Skip to main content
Pillar 10 · Compliance Doctrine

AI Compliance by Industry

AI compliance is the practice of making sure your AI systems meet the laws and standards that govern your industry and the data you process. It matters now because the rules have teeth: the EU AI Act, phased in from February 2025, carries penalties up to 35 million euros or 7% of global annual turnover for prohibited practices, while GDPR already caps fines at 20 million euros or 4% of turnover. HIPAA governs any AI touching health data, and financial regulators treat AI models as decisions they can audit. Compliance is not a legal footnote you bolt on at the end, it is an architecture decision you make at the start, because retrofitting governance onto a deployed model is far more expensive than building it in.

35M euros / 7%maximum EU AI Act fine for prohibited AI practices, whichever is higher, of a fixed sum or a share of global annual turnover, EU AI Act, Article 99, effective Feb 2, 2025
The short version
  • 01The EU AI Act uses tiered fines: up to 35M euros or 7% of global turnover for prohibited practices, up to 15M euros or 3% for high-risk violations, and up to 7.5M euros or 1% for supplying misleading information (EU AI Act, Article 99).
  • 02Deadlines are staggered: prohibited-practice rules applied Feb 2, 2025; transparency obligations apply Aug 2, 2026; most high-risk obligations become enforceable Aug 2, 2026 through 2027.
  • 03GDPR already applies to AI that processes personal data, with fines up to 20M euros or 4% of global turnover, the two regimes stack rather than replace each other.
  • 04HIPAA governs any AI system that creates, receives, or transmits protected health information, requiring safeguards and business-associate agreements before a tool touches patient data.
  • 05SMEs get relief: the EU AI Act applies the lower of the fixed sum or the percentage for smaller firms, but the obligation to comply is identical.

Why compliance is an architecture decision

Compliance is decided when you design the system, not when the auditor arrives. Where data lives, who can access the model, and whether decisions are logged are architecture choices, and retrofitting them onto a live system costs far more than building them in.

Every AI regulation reduces to a small set of questions: what data does the model see, where does that data live, who can access it, can you explain a decision, and can you prove all of the above? Those are architecture questions, answered by design choices you make before deployment. The organizations that get fined are almost never the ones that read the law and decided to break it, they are the ones who deployed first and discovered afterward that they could not produce a log, an explanation, or a data-processing record.

The operator's reframe

Do not ask "are we allowed to use this AI?" Ask "if a regulator asked us to prove what this system did, to whom, and why, could we?" If the answer is no, the compliance gap is an engineering gap.

The EU AI Act and its fine tiers

The EU AI Act is the first comprehensive AI law and it classifies systems by risk. Fines scale with severity: up to 35M euros or 7% of global turnover for banned uses, down to 7.5M euros or 1% for misleading information, whichever figure is higher.

The EU AI Act sorts AI into risk tiers, unacceptable (banned), high-risk (heavily regulated), limited-risk (transparency duties), and minimal-risk. It applies extraterritorially: if your AI output is used in the EU, the rules can reach you even from the US. Enforcement is decentralized across national authorities and the EU AI Office, and the deadlines are staggered so obligations phase in over several years rather than all at once.

35M / 7%
max fine for prohibited AI practices (euros or % of global turnover)
EU AI Act, Art. 99
15M / 3%
max fine for most high-risk and obligation breaches
EU AI Act, Art. 99
7.5M / 1%
max fine for supplying incorrect or misleading information
EU AI Act, Art. 99

Sector rules: HIPAA, finance, and GDPR

General AI law sits on top of rules you already have. Healthcare AI must satisfy HIPAA, financial AI must satisfy model-risk and fair-lending rules, and any AI touching EU personal data must satisfy GDPR. These stack, meeting one does not exempt you from the others.

HIPAA treats any AI that creates, receives, or transmits protected health information as subject to its safeguards, requiring business-associate agreements with vendors and controls on access and disclosure. Financial regulators apply model risk management expectations to AI used in credit, trading, and fraud decisions, demanding documentation, validation, and explainability. GDPR governs automated decision-making and profiling on EU residents, giving individuals rights to explanation and objection. The practical lesson: identify every regime that touches your use case before you build, because they combine.

  • Healthcare, HIPAA safeguards, business-associate agreements, minimum-necessary access to PHI.
  • Financial services, model-risk management, fair-lending and anti-discrimination testing, auditable decision logs.
  • Any EU personal data, GDPR lawful basis, data-subject rights, and limits on solely automated decisions.

Building a compliance program that survives an audit

A durable program has four parts: an inventory of every AI system and the data it touches, a risk classification, documented controls and human oversight, and logs that prove what happened. Without logs you cannot demonstrate compliance, only assert it.

Start with an inventory, you cannot govern AI you have not catalogued, and shadow AI hides in exactly the gaps an inventory closes. Classify each system by risk and applicable regime, attach controls proportional to that risk, assign a human owner, and log inputs, outputs, and overrides. The organizations that pass audits are the ones who can hand over records on demand; the ones that fail are the ones who can only describe their intentions.

Documentation is the deliverable

Regulators do not grade good intentions. A compliance program is only as strong as the evidence it can produce, the policy, the risk assessment, the access logs, and the decision records. Build the paper trail as you build the system, not after.

Major AI-relevant regulations at a glance

RegulationWhat it governsMaximum penaltyKey deadline
EU AI Act (prohibited)Banned AI practices35M euros or 7% of global turnoverApplied Feb 2, 2025
EU AI Act (high-risk)High-risk system obligations15M euros or 3% of global turnoverPhased Aug 2, 2026 onward
GDPRPersonal data and automated decisions20M euros or 4% of global turnoverIn force since 2018
HIPAAProtected health informationUp to 1.5M USD per violation category/yearIn force
Major AI-relevant regulations at a glance
Questions

Frequently asked questions.

Does the EU AI Act apply to US companies?

It can. The Act applies extraterritorially when an AI system or its output is used within the EU, so a US company serving EU users or customers may fall within scope even without an EU office.

What is the difference between the EU AI Act and GDPR?

GDPR governs personal data and automated decisions; the EU AI Act governs AI systems by risk level regardless of whether personal data is involved. They overlap and stack, an AI system processing EU personal data must satisfy both.

When do the EU AI Act rules take effect?

They phase in: prohibited-practice bans applied February 2, 2025, transparency and general-purpose model obligations apply August 2, 2026, and most high-risk obligations become enforceable across 2026 and 2027.

Do smaller companies get any relief under the EU AI Act?

Yes. For SMEs and startups the Act applies the lower of the fixed monetary cap or the turnover percentage, and offers proportionate guidance, but the underlying obligation to comply is the same as for large firms.

From principle to installed system.

We turn the ideas on this page into owned, working infrastructure inside your business. It starts with a diagnostic of where your operation leaks time and money.