Hello everyone,
Here is the 4th and final article of my series on the EU AI Act!
The 1st one was an introduction to the text and the prohibited practices, the 2nd one focused on the High-Risk AI systems, the 3rd was covering all the others requirements for not high-risk AI systems and general purpose AI models, and this one is talking about the innovation, the Governance and penalities as well as the timeline of its entry into force.
In this final part of the series on the EU AI Act, we examine its approach to innovation support, compliance, and penalties. The Act aims to balance fostering AI development with setting strict standards and phased enforcement timelines. As the EU works toward cohesive AI governance, these measures highlight both the opportunities and challenges of regulating AI across Member States.
The EU AI Act’s AI sandboxes aim to support innovation by allowing companies to develop and test AI systems in a controlled environment with regulatory oversight. Set for launch by 2026, these sandboxes are intended to help businesses — particularly startups — navigate compliance.
Here are the key points:
AI Sandboxes by 2026: Each EU Member State must set up at least one national AI regulatory sandbox by August 2026. Sandboxes may also be created jointly across countries or regions.
Function of Sandboxes: These sandboxes provide a controlled environment for developing, testing, and validating AI systems before they enter the market. They aim to foster innovation and competitiveness while ensuring compliance with EU laws, especially regarding fundamental rights, health, and safety.
Supervision & Guidance: Competent authorities will provide guidance, supervision, and support within these sandboxes to help identify and mitigate risks, and ensure adherence to relevant regulations.
Documentation & Reporting: Providers in the sandbox receive documentation (exit reports) on their activities, which can be used to demonstrate regulatory compliance. These reports may be shared with the EU Commission and, with consent, made public.
Collaboration & Innovation: The sandboxes are meant to improve legal clarity, foster innovation, share best practices, and support cross-border cooperation. They especially benefit SMEs and startups by facilitating quicker market access.
Liability: Providers remain liable for any damages caused during sandbox experiments, but no administrative fines will be imposed if they follow the sandbox plan and authority guidance.
EU-wide Interface: The Commission will create an interface for stakeholders to access information and guidance related to the sandboxes.
Personal data lawfully collected for other purposes can be used in AI sandboxes, but only if the AI system is developed for public interest in areas such as public health, environmental protection, energy sustainability, public safety, transport, or public administration efficiency.
This can be done under strict conditions:
This data processing is necessary for meeting legal requirements and anonymized data cannot be used for it.
Effective monitoring and response mechanisms must be in place to identify and mitigate risks to data subjects.
Data must be processed in isolated, secure environments, accessible only by authorized personnel.
Data can only be shared according to data protection laws, and data generated within the sandbox cannot be shared outside it.
Personal data must be securely protected and deleted once the sandbox participation ends or when the data’s retention period expires.
The processing must not lead to decisions affecting the data subjects and must respect their rights.
Logs and detailed records of the process and AI system development must be maintained.
A detailed description of the AI system’s training, testing, and validation process, along with the testing results, must be documented and included in the technical records.
A summary of the AI project’s objectives and results should be published, excluding sensitive operational data related to law enforcement, border control and immigration.
For criminal justice purposes, personal data use in sandboxes requires specific legal provisions and must meet the same conditions as above.
Providers of high-risk AI systems, can conduct real-world tests before the AI system is officially placed on the market, under those conditions:
Real-world testing plan: A detailed testing plan must be submitted and approved by the relevant national market surveillance authority. Approval is implied if no response is given within 30 days.
Ethical review and compliance: Tests must comply with ethical standards and other EU laws. Providers must register these tests in a database, certain sensitive areas like law enforcement and migration are to registered those test in a secure and non-public section.
EU jurisdiction: Be based in EU or have appointed a legal representative based in the EU. Furthermore, data from testing can only be transferred to third countries if proper safeguards, in line with EU law, are in place.
Conditions for testing:
Submitting a testing plan.
Ensuring data privacy and allow data withdrawal.
Limiting the test duration to six months (extendable).
Protecting vulnerable groups.
Ensuring informed consent from subjects, except in specific law enforcement cases.
Monitoring and responsibility: Providers are responsible for overseeing the tests, which must be reversible, and they are liable for any damages. When working with deployers, they must sign an agreement outlining their roles and responsibilities. Market authorities can inspect and monitor tests.
Incident reporting: Any serious incidents during testing must be reported, and mitigation actions taken, including suspending or terminating the test if necessary.
Final reporting: Providers must notify authorities about the suspension or termination of tests and provide final results.
The EU AI Act’s penalties are structured to enforce compliance, with fines up to €35 million or 7% of turnover for major violations. Lesser fines address non-compliance with safety and transparency standards, with the goal to encourage responsible practices across the AI sector while providing some flexibility for smaller businesses. This framework seeks to promote accountability industry-wide.
Non-compliance with prohibited AI practices can result in fines up to 35 million euros or 7% of a company's global annual turnover, whichever is higher.
