EU AI Act Compliance

By Chuck Gallagher — Business Ethics Keynote Speaker and Trainer

TL;DR: The European AI Office now holds enforceable powers to evaluate general-purpose AI (GPAI) models, demand corrective action from providers, and apply sanctions under the EU AI Act — obligations that became applicable in August 2025. Chuck Gallagher, business ethics keynote speaker and AI speaker and author, argues that companies treating EU compliance as a geography problem are making the same rationalization error at the root of every major ethics failure: assuming consequences apply to someone else, somewhere else, sometime later. If your model touches European users, students, patients, or employees, the governance requirements are already in effect — and “we’ll deal with it when we scale there” is not a strategy.

Here is a rationalization I hear from technology leaders more often than I should: “We’ll deal with EU compliance when we actually scale into that market.” I want to be direct about what that sentence really means. It means: “We know the rules exist, we know they apply to us, and we have chosen to ignore them until someone forces us to stop.” That is not a business strategy. That is the rationalization phase of an ethics failure — and it ends the same way every other rationalization ends.

The European AI Office — established within the European Commission as the center of AI expertise and governance for the EU — has made clear what it can do. Under the EU AI Act, the AI Office holds authority to conduct evaluations of general-purpose AI models, request information and corrective measures from providers, and apply sanctions. These are not aspirational principles or future intentions. The rules for GPAI models became applicable on August 2, 2025. If your organization builds on, integrates, or deploys a general-purpose AI model in applications that touch HR decisions, educational systems, financial services, or healthcare anywhere in the EU, you are already inside the regulatory perimeter.

Why Do Companies Keep Treating Regulation as a Geography Problem?

As a business ethics keynote speaker and AI speaker and author, I have spent years watching organizations make the same structural error with regulation that they make with ethics more broadly: they treat it as something external, something that happens to other companies in other places. The logic sounds reasonable until you look at how AI actually works. A large language model or generative AI system does not have a passport. It does not know which user is in Dresden and which is in Dallas. When you deploy a GPAI-based product — an HR screening tool, a financial advice assistant, a healthcare triage chatbot — that product goes where your users are. And your users include people protected by EU law.

The AI Office’s structure makes this concrete. Its Regulation and Compliance unit and AI Safety unit are not advisory bodies. They investigate possible infringements, assess model capabilities through formal evaluations, and can require providers to take corrective action. The November 2025 Digital Simplification Package proposed amendments that would further reinforce the AI Office’s powers and centralize oversight of AI systems built on GPAI models. The EU is not backing away from enforcement. It is tightening it.

The penalties for noncompliance under the AI Act can reach 3 percent of global annual turnover for violations of GPAI obligations, and up to 7 percent for providing incorrect or misleading information to the AI Office. For a mid-size technology company with global operations, those figures are not rounding errors. They are existential.

What Does Governance That Actually Travels Look Like?

I have argued at ChuckGallagher.com, repeatedly, that compliance is downstream of ethics — not parallel to it. A company that builds genuine governance around its AI systems does not need to scramble when a regulator asks for documentation. It already has it, because it made accountability decisions before deployment rather than after a complaint. The EU AI Act makes the same demand in legal terms. For GPAI providers and deployers, the AI Office expects model documentation, logging and traceability of outputs, incident reporting pathways, and a demonstrable human-oversight story.

That last item deserves more attention than it typically receives. Human oversight is not a checkbox. It is a design decision made before a system goes live. It requires knowing which decisions your AI system is influencing, who in the organization is responsible for reviewing those influences, and what happens when the system produces an outcome that no one would have approved if a human had been in the loop. The ISO/IEC 42001 standard for AI management systems provides a discipline for exactly this kind of structured accountability — documenting how risk is identified, assigned, and monitored across the AI lifecycle.

The companies I see getting this right share a common trait: they do not treat their governance documentation as a legal defense artifact. They treat it as an operational tool. Their people know what the model is authorized to do, what it is prohibited from doing, and who owns the answer when something goes wrong. That clarity is not expensive to build. The absence of it is.

The EU’s GPAI Code of Practice, published in July 2025, offers practical guidance on transparency, copyright compliance, and safety and security for GPAI providers. It is a voluntary tool — for now. But the pattern in EU digital regulation has been consistent: voluntary alignment today tends to become mandatory baseline tomorrow. Companies that engage with the Code of Practice now are building the governance infrastructure that enforcement will eventually require. Companies that wait are building the paper trail of evidence that they knew and chose not to act.

