European Union

EU AI Act Penalties: The Full Tiered Structure

The Act doesn't set one fine — it sets three tiers keyed to what actually went wrong, a fourth track for general-purpose AI model providers, and an SME rule most compliance teams get backwards.

In force since Aug 2025 (GPAI track since Aug 2026)Effective August 2, 2025
Compliance team calculating potential EU AI Act fine exposure across the tiered penalty structure
Photo: Vitaly Gariev via Unsplash

Most coverage of EU AI Act fines flattens the whole penalty regime into one number: €35 million, or 7% of global turnover, whichever is higher. That figure is real, but it's the ceiling of exactly one category of violation — the most severe one — not the fine that applies across the board. Article 99 actually sets out three separate tiers, keyed to what a company specifically did wrong, and most real-world violations don't land in the tier everyone quotes. On top of that, Article 101 creates a fourth, entirely separate fine track for general-purpose AI model providers, and Article 100 reaches EU institutions themselves. Treating "€35 million or 7%" as the whole story means misjudging your actual exposure, in either direction.

Tier 1: prohibited practices — up to €35 million or 7% of turnover

The top tier is reserved specifically for violations of Article 5's prohibited AI practices — the eight categories the Act bans outright, like social scoring, manipulative dark-pattern AI, and untargeted facial-recognition scraping. Under Article 99(3), non-compliance with the Article 5 prohibitions carries administrative fines of up to €35,000,000, or, for an undertaking, up to 7% of its total worldwide annual turnover for the preceding financial year, whichever is higher. Nothing else in the Act's operator obligations reaches this ceiling. That's a deliberate signal: the eight prohibited practices aren't treated as a documentation gap to be corrected later, they're treated as the regulation's most serious category of wrongdoing, and the fine structure reflects it.

Tier 2: most other obligations — up to €15 million or 3% of turnover

This is the tier that catches the overwhelming majority of real compliance failures. Article 99(4) sets fines of up to €15,000,000, or up to 3% of worldwide annual turnover, whichever is higher, for non-compliance with the Act's provider, deployer, importer, and distributor obligations — everything other than the Article 5 prohibitions. A high-risk hiring-screening tool deployed without the Article 9 risk management system it's supposed to have, or a system placed on the market with CE marking that doesn't actually reflect a completed conformity assessment, both fall here. If your organization is running a realistic risk assessment of AI Act exposure, this is the tier to model against — it's the one most compliance programs are actually built to avoid, precisely because it covers the largest share of obligations in the statute.

Tier 3: lying to regulators — up to €7.5 million or 1% of turnover

The narrowest and most overlooked tier exists independently of whatever the underlying compliance gap was. Article 99(5) fines the supply of incorrect, incomplete, or misleading information to notified bodies or national competent authorities, in response to a request, at up to €7,500,000, or up to 1% of worldwide annual turnover, whichever is higher. The point worth internalizing here: this is a separate violation from whatever a regulator was originally investigating. A company under review for a Tier 2 documentation gap that then hands the investigating authority an incomplete technical file — whether out of carelessness or an attempt to minimize exposure — has created a second, independent fine exposure on top of the first. Regulators reward candor and punish evasiveness as its own category of harm.

The SME rule almost everyone states backwards

Every tier above describes the ceiling for a large undertaking, where the fine is whichever of the fixed euro amount or the turnover percentage is higher. Article 99(6) flips that for small and medium-sized enterprises, including startups: the fine is capped at whichever of the two figures is lower. It's a one-word difference in the statute — higher versus lower — that changes real financial exposure by orders of magnitude, and it's the detail that gets dropped most often when the headline numbers get repeated without context.

Take a hypothetical seed-stage company, Halcyon Analytics, building an AI-driven credit-risk scoring tool with €3 million in annual turnover — comfortably under the EU's standard SME threshold of fewer than 250 staff and turnover at or below €50 million (or a balance sheet total at or below €43 million). Suppose Halcyon's tool is found to have deployed without the human oversight measures a high-risk system requires — a Tier 2 violation. For a large undertaking, the fine would be whichever of €15 million or 3% of turnover is higher; at any realistic large-company turnover, that's the flat €15 million figure. For Halcyon as an SME, the calculation runs the other way: 3% of its €3 million turnover is €90,000, against the €15 million ceiling — and Article 99(6) caps the fine at whichever is lower, meaning Halcyon's maximum exposure on that violation is €90,000, not €15 million. Run the same comparison on a Tier 1 prohibited-practices violation and the gap is even starker: 7% of Halcyon's turnover is €210,000, against a €35 million ceiling for a large undertaking facing the same violation. The tier structure sets the outer bounds; the SME rule is what actually determines whether a small company's exposure is measured in the hundreds of thousands or the tens of millions.

