Advanced

The Compliance Playbook

Everything in this course condenses to one workflow: find your AI, classify it, assign roles, and meet the duties for each tier before its deadline. This final lesson turns the law into a one-page action plan - plus the penalties that make it worth doing.

✍️ AI School Editorial Team · Lilly Tech Systems 📅 Published Jun 13, 2026 · Reviewed Jun 13, 2026

What Non-Compliance Costs

The Act’s fines are tiered by the seriousness of the breach, and like the GDPR they bite on global turnover:

BreachMaximum fine
Using a prohibited practice (Lesson 3)Up to €35M or 7% of total worldwide annual turnover, whichever is higher
Breaching most other obligations (high-risk, GPAI, transparency)Up to €15M or 3% of turnover
Supplying incorrect or misleading information to authoritiesUp to €7.5M or 1% of turnover

For SMEs and startups, the caps are applied proportionately (the lower of the fixed amount or the percentage). The headline numbers are aimed at large providers, but enforcement, corrective orders, and forced withdrawal from the EU market apply to everyone.

⚠️
Reputational and market-access risk often exceeds the fine. A market-surveillance order to withdraw a non-conforming system, or losing the ability to sell into the EU, can hurt far more than the monetary penalty - especially for a young company.

The Ten-Step Action Plan

  1. Build an AI inventory. List every AI system you build, embed, or use. You cannot classify what you have not catalogued.
  2. Assign a role to each system. Provider, deployer, importer, distributor - per system, not per company (Lesson 1).
  3. Run the Article 5 screen first. Anything near a prohibited practice is the top priority - it is already enforceable and carries the 7% fine (Lesson 3).
  4. Classify each system into a tier. High, limited, or minimal, using the decision path from Lesson 2.
  5. Flag the high-risk systems early. They need risk management, data governance, documentation, human oversight, and a conformity assessment - the longest lead time (Lesson 4).
  6. Map your GPAI exposure. Do you train, fine-tune, or just call foundation models? Fine-tuning can make you a provider (Lesson 5).
  7. Add transparency labels. Disclose AI chat, mark generated content, label deepfakes - cheap, so just do it (Lesson 6).
  8. Stand up the management systems. Risk-management and quality-management processes, plus the documentation templates behind them (Lesson 7).
  9. Deliver AI-literacy training. Already required since Feb 2025; record what you do.
  10. Set up post-market monitoring. Incident reporting, logging retention, and a corrective-action path before launch, not after.
Steps 1-4 are a weekend, not a quarter. An inventory, role assignment, the Article 5 screen, and tier classification can be done quickly and tell you exactly how much work remains. Most teams discover the majority of their systems are minimal-risk - the value of the exercise is isolating the few that are not.

Tailored Quick-Starts

If you mostly build AI products (provider)

Your weight is in Lessons 3, 4, and 5. Prioritise the Article 5 screen, then the high-risk documentation stack for any Annex III system, and determine whether any model you train or fine-tune pulls you into GPAI-provider duties.

If you mostly use third-party AI (deployer)

Your weight is in Lessons 4 (deployer duties) and 6. Use systems per the provider’s instructions, assign human oversight, inform staff before workplace deployment, and add transparency disclosures. Watch the deployer-to-provider trap if you re-brand or re-purpose a system.

If you resell or distribute AI (importer/distributor)

Verify that the systems you place on the market carry the CE marking, declaration of conformity, and provider information before you pass them on, and keep records.

Where This Course Ends and Counsel Begins

This course gives you the map: the tiers, the duties, the timeline, and the action plan. It does not replace legal advice on your specific systems. Use it to scope the work, ask the right questions, and brief your counsel efficiently - then confirm the close calls (is this Annex III? have we become a provider?) against the official text and qualified legal advice.

🎉
You’ve finished the course. You can now classify any AI system, identify your role, and map a system to its obligations and deadline. To go deeper on the governance machinery behind compliance, continue with AI Governance; for the data and security engineering behind the high-risk requirements, see AI Bias & Fairness and LLM Security.
🤝
Want a partner for the work? Lilly Tech Systems helps teams build their AI inventory, classify systems, produce the high-risk documentation, and design human-oversight and governance processes. Talk to our team →

Ready to Go Deeper?

Live instructor-led courses from our partners. Affiliate disclosure.