← All articles

Penalties Under the EU AI Act: How Fines Are Calculated

· Updated

Update — 11 May 2026: The AI Act Omnibus deal reached at the May trilogue moves the 2 August 2026 deadline for Annex III high-risk obligations to 2 December 2027, pending formal adoption and publication in the Official Journal. The Article 50 deadline to mark AI-generated content moves to 2 December 2026. See: EU AI Act High-Risk Deadline Delayed to December 2027.

The EU AI Act’s penalty framework follows the GDPR playbook with headline-grabbing maximum fines designed to ensure that non-compliance is more expensive than compliance. But like GDPR, the actual mechanics of how fines are calculated and applied matter more than the maximums.

The three penalty tiers

The Act establishes three tiers of administrative fines, each tied to different categories of violation.

Tier 1: Prohibited practices. Up to €35 million or 7% of global annual turnover

The highest penalties apply to violations of Article 5, the outright bans. This covers:

  • Deploying AI systems that manipulate behaviour through subliminal or deceptive techniques
  • Exploiting vulnerabilities of specific groups
  • Social scoring by public authorities (or private entities where it leads to detrimental treatment in unrelated contexts)
  • Untargeted facial image scraping for facial recognition databases
  • Emotion recognition in workplaces or educational institutions (with limited exceptions)
  • Real-time remote biometric identification in public spaces (with limited exceptions)

The 7% figure applies to global annual turnover of the preceding financial year, whichever is higher than the fixed amount. For a company with €1 billion in annual revenue, the maximum fine for a prohibited practice violation is €70 million.

Tier 2: High-risk and other obligations. Up to €15 million or 3% of global annual turnover

This tier covers most of the Act’s substantive requirements:

  • Failure to comply with high-risk AI system obligations (Articles 6–27)
  • Non-compliance with GPAI model obligations (Articles 51–56)
  • Failure to meet transparency requirements (Article 50)
  • Non-compliance with obligations for providers, deployers, importers, or distributors

For a company with €1 billion in revenue, the maximum here is €30 million.

Tier 3: Incorrect information. Up to €7.5 million or 1% of global annual turnover

The lowest tier applies to supplying incorrect, incomplete, or misleading information to national competent authorities or notified bodies. This might seem minor, but it covers situations where an organisation misrepresents its compliance status during an investigation or audit.

How fines are actually determined

The Act doesn’t require regulators to impose maximum fines for every violation. Article 99 sets out the factors that national competent authorities must consider when deciding whether to impose a fine and how large it should be:

Nature, gravity, and duration of the infringement. A systematic, deliberate violation sustained over months will attract a higher fine than a one-off technical oversight quickly corrected.

Whether the infringement was intentional or negligent. Deliberate non-compliance is treated more severely than an honest mistake. But negligence — failing to take reasonable steps to comply — is still punishable.

Actions taken to mitigate harm. If you detected the issue, took corrective action, and mitigated the impact on affected people, that works in your favour.

Degree of responsibility. The Act considers what technical and organisational measures were in place. Demonstrating a genuine compliance programme — even one with gaps — is better than demonstrating no effort at all.

Previous infringements. Repeat offenders face higher penalties, as under GDPR.

Cooperation with authorities. Cooperating with the investigation, providing requested information promptly, and engaging constructively with regulators reduces the fine.

The manner in which the infringement became known. If the authority discovered the violation through a complaint or its own investigation, that’s different from the organisation self-reporting.

Financial strength of the entity. Fines must be “effective, proportionate and dissuasive.” A €1 million fine is dissuasive for a startup but negligible for a global technology company.

Economic benefit gained. If the organisation profited from the non-compliance, the fine should at least exceed that benefit — otherwise non-compliance is rational.

SME and startup provisions

The Act treats small and medium enterprises differently. Article 99(6) caps each fine for SMEs, including startups, at the percentage or the fixed amount, whichever is lower. Article 99(1) separately requires national penalty rules to take account of the interests of SMEs and their economic viability.

This is an acknowledgement that a €15 million fine would bankrupt most SMEs, which wouldn’t serve the Act’s objectives. But it’s not a blanket exemption. SMEs are still subject to fines, just calibrated to their circumstances. The Digital Omnibus agreement extends the same lower-of cap to small mid-cap enterprises, pending formal adoption.

What GDPR enforcement tells us

The AI Act is enforced by national competent authorities, much as GDPR is enforced by national data protection authorities. GDPR’s enforcement history offers useful signals for what to expect:

Enforcement will be uneven across member states. Some GDPR authorities (France’s CNIL, Ireland’s DPC, Italy’s Garante) have been far more active than others. Expect similar variation under the AI Act. Organisations with significant operations in enforcement-active jurisdictions face higher practical risk.

Early enforcement focuses on visible violations. The first GDPR fines targeted the most visible failures: inadequate consent mechanisms, data breach notification failures, large-scale processing without legal basis. For the AI Act, expect early enforcement to target easy-to-detect violations: undisclosed chatbots, prohibited practices, missing transparency labels.

Large fines come later. GDPR’s record fines (€1.2 billion against Meta, €746 million against Amazon) came years after the regulation took effect, as enforcement agencies built expertise and case law developed. The AI Act’s largest fines will likely follow a similar trajectory.

