⚠  THE COMPLIANCE GAP

The whole market is exposed. Almost nobody can prove otherwise.

Six laws now govern an AI product at once. The penalties are a slice of your global turnover — and they stack, one on top of another. The regulators have stopped warning and started issuing.

€6.11bn

in GDPR fines already issued — and GDPR is the oldest, simplest law on this page.

The six you're standing under

For each one, the maximum penalty, the duty that's hardest to actually evidence, and what's already happening.

GDPR

EU/UK General Data Protection Regulation
€20M or 4%
of global annual turnover
The duty almost nobody can prove: Art 22 — a human must be able to review an automated decision; Art 30 — records of processing; Art 5 — accountability you can demonstrate.
€6.11 billion in fines already issued — 2,685+ penalties, the largest €1.2 billion. And GDPR is the oldest, best-understood law on this list.

EU AI Act

EU Artificial Intelligence Act
€35M or 7%
of global annual turnover
The duty almost nobody can prove: Art 12 — automatic logging of every decision; Art 14 — human oversight; Art 10 — data governance and bias testing.
High-risk duties became fully enforceable on 2 August 2026 — live now. Prohibited-practice and AI-literacy duties have applied since February 2025. Most deployers cannot evidence Art 12 or Art 14 today.

Online Safety Act

UK Online Safety Act
£18M or 10%
of global annual turnover — and senior managers can be personally liable
The duty almost nobody can prove: Illegal-content and children's risk assessments; age assurance; a provable record of the safety measures you took.
Illegal-content duties live since March 2025; Ofcom began issuing fines in 2026. Category 1 providers owe children's risk-assessment records from October 2026.

EU DSA

EU Digital Services Act
6%
of worldwide annual turnover (plus up to 5% of daily turnover for every day you stay non-compliant)
The duty almost nobody can prove: A statement of reasons for every moderation action; systemic-risk assessments; recommender-system transparency.
Formal proceedings already opened against the largest platforms over transparency, dark patterns and child protection (2024–25). The regulator is investigating, not warning.

DORA

EU Digital Operational Resilience Act
2% / €1M
up to 2% of worldwide turnover for firms; critical ICT providers face 1% of daily turnover per day; individuals up to €1M plus management bans
The duty almost nobody can prove: A live ICT third-party register; digital-resilience testing; major-incident reporting on a clock.
Fully applicable since January 2025. Financial entities are on the hook now, and so are their critical ICT suppliers.

NIS2

EU NIS2 Directive
€10M or 2%
of worldwide turnover for essential entities (€7M or 1.4% for important ones) — and management is personally liable
The duty almost nobody can prove: Supply-chain security; 24-hour incident early-warning; a management body that is trained and accountable.
In transposition across the EU with enforcement powers switching on; essential-entity management can be banned from their role for persistent failure.

Now add them up.

A single AI feature that touches people can sit under GDPR, the EU AI Act, the DSA or Online Safety Act, and DORA or NIS2 at the same time. The penalties don't replace each other — they stack. 7% here. 10% there. 6% there. All calculated on global turnover, and several now carry personal liability for named managers. The EU AI Act's high-risk duties went fully live on 2 August 2026. The clock isn't coming — it's running.

The gap isn't the law. It's proof.

Every one of these duties comes down to the same thing: can you prove, after the fact, what your AI did and that your controls were in place? A questionnaire isn't proof. A policy document isn't proof. A screenshot isn't proof. When the regulator or the insurer asks, you need evidence that was sealed at the time and can't be quietly edited.

That's the one thing sebbi.pro does. Every decision sealed into a tamper-evident chain anchored to Bitcoin. Inputs checked for provenance. Tools shielded. And a single provable rating — the Insurable AI Standard — composed from 328 real conformance checks across 18 of these frameworks, that a regulator or an underwriter can verify without trusting you.

Get rated against the standard →See the 328 conformance checks →Put sebbi under your AI →

On the figures. Every number here is from the public record — enforcement trackers and regulator summaries, listed below. They are point-in-time and drawn from secondary sources; penalty ceilings and dates should be confirmed against the official legal texts (EUR-Lex, legislation.gov.uk, Ofcom). This page describes the market at the pattern level and names no organisation as being in breach. It is information, not legal advice.