A separate track: fines for general-purpose AI model providers

Providers of general-purpose AI models — the foundation models underlying much of the generative AI market — don't fall under Articles 99 or 100 at all. Article 101 creates its own fine, of up to €15 million or 3% of worldwide annual turnover, whichever is higher, imposed directly by the European Commission through the AI Office rather than by a national market surveillance authority. The trigger conditions are also different from the operator obligations covered above: a Commission finding that a GPAI provider intentionally or negligently infringed the Act's GPAI-specific provisions, failed to respond properly to a Commission document or information request, ignored a corrective measure the Commission ordered, or blocked the Commission's access to the model for evaluation. In fixing the actual amount within that ceiling, the Commission is required to weigh the nature, gravity, and duration of the infringement — the same proportionality principle that runs through the rest of the penalty framework.

One more distinction worth flagging: this track came online later than the rest of the regime. The Commission's Article 101 enforcement powers over GPAI providers only became applicable on August 2, 2026 — meaning this is the newest live enforcement mechanism in the entire Act, and one where an actual enforcement track record is still thin.

Even EU institutions aren't exempt

A detail most coverage of AI Act penalties skips entirely: the fine structure doesn't stop at the EU's border with the private sector. Article 100 lets the European Data Protection Supervisor impose administrative fines directly on EU institutions, bodies, offices, and agencies that fall within the Act's scope — up to €1,500,000 for an Article 5 prohibited-practices violation, and up to €750,000 for any other non-compliance. The absolute numbers are far smaller than the private-sector tiers, and the enforcer is different — the EDPS, not a national market surveillance authority or the AI Office — but the underlying logic is identical: a materially higher ceiling for prohibited practices than for everything else. It's a structural signal that the regulation was built to apply symmetrically, not as a rulebook written for industry alone while EU bodies police themselves informally.

Who actually brings the case

Three different enforcers sit behind these numbers, and knowing which one applies to your situation matters as much as knowing the fine amount. National market surveillance authorities, designated by each member state under Articles 70 and 74, bring the great majority of cases — the Tier 1 through Tier 3 fines under Article 99 against providers, deployers, importers, and distributors operating in their territory. The European Commission's AI Office is the sole enforcer of Article 101 against general-purpose AI model providers, a deliberately centralized arrangement given how few companies actually train frontier-scale foundation models. The European Data Protection Supervisor separately enforces Article 100 against EU institutions themselves.

Timing matters too. The penalty framework in Chapter XII, including Article 99, became applicable on August 2, 2025 — the same wave of the Act's implementation timeline that brought the general-purpose AI model obligations into force. Article 101's Commission enforcement power against GPAI providers is the exception, arriving a full year later on August 2, 2026. If you're assessing exposure today, the national-authority tiers under Article 99 have had over a year of runway; the Commission's direct GPAI enforcement track is still new enough that its practical case history is only beginning to build. For how these dates line up against the high-risk-system deadlines the 2026 Digital Omnibus pushed further out, see our full EU AI Act implementation timeline.

Frequently asked questions

Is €35 million or 7% of turnover the fine for any EU AI Act violation?
No. That figure is the ceiling for Article 5 prohibited-practices violations specifically — the top of a three-tier structure, not the fine itself. Most real-world violations, like a high-risk system deployed without the required technical documentation or human oversight, fall into the second tier: up to €15 million or 3% of worldwide annual turnover, whichever is higher for a large undertaking.
How does the fine calculation change for a small company or startup?
Article 99(6) inverts the rule for SMEs, including startups. Large undertakings face whichever of the fixed euro amount or the turnover percentage is higher; SMEs face whichever is lower. For a small company, the percentage figure is almost always the binding number, which reduces real exposure by orders of magnitude relative to the headline amounts everyone quotes.
Do general-purpose AI model providers face the same fines as everyone else under the AI Act?
No — they're on a separate track under Article 101. The European Commission, acting through the AI Office, can fine GPAI model providers up to €15 million or 3% of worldwide annual turnover, whichever is higher, for infringements like refusing a document request or blocking the Commission's access to a model for evaluation. This enforcement power only started applying from August 2, 2026, a full year after the rest of the penalty framework.
Who actually enforces EU AI Act fines — an EU body or each country separately?
Both, depending on the case. National market surveillance authorities designated by each member state bring most Article 99 cases against providers, deployers, importers, and distributors operating in their territory. The European Commission's AI Office directly enforces Article 101 against general-purpose AI model providers. The European Data Protection Supervisor separately enforces Article 100 against EU institutions and agencies.
Can EU institutions themselves be fined under the AI Act?
Yes. Article 100 lets the European Data Protection Supervisor fine EU institutions, bodies, offices, and agencies that fall within the Act's scope — up to €1.5 million for an Article 5 prohibited-practices violation, and up to €750,000 for any other non-compliance. The amounts are smaller than the private-sector tiers, but the same structural logic — a top tier for prohibited practices, a lower tier for everything else — applies to the EU's own institutions.

