By the numbers
Violating the EU AI Act's prohibited-practice bans can trigger fines up to €35 million or 7% of global annual turnover, whichever is higher (EU AI Act Article 99, 2024).
Source: EU AI Act, Article 99
The EU AI Act's ban on 'unacceptable-risk' AI practices has applied since 2 February 2025 (EU AI Act implementation timeline, 2025).
Source: EU AI Act timeline
The 2026 Digital Omnibus deferred compliance for standalone high-risk (Annex III) AI systems to 2 December 2027, and product-embedded systems to 2 August 2028 (Gibson Dunn, 2026).
Source: Gibson Dunn
63% of breached organizations had no AI governance policy to manage AI or were still developing one (IBM Cost of a Data Breach, 2025).
Source: IBM, 2025
Breaches involving high levels of 'shadow AI' cost an average of $670,000 more than those with little or none (IBM Cost of a Data Breach, 2025).
Source: Jones Walker / IBM 2025
NIST released its voluntary AI Risk Management Framework (AI RMF 1.0) on 26 January 2023, organizing AI risk into four functions: Govern, Map, Measure, and Manage (NIST, 2023).
Source: NIST
Key terms
- Enterprise AI governance
- The policies, roles, controls, and monitoring that let an organization deploy AI in production accountably. In practice it means inventorying AI systems, classifying their risk, documenting them, ensuring human oversight, and monitoring them once live.
- EU AI Act
- The European Union's risk-based AI law. It sorts AI systems into four tiers, prohibited, high-risk, limited, and minimal, and attaches obligations and penalties that scale with risk. It also reaches non-EU providers whose AI output is used in the EU.
- High-risk AI system
- Under the EU AI Act, AI used in sensitive contexts such as employment, credit, education, biometrics, or critical infrastructure. These systems face the strictest duties: risk management, data governance, documentation, logging, human oversight, and conformity assessment.
- GPAI (general-purpose AI) model
- A broadly capable model, such as a large language model, that can be adapted to many tasks. EU AI Act transparency and documentation duties for GPAI providers have applied since 2 August 2025, supported by a voluntary GPAI Code of Practice.
- NIST AI RMF
- The US National Institute of Standards and Technology's voluntary AI Risk Management Framework. It structures AI risk management into four continuous functions, Govern, Map, Measure, and Manage, and is widely used to shape governance programs.
- ISO/IEC 42001
- The first international, certifiable standard for an AI management system (AIMS). It gives organizations an auditable structure for governing AI development and use, and independent third parties can certify conformity against it.
At a glance
| Risk tier | What it covers | Core obligations and status |
|---|---|---|
| Unacceptable / Prohibited | Manipulative or exploitative AI, social scoring, untargeted facial-image scraping, most real-time public biometric ID | Banned outright; in force since 2 February 2025 |
| High-risk | AI in hiring, credit scoring, education, biometrics, and critical infrastructure | Risk management, data governance, documentation, logging, human oversight, and conformity assessment; standalone systems deferred to 2 December 2027 |
| Limited risk | Chatbots, emotion recognition, and AI-generated content or deepfakes | Transparency: disclose AI interaction and label AI-generated content (Article 50, from 2 August 2026) |
| Minimal risk | Spam filters, AI in video games, and most other AI | No mandatory obligations; voluntary codes of conduct encouraged |
What to check before you buy
- Build and maintain an AI system inventory, capturing every model, use case, owner, and data source.
- Classify each system by risk, mapping it to EU AI Act tiers and any applicable US or state regimes, and document the rationale.
- Anchor the program to a recognized framework such as the NIST AI RMF or ISO/IEC 42001 so controls are auditable and defensible.
- Require technical documentation and data-governance records for every high-risk system: intended purpose, training data, known limitations, and evaluation results.
- Design human oversight into consequential decisions so a person can review, override, or halt the system.
- Instrument production monitoring and logging so drift, accuracy, and incidents are tracked and retained for audit.
- Verify any AI builder ships auditability by default: audit trails, human-in-the-loop review, workflow integration, and an evaluation harness that measures accuracy, and ask for evidence rather than guarantees.
- Assign clear accountability, such as a Chief AI Officer or governance committee, and keep legal and compliance sign-off in the deployment path, because compliance is your legal responsibility, not the vendor's.
Frequently asked questions
Does the EU AI Act apply to us if we are not based in the EU?
Likely yes. The Act has extraterritorial reach: it applies to providers that place AI systems on the EU market and to providers and deployers whose AI output is used in the EU, regardless of where the company sits. Non-EU firms serving EU users or markets should assume scope and confirm the details with counsel.
The high-risk deadline moved to December 2027, so can we slow down?
No. The 2026 Digital Omnibus deferred standalone high-risk obligations to 2 December 2027, but prohibited practices have applied since February 2025, GPAI duties since August 2025, and transparency labeling from August 2026. The extra time is for building a defensible program, not for delaying it.
What are the penalties for getting it wrong?
Under Article 99, up to €35 million or 7% of global annual turnover for prohibited practices, €15 million or 3% for most high-risk non-compliance, and €7.5 million or 1% for supplying misleading information, whichever is higher. Reputational, contractual, and operational costs compound the fines.
NIST AI RMF or ISO/IEC 42001, which do we need?
They are complementary. The NIST AI RMF is a voluntary framework for structuring risk management through Govern, Map, Measure, and Manage; ISO/IEC 42001 is a certifiable management-system standard you can be audited against. Many enterprises use NIST to shape the program and ISO 42001 to certify it. Neither replaces EU AI Act legal compliance.
What does AI governance actually require day to day?
Inventory every AI system, classify its risk, document each high-risk system, keep humans in the loop on consequential decisions, and monitor models in production for drift and accuracy, all with clear ownership and retained logs. Governance is an operating discipline, not a one-time filing.
How do we choose an AI builder that ships governable systems?
Look for production engineering that bakes in audit trails, human-in-the-loop review, workflow integration, and an evaluation harness that measures accuracy, and be wary of anyone guaranteeing a compliance outcome. CONE RED is one option that engineers for auditability and measured accuracy; evaluate several builders and keep legal sign-off in-house.
This guide is educational and even-handed: CONE RED is one option among several, and no honest firm guarantees a fixed accuracy, compliance, or business outcome. Every statistic above links to a source you can check; figures are current as of publication and may change.