Other non-compliance with operator or notified body provisions (listed after) can lead to fines up to 15 million euros or 3% of a company's global annual turnover, whichever is higher:
obligations for providers of high-risk AI systems;
obligations of authorised representatives;
obligations of importers;
obligations of distributors;
obligations of deployers;
requirements and obligations of notified bodies;
transparency obligations for providers and deployers.
Providing incorrect, incomplete, or misleading information to notified bodies or authorities can result in fines up to €7.5 million or 1% of a company's global annual turnover, whichever is higher.
For SMEs and start-ups, the fines shall be up to the percentages or amount referred to, whichever is lower.
The Commission may fine providers of general-purpose AI models up to 3% of their global annual turnover or 15 million euros, whichever is higher, if they intentionally or negligently:
violate the Regulation;
fail to comply with document or information requests or supplied incorrect/incomplete information;
ignore measures requested by the Commission to the provider;
deny access to AI models with systemic risk for evaluation.
Overall, the Regulation should start apply from 2 August 2026. Howerver, there are some points that will be enforced before or after as detailed in the following general timeline.
The AI Act Regulations has officially entered into force on this date, but none of the requirements do apply yet.
Member States should identify the authorities and bodies responsible for protecting fundamental rights and notify the Commission and other Member States.
Two requirements become applicable:
AI literacy obligations for providers and deployers of AI systems.
Prohibited AI practices.
Codes of practice by the Commission must be ready to enable providers to demonstrate compliance.
The following parts of the Act become applicable:
Rules and requirements realated to notifying authorities and notified bodies.
General-Purpose AI models requirements and procedures — except for those on the market before this date (cf. details after).
Governance at Union level and national authorities.
Penalities and fines (apart for general purpose AI models).
Confidentitality requirements for the authorities.
Moreover, those points also start to be applicable:
Commission deadline for its review of the list of high-risk systems and prohibited AI practices for the European Parliament and the Council.
From then, every years until the delegation period ends.
If a code of practice — intended for 2 May 2025 — is not finalized by this date, or if the AI Office finds it inadequate, the Commission may establish common rules to implement the obligations.
Member States must set and notify penalty rules, including fines, to the Commission and ensure they are effectively enforced.
Member States must inform the Commission of their notifying and market surveillance authorities and designate a single contact point for the Regulation, with public contact details provided online.
Member States must report to the Commission on the resources of their national authorities, assessing adequacy.
And every two years thereafter.
The Commission will provide guidelines for high-risk AI classification with examples and establish a template for required post-market monitoring plans.
Application of the rest of the AI Act (apart from high-risk AI systems), including:
Requirements related to standards, conformity, assements, certificates and registration.
Transparency obligations for providers and deployers of certain AI systems.
Measures in suport of innovation.
Also, Member States must ensure their authorities set up at least one national AI regulatory sandbox by this date.
Requirements for high-risk AI systems start to apply — except for those on the market before 2 August 2026 (cf. details after).
The Commission will have review the AI Office’s effectiveness and report to Parliament and the Council on potential improvements.
Also by this date, and every four years after, the Commission:
Will evaluate and report to the Parliamant and Concil the needs for amendments regarding:
The list of high-risk AI systems.
The list of AI systems requiring additional transparency measures.
The supervision and governance system.
Will report on progress in energy-efficiency standards for general-purpose AI, assessing if further actions are needed.
The Commission will also assess, by this date, and every three years after, the impact and effectiveness of voluntary codes of conduct.
The Commission must draw up a report on the delegation of power before this date.
By this date, and every four years after, the Commission will review the regulation, assessing enforcement and potential need for an EU agency. The report will go to Parliament, the Council, and be made public.
The Commission will assess the Regulation’s enforcement and report to Parliament, the Council, and the European Economic and Social Committee.
For high-risk AI systems — apart from large-scale IT systems as referred after — that have been placed on the market before 2 August 2026 and are not subject to significant changes in their designs after this date, and are not intended to be used by public authorities, the AI Act does not apply! For those same systems but used by public authorities the Act apply from 2 August 2030.
AI systems which are components of the large-scale IT systems in the area of Freedom, Security and Justice (as detailed in annex X), and that have been placed on the market before before 2 August 2027 must be compliant with the AI Act “only” by 31 December 2030.
Providers of general-purpose AI models marketed before 2 August 2025, must ensure compliance with the Regulation by 2 August 2027.
The EU AI Act’s phased approach reflects an attempt to anticipate risks and establish clear guidelines for AI governance before its full enforcement. While these structured timelines, innovation support, and penalties are essential steps, much of the Act’s impact will depend on how effectively its rules are enforced. By defining prohibited practices and promoting responsible AI innovation, the Act aims to guide the sector’s development, yet its effectiveness will ultimately hinge on the EU’s ability to monitor compliance and adjust to the evolving AI landscape.
Thanks for reading Artificial Impact! This post is public so feel free to share it.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.