What the EU AI Act requires, and what it costs to get wrong
This page is written for the people who carry the exposure rather than the people who run the models. It explains the obligations, the penalties and the evidence a regulator expects. It is useful whether or not you ever buy anything from us, which is the point of publishing it.
Nothing here is legal advice. It is a plain reading of the legislation with links to the text, so you can check every statement against the source.
The dates that already passed
2 August 2026
Article 50 transparency obligations apply. Systems that interact with people must make clear that a person is dealing with AI. Generative outputs must carry machine-readable marks that allow them to be detected as AI-generated. Deployers must disclose deepfakes and certain AI-generated public-interest text.
This is not a future deadline. It is in force now.
10 June 2026
The Article 50 Code of Practice was published. Codes and guidelines are how the detail of the obligation gets settled, and they move. An assessment that was accurate against the draft is not automatically accurate against the final text.
Continuously
Your own systems change. A model is swapped, a prompt is edited, a workflow is extended. Each of those can move a system in or out of scope, and none of them file a ticket telling compliance that it happened.
What non-compliance costs
Article 99 sets three tiers. The figures are the higher of a fixed amount or a percentage of worldwide annual turnover. Turnover is revenue, not profit, which is why the numbers are larger than people expect.
| Tier | Ceiling | What triggers it |
|---|---|---|
| Prohibited practices | €35 million or 7% | Breach of Article 5, the practices the Act bans outright. |
| Most other obligations | €15 million or 3% | Breach of the Act's other obligations, including the transparency duties. |
| Misleading information | €7.5 million or 1% | Supplying incorrect, incomplete or misleading information to authorities. |
Article 99(6) works in the opposite direction for small and medium enterprises: the fine is the lower of the fixed amount and the percentage, not the higher. If you are an SME, use the lower figure. Quoting the headline maximum at your own board is not a stronger argument, it is a less credible one.
The part that catches people
Most organisations can answer "do we disclose that this is AI". Far fewer can answer the three questions underneath it, and those are the ones an auditor asks second.
Why was this allowed?
A model returns a probability. An auditor wants a reason. A confidence score of 0.94 does not say which rule was applied, so the evidence you are asked for does not exist as a by-product of running the system.
The evidence changed. What does that affect?
A reference record, a protocol version or a source dataset is superseded. Which earlier decisions are now invalid? Most teams cannot say, so they redo everything or redo nothing. One is expensive and the other is dangerous.
The rules changed. What does that affect?
Guidance is updated. Which of your assessments, approvals and running workflows were built on the superseded version? Work usually continues on the old rule until somebody notices, and that somebody is often the auditor.
What we do about it, briefly
EcoKure sits after your model and decides what is allowed to proceed. Every decision returns a categorical verdict, allow, block, review or abstain, with the reason recorded and signed. When your evidence or your rules change, the affected work is identified and held, and the work that is unaffected stays valid instead of being redone.
The output is an evidence pack you can hand to an auditor and they can verify offline, against a published key, without our source code and without contacting us.
What we do not claim
We cannot guarantee compliance
Compliance is determined by a regulator, not by a vendor. Any supplier who offers you guaranteed compliance is either misunderstanding the obligation or hoping you will not ask what indemnity sits behind the word. We produce evidence. Deciding whether that evidence satisfies the obligation is your counsel's call and ultimately your regulator's.
We do not interpret the law
We do not tell you what a rule means, and we are not a substitute for legal advice, a GRC platform or your quality system. We govern the computational consequences of a decision and a change, which is a narrower job, and the one that currently has no evidence trail.
We do not mark or watermark content
Article 50(2) requires machine-readable marking of synthetic content in the cases it covers. EcoKure does not provide that and has no plans to build it. It is a different technology — provenance signalling embedded in the artefact itself — and it needs a specialist provider such as a C2PA implementation.
What we do is the layer beside it: record that the marking step ran, on which artefact, under which control version, and who signed it off. If you need the marking itself, you need a second supplier, and you should hear that from us before you hear it from your counsel.
Sources: the consolidated Act and the Commission's own guidance. We link to the text rather than paraphrasing it, because a briefing you cannot check against the source is a sales document wearing a briefing's clothes. Article 50 · Article 99 · Commission transparency guidelines
Where it sits in what you already run
Nothing is replaced. The runtime deploys in your own account, so the only thing crossing the seam is a decision request one way and a verdict with its evidence coming back.
What one decision actually does
The same runtime and the same evidence contract as every other pathway. What changes is the control pack and the workflow.
