EU AI Act Fines Explained: A Plain-English Guide to Article 99 Penalties

If your compliance team has been benchmarking EU AI Act risk against GDPR, you need to recalibrate. The EU AI Act's top-tier fine - €35 million or 7% of total worldwide annual turnover, whichever is higher - deliberately exceeds GDPR's maximum of €20 million or 4% of turnover. That's not a drafting accident. The EU wanted a ceiling high enough to be felt by the world's largest technology companies, and it got one.
This guide breaks down exactly how the penalty structure works under Article 99, who has the power to impose fines, what the enforcement timeline looks like right now (including the Digital Omnibus caveat), and what practical steps reduce your exposure. It is not legal advice - for your specific situation, consult qualified counsel.
The Three-Tier Fine Structure Under Article 99
Article 99 of Regulation (EU) 2024/1689 establishes three tiers of administrative fines, each calibrated to the severity and category of the violation. The structure is deliberately GDPR-shaped - turnover-based so that penalties scale with corporate size - but with higher ceilings across the board.
| Tier | What Triggers It | Maximum Fine (Large Undertakings) | SME / Start-up Cap |
|---|---|---|---|
| Tier 1 — Prohibited Practices | Violations of Article 5 banned AI practices (social scoring, subliminal manipulation, real-time biometric ID, emotion recognition in workplaces/schools, etc.) | €35,000,000 OR 7% of total worldwide annual turnover — whichever is HIGHER | Lower of the two amounts |
| Tier 2 — Operator & Notified-Body Obligations | Non-compliance with provider (Art. 16), deployer (Art. 26), importer (Art. 23), distributor (Art. 24), authorised representative (Art. 22), notified-body (Arts. 31/33/34), or transparency (Art. 50) obligations | €15,000,000 OR 3% of total worldwide annual turnover — whichever is HIGHER