EU AI Act fines run in three tiers: €35M or 7% of turnover for prohibited practices, €15M or 3% for most breaches, €7.5M or 1% for misleading information.
The three penalty tiers at a glance
The EU AI Act sets maximum fines in Article 99. The tier depends on which obligation was breached, not on how much harm resulted.
| Tier | Maximum fine | What triggers it |
|---|---|---|
| Prohibited practices | €35 million or 7% of total worldwide annual turnover, whichever is higher | Breach of the Article 5 prohibitions: manipulative techniques, exploitation of vulnerabilities, social scoring, untargeted facial-image scraping, emotion inference at work or school, and most real-time remote biometric identification in public spaces |
| Most other obligations | €15 million or 3% | Provider obligations (Art. 16), authorised representatives (Art. 22), importers (Art. 23), distributors (Art. 24), deployers (Art. 26), notified bodies, and the transparency duties in Art. 50 |
| Incorrect information | €7.5 million or 1% | Supplying incorrect, incomplete or misleading information to notified bodies or national competent authorities in reply to a request |
The percentage is calculated on the preceding financial year's total worldwide annual turnover of the undertaking, not on EU turnover and not on the revenue of the specific product.
The SME rule works in reverse
This is the detail most summaries get wrong. For ordinary undertakings the fine is the higher of the fixed amount and the percentage. For SMEs and start-ups, Article 99 applies whichever figure is lower.
The practical effect is large:
- A group with €10 billion turnover breaching Article 5 faces up to 7% — €700 million, far above the €35 million figure.
- A start-up with €2 million turnover breaching the same article faces 7% of €2 million — €140,000, far below €35 million.
So the headline "€35 million" number is close to meaningless for small companies, and much too low for large ones. Always compute both figures before quoting an exposure.
Who enforces what
Three separate enforcement tracks run in parallel, and they are frequently conflated.
Article 99 — national market surveillance authorities. Each Member State designates the authorities that supervise operators on its territory and lays down the penalty regime, within the ceilings above. Member States were required to notify their rules to the Commission. Because the ceilings are maxima rather than fixed amounts, actual exposure varies by country.
Article 100 — the European Data Protection Supervisor. EU institutions, bodies, offices and agencies are in scope of the AI Act, but not of national enforcement. The EDPS may impose administrative fines of up to €1,500,000 for breaches of the Article 5 prohibitions and up to €750,000 for other breaches. The scale is deliberately far lower than for private operators.
Article 101 — the Commission, via the AI Office. Providers of general-purpose AI models answer to the Commission rather than to national authorities. The Commission may impose fines of up to €15 million or 3% of worldwide annual turnover. This power activates on 2 August 2026.
When penalties started applying
The penalty framework did not arrive with the rest of the Regulation. It phased in:
- 2 February 2025 — the Article 5 prohibitions took effect, but the penalty machinery was not yet applicable.
- 2 August 2025 — Article 99 became applicable, alongside the governance architecture and the GPAI obligations. From this date national authorities could sanction breaches.
- 2 August 2026 — the Commission's enforcement powers over general-purpose AI model providers under Article 101 activate.
The 2026 Digital Omnibus deferred the substantive high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I). It did not defer the prohibitions or the penalty regime — a distinction worth checking against the full compliance timeline.
What regulators weigh before fining
Article 99 requires authorities to take into account, among other factors:
- the nature, gravity and duration of the infringement, and the number of people affected
- whether the same operator has already been fined for the same infringement by another authority
- the size, annual turnover and market share of the operator
- whether the infringement was intentional or negligent
- any action taken to mitigate harm
- the degree of cooperation with authorities
- how the authority became aware of the infringement, and in particular whether the operator notified it
That last point matters operationally: self-reporting is an explicit mitigating factor.
Reducing exposure in practice
Penalty exposure is mostly a function of classification accuracy. Most organisations are not at risk of the 7% tier — the Article 5 prohibitions are narrow and largely cover practices no compliant business intends. The realistic exposure sits in the 3% tier, and it follows from three questions:
- Do we operate a high-risk system without knowing it? Annex III use cases in recruitment, credit scoring, education and essential services catch many systems that were never described internally as "AI". Start from the high-risk classification rather than from the vendor's label.
- Are we a provider or a deployer? The obligation sets differ sharply, and modifying a system or putting it on the market under your own name can convert a deployer into a provider. See providers vs deployers.
- Can we evidence compliance? The €7.5 million tier punishes bad answers to regulators, independent of the underlying breach. Technical documentation, logs and a conformity trail are what turn a defensible position into a demonstrable one.
Run the compliance checklist to establish where you stand, and use the sanction estimator to model exposure against your own turnover.
Official AI Act Compliance Deadline Calendar
Updated · Sources: Regulation (EU) 2024/1689 and the 2026 Digital Omnibus on AI.
| Obligation | Applies to | Original date | New date | Status | Countdown | Legal basis |
|---|---|---|---|---|---|---|
| Prohibited Practices (Art. 5) | All providers and deployers | active | — | AI Act Art. 5 | ||
| GPAI Rules (Chapter 5) | GPAI model providers | active | — | AI Act Art. 51-56 | ||
| High-risk AI — Annex III (standalone) | Providers of standalone Annex III systems | deferred | — | AI Omnibus 2026 Art. 6(2) | ||
| High-risk AI — Annex I (embedded) | AI embedded in Annex I regulated products | deferred | — | AI Omnibus 2026 Art. 6(1) | ||
| AI-Generated Content Marking | Providers of generative GPAI systems | active | — | AI Act Art. 50(2) | ||
| Regulatory Sandboxes | National competent authorities | active | — | AI Act Art. 57 |
⬇ Download JSON · CC BY 4.0
AI Act meets DORA and NIS2
Is your organisation subject to both the AI Act and DORA? The two regulations intersect on the operational resilience of financial AI systems. Our sister site regulation-dora.eu covers DORA in depth — including what the AI Act adds on top of an existing DORA programme.
The AI Act for financial institutions ↗ Explore regulation-dora.eu ↗Frequently Asked Questions
The maximum is €35 million or 7% of total worldwide annual turnover, whichever is higher. This top tier applies only to breaches of the Article 5 prohibited practices. Most other infringements fall under the €15 million or 3% tier.
Yes, and the mechanism is unusual. For SMEs and start-ups the cap is whichever of the two figures is LOWER, not higher. A start-up with €2 million turnover facing the top tier is therefore capped at 7% of €2 million, not at €35 million.
The penalty framework in Article 99 became applicable on 2 August 2025, together with the governance architecture and the GPAI obligations. The Commission's separate power to fine general-purpose AI model providers under Article 101 activates on 2 August 2026.
National market surveillance authorities designated by each Member State enforce Article 99 against private operators. The European Data Protection Supervisor enforces Article 100 against EU institutions. The Commission, through the AI Office, enforces Article 101 against providers of general-purpose AI models.
Stay ahead of AI Act changes
Get compliance alerts when deadlines or obligations change.
No spam. One-click unsubscribe.
Take compliance further with the AI Act Academy
Templates, training modules, and live Q&A — everything needed to implement AI Act compliance.