EU AI Act: Internal Models Face 30M Euro Fines in 2026

Listen to this article · 9 min listen

The regulatory field for artificial intelligence is rife with misconceptions, particularly concerning the EU AI Act and its reach into non-public models. Many believe that if an AI system isn’t directly sold to consumers, it escapes stringent oversight, but this perspective overlooks critical nuances of the forthcoming legislation. Understanding the full scope of the EU AI Act is paramount for any organization developing or deploying AI, irrespective of its immediate market visibility.

Key Takeaways

  • The EU AI Act’s scope extends far beyond publicly available AI systems, encompassing internal tools and components used within organizations.
  • Even AI models developed and used solely for internal operational efficiency can be classified as high-risk, triggering complete compliance obligations.
  • Organizations must proactively map their AI systems against the Act’s risk categories, focusing on potential impacts on fundamental rights and safety, not just market availability.
  • Compliance requires a deep understanding of data governance, human oversight mechanisms, and strong documentation for all AI systems, regardless of their deployment model.
  • Ignoring the Act’s provisions for non-public models creates significant legal and reputational risks, including substantial fines up to 30 million Euros or 6% of global annual turnover.

Myth 1: The EU AI Act Only Targets Consumer-Facing AI Products

This is perhaps the most pervasive misunderstanding. Many developers and businesses operate under the assumption that if their AI model isn’t directly offered to the public, or if it’s an internal tool, it exists outside the EU AI Act’s regulatory perimeter. This couldn’t be further from the truth. The Act defines “AI system” broadly and focuses its regulatory intensity on the risk an AI system poses, not solely on its commercial availability or direct interaction with end-users. A system used internally by a company for HR decisions, credit scoring, or even predictive maintenance in critical infrastructure can fall squarely within the Act’s “high-risk” classification. Consider an AI system used by a financial institution to detect fraud. While this system isn’t a consumer product, its failure or bias could lead to significant financial harm for individuals, triggering a high-risk designation under Annex III of the Act. According to the European Commission’s latest guidance, the key determinant is the potential impact on fundamental rights, safety, and existing legal frameworks, such as the General Data Protection Regulation (GDPR). The Act explicitly covers AI systems intended to be used as safety components of products, those used in critical infrastructure, employment, access to essential private and public services, law enforcement, migration management, and the administration of justice. An internal AI tool assisting in hiring decisions, for example, directly impacts individuals’ access to employment, making it a high-risk system regardless of its non-public status.

Myth 2: Non-Public Models are Exempt from High-Risk Classification

Another common error is believing that if an AI model is not publicly deployed or directly sold, it automatically avoids the stringent requirements associated with “high-risk” AI. This is a dangerous misinterpretation. The classification of an AI system as high-risk is predicated on its intended purpose and the potential for significant harm, not its visibility. A system developed for internal use within a hospital that assists in diagnosing diseases, for instance, would almost certainly be deemed high-risk due to its direct impact on health and safety. The European Parliament has been clear on this point. The intent is to regulate AI where it matters most, where it can cause the most damage to individuals or society. The obligations for high-risk AI systems are extensive, covering everything from data governance and technical documentation to human oversight, robustness, accuracy, and cybersecurity. For internal systems, this means organizations must implement rigorous quality management systems, conduct conformity assessments, and ensure appropriate human oversight throughout the AI system’s lifecycle. We see many organizations failing to grasp the depth of these requirements for their internal tools, assuming a lower bar for compliance. This oversight can lead to significant penalties. The fines for non-compliance are substantial, reaching up to 30 million Euros or 6% of the company’s total worldwide annual turnover, whichever is higher, for serious infringements. This financial exposure alone should compel every organization to scrutinize its internal AI deployments.

Aspect Common Misconception Reality (EU AI Act)
Scope of Regulation Only targets consumer-facing AI products. Extends to internal tools and components within organizations.
High-Risk Classification Non-public models are exempt from high-risk classification. Based on intended purpose and potential for significant harm.
Geographical Reach Only applies to AI developed or deployed within the EU. Extraterritorial reach, similar to GDPR.
Penalty for Non-Compliance Assumed lower bar for compliance for internal tools. Up to 30 million Euros or 6% of global annual turnover.
Key Determinant for Risk Market availability or direct user interaction. Potential impact on fundamental rights and safety.