Complaints drive enforcement. Many GDPR investigations started with individual complaints. Under the AI Act, complaints from people affected by AI systems (job applicants screened by AI, customers interacted with by undisclosed chatbots, individuals subject to biometric processing) will likely trigger investigations.

Sectoral focus matters. GDPR enforcement has concentrated on specific sectors: adtech, social media, financial services. AI Act enforcement will likely focus on sectors with visible AI use: recruitment, financial services, healthcare, and customer-facing AI in large consumer platforms.

Beyond fines: other enforcement powers

Administrative fines aren’t the only consequence of non-compliance. National competent authorities have additional powers:

Corrective measures. Authorities can order organisations to bring their AI systems into compliance, modify or withdraw non-compliant systems from the market, or take other corrective action.

Market withdrawal. For high-risk AI systems that don’t meet the requirements, authorities can order the system to be withdrawn from the market entirely. For a provider whose revenue depends on that product, this is potentially more damaging than a fine.

Temporary bans. Authorities can prohibit the use of an AI system on a temporary basis while they investigate.

Public disclosure. Enforcement actions and decisions may be published, creating reputational damage that can exceed the financial penalty.

Prioritising your compliance investment

Given the tiered penalty structure, the rational approach to compliance investment follows the risk hierarchy:

Highest priority: prohibited practices. The penalties are the highest (7% of turnover), the violations are the easiest to detect, and there’s no grace period — these are already enforceable. Review your AI systems against Article 5 immediately.

Second priority: transparency obligations. These are enforceable from 2 August 2026 (with AI-generated content marking from 2 December 2026), easy for regulators to detect, and relatively cheap to implement. There’s no excuse for non-compliance on chatbot disclosure or content labelling.

Third priority: high-risk compliance. The obligations are extensive, but they apply only to systems classified as high-risk. The investment is significant but justified by the penalty exposure (3% of turnover) and the reputational risk of a compliance failure involving a system that affects people’s employment, credit, or safety.

Ongoing: cooperation and documentation. Whatever the state of your compliance, maintain good documentation and cooperate fully with any regulatory inquiry. The factors that reduce fines — corrective action, cooperation, genuine compliance effort — are entirely within your control.

The penalty framework is designed to make compliance the rational economic choice. For most businesses, the cost of compliance is a fraction of the potential penalties. The organisations that will face the largest fines are those that made a deliberate choice to ignore the Act — or failed to give it any attention at all.

Frequently asked questions

What is the maximum penalty under the EU AI Act?

€35 million or 7% of global annual turnover, whichever is higher — the top tier, reserved for prohibited practices under Article 5. Most other obligations — high-risk systems, GPAI models, and Article 50 transparency — carry up to €15 million or 3%. Supplying incorrect, incomplete or misleading information to authorities or notified bodies: up to €7.5 million or 1%. For SMEs and startups, each cap flips to whichever of the two figures is lower (Article 99(6)).

What are the monetary fines for violating prohibited practice obligations under the EU AI Act?

Up to €35 million or, for a company, up to 7% of total worldwide annual turnover for the preceding financial year — whichever is higher (Article 99(3)). For a company with €1 billion in revenue, that is a potential €70 million fine. The Article 5 prohibitions have applied since 2 February 2025, so these fines are already enforceable. For SMEs and startups the cap is the lower of the two figures: a startup with €2 million turnover faces a maximum of €140,000, not €35 million.

How are EU AI Act fines actually calculated?

Maximums are ceilings, not defaults. Article 99 requires authorities to weigh the nature, gravity and duration of the infringement; whether it was intentional or negligent; steps taken to mitigate harm; the technical and organisational measures in place; previous infringements; cooperation with the authority; and any economic benefit gained. Fines must be 'effective, proportionate and dissuasive', so they are also scaled to the entity's financial strength.

Are there reduced penalties for SMEs and startups?

Yes. Article 99(6) caps each fine for SMEs, including startups, at the percentage or the fixed amount, whichever is lower — the reverse of the rule for everyone else, where the higher figure applies. Article 99(1) also requires Member States' penalty rules to take account of SMEs' interests and economic viability. It is a real cap, not an exemption — SMEs are still subject to fines.

Can the EU AI Act penalise you beyond fines?

Yes. National authorities can order corrective measures, require a non-compliant high-risk system to be withdrawn from the market, impose a temporary ban on its use while they investigate, and publish enforcement decisions — and the resulting reputational damage can exceed the fine itself.

Written by
John Pitchers
John Pitchers
Founder, ComplyDrive

John holds editorial responsibility for all ComplyDrive content.

About the author →
The Toolkit

The 47-item checklist, an editable tracker, nine sample documents and nine fill-in templates.

Get the Toolkit

Free worked document

Get a complete Article 26 AI System Register, free.

One of the nine worked documents from the toolkit. A finished Article 26 AI System Register for a high-risk AI deployment, completed end-to-end so you can see exactly what a completed register looks like instead of starting from a blank page. Enter your email and we'll send you the download link. Unsubscribe at any time.