This article exists to balance the others in its block. What follows deals with what the Regulation does not provide for, because in this field more fear than precision is in circulation, and fear sells better.
Nothing here says there is nothing to do. It says which specific things are not going to happen, and why.
There is no penalty for not having an inventory
Let's start with the most repeated one. The AI Act does not require keeping an inventory of AI systems — the word doesn't appear once in the Regulation — so its absence can hardly be penalised.
What does happen is subtler and less marketable: without an inventory you cannot meet the obligations that do exist, because all of them are written against specific systems. Not having an inventory is not an infringement. It is what makes it impossible to show that there isn't one.
No database registration for a private company
The EU database of Art. 71 exists, and Art. 49 imposes registrations. But it only reaches a deployer that is one of the “public authorities, Union institutions, bodies, offices or agencies or persons acting on their behalf”.
A private company deploying high-risk systems has no duty to register itself. The one who registers the system is the provider, and the one who registers its use is the public sector.
The fine is not automatically set at the top bracket
The brackets exist and they are high. But the article that sets them deserves a full read: for SMEs, Art. 99(6) caps every fine at the lower magnitude of the two that would otherwise apply.
With two clarifications that that article develops and are only recalled here: the rule says “up to” — a ceiling, not an amount fixed in advance, and Art. 99(7) requires weighing all the circumstances of each individual case; and the top brackets belong to the prohibited practices of Art. 5, not to a company's ordinary use of AI.
The high-risk regime does not apply yet
This is the one most used as an urgency argument, and it is easy to check: Annex III starts applying on 2 December 2027, and Annex I on 2 August 2028. The date circulating in a good part of the guides — August 2026 — is wrong.
So today no infringement of Art. 26 is possible for anyone. Whoever claims otherwise is using a deadline that is not in the law — and it is worth noticing that it is almost always claimed by someone selling the solution.
And what does happen, so the conclusion doesn't come out crooked
Three things, and all three have been enforceable for a while.
Art. 4 and Art. 5 have been in force since 2 February 2025. AI literacy for everyone — in the wording the Digital Omnibus gave it, which softened the duty without removing it — and an absolute prohibition of certain practices, with no exception by size or sector.
The GDPR has been applying for years, and it waits for the AI Act for nothing. Most AI uses in a company process personal data, and there you have legal basis, information to data subjects, impact assessments where they apply, and rights to honour. A good part of what gets presented as "AI Act work" is actually data protection work that was already due.
And Art. 50 transparency already applies since 2 August 2026, with the main obligation falling on the provider.
Why this matters more than the fear
Because an organisation acting out of fear does whatever it is told, in the order it is told — and what it usually does first is the most expensive and the least enforceable.
The order that comes out of reading the dates is the reverse: first what already binds everyone and costs little; then, calmly, what will bind a few in 2027. In between, the single task that decides which of the two groups you are in.
None of that needs an invented urgency. And whoever puts one in front of you is telling you, without meaning to, that they haven't read the article that disproves it.
Content under Articles 4, 5, 26, 49, 50, 71 and 99 and Annexes I and III of Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744 (OJEU of 24 July 2026).
This article is for informational purposes only and does not constitute legal advice.