⚠ THE COMPLIANCE GAP
The whole market is exposed. Almost nobody can prove otherwise.
Six laws now govern an AI product at once. The penalties are a slice of your global turnover — and they stack, one on top of another. The regulators have stopped warning and started issuing.
€6.11bn
in GDPR fines already issued — and GDPR is the oldest, simplest law on this page.
The six you're standing under
For each one, the maximum penalty, the duty that's hardest to actually evidence, and what's already happening.
GDPR
EU/UK General Data Protection Regulation
€20M or 4%
of global annual turnover
The duty almost nobody can prove: Art 22 — a human must be able to review an automated decision; Art 30 — records of processing; Art 5 — accountability you can demonstrate.
€6.11 billion in fines already issued — 2,685+ penalties, the largest €1.2 billion. And GDPR is the oldest, best-understood law on this list.
EU AI Act
EU Artificial Intelligence Act
€35M or 7%
of global annual turnover
The duty almost nobody can prove: Art 12 — automatic logging of every decision; Art 14 — human oversight; Art 10 — data governance and bias testing.
High-risk duties became fully enforceable on 2 August 2026 — live now. Prohibited-practice and AI-literacy duties have applied since February 2025. Most deployers cannot evidence Art 12 or Art 14 today.
Online Safety Act
UK Online Safety Act
£18M or 10%
of global annual turnover — and senior managers can be personally liable
The duty almost nobody can prove: Illegal-content and children's risk assessments; age assurance; a provable record of the safety measures you took.
Illegal-content duties live since March 2025; Ofcom began issuing fines in 2026. Category 1 providers owe children's risk-assessment records from October 2026.
EU DSA
EU Digital Services Act
6%
of worldwide annual turnover (plus up to 5% of daily turnover for every day you stay non-compliant)
The duty almost nobody can prove: A statement of reasons for every moderation action; systemic-risk assessments; recommender-system transparency.
Formal proceedings already opened against the largest platforms over transparency, dark patterns and child protection (2024–25). The regulator is investigating, not warning.
DORA
EU Digital Operational Resilience Act
2% / €1M
up to 2% of worldwide turnover for firms; critical ICT providers face 1% of daily turnover per day; individuals up to €1M plus management bans
The duty almost nobody can prove: A live ICT third-party register; digital-resilience testing; major-incident reporting on a clock.
Fully applicable since January 2025. Financial entities are on the hook now, and so are their critical ICT suppliers.
of worldwide turnover for essential entities (€7M or 1.4% for important ones) — and management is personally liable
The duty almost nobody can prove: Supply-chain security; 24-hour incident early-warning; a management body that is trained and accountable.
In transposition across the EU with enforcement powers switching on; essential-entity management can be banned from their role for persistent failure.
Now add them up.
A single AI feature that touches people can sit under GDPR, the EU AI Act, the DSA or Online Safety Act, and DORA or NIS2 at the same time. The penalties don't replace each other — they stack. 7% here. 10% there. 6% there. All calculated on global turnover, and several now carry personal liability for named managers. The EU AI Act's high-risk duties went fully live on 2 August 2026. The clock isn't coming — it's running.
The gap isn't the law. It's proof.
Every one of these duties comes down to the same thing: can you prove, after the fact, what your AI did and that your controls were in place? A questionnaire isn't proof. A policy document isn't proof. A screenshot isn't proof. When the regulator or the insurer asks, you need evidence that was sealed at the time and can't be quietly edited.
That's the one thing sebbi.pro does. Every decision sealed into a tamper-evident chain anchored to Bitcoin. Inputs checked for provenance. Tools shielded. And a single provable rating — the Insurable AI Standard — composed from 328 real conformance checks across 18 of these frameworks, that a regulator or an underwriter can verify without trusting you.
Get rated against the standard →See the 328 conformance checks →Put sebbi under your AI →- • GDPR Enforcement Tracker Report (CMS), figures to 1 Mar 2026 — source
- • EU AI Act timeline & penalties (summary); official text on EUR-Lex — source
- • UK Online Safety Act — Ofcom enforcement powers (summary) — source
- • EU DSA penalty framework & open proceedings (summary) — source
- • DORA penalties & enforcement (summary) — source
- • NIS2 penalties & management liability (summary) — source