timeline
Key dates
The dates matter for planning: prohibited practices applied from 2 February 2025; GPAI obligations from 2 August 2025; high-risk system obligations from 2 August 2026; and full application from 2 August 2027. Each date turned a future requirement into a live one.
The omnibus extension
One important adjustment: under the AI omnibus political agreement (reached late 2025 into 2026), high-risk AI embedded into regulated products received an extended transition until 2 August 2028. The core high-risk and GPAI duties still apply on the original schedule — the extension covers a specific category, not the whole Act. Operators should not assume a blanket delay.
3. What High-Risk Deployers Must Do
Documentation, risk management, oversight
Organizations deploying high-risk AI face extensive requirements: detailed technical documentation, robust risk management, and effective human oversight mechanisms. These are not box-checks — they require building processes that govern how the AI is developed, monitored, and supervised by humans throughout its use.
Conformity assessment and CE marking
High-risk systems must also pass formal conformity assessments by designated Notified Bodies, leading to CE marking of approved systems. This mirrors how the EU regulates physical products: an independent body certifies the system before it can be marketed. For AI, it means a high-risk model cannot simply ship — it must be assessed and marked first.
4. The Penalties
A slice of global turnover
The enforcement teeth are large. GPAI breaches draw fines up to €15 million or 3% of global turnover; broader AI Act violations up to €35 million or 7%. The critical detail is global turnover — the percentage applies to worldwide revenue, not EU revenue, so a violation can cost a meaningful share of a company's entire business, the same structure that made GDPR fines so feared.
What gets enforced
Enforcement targets include non-compliance with transparency, refusal of model access, and deployment in prohibited AI practices. GPAI providers carry specific duties — technical documentation, transparency, human oversight, post-market monitoring, and systemic-risk mitigation. The obligations continue after deployment through post-market monitoring, so compliance is ongoing, not a one-time gate.
5. The Operator and Compliance Lessons
Classify your AI by risk first
The clearest lesson is to classify your AI systems by risk tier first, because the obligations — and the fines — flow from the classification. Operators should inventory every AI use and map it to unacceptable, high-risk, limited, or minimal, since a single high-risk system pulls in documentation, oversight, and conformity duties the rest do not. You cannot comply with what you have not classified.
Build documentation and oversight early
High-risk duties — documentation, risk management, human oversight, conformity assessment — take months to stand up, not days. Operators should build these ahead of need, because retrofitting governance onto a deployed system under enforcement pressure is far harder. The teams that treated AI governance like GDPR readiness are the ones that met the August 2026 high-risk deadline calmly.
The fine is global — size it accordingly
Because penalties reach 7% of global turnover, operators must size the risk against worldwide revenue, not EU sales. A modest EU footprint does not cap the fine — the percentage applies to the whole company. Operators serving the EU at all should treat AI compliance as a material, board-level risk, exactly as they treat data-privacy exposure under GDPR.
Practical Steps for High-Risk AI Compliance in 2027
By 2027, businesses deploying or developing high-risk AI systems must have fully operational compliance frameworks. The first critical step is system classification: map every AI system against the Act’s high-risk categories (e.g., biometric identification, critical infrastructure, education, employment, law enforcement). If a system qualifies, you must establish a risk management system that runs continuously—identifying, analyzing, and mitigating risks throughout the AI’s lifecycle. This includes documented testing for bias, accuracy, and cybersecurity vulnerabilities.
Next, implement data governance practices. High-risk systems require training data that is relevant, representative, and free from discriminatory biases. You’ll need to maintain detailed technical documentation—covering design, development, and testing—that proves compliance. This documentation must be available to Notified Bodies (EU-designated auditors) who will perform conformity assessments before you can affix a CE mark. For many businesses, this means hiring or contracting a compliance officer or AI ethics team to manage the paperwork and audits. Finally, ensure human oversight is baked into the system—users must be able to override or stop the AI’s outputs when risks arise. Budget for these steps: compliance costs for high-risk systems can range from €50,000 to €500,000 depending on complexity, though small and medium enterprises (SMEs) may qualify for reduced fees from Notified Bodies.
How the AI Act Interacts with GDPR and Other EU Laws
The EU AI Act doesn’t replace GDPR or other regulations—it layers on top. If your AI system processes personal data (e.g., facial recognition or hiring algorithms), you must comply with both. GDPR’s data protection impact assessments (DPIAs) now often overlap with the AI Act’s risk management requirements. By 2027, businesses should integrate these processes into a single compliance dashboard to avoid duplication. For example, a high-risk AI system using biometric data must pass both a DPIA and an AI conformity assessment—and the results must be consistent.
