Guide · Comparisons · Article 99

What does an EU AI Act violation cost?

Updated 9 August 2026 for Regulation (EU) 2026/1744.

A prohibited practice under Article 5 "shall be subject to administrative fines of up to EUR 35 000 000" — or 7 % of total worldwide annual turnover for the preceding financial year, whichever is higher (Article 99(3) of Regulation (EU) 2024/1689). The duties on operators and notified bodies in Article 99(4) are capped at EUR 15 000 000 or 3 %. Five levels, every figure a ceiling: the law says "up to" — the most an authority may impose, not what it will. The other three: €7.5 million or 1% for misleading information, fixed caps for EU institutions, 3%/€15 million for GPAI providers. Provider is the Act's word for whoever develops a system and puts it on the market under their own name.

The short answer

  • Top tier: an Article 5 prohibition breach costs up to €35 million or 7% of worldwide annual turnover, whichever is higher (Article 99(3)).
  • Middle tier: the core provider, deployer, importer, distributor, notified-body and transparency obligations — up to €15 million or 3%, whichever is higher (Article 99(4)).
  • Information tier: incorrect, incomplete or misleading information to authorities — up to €7.5 million or 1%, whichever is higher (Article 99(5)).
  • SMEs, start-ups and now SMCs: the rule inverts — each fine is capped at the percentage or the amount, whichever is lower (Article 99(6); Article 99(6a) for small mid-cap enterprises, added by Regulation (EU) 2026/1744).
  • Who fines whom: Member State authorities fine operators; the EDPS fines Union institutions (max €1.5 million); the Commission fines GPAI providers (Article 101(1), applicable since 2 August 2026).

What are the five fine tiers?

TierCeilingDirectionWho it bindsProvision
Prohibited practices€35 000 000 or 7% of total worldwide annual turnoverWhichever is higherAny offender; the turnover limb applies "if the offender is an undertaking"Article 99(3)
Core obligations€15 000 000 or 3%Whichever is higherOperators and notified bodies — the lettered list belowArticle 99(4)
Bad information€7 500 000 or 1%Whichever is higherWhoever replies to a notified body or national competent authorityArticle 99(5)
Union institutions€1 500 000 (Article 5 breaches) / €750 000 (everything else)Fixed caps, no turnover limbUnion institutions, bodies, offices and agenciesArticle 100(2); Article 100(3)
GPAI providers3% of annual total worldwide turnover or €15 000 000Whichever is higherProviders of general-purpose AI models, fined by the CommissionArticle 101(1)

These are ceilings, not tariffs — Article 99(1) requires penalties to be "effective, proportionate and dissuasive", and the Article 99(7) criteria (below) decide where in the range a case lands. The Article 99(6) SME cap adjusts the first three tiers rather than adding a sixth. The top tier is why the ten prohibited practices deserve a dedicated audit: one banned capability outprices every other compliance failure in the Act.

Which breaches fall into the €15 million / 3% tier?

Article 99(4) enumerates them exhaustively — non-compliance with:

Note what is not here: GPAI model obligations. Those are enforced by the Commission under Article 101, not through the national Article 99(4) route.

How do the small-company caps invert the rule?

For the three national tiers, the two limbs normally combine upward: whichever is higher. Article 99(6) flips this for small companies: "In the case of SMEs, including start-ups, each fine referred to in this Article shall be up to the percentages or amount referred to in paragraphs 3, 4 and 5, whichever thereof is lower."

In practice: an SME with €20 million turnover facing an Article 5 breach is capped at 7% — €1.4 million — because that is lower than €35 million. The percentage limb, not the headline number, is the binding ceiling; for larger companies the whichever-is-higher rule keeps the euro figure in play.

The 2026 amendment extended it, but not identically. New Article 99(6a) caps each fine "referred to in paragraphs 4 and 5" for SMCs at the percentage or amount, "whichever is lower". Note what it omits: paragraph 3 — an SMC breaching an Article 5 prohibition still faces the whichever-is-higher top tier; only the €15 million / 3% and €7.5 million / 1% tiers invert. "SMC" is newly defined in Article 3, point (14b) by reference to point (2) of the Annex to Recommendation (EU) 2025/1099. Article 99(1), also replaced, names SMCs alongside SMEs and start-ups whose interests and economic viability Member States must weigh when imposing penalties, and adds a duty to take account of Commission guidelines under Article 96.

What do authorities weigh before fining you?

Article 99(7) lists what must be considered when deciding whether to fine at all and how much. The criteria fall into three groups:

The infringement itself: its nature, gravity, duration and consequences, including the number of affected persons and level of damage (point (a)); whether it was intentional or negligent (point (i)); and any other aggravating or mitigating factor, such as financial benefits gained or losses avoided (point (e)).

Who you are and your record: size, annual turnover and market share (point (d)); whether other market surveillance authorities already fined you for the same infringement (point (b)); whether any other authority already fined you under other Union or national law for the same activity or omission (point (c)) — the double-jeopardy guard for AI systems that also breach the GDPR.

