Nobody's Been Fined Under the EU AI Act Yet. People Are Already Losing Deals Because of It.

A procurement lead at a European pharma company said something blunt to one of our clients last month:
"We're not asking if your AI is compliant. We're asking if you can prove it in writing by Friday."
No regulator was involved. No investigation, no fine, nothing on a headline. Just a client's legal team asking a question, the sales team couldn't answer fast enough. Three weeks of scrambling later, the deal went to a competitor who already had the paperwork ready.
That's the version of "AI Act risk" that never makes it into a compliance webinar. And it's the one actually hitting companies this year.
The penalties are real, but they are not what is hurting people
The regulation does have real penalties, to be clear. Prohibited practices, manipulative systems, certain biometric categorisation, social scoring, go up to €35M or 7% of global turnover. Fall short on the obligations for high-risk systems, risk management, documentation, human oversight, and it's up to €15M or 3%. Mislead a regulator and it's €7.5M or 1%.
Big numbers. Almost nobody we talk to has actually paid one.
What they have done: lost a deal. Stalled a funding round. Spent six figures on emergency remediation because one due diligence question exposed a folder that should've had documents in it and didn't.

Regulators take months. Procurement teams take an afternoon.
Here's the part that doesn't get said out loud enough: enforcement is slow. Regulators take months, sometimes years, to investigate a complaint. Procurement teams don't. A client can disqualify you in a single afternoon if you can't produce your AI governance file when they ask for it.
The Act didn't just create legal exposure. It quietly rewrote the due diligence checklist that shows up in RFPs, MSAs, and term sheets across pharma, fintech, and manufacturing. Most companies haven't noticed the checklist changed.
Buying the tool does not transfer the obligation
There's a piece of this that catches people off guard specifically: using someone else's AI tool doesn't get you off the hook. A vendor's hiring algorithm. A clinical support system you didn't build. You still carry deployer obligations, monitoring for drift, human oversight, incident reporting.
"We bought it from a certified vendor" answers half the question a client will ask. It doesn't answer what you did with it after.
Same AI, same risk, very different outcome
We've watched two companies face the exact same situation and come out completely differently. One kept a single, current inventory of every AI system in use, risk level, owner, oversight process, all documented. When a client asked for proof, it took an afternoon. The other had roughly the same systems, roughly the same level of actual compliance, just nothing written down. Three weeks, two escalations, a visibly cooler client relationship by the end of it.
Same AI. Same underlying risk. Completely different outcome, because one of them could prove it on demand, and the other couldn't.
That's really what changed this year. Not just a fine schedule. A new question buyers now ask before they sign anything, and most companies still can't answer it in under a week.
If someone asked you tomorrow to prove your AI governance in writing, how long would it actually take you?