How much is the maximum EU AI Act fine?
The maximum EU AI Act fine is €35 million or 7% of a company's total worldwide annual turnover from the previous financial year — whichever is higher. This top tier applies to prohibited practices under Article 5. Non-compliance with other provisions is capped at €15M / 3%, GPAI provider violations at €15M / 3%, and providing incorrect information to authorities at €7.5M / 1%. For SMEs, Article 99(6) applies the lower of the two figures instead of the higher.
When does the EU AI Act take effect?
The EU AI Act entered into force on August 1 2024. Application is staggered: Article 5 prohibited practices apply from February 2 2025, GPAI model obligations from August 2 2025, Annex III high-risk system obligations from August 2 2026, and Article 6(1) product-safety high-risk systems from August 2 2027. Public-sector legacy systems have until August 2 2030.
Does ISO/IEC 42001 satisfy the EU AI Act?
No single standard fully satisfies the EU AI Act, but ISO/IEC 42001 covers most of the Article 17 quality management system, Article 9 risk management, and Article 11 documentation requirements. The AI Office is expected to designate harmonized standards under Article 40 that provide a presumption of conformity — ISO/IEC 42001 is a leading candidate. Certification today gives strong evidence of due diligence but does not by itself grant conformity presumption.
Is SOC 2 enough for AI companies?
SOC 2 covers general security, availability, and confidentiality controls but does not include AI-specific criteria such as model documentation, adversarial testing, bias assessment, or impact assessments. For enterprise sales, SOC 2 remains the minimum bar for AI vendors selling into US enterprises. For EU market access or NIST AI RMF alignment, SOC 2 is complementary but not sufficient — most mature AI companies stack SOC 2 + ISO/IEC 42001 or NIST AI RMF.
Do I need a bias audit if I am not in New York City?
Not for NYC Local Law 144 — but you may still need a bias audit under other laws. Colorado SB 24-205 requires an impact assessment (which includes bias analysis) for high-risk AI systems from June 30 2026. Illinois HB 3773 (effective January 1 2026) restricts biased employment AI. The EU AI Act Article 10 mandates data-governance measures including bias detection. Federal EEOC guidance (2023) treats disparate-impact AI as covered by Title VII.
Which US states have AI laws in force?
As of 2026: Colorado (SB 24-205 effective June 30 2026), Texas (TRAIGA HB 149 effective January 1 2026), Illinois (HB 3773 effective January 1 2026), Utah (SB 149 in force since May 2024), Tennessee (ELVIS Act), and California (multiple, including SB 1047 vetoed, but AB 2013 and AB 2905 in force). New York City has LL-144 in force since July 2023. New York RAISE Act takes effect January 1 2027. Nearly every state has pending AI legislation.
What is the difference between NIST AI RMF and ISO/IEC 42001?
NIST AI RMF is voluntary US guidance built around four functions (Govern, Map, Measure, Manage). ISO/IEC 42001 is a certifiable global ISO management-system standard with 38 Annex A controls and a mandatory Plan-Do-Check-Act cycle. Both cover risk, governance, documentation, and monitoring. Companies routinely implement RMF operationally and certify against 42001 for external assurance. NIST has published an official crosswalk between them.
What is a General-Purpose AI (GPAI) model under the EU AI Act?
A GPAI model is defined in Article 3(63) as an AI model that shows significant generality, can competently perform a wide range of distinct tasks, and can be integrated into a variety of downstream systems. GPAI providers face documentation, copyright-policy, and training-data-summary obligations under Article 53. A GPAI with systemic risk (10^25 FLOPs training-compute threshold under Article 51) faces additional obligations including evaluations, adversarial testing, and serious incident reporting under Article 55.
How long does ISO/IEC 42001 certification take?
Typical timelines are 6 to 12 months from kickoff to certificate issuance. Gap assessment and remediation usually takes 3 to 6 months; the audit itself is split into a Stage 1 documentation review and a Stage 2 on-site audit 4 to 8 weeks later. Recertification runs on a three-year cycle with annual surveillance audits. Companies with existing ISO/IEC 27001 or 9001 certifications can compress the timeline by reusing management-system infrastructure.
What is the difference between an AI Act provider and deployer?
A provider (Article 3(3)) develops an AI system and places it on the EU market under its own name — providers bear the primary Article 16 obligations including conformity assessment, CE marking, and post-market monitoring. A deployer (Article 3(4)) uses an AI system under its authority in a professional capacity. Deployer obligations under Article 26 include monitoring, human oversight, keeping logs 6+ months, notifying affected persons, and running a fundamental rights impact assessment (FRIA) for certain high-risk systems.
Do open-source AI models have to comply with the EU AI Act?
Yes but with reduced obligations. Article 2(12) exempts free and open-source AI systems from the Act except when they are placed on the market as high-risk systems, prohibited systems, or GPAI models with systemic risk. Open-source GPAI providers still owe copyright-policy and training-data-summary obligations (Article 53) unless they are non-systemic and released under a free license with public parameters and architecture.
What must be in an EU AI Act technical documentation file?
Annex IV lists nine mandatory sections: (1) general description including intended purpose, versions, and hardware; (2) detailed system description and design; (3) monitoring, functioning and control; (4) risk management system per Article 9; (5) changes to the system through lifecycle; (6) harmonized standards applied; (7) EU declaration of conformity; (8) post-market monitoring plan; (9) list of the specific data used for training and validation.