Sources & references

  1. Official source
  2. Regulation (EU) 2024/1689, Article 99 — Penalties (full text, EUR-Lex)
  3. Regulation (EU) 2024/1689, Article 100 — Administrative Fines on Union Institutions (full text, EUR-Lex)
  4. Regulation (EU) 2024/1689, Article 101 — Fines for Providers of General-Purpose AI Models (full text, EUR-Lex)
  5. Regulation (EU) 2024/1689, Article 113 — Entry into Force and Application (full text, EUR-Lex)
European Union policy officials in discussion at a government building
Photo: Karson via Unsplash

regulations eu

The EU AI Act

The EU AI Act classifies AI systems into risk tiers and phases its obligations in on a multi-year schedule. Here's what's actually in force today, what's still phasing in, and how the risk tiers work.
Governome Editorial Team · 4 min read
Legal and compliance professionals reviewing which AI practices are prohibited under the EU AI Act
Photo: Leon Seibert via Unsplash
Article 5 of the EU AI Act prohibits eight specific AI practices — social scoring, manipulative and exploitative AI, untargeted facial-recognition scraping, workplace emotion inference, and more — with no compliance path around them. It's also been in force since February 2025, earlier than almost everything else in the Act.
Governome Editorial Team · 8 min read
Compliance team reviewing CE marking documentation for a high-risk AI system before EU market placement
Photo: Vitaly Gariev via Unsplash
CE marking under Article 48 of the EU AI Act is the provider's own compliance signal, applied after conformity assessment — for most high-risk systems, with no external body involved at all. Here's what has to be visible, legible, and indelible, how digital marking works for software-delivered AI, and what importers have to verify before a marked system reaches the EU market.
Governome Editorial Team · 8 min read
European Commission officials at a policy meeting discussing AI regulation
Photo: Zoshua Colah via Unsplash
The EU AI Office is a European Commission body with real fining power — but only over one specific category of company: providers of general-purpose AI models. Everyone else's high-risk obligations are enforced by their national market surveillance authority instead. Here's the actual jurisdiction map, the fine amounts, and how the Office differs from the AI Board, the Advisory Forum, and the Scientific Panel.
Governome Editorial Team · 7 min read
Compliance team reviewing conformity assessment documentation for a high-risk AI system
Photo: Zulfugar Karimov via Unsplash
Article 43 conformity assessment has two routes: internal control, which covers most high-risk systems and involves no external reviewer at all, and notified-body assessment, reserved for a narrow slice of biometric systems. Here's how each one actually works, what gets produced, and what forces a redo.
Governome Editorial Team · 7 min read
The formal process a high-risk AI system goes through to demonstrate it meets the EU AI Act's requirements — internal self-assessment for most Annex III systems, or third-party assessment where a notified body is involved — before the system can be placed on the market or put into service.
Governome Editorial Team · 2 min read
Compliance reviewer working through a classification checklist at a desk
Photo: Zulfugar Karimov via Unsplash
Step through this checklist before concluding an AI system falls outside the EU AI Act's high-risk category. It mirrors the actual two-track Article 6 test, not a simplified summary of it.
Governome Editorial Team · 2 min read
European Union policy officials reviewing a phased regulatory implementation schedule
Photo: Zoshua Colah via Unsplash
The EU AI Act's original phased schedule got rewritten mid-2026: the Digital Omnibus on AI pushed the high-risk-system deadline from August 2026 to December 2027, and the product-embedded high-risk deadline from August 2027 to August 2028. Article 5 prohibited practices, GPAI obligations, and the governance framework weren't touched. Here's what's actually in force right now, what moved, what didn't, and why.
Governome Editorial Team · 8 min read