Additionally, the AI Liability Directive (proposed in 2022, likely in force by 2027) will make it easier for consumers to sue for damages caused by AI. This means your compliance documentation becomes critical legal evidence. The Act also interacts with sector-specific laws like MDR (Medical Device Regulation) for AI in healthcare or GDPR’s right to explanation for automated decisions. Businesses in regulated industries should expect joint audits from both AI Notified Bodies and existing regulators (e.g., data protection authorities). A practical tip: appoint a single compliance coordinator who understands all overlapping laws—this can reduce friction and fines, which for GDPR breaches alone can reach €20 million or 4% of global turnover.
Enforcement Realities and Penalty Risks in 2027
By 2027, EU member states must have designated market surveillance authorities to enforce the AI Act. These bodies can conduct spot checks, request documentation, and issue corrective measures—including system recalls or bans. The penalties are not theoretical: the Act sets maximum fines at €35 million or 7% of global annual turnover (whichever is higher) for the most serious violations (e.g., prohibited AI practices). For high-risk system non-compliance, fines reach €15 million or 3% of turnover; for supplying incorrect information to authorities, €7.5 million or 1%.
However, enforcement is tiered. SMEs and startups may receive proportionate penalties and guidance before fines escalate. The European Commission also runs an AI Office (since 2025) that coordinates enforcement and offers a safe harbor for companies that self-report violations early. Real-world risk: in 2026, several large tech firms faced preliminary investigations for GPAI transparency failures, signaling that regulators are active. By 2027, expect class-action-style lawsuits from consumer groups, leveraging the AI Liability Directive. To mitigate risk, maintain a compliance log with timestamps of all risk assessments, audits, and corrective actions—this can reduce fines by up to 50% under some member state regimes. Budget for legal defense: annual compliance insurance for high-risk AI starts at roughly €10,000 for SMEs and scales with system complexity.
FAQ
What is the first step my business needs to take for EU AI Act compliance in 2027? Start by mapping every AI system you use or deploy in the EU market, then classify each by risk tier — prohibited, high-risk, limited-risk, or minimal-risk. High-risk systems require detailed technical documentation and risk management, so early classification is critical to avoid last-minute penalties.
Do I need to certify my AI systems before 2027? Yes, if your AI is high-risk, you must pass a formal conformity assessment by a Notified Body and obtain CE marking before deployment. The deadline for most high-risk systems was August 2026, but those embedded in regulated products have until August 2028 under the omnibus agreement.
What happens if my business doesn't comply by 2027? Penalties can reach up to €35 million or 7% of your global annual turnover, depending on the violation type. For GPAI breaches, fines go up to €15 million or 3% of turnover, so non-compliance is financially severe.
Does the Act apply to my business if I'm based outside the EU? Yes, if your AI systems affect people in the EU — whether you deploy or market them there — you fall under the Act. It has extraterritorial reach similar to GDPR, so any business serving EU users must comply.
What are the key documentation requirements for high-risk AI? You need detailed technical documentation covering system design, training data, accuracy, and robustness, plus a risk management system that identifies and mitigates potential harms. Human oversight measures must also be documented and demonstrated to a Notified Body.
Is there any grace period for small businesses? The Act does not exempt small businesses, but it includes proportionality measures — for example, simplified documentation for SMEs if they deploy low-risk AI. However, all high-risk obligations apply regardless of company size, so early planning is essential.
Bottom Line
By 2027 the EU AI Act is largely in force on a risk-based model — prohibited uses banned since February 2025, GPAI duties since August 2025, high-risk obligations since August 2026 — with conformity assessments, CE marking, and fines up to €35 million or 7% of global turnover. It is GDPR-scale compliance for AI, reaching any business serving the EU. For operators, the lessons are exact: classify your AI by risk first, build documentation and human oversight early, and size the fine against your global revenue, not just EU sales.
Related on PULSE
- [How should a 2027 GTM team adjust motion for EU GDPR and AI Act requirements?](/knowledge/q12582)
- [How do you achieve EU AI Act compliance in 2027?](/knowledge/q12306)
- [What is the best AI-powered CRM for small businesses in 2024?](/knowledge/q14509)
- [Top 10 security software solutions for small businesses in 2027](/knowledge/q14459)
- [What does the FTC junk-fees rule mean for ticket pricing and businesses in 2027?](/knowledge/q13092)
- [How do you coach reps to act on AI call-coaching feedback?](/knowledge/q13970)
Sources
- EU Artificial Intelligence Act — Implementation timeline
- European Commission — AI Act: regulatory framework for AI
- MediaLaws — EU AI obligations for GPAI providers: compliance, enforcement and deadlines (2025–2027)
- Legiscope — EU AI Act deadlines 2026-2027: compliance calendar and fines
- Trilateral Research — EU AI Act compliance timeline: key dates by risk tier
- DataGuard — EU AI Act timeline: key compliance dates and deadlines explained
---
*EU AI Act review — EU AI Act reviews, rating, EU AI Act review 2027, and a review of the risk tiers, high-risk obligations, conformity assessment, and global-turnover fines for business operators.*










