What are the penalties under the EU AI Act? What non-compliance actually costs
Updated 9 August 2026 for Regulation (EU) 2026/1744.
Break the EU AI Act and what it costs depends on which rule you broke. There are five levels, and every figure is a ceiling: the law says "up to", so it is the most an authority may impose and not what it will. The levels are €35 million or 7% of worldwide turnover for prohibited practices, €15 million or 3% for core obligations, €7.5 million or 1% for misleading information, fixed caps for EU institutions, and 3%/€15 million for GPAI providers. Provider is the Act's word for whoever develops a system and puts it on the market under their own name.
Quick answer
- Top tier: an Article 5 prohibition breach costs up to €35 million or 7% of worldwide annual turnover, whichever is higher (Article 99(3)).
- Middle tier: the core provider, deployer, importer, distributor, notified-body and transparency obligations — up to €15 million or 3%, whichever is higher (Article 99(4)).
- Information tier: incorrect, incomplete or misleading information to authorities — up to €7.5 million or 1%, whichever is higher (Article 99(5)).
- SMEs, start-ups and now SMCs: the rule inverts — each fine is capped at the percentage or the amount, whichever is lower (Article 99(6); Article 99(6a) for small mid-cap enterprises, added by Regulation (EU) 2026/1744).
- Who fines whom: Member State authorities fine operators; the EDPS fines Union institutions (max €1.5 million); the Commission fines GPAI providers (Article 101(1), applicable since 2 August 2026).
What are the five fine tiers?
| Tier | Ceiling | Direction | Who it binds | Provision |
|---|---|---|---|---|
| Prohibited practices | €35 000 000 or 7% of total worldwide annual turnover | Whichever is higher | Any offender; the turnover limb applies "if the offender is an undertaking" | Article 99(3) |
| Core obligations | €15 000 000 or 3% | Whichever is higher | Operators and notified bodies — the lettered list below | Article 99(4) |
| Bad information | €7 500 000 or 1% | Whichever is higher | Whoever replies to a notified body or national competent authority | Article 99(5) |
| Union institutions | €1 500 000 (Article 5 breaches) / €750 000 (everything else) | Fixed caps, no turnover limb | Union institutions, bodies, offices and agencies | Article 100(2); Article 100(3) |
| GPAI providers | 3% of annual total worldwide turnover or €15 000 000 | Whichever is higher | Providers of general-purpose AI models, fined by the Commission | Article 101(1) |
These are ceilings, not tariffs — Article 99(1) requires penalties to be "effective, proportionate and dissuasive", and the Article 99(7) criteria (below) decide where in the range a case lands. The Article 99(6) SME cap adjusts the first three tiers rather than adding a sixth. The top tier is why the ten prohibited practices deserve a dedicated audit: one banned capability outprices every other compliance failure in the Act.
Which breaches fall into the €15 million / 3% tier?
Article 99(4) enumerates them exhaustively — non-compliance with:
- (a) provider obligations under Article 16 — the full high-risk stack, from risk management to registration;
- (b) authorised-representative obligations under Article 22;
- (c) importer obligations under Article 23;
- (d) distributor obligations under Article 24;
- (da) — added in 2026 — obligations of providers and operators under Article 25(2) and (4): value-chain cooperation after a role switch, and the written agreement with integrated third-party suppliers;
- (e) deployer obligations under Article 26 — deployers carry their own fine exposure, not just providers;
- (f) notified-body requirements under Article 31, Article 33(1), (3) and (4) or Article 34;
- (g) the Article 50 transparency obligations for providers and deployers — chatbot disclosure, deepfake labelling.
Note what is not here: GPAI model obligations. Those are enforced by the Commission under Article 101, not through the national Article 99(4) route.
How do the small-company caps invert the rule?
For the three national tiers, the two limbs normally combine upward: whichever is higher. Article 99(6) flips this for small companies: "In the case of SMEs, including start-ups, each fine referred to in this Article shall be up to the percentages or amount referred to in paragraphs 3, 4 and 5, whichever thereof is lower."
In practice: an SME with €20 million turnover facing an Article 5 breach is capped at 7% — €1.4 million — because that is lower than €35 million. The percentage limb, not the headline number, is the binding ceiling; for larger companies the whichever-is-higher rule keeps the euro figure in play.
The 2026 amendment extended it, but not identically. New Article 99(6a) caps each fine "referred to in paragraphs 4 and 5" for SMCs at the percentage or amount, "whichever is lower". Note what it omits: paragraph 3 — an SMC breaching an Article 5 prohibition still faces the whichever-is-higher top tier; only the €15 million / 3% and €7.5 million / 1% tiers invert. "SMC" is newly defined in Article 3, point (14b) by reference to point (2) of the Annex to Recommendation (EU) 2025/1099. Article 99(1), also replaced, names SMCs alongside SMEs and start-ups whose interests and economic viability Member States must weigh when imposing penalties, and adds a duty to take account of Commission guidelines under Article 96.
What do authorities weigh before fining you?
Article 99(7) lists what must be considered when deciding whether to fine at all and how much. The criteria fall into three groups:
The infringement itself: its nature, gravity, duration and consequences, including the number of affected persons and level of damage (point (a)); whether it was intentional or negligent (point (i)); and any other aggravating or mitigating factor, such as financial benefits gained or losses avoided (point (e)).
Who you are and your record: size, annual turnover and market share (point (d)); whether other market surveillance authorities already fined you for the same infringement (point (b)); whether any other authority already fined you under other Union or national law for the same activity or omission (point (c)) — the double-jeopardy guard for AI systems that also breach the GDPR.