As an AI ethics speaker and author, I keep returning to the three forces that drive ethical failures: need, opportunity, and rationalization. The rationalization here is the geography argument. The opportunity is the regulatory gap between where enforcement currently focuses and where your system actually operates. And the need — the business pressure to move fast and worry about compliance later — is real and understandable. But understanding why people rationalize does not make the rationalization correct. Every person I have studied who found themselves on the wrong side of a federal investigation understood, in hindsight, exactly which moment they chose convenience over accountability.

The EU AI Act enforcement posture is not a European problem. It is a governance problem. And governance problems do not resolve themselves when you grow large enough to care about them. They compound.

Frequently Asked Questions

What powers does the EU AI Office have over general-purpose AI models?

The European AI Office, established within the European Commission, holds authority under the EU AI Act to conduct evaluations of GPAI models, request information and corrective measures from providers, and apply sanctions. These enforcement powers became applicable on August 2, 2025, when the GPAI obligations under the AI Act entered into force. The November 2025 Digital Simplification Package proposed amendments to further strengthen the AI Office’s oversight authority.

When did the EU AI Act GPAI obligations take effect?

The EU AI Act entered into force on August 1, 2024, but the specific rules for general-purpose AI models became applicable on August 2, 2025. Prohibited AI practices took effect earlier, in February 2025. Full application of the AI Act across all risk categories is scheduled for August 2, 2026, with some high-risk AI system rules for products extended to August 2028 following the AI omnibus political agreement reached in May 2026.

What penalties apply for GPAI noncompliance under the EU AI Act?

Under the EU AI Act, fines for violations of GPAI obligations can reach 3 percent of global annual turnover. Providing incorrect or misleading information to the AI Office carries penalties of up to 1.5 percent of global annual turnover, while systemic violations can reach 7 percent. These figures apply on a global basis — not just to EU revenue — making them significant for any company with substantial worldwide operations.

What should companies do to prepare for EU AI Office enforcement of GPAI rules?

Chuck Gallagher, business ethics keynote speaker and AI speaker and author, recommends building what he calls governance that travels: model documentation that explains what the system does and why, logging and traceability of outputs, a defined incident reporting pathway, and a human-oversight design that is embedded before deployment rather than added after a complaint. Alignment with the EU’s voluntary GPAI Code of Practice, published in July 2025, provides a structured starting point. ISO/IEC 42001 offers additional management system discipline for organizations that want a certified framework.

Does the EU AI Act apply to non-EU companies whose AI products are used by EU residents?

Yes. The EU AI Act applies to providers and deployers of AI systems whose outputs are used within the EU, regardless of where the provider is based. A U.S.-headquartered company whose GPAI-based HR screening tool, healthcare assistant, or financial advice product serves EU users is subject to the AI Act’s requirements. Geographic distance from Brussels does not determine regulatory exposure — deployment into the EU market does.

I want to hear from you. If you are building or deploying AI systems that touch European users in any way, what does your governance posture look like right now — and do you honestly believe it would hold up to an AI Office inquiry? Share your experience in the comments below, and let’s have the real conversation that most compliance briefings avoid. The five questions below are designed to make that conversation harder to dodge.

Five Questions for Further Thought and Consideration

  1. If the EU AI Office requested your model documentation today, how long would it take your organization to produce it — and would what you produced tell an accurate story about how the system actually behaves?
  2. Which executive in your organization is personally accountable for GPAI compliance under the EU AI Act — and does that person know it?
  3. If you are currently treating EU AI governance as a future problem, what specific event would need to occur for it to become a present problem? Is that event less likely than you assume?
  4. How does your organization define “human oversight” in the context of AI-assisted decisions in HR, finance, healthcare, or education — and is that definition written down anywhere?
  5. The EU’s voluntary GPAI Code of Practice tends to become mandatory baseline in EU digital regulation over time. Is your organization engaging with it now, or waiting to be required?

Related Articles:

Why White-Collar Crime Rises: The Financial, Health, and Relationship Trifecta The Three Pressures Behind Every Bad Decision

NC White-Collar Crime Surged 108% in Extortion, 2020–2024 – What the Numbers Actually Say

Leave a Reply