Quick answer: The EU AI Act's next wave of obligations, covering transparency, general-purpose AI models, and governance, took effect on 2 August 2026. Compliance under the Act isn't a single checkbox: it depends on being able to show clean, traceable, auditable data behind every AI-touched decision. Pearstop's platform generates that audit trail automatically as a by-product of the classification and data quality work it already does, so compliance becomes a report you can run rather than a project you have to commission.
On this page: What just happened · Consequences of non-compliance · How Pearstop maps to the obligations · The value proposition · FAQ
What just happened: the EU AI Act context
The EU AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024 and is rolling out on a staggered timeline. As of the most recent milestone, the following are in effect:
- General provisions and foundational definitions (Articles 1–4)
- Prohibited AI practices (Article 5)
- Obligations for general-purpose AI (GPAI) model providers (Articles 51–56)
- Transparency obligations (Article 50)
- Measures in support of innovation (Articles 57–63)
- Governance and enforcement (Articles 64–76 and 99–101)
There's one grandfathering carve-out worth knowing: existing generative AI systems have until 2 December 2026 to meet machine-readable marking and watermarking requirements. Everything else on the list above is live now, which makes clean, categorised, auditable data a present-tense requirement rather than something to plan for next year.
Consequences of non-compliance
Non-compliance with these obligations carries heavier penalties than ever before, as captured in the table below:
| Tier | Violation Type | Fixed Maximum | Turnover % | Applied Amount |
|---|---|---|---|---|
| Tier 1 | Prohibited AI practices (Article 5) | EUR 35 million | 7% of global annual turnover | Whichever is higher |
| Tier 2 | Non-compliance with high-risk requirements and most other obligations | EUR 15 million | 3% of global annual turnover | Whichever is higher |
| Tier 3 | Supplying incorrect, incomplete, or misleading information to authorities or notified bodies | EUR 7.5 million | 1% of global annual turnover | Whichever is higher |
The Act does, however, provide for proportionality for SMEs and small mid-caps, but exposure still scales with turnover, so smaller entities aren't exempt in practice. And the fine is rarely the whole story. Alongside the monetary penalty, entities can face reputational damage, loss of market access through an inability to legally carry the CE mark, and heavier ongoing scrutiny from market surveillance authorities. In combination, these consequences can affect a business well beyond the initial enforcement action, regardless of its size. The most direct way to reduce exposure to all of it is the same in every case: clean, categorised, auditable data.
Enter Pearstop: compliance isn't one feature, it's the whole platform
Compliance under the Act doesn't come from a single safeguard. It comes from traceability, clean data, and documentation working together across every point where AI touches your workflow. Here's how each part of the Pearstop platform maps to that.
File Drop — the audit trail, automated
Every use of Pearstop's file drop feature automatically generates a timestamped, tamper-evident audit trail. That's exactly the kind of record Article 50's transparency obligations require entities to be able to produce on request. Because it's generated automatically, there's no manual logging step to skip, and no after-the-fact reconstruction if a regulator asks for it.
Pearstop Ledger — traceable categorisation
Pearstop classifies procurement and asset data against UNSPSC, with built-in quality assurance and control checks at every step. That turns categorisation into a systematised process instead of an ad hoc one, which is where most data reliability problems start. The result is twofold: it's easier to show how a classification or pricing decision was reached, which is the standard regulators are applying to AI-driven decisions generally, and the business gets more reliable data to work from day to day.
Data Quality — the foundation underneath everything
Underneath both of the above, the platform structures, validates, and maintains the procurement, asset, and cost data flowing through an entity's systems. Clean, governed data isn't just an efficiency gain here — it's what trust, compliance, and competitive advantage are all built on.
AI Readiness — compliance-ready data for whatever you deploy next
The same clean, structured data also prepares an entity to feed its own AI systems, so outputs stay reliable and traceable from the start. Rather than scrambling when the next tier of high-risk obligations lands, entities working from clean data are already positioned to meet them. Not only will your entity meet each new obligation as it lands, it will do so without the scramble many organisations are only now starting to feel under the current rollout.
Why the platform view matters: compliance isn't solved by a single checkbox feature, it's solved when every point where AI touches your workflow leaves a record. And because the underlying infrastructure is the same across all four areas, what supports transparency compliance today extends naturally to high-risk system documentation requirements as they come into effect.
The Pearstop value proposition
Each part of the platform maps to a different obligation:
- File Drop for audit trails
- Ledger for traceable categorisation
- Data Quality for governance
- AI Readiness for what's coming next
Beyond the compliance case, this cuts audit prep time from weeks to minutes, with exportable, timestamped records and data that's easy to retrieve on request.
If you're building a foundation for data credibility and compliance, book a discovery call with Pearstop: pearstop.com
Frequently asked questions
What EU AI Act obligations came into effect on 2 August 2026? The latest wave covers high-risk system obligations and most remaining general obligations under the Act, building on provisions already in force since 2024 and 2025, including prohibited practices, GPAI provider duties, and transparency requirements.
What are the penalties for non-compliance with the EU AI Act? Article 99 sets three tiers: up to €35 million or 7% of global turnover for prohibited practices, up to €15 million or 3% for non-compliance with high-risk requirements and most other obligations, and up to €7.5 million or 1% for supplying incorrect, incomplete, or misleading information to authorities or notified bodies. In every tier, whichever figure is higher applies.
How does Pearstop help with EU AI Act compliance? Pearstop classifies and structures procurement and asset data with built-in audit trails and quality checks, so the traceability the Act requires is a by-product of data cleanup work you're already doing, rather than a separate compliance project.
Is compliance only relevant to companies building AI systems? No. Deployers and users of AI systems carry obligations too, particularly around transparency and high-risk system documentation, so the requirement to show clean, traceable data applies broadly across the supply chain, not just to AI providers.
Free resources
- Pearstop case studies
- Procurement Opportunity Mapper
- Taxonomy generator — coming soon

Rae Thomas
Chief of Staff, Pearstop
Rae heads up operations at Pearstop, in both the traditional and non-traditional sense. She's as committed to the internal success of the business as she is to the value clients get out of it, which is why she leads delivery on most projects and is the main point of contact for clients throughout.
LinkedIn →Further reading
Can AI Actually Classify Procurement Data, or Is That Still a Myth?
Every procurement platform claims AI classification now. Here's what it can genuinely do today, and where it still needs a human check.
Read more →Data QualityMRO Spend Is the Most Under-Classified Category in Facilities Management
Maintenance, repair, and operations spend covers everything from spare parts to consumables to emergency purchases. Most of it never gets classified consistently enough to manage.
Read more →