How you behaved — the levers you control: your "degree of responsibility... taking into account the technical and organisational measures implemented" (point (g)); your degree of cooperation with authorities to remedy the infringement (point (f)); whether you notified the infringement yourself (point (h)); and any action taken to mitigate harm to affected persons (point (j)).

The third group is the operational one. The measures answer has to exist before the letter arrives — a register that ties every system to its classification, obligations and evidence is the record points (f), (g) and (h) reward: it shows the measures implemented, speeds cooperation, and lets you notice problems before the authority does.

Who actually imposes the fines?

Three enforcers, split by target. Member States lay down the penalty rules and enforce them against operators (Article 99(1)); depending on the national legal system, fines are imposed by competent national courts or other bodies (Article 99(9)). The European Data Protection Supervisor fines Union institutions, bodies, offices and agencies (Article 100(1)), and the Commission — which has "exclusive powers to supervise and enforce Chapter V" (Article 88(1)) — fines GPAI model providers (Article 101(1)), with unlimited review by the Court of Justice, which "may cancel, reduce or increase the fine" (Article 101(5)).

Two honest caveats. Article 99(2) obliges Member States to notify the Commission of their penalty rules "without delay and at the latest by the date of entry into application" — it names no calendar date, though both candidate anchors (2 August 2025 for Article 99 itself; the general date of 2 August 2026, Article 113, second paragraph) have now passed. And how far each Member State has actually implemented and staffed its regime varies — a statement about the world, not the Regulation — so check your national implementing law rather than assuming uniformity.

When did penalty exposure start?

By provision class, per Article 113:

Every surrounding date is in the EU AI Act timeline.

What this means for you

If you're a provider: your realistic exposure is Article 99(4), point (a) — the Article 16 stack, live for Annex III systems from 2 December 2027 — plus Article 99(5), live now, if your answers to an authority are wrong or incomplete. Price the percentage limb against your own turnover: under the Article 99(6) inversion, a €10 million-turnover provider's Article 99(4) cap is €300 000 — survivable, but the remediation order and the customer letters that follow cost more. The Article 99(7) record is the variable you still control.

If you're a deployer: Article 99(4), point (e) fines Article 26 deployer obligations directly, and Article 5 binds use — the €35 million/7% tier reaches you if you operate a banned system a vendor built, and vendor assurances shift none of it. Your Article 99(7) position rests on the same evidence: what you run, how it is classified, what measures you implemented. Whether that evidence needs counsel behind it is its own question: do we still need a lawyer?

FAQ

What is the maximum fine under the EU AI Act? €35 million or 7% of total worldwide annual turnover for the preceding financial year, whichever is higher — reserved for breaches of the Article 5 prohibited practices (Article 99(3)). Every other tier is lower: €15 million/3%, €7.5 million/1%, and the Article 100 and 101 regimes.

Are EU AI Act fines lower for SMEs, start-ups and SMCs? Yes, but not equally. Article 99(6) caps each of the three national tiers at the percentage or the amount, whichever is lower, for SMEs including start-ups. Article 99(6a), added in 2026, does the same for SMCs — but only for paragraphs 4 and 5, so the Article 5 tier still runs whichever-is-higher.

Who enforces EU AI Act penalties? Member State authorities or courts fine operators under nationally adopted rules (Article 99(1) and (9)). The European Data Protection Supervisor fines Union institutions, bodies, offices and agencies (Article 100). The Commission alone fines general-purpose AI model providers — exclusive powers under Article 88(1) — subject to review by the Court of Justice (Article 101).

Can GPAI providers be fined yet? Yes. Article 101 was excepted from the 2 August 2025 start by Article 113, third paragraph, point (b) and fell to the Regulation's general application date, so the Commission's power to fine GPAI providers — up to 3% of worldwide turnover or €15 million, whichever is higher — has applied since 2 August 2026.


Sources: Regulation (EU) 2024/1689 (EUR-Lex), Articles 99, 100, 101 and 113, as amended by Regulation (EU) 2026/1744 (EUR-Lex), Article 1, points (4)(b), (38) and (40). Chapter XII's own 2 August 2025 application date was not amended, and neither were the ceilings in Article 99(3), (4) and (5) or Articles 100 and 101. Fine ceilings and criteria are stated in the Regulation; the state of each Member State's implementing rules, designated bodies and enforcement practice varies by country and is not derivable from the Regulation's text — verify your national regime. Article 99(2) anchors the Member State notification deadline to "the date of entry into application" without naming a calendar date.

Where this question meets the product: EU AI Act compliance software for SMEs. Answering it in a customer's questionnaire: how to answer AI questions in a supplier questionnaire.

Read nextEU AI Act vs GDPR: what's actually different?Article 2

See which of your AI systems the Act covers.

No account needed. Every answer cites the article it rests on.

Get your free readiness review

Check your AI systems, free