AI news
TechCrunchThese execs think voice AI hasn’t reached its ChatGPT moment yet1hWiredI Made Terrible Games With Google’s AI Playground3hThe VergeLearning to use local AI is exciting, overwhelming, and frustrating4hThe VergeSatya Nadella says we should assume all AI models are ‘compromised’17hTechCrunchMicrosoft’s Satya Nadella says AI models need an ‘emergency brake’17hThe VergeAnthropic is cutting off its internal evaluations from the internet1dTechCrunchHere are the top AI agents that can live in your text messages1dThe VergeAI agent makers are promising privacy — will they deliver?1dWiredAI Is Getting Really Good at Messing With Cybercriminals1dBBC NewsRogue Anthropic AI agent gave police fake tip in unsolved murder case1dTechCrunchAnthropic can’t reliably control its AI agents. It’s cutting off its internal evals from the live internet instead1dArs TechnicaUkraine’s drones knock out AI data center belonging to "Russia’s Google"1dTechCrunchThe maker of non-text AI model Jev valued at $7.5B just weeks after launch1dThe VergeAnthropic’s AI gave Philadelphia police a fake tip about an unsolved homicide1dArs TechnicaAI coding agents generate more code, but not more software1dWiredBook Publishers Are Quietly Using More AI. Staff Are Revolting1dArs TechnicaAI disqualification yields new Nikon Small World in Motion winner1dBBC NewsPrize-winning image which sparked backlash was AI-generated, Nikon rules1dBBC NewsAnthropic bans users from being 'cruel' to its AI systems2dWiredEven ‘Law & Order’ Is Terrified of AI2dBBC NewsFired OpenAI researchers say they were let go for 'prioritising safety'2dMIT Technology ReviewWe’re putting too much faith in AI’s ability to say no2dBBC NewsNvidia-backed data centre firm scraps IPO as AI valuation concerns deepen2dMIT Technology ReviewRoundtables: A Conversation With the Creator of AI-Designed Viruses2dTechCrunchThese execs think voice AI hasn’t reached its ChatGPT moment yet1hWiredI Made Terrible Games With Google’s AI Playground3hThe VergeLearning to use local AI is exciting, overwhelming, and frustrating4hThe VergeSatya Nadella says we should assume all AI models are ‘compromised’17hTechCrunchMicrosoft’s Satya Nadella says AI models need an ‘emergency brake’17hThe VergeAnthropic is cutting off its internal evaluations from the internet1dTechCrunchHere are the top AI agents that can live in your text messages1dThe VergeAI agent makers are promising privacy — will they deliver?1dWiredAI Is Getting Really Good at Messing With Cybercriminals1dBBC NewsRogue Anthropic AI agent gave police fake tip in unsolved murder case1dTechCrunchAnthropic can’t reliably control its AI agents. It’s cutting off its internal evals from the live internet instead1dArs TechnicaUkraine’s drones knock out AI data center belonging to "Russia’s Google"1dTechCrunchThe maker of non-text AI model Jev valued at $7.5B just weeks after launch1dThe VergeAnthropic’s AI gave Philadelphia police a fake tip about an unsolved homicide1dArs TechnicaAI coding agents generate more code, but not more software1dWiredBook Publishers Are Quietly Using More AI. Staff Are Revolting1dArs TechnicaAI disqualification yields new Nikon Small World in Motion winner1dBBC NewsPrize-winning image which sparked backlash was AI-generated, Nikon rules1dBBC NewsAnthropic bans users from being 'cruel' to its AI systems2dWiredEven ‘Law & Order’ Is Terrified of AI2dBBC NewsFired OpenAI researchers say they were let go for 'prioritising safety'2dMIT Technology ReviewWe’re putting too much faith in AI’s ability to say no2dBBC NewsNvidia-backed data centre firm scraps IPO as AI valuation concerns deepen2dMIT Technology ReviewRoundtables: A Conversation With the Creator of AI-Designed Viruses2d