How you behaved — the levers you control: your "degree of responsibility... taking into account the technical and organisational measures implemented" (point (g)); your degree of cooperation with authorities to remedy the infringement (point (f)); whether you notified the infringement yourself (point (h)); and any action taken to mitigate harm to affected persons (point (j)).
The third group is the operational one. The measures answer has to exist before the letter arrives — a register that ties every system to its classification, obligations and evidence is the record points (f), (g) and (h) reward: it shows the measures implemented, speeds cooperation, and lets you notice problems before the authority does.
Who actually imposes the fines?
Three enforcers, split by target. Member States lay down the penalty rules and enforce them against operators (Article 99(1)); depending on the national legal system, fines are imposed by competent national courts or other bodies (Article 99(9)). The European Data Protection Supervisor fines Union institutions, bodies, offices and agencies (Article 100(1)), and the Commission — which has "exclusive powers to supervise and enforce Chapter V" (Article 88(1)) — fines GPAI model providers (Article 101(1)), with unlimited review by the Court of Justice, which "may cancel, reduce or increase the fine" (Article 101(5)).
Two honest caveats. Article 99(2) obliges Member States to notify the Commission of their penalty rules "without delay and at the latest by the date of entry into application" — it names no calendar date, though both candidate anchors (2 August 2025 for Article 99 itself; the general date of 2 August 2026, Article 113, second paragraph) have now passed. And how far each Member State has actually implemented and staffed its regime varies — a statement about the world, not the Regulation — so check your national implementing law rather than assuming uniformity.
When did penalty exposure start?
By provision class, per Article 113:
- Prohibited practices: the original eight banned from 2 February 2025 (Article 113, third paragraph, point (a)); the penalties chapter (Chapter XII) applied from 2 August 2025 (point (b)) — a six-month gap in which the conduct was unlawful before the EU fine framework was live. Points (ba) and (bb), added in 2026, apply from 2 December 2026 — no gap.
- Article 99(4) tier: the framework was live from 2 August 2025, but the obligations behind it no longer share one date. Article 50 applied from 2 August 2026, and Article 111(4) gives synthetic-content systems on the market before that date until 2 December 2026 for 50(2). Articles 16 and 22 to 26 sit in Chapter III, Section 3, moved by Regulation (EU) 2026/1744 to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I (Article 113, third paragraph, point (c), as amended) — so most of this tier's exposure has not ripened. Notified-body provisions ran from 2 August 2025.
- GPAI: Chapter V duties applied from 2 August 2025, but Article 113, third paragraph, point (b) excepted Article 101 — the fining power — which fell to the default date in Article 113, second paragraph, and has applied since 2 August 2026. The GPAI first year was duties without fines; that window is closed.
Every surrounding date is in the EU AI Act timeline.
What this means for you
If you're a provider: your realistic exposure is Article 99(4), point (a) — the Article 16 stack, live for Annex III systems from 2 December 2027 — plus Article 99(5), live now, if your answers to an authority are wrong or incomplete. Price the percentage limb against your own turnover: under the Article 99(6) inversion, a €10 million-turnover provider's Article 99(4) cap is €300 000 — survivable, but the remediation order and the customer letters that follow are the larger cost. The Article 99(7) record is the variable you still control.
If you're a deployer: Article 99(4), point (e) fines Article 26 deployer obligations directly, and Article 5 binds use — the €35 million/7% tier reaches you if you operate a banned system a vendor built, and vendor assurances shift none of it. Your Article 99(7) position rests on the same evidence discipline: what you run, how it's classified, what measures you implemented.
Which classification are yours in? The fine tier follows from that.
Classify your system now — 7 questions on the main line, plus follow-ups where they apply, no account, and the classification runs in your browser: answers stay there unless you choose to keep the result.
FAQ
What is the maximum fine under the EU AI Act? €35 million or 7% of total worldwide annual turnover for the preceding financial year, whichever is higher — reserved for breaches of the Article 5 prohibited practices (Article 99(3)). Every other tier is lower: €15 million/3%, €7.5 million/1%, and the Article 100 and 101 regimes.
Are EU AI Act fines lower for SMEs, start-ups and SMCs? Yes, but not equally. Article 99(6) caps each of the three national tiers at the percentage or the amount, whichever is lower, for SMEs including start-ups. Article 99(6a), added in 2026, does the same for SMCs — but only for paragraphs 4 and 5, so the Article 5 tier still runs whichever-is-higher.
Who enforces EU AI Act penalties? Member State authorities or courts fine operators under nationally adopted rules (Article 99(1) and (9)). The European Data Protection Supervisor fines Union institutions, bodies, offices and agencies (Article 100). The Commission alone fines general-purpose AI model providers — exclusive powers under Article 88(1) — subject to review by the Court of Justice (Article 101).
Can GPAI providers be fined yet? Yes. Article 101 was excepted from the 2 August 2025 start by Article 113, third paragraph, point (b) and fell to the Regulation's general application date, so the Commission's power to fine GPAI providers — up to 3% of worldwide turnover or €15 million, whichever is higher — has applied since 2 August 2026.
Sources: Regulation (EU) 2024/1689 (EUR-Lex), Articles 99, 100, 101 and 113, as amended by Regulation (EU) 2026/1744 (EUR-Lex), Article 1, points (4)(b), (38) and (40). Chapter XII's own 2 August 2025 application date was not amended, and neither were the ceilings in Article 99(3), (4) and (5) or Articles 100 and 101. Fine ceilings and criteria are stated in the Regulation; the state of each Member State's implementing rules, designated bodies and enforcement practice varies by country and is not derivable from the Regulation's text — verify your national regime. Article 99(2) anchors the Member State notification deadline to "the date of entry into application" without naming a calendar date.