By Rafael Luque Ocaña

What doesn't happen if you do nothing: there is no automatic penalty for not having an inventory

Fear sells better than precision, so it's worth saying what the Regulation does not provide for. There is no automatic fine, no registration duty for a private company, and the high-risk regime does not apply yet.

This article exists to balance the others in its block. What follows deals with what the Regulation does not provide for, because in this field more fear than precision is in circulation, and fear sells better.

Nothing here says there is nothing to do. It says which specific things are not going to happen, and why.

There is no penalty for not having an inventory

Let's start with the most repeated one. The AI Act does not require keeping an inventory of AI systemsthe word doesn't appear once in the Regulation — so its absence can hardly be penalised.

What does happen is subtler and less marketable: without an inventory you cannot meet the obligations that do exist, because all of them are written against specific systems. Not having an inventory is not an infringement. It is what makes it impossible to show that there isn't one.

No database registration for a private company

The EU database of Art. 71 exists, and Art. 49 imposes registrations. But it only reaches a deployer that is one of the “public authorities, Union institutions, bodies, offices or agencies or persons acting on their behalf”.

A private company deploying high-risk systems has no duty to register itself. The one who registers the system is the provider, and the one who registers its use is the public sector.

The fine is not automatically set at the top bracket

The brackets exist and they are high. But the article that sets them deserves a full read: for SMEs, Art. 99(6) caps every fine at the lower magnitude of the two that would otherwise apply.

With two clarifications that that article develops and are only recalled here: the rule says “up to” — a ceiling, not an amount fixed in advance, and Art. 99(7) requires weighing all the circumstances of each individual case; and the top brackets belong to the prohibited practices of Art. 5, not to a company's ordinary use of AI.

The high-risk regime does not apply yet

This is the one most used as an urgency argument, and it is easy to check: Annex III starts applying on 2 December 2027, and Annex I on 2 August 2028. The date circulating in a good part of the guides — August 2026 — is wrong.

So today no infringement of Art. 26 is possible for anyone. Whoever claims otherwise is using a deadline that is not in the law — and it is worth noticing that it is almost always claimed by someone selling the solution.

And what does happen, so the conclusion doesn't come out crooked

Three things, and all three have been enforceable for a while.

Art. 4 and Art. 5 have been in force since 2 February 2025. AI literacy for everyone — in the wording the Digital Omnibus gave it, which softened the duty without removing it — and an absolute prohibition of certain practices, with no exception by size or sector.

The GDPR has been applying for years, and it waits for the AI Act for nothing. Most AI uses in a company process personal data, and there you have legal basis, information to data subjects, impact assessments where they apply, and rights to honour. A good part of what gets presented as "AI Act work" is actually data protection work that was already due.

And Art. 50 transparency already applies since 2 August 2026, with the main obligation falling on the provider.

Why this matters more than the fear

Because an organisation acting out of fear does whatever it is told, in the order it is told — and what it usually does first is the most expensive and the least enforceable.

The order that comes out of reading the dates is the reverse: first what already binds everyone and costs little; then, calmly, what will bind a few in 2027. In between, the single task that decides which of the two groups you are in.

None of that needs an invented urgency. And whoever puts one in front of you is telling you, without meaning to, that they haven't read the article that disproves it.

Content under Articles 4, 5, 26, 49, 50, 71 and 99 and Annexes I and III of Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744 (OJEU of 24 July 2026).

This article is for informational purposes only and does not constitute legal advice.

Get analysis like this in your inbox

Alethexis regulatory and product news. No noise.

I agree to receive communications from Alethexis: content about AI and regulation, and product news. I can unsubscribe at any time.

Controller: ALETHEXIS, S.L. (CIF B88758057). Purpose: to send you the Alethexis newsletter (content about AI and regulation, and product news). Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time. Retention: until you unsubscribe or after 24 months of inactivity. Rights of access, rectification, erasure, objection, restriction and portability: [email protected]. You may lodge a complaint with the Spanish Data Protection Authority (AEPD, www.aepd.es). More information in the privacy policy.