Myth 3: The Act Only Applies to AI Developed Within the EU

Some entities outside the EU mistakenly believe they are immune to the Act’s provisions if their AI models are not directly marketed or deployed within the Union. This is incorrect. The EU AI Act has an extraterritorial reach, similar to the GDPR. It applies to providers of AI systems placed on the market or put into service in the EU, regardless of whether that provider is established in the EU or in a third country. It also applies to deployers of AI systems located in the EU, and to providers and deployers of AI systems located in a third country where the output produced by the system is used in the EU. This means a company based in, say, North America, that develops an internal AI tool for a European subsidiary, or whose AI-driven service impacts individuals within the EU, could still be subject to the Act. This broad jurisdictional scope ensures that AI systems affecting EU citizens or operating within the EU market are regulated consistently, preventing regulatory arbitrage. Organizations must assess their global AI operations through the lens of the EU AI Act, not just their local deployments. The concept of “putting into service” is particularly relevant here. Even if an AI system is developed elsewhere, if it’s used to provide services or make decisions impacting EU residents, it falls under the Act.

Myth 4: Compliance is a One-Time Technical Fix

Many organizations view AI compliance as a checklist of technical requirements that, once met, are done. This is a fundamental misunderstanding of the Act’s demands. Compliance with the EU AI Act, especially for high-risk systems, is an ongoing process that requires continuous monitoring, adaptation, and a strong governance framework. It’s not a set-it-and-forget-it endeavor. The Act mandates post-market monitoring systems, requiring providers to implement a system to actively collect and analyze data on the performance of their high-risk AI systems throughout their lifespan. This includes monitoring for potential biases, accuracy degradation, and unexpected risks. Plus, AI models are dynamic. They evolve, they are retrained, and their operating environments change. These changes can introduce new risks or alter existing ones, necessitating re-evaluation and potential re-certification. Imagine an internal AI system used for fraud detection. As new fraud patterns emerge, the model is updated. Each significant update might require a fresh assessment to ensure it remains compliant, particularly regarding fairness and accuracy. This continuous compliance mindset demands dedicated resources, clear internal policies, and often, new roles within an organization focused on AI governance and ethics. The EU AI Act represents a significant shift in how AI is developed and deployed globally. Its complete approach, particularly its focus on risk and its broad jurisdictional reach, means that organizations can no longer afford to operate under the illusion that internal or non-public AI models are outside its purview. Proactive engagement with the Act’s requirements, driven by a deep understanding of its nuances, is the only sustainable path forward.

What constitutes a “high-risk” AI system under the EU AI Act for non-public models?

A non-public AI system is classified as high-risk if its intended purpose aligns with one of the categories listed in Annex III of the Act, such as systems used in critical infrastructure, employment and worker management, access to essential private and public services, law enforcement, or migration, asylum, and border control. The key factor is the potential to cause significant harm to health, safety, or fundamental rights.

Do internal AI tools used solely for operational efficiency need to comply with the EU AI Act?

Yes, potentially. If an internal AI tool, even one focused on operational efficiency, falls into a high-risk category due to its impact (e.g., an AI system assisting in employee performance evaluations that could lead to unfair treatment), it must comply with the Act’s stringent requirements. The focus is on impact, not just external deployment.

What are the primary compliance steps for an organization with high-risk internal AI systems?

Organizations must establish a strong quality management system, conduct conformity assessments before deployment, ensure technical documentation is complete and up-to-date, implement appropriate human oversight mechanisms, ensure data governance practices support accuracy and fairness, and establish post-market monitoring systems to track performance and mitigate emerging risks throughout the system’s lifecycle.

Can a non-EU company be penalized under the EU AI Act for its internal AI systems?

Yes. The EU AI Act has extraterritorial scope. If a non-EU company provides an AI system that is placed on the market or put into service in the EU, or if the output of its AI system is used in the EU, it can be subject to the Act’s provisions and associated penalties, regardless of where the AI system was developed or primarily used.

How does the EU AI Act define “provider” and “deployer” in the context of non-public models?

A “provider” is any natural or legal person who develops an AI system or has an AI system developed and places it on the market or puts it into service under its own name or trademark. A “deployer” is any natural or legal person, public authority, agency, or other body using an AI system under its authority. For internal AI, a single organization can act as both provider and deployer, incurring responsibilities for both roles.

Corey Swanson

Senior Policy Analyst MPP, Georgetown University

Corey Swanson is a Senior Policy Analyst at the Center for Digital Futures, bringing over 14 years of experience to the field of tech policy. Her expertise lies in the ethical development and deployment of artificial intelligence, particularly concerning issues of bias and accountability. Previously, she served as a lead consultant for the Global Tech Governance Initiative, advising governments on responsible AI frameworks. Her seminal white paper, "Algorithmic Transparency in Public Sector Applications," has significantly influenced international policy discussions