ApexClaw
HomeGovernance › Cost of audit failure
GOVERNANCE

What failing an agent governance audit costs, in the obligations it leaves unevidenced

No invented figures. Only Article 99's own three penalty tiers, mapped to the specific controls that evidence the obligation articles those tiers attach to.

Published · updated · by , founder

Get an Agent Trust Gap Brief

Does failing an agent governance audit itself trigger a fine?

No. AGA is not a regulator and issues no penalty. It shows which EU AI Act obligation article — Art.10, 12, 13, 14 or 15 — has no file-and-line evidence behind it, ahead of anyone else asking.

What does the EU AI Act actually specify as the penalty for non-compliance?

Article 99 sets three tiers: up to €35M or 7% of global turnover for a prohibited Article 5 practice, up to €15M or 3% for most other breaches, and up to €7.5M or 1% for false information to authorities.

Which controls map to which fined obligation?

Four controls evidence Article 14 (human oversight): au.explicit_gate, ov.kill_switch, ov.human_gate and rt.no_real_sends. Two evidence Article 12 (logging): ev.receipts and ev.tamper_evidence — the two articles most scrutinized once an incident is already under review.

Does having ISO 42001 or NIST AI RMF alignment reduce EU AI Act fine exposure?

Neither is itself a legal defense. Both are non-binding frameworks; the fine tiers in Article 99 attach to the Act's own obligation articles regardless of any voluntary certification or framework alignment a deployer claims to follow.

The three penalty tiers, as published in Article 99

TierTriggerMaximum fine
Tier 1 — prohibited practiceNon-compliance with Article 5 (prohibited AI practices)Up to €35,000,000 or 7% of total worldwide annual turnover, whichever is higher
Tier 2 — other obligationsNon-compliance with other operator obligations (e.g. Articles 9–15 risk management, logging, transparency, human oversight, accuracy/robustness/cybersecurity)Up to €15,000,000 or 3% of total worldwide annual turnover, whichever is higher
Tier 3 — incorrect informationSupplying incorrect, incomplete or misleading information to a notified body or national competent authorityUp to €7,500,000 or 1% of total worldwide annual turnover, whichever is higher

Source: EU AI Act (Regulation (EU) 2024/1689), Article 99, verified against artificialintelligenceact.eu/article/99 and the official consolidated text at eur-lex.europa.eu. For SMEs, including start-ups, each fine is capped at the lower of the amount or the percentage, not the higher.

Which controls evidence which fined obligation article

EU AI Act articleObligation AGA controls that evidence itGoverning Art.99 tier
Art.10Data and data governancegv.data_handlingTier 2 — up to €15M or 3% of turnover
Art.12Record-keeping (logging)ev.receipts, ev.tamper_evidenceTier 2 — up to €15M or 3% of turnover
Art.13Transparency and provision of informationgv.model_pinnedTier 2 — up to €15M or 3% of turnover
Art.14Human oversightau.explicit_gate, ov.kill_switch, ov.human_gate, rt.no_real_sendsTier 2 — up to €15M or 3% of turnover
Art.15Accuracy, robustness and cybersecurityis.untrusted_contentTier 2 — up to €15M or 3% of turnover

No AGA control maps to Article 5 (prohibited practices) directly — that article classifies what an AI system may do at all, which is a legal/product-scope question, not a technical control aga.py can read from a file. The mapping above covers only the five EU AI Act articles that already appear in aga.py's own control references.

Primary standards cited on this page: OWASP Agentic Top 10, NIST AI RMF, ISO/IEC 42001, EU AI Act.

What this means for an organisation, precisely

An agent governance audit failure is not a citation. It is a list of which of the EU AI Act's own obligation articles — the ones that carry the Tier 2 fine exposure above once a regulator or plaintiff is already looking — have no evidence behind them yet. Fixing a control before that review happens is strictly cheaper than reconstructing the evidence after. ApexClaw holds no ISO/IEC 42001 certification and makes no certification claim; see /trust/. No figure on this page is invented: every number above is quoted from Article 99 itself.

By Julian Joseph, Founder, ApexClaw. Every figure on this page is recomputed at build time from a named source file and date — see the method notes above. Reviewed against the claims policy: sourced, first-party, or labelled.