PENALTIES GO LIVE AUGUST 2026 · HIGH-RISK RULES DECEMBER 2027

€35M fines.
Or 7% of global turnover.
Whichever is higher.

The EU AI Act doesn't ask if you're trying. It asks for evidence — Article by Article — that you meet the obligations that apply to your AI systems. Conformis produces that evidence. A defensible, audit-grade gap assessment for companies that deploy AI in the EU.

Enforcement countdown
From 2 August 2026, transparency duties (Art. 50), AI-literacy enforcement (Art. 4) and the full €35M / 7% penalty regime apply. High-risk deployer obligations (Art. 26) now move to 2 December 2027 under the Digital Omnibus — the window to get ready, not a reprieve.
Status: the Digital Omnibus on AI was approved by Parliament (16 Jun) and the Council (29 Jun 2026); the new dates take legal effect on publication in the EU Official Journal, expected July 2026. Marking of AI-generated content (Art. 50(2)) applies from 2 December 2026.
Days
Hours
Mins
What's at stake · Article 99

The penalty regime is tiered. So is the exposure.

Article 99 establishes administrative fines on a sliding scale tied to the severity of the violation and the size of the offender. The maxima are real numbers. They are the higher of a fixed euro amount or a percentage of worldwide annual turnover.

Tier 1 — Prohibited practices
€35,000,000
or 7% of worldwide annual turnover
Social scoring, untargeted face-scraping, emotion inference at work or school, biometric categorisation of sensitive traits, subliminal manipulation, certain real-time biometric ID. The Act prohibits these outright. From 2 December 2026 the Digital Omnibus adds a further ban: AI that generates non-consensual intimate imagery or child sexual abuse material.
Article 99(3) · Article 5
Tier 2 — High-risk & operator duties
€15,000,000
or 3% of worldwide annual turnover
Failure to meet deployer or provider obligations on high-risk AI systems — human oversight, transparency, monitoring, logging, FRIA where required. This is the tier most deployers are exposed to.
Article 99(4)
Tier 3 — Misleading authorities
€7,500,000
or 1% of worldwide annual turnover
Supplying incorrect, incomplete, or misleading information to national competent authorities or notified bodies. Cooperation failures are penalised on their own terms.
Article 99(5)
It is not only the fine. National authorities can also order withdrawal of AI systems from the market, mandate corrective measures, and refer matters for further enforcement. For deployers, customer procurement teams are already asking for compliance evidence — long before any regulator does. A €1,999 audit looks different against this backdrop.
The problem

A checklist tool tells you you're in scope. That's the easy 10%.

The Act doesn't ask whether you've read it. It asks for evidence — by Article — that you meet the obligations applicable to your specific AI systems. The hard 90% is that gap between "the regulation applies" and "we can defend ourselves." That gap is what Conformis closes.

Free online checkers tell you "the AI Act might apply" You already suspected that. The question is what to do about it.
Big-Four advisory engagements start at €40–80k Right for a multinational. Wrong for a 100-person fintech with five AI use cases.
In-house counsel is not an AI-Act specialist And likely already overloaded with GDPR, DORA, NIS2, and DSA work.
Conformis: a fixed-fee, written, defensible gap audit What you're missing, by Article. What to do about it, in priority order. Conservative by default.
The method

One engagement. Four stages. A written report your lawyer can rely on.

We treat your own risk classification as a claim to test — not a fact. Every finding is tied to a specific Article. Legal obligations are kept separate from good-practice recommendations, so your counsel knows exactly what's binding.

01 / SCOPE

Map the AI estate

We inventory every AI system in actual use, identify your role (deployer, provider, or both) per system, and establish the EU nexus.

02 / CLASSIFY

Test the risk tier

We pressure-test each system against Article 5 (prohibited), Annex III (high-risk), Article 50 (transparency), and minimal-risk categories. Self-classification is examined, not accepted.

03 / GAP

Map findings to Articles

For each applicable obligation — Art. 4 literacy, Art. 26 deployer duties, Art. 27 FRIA, Art. 50 transparency — we state what's in place, what's missing, and what evidence would close the gap.

04 / REPORT

Deliver, prioritised

A written report with an executive summary, eight required sections, and a prioritised action list. Final on first delivery for most clients; preliminary only where a classification question genuinely needs a follow-up call to settle.

Why we're different

Built for credibility, not volume.

Most "AI Act compliance" offers are content marketing for something else — a SaaS platform, a Big-Four upsell, or a generic GRC tool. Conformis is one thing: a written gap audit, conservative by default, scoped to what you actually deploy.

What you get
Checklist tools / free checkers
Conformis
Article-by-Article gap analysis
No — tells you scope only
Yes — every finding tied to an Article
Risk classification tested, not accepted
No — you self-classify
Yes — we examine, not assume
Legal obligations vs. good-practice separated
No — mixed together
Yes — your lawyer can rely on it
Adjacent-regime check (GDPR, FRIA overlap)
No
Yes — included by default
Right-sized: depth scales to your risk
N/A
Yes — low risk gets a short, honest report
Fixed fee, no per-seat, no surprises
N/A
€1,999 — single tier
Engagement

One audit. Fixed fee. No upsell.

A single price for a single deliverable. If your exposure turns out to be small, we say so in writing — and you've still paid less than one hour of a Big-Four senior. Monitoring is available afterwards if useful.

Core engagement

EU AI Act Gap Audit

A written, defensible gap assessment of your AI estate. Article-by-Article. Conservative by default. Delivered as PDF and Word.

€1,999 fixed fee
~10 business days · One engagement, no retainer
  • Scope & deployer/provider role determination
  • Risk classification tested against Articles 5, 6, 50 + Annex III
  • Article-by-Article gap analysis (Arts. 4, 26, 27, 50 as applicable)
  • FRIA & DPIA-overlap analysis where relevant
  • Adjacent-regime check (GDPR + sector-specific)
  • Prioritised remediation action list
  • Eight-section written report — executive summary to limitations
  • One kick-off call + one review call included
Start with a free 2-minute check
Add-on (optional)

Ongoing Monitoring

For clients who want continuous coverage after the initial audit. Cancel anytime.

€500 /month
Available after first audit only
  • Quarterly re-assessment
  • Regulatory change alerts
  • New-system reviews on request
  • Audit-ready evidence file maintained
Discuss after audit
Free · 2-minute exposure check

Where do you stand?

Six quick questions and an indicative read on your EU AI Act exposure, shown right here on the page.

EU AI Act exposure check

Indicative only — a paid audit confirms it. ~2 minutes.

Does your organisation build AI systems, or use ones built by others?

This determines which set of obligations applies.

We use AI built by others e.g. a vendor tool, an API like GPT or Claude
We build or substantially modify AI and put it on the market under our name
Both
Unsure

Is the AI used by people in the EU, or do its outputs affect people in the EU?

The Act applies even to non-EU companies if outputs reach the EU.

Yes
No
Unsure

Does any system do any of these?

Social scoring · inferring emotions at work or school · biometric categorisation of sensitive traits · untargeted face scraping · subliminal manipulation · generating intimate or sexual images of real people without consent.

Yes, at least one might apply
No, none of these
Unsure

Does the AI operate in any of these areas?

Employment/hiring · credit scoring · insurance pricing · education · essential services · biometrics · critical infrastructure · law enforcement · justice.

Yes, at least one
No, none of these
Unsure

What does the AI's output do?

Be honest about whether a person or the machine effectively decides.

Makes or effectively determines a decision about a person approve/reject, rank, score
Recommends; a human always decides
Assistive only — no decisions about people summarise, draft, search, classify documents
Unsure

Do staff who use the AI have any formal AI-literacy training?

Article 4 — in force since February 2025, applies broadly.

Yes, structured
No / ad hoc
Unsure

Your result is ready.

One step before your result — your name and work email. We use these only to follow up about a scoped next step for your situation.

    This is an automated, indicative reading based on six answers — not a compliance determination and not legal advice. Real classification depends on specifics a short audit examines properly.

    Time-sensitive · offer ends

    Turn this into a defensible, written audit — off.

    Book your scoping call before and your full Article-by-Article gap audit is instead of the standard . Same deliverable, same conservative method — nothing padded, nothing inflated.

    Claim the discount — book your call →

    One engagement, fixed fee, no retainer. We confirm scope on the call before anything is invoiced.

    Questions we get often

    Reasonable scepticism, answered.

    Why €1,999 — isn't this more complex than that?

    It depends on what you deploy. For a 100-person fintech with three or four well-defined AI use cases, €1,999 reflects roughly 10 business days of focused work, a structured methodology, and a written deliverable your lawyer can rely on. If your estate is much larger or more complex, we say so on the scoping call before quoting — we don't surprise you with scope creep. If your exposure is genuinely small, you still get a short, honest written report.

    How is this different from what my law firm would do?

    A law firm gives you a legal opinion. We give you a gap audit — a structured, evidence-based mapping of your actual AI estate to the obligations that apply. The two are complementary. Many of our clients pair our written report with a brief legal review from their existing counsel; the report makes that review faster and cheaper because the factual work is already done.

    What if you tell me I'm not high-risk and I disagree?

    The report is conservative by default, which means if anything we lean toward flagging exposure, not dismissing it. But "conservative" doesn't mean "manufactured." If we conclude your AI use is genuinely limited or out of scope, we say so in writing — and we explain the reasoning. You can take that to your customer or DPO; that's often exactly what they're asking for.

    Are you a law firm? Is this legal advice?

    No, and no. Conformis produces a compliance gap audit — a factual, structured assessment against the Act's provisions. It is not a legal opinion and does not establish a lawyer-client relationship. Where you need a binding legal view (for example, on an ambiguous classification), we will say so and recommend you take that specific question to counsel. The report is designed to make that handoff efficient.

    What about GDPR, DORA, NIS2 overlap?

    Every audit includes an adjacent-regime check — primarily GDPR (because most AI systems process personal data and FRIA/DPIA obligations overlap), and sector-specific overlays where relevant (DORA for financial services, the EU Health Data Space for health, etc.). We flag where the AI Act adds obligations versus where it duplicates existing ones.

    What happens after I do the free check?

    You answer six quick questions, then enter your name and work email to see your indicative result on the page. We use those details only to follow up within two business days with a scoped next step. The check itself is genuinely free; if your exposure looks minimal we'll tell you that and not pitch you an audit.

    The high-risk deadline moved. The August one didn't.

    Find out where you stand. Two minutes, and you'll see your result right on the page.