The fines under the EU (AI Act) are tiered:
Top tier (up to €35 million or 7% of global annual turnover, whichever is higher): applies to prohibited AI practices (Article 5), e.g., subliminal manipulation, social scoring, certain biometric uses, etc.
Mid tier (up to €15 million or 3%): applies to most other obligations, including the core compliance requirements for high-risk AI systems (such as data governance, risk management, technical documentation, human oversight, etc.), as well as transparency obligations.
Low tier (up to €7.5 million or 1%): mainly targets providing incorrect, incomplete, or misleading information to regulatory authorities.
High-risk AI systems (Article 10) have strict data governance requirements:
Training, validation, and test datasets must include appropriate governance and management practices, including records of the data collection process and data sources (origin).
Datasets must be relevant, sufficiently representative, as error-free and complete as possible, and checked and mitigated for bias.
Technical documentation (Annex IV) requires a detailed description of the dataset, sources, collection/selection/labeling methods, preprocessing, etc.
For GPAI models, you also need to publish summaries of the training content according to the template (including data source categories).
This emphasizes the traceability (provenance) and governance of data, but the focus is on documentation, auditability, and explainability so as to support regulators and post-event monitoring.
Filecoin’s relevance
Filecoin (combined with IPFS’s content addressing, transaction proofs, storage proofs, etc.) can provide verifiable data source traceability and integrity proofs:
Achieves content addressing and tamper-evident references through the Content Identifier (CID).
Storing deals and the proof mechanism can provide encrypted evidence of data existence, integrity, and timestamps.
A suitable auditable, decentralized proof-of-storage layer for training datasets can help meet the AI Act’s requirements for data source documentation, version control, and traceability.
It is not an official compliance solution, but as a technical tool it can effectively support “verifiable source tracing,” especially in scenarios requiring long-term, cross-organizational audits. Many projects are already exploring using Filecoin/IPFS as a provenance layer for AI training data.
In short:
The highest tier of fines is €35 million (for prohibited practices); the main tier for high-risk obligations is €15 million. The full set of high-risk requirements has been postponed to the end of 2027. Data source and governance requirements are indeed strict, and Filecoin’s verifiable storage properties align closely with them. It is recommended to review the latest official AI Office guidelines and the final text of the Digital Omnibus to get precise compliance details.
Material sourced from official media/web news. Content is for reference, learning, and exchange only. Please strictly comply with local laws and regulations. This article does not represent any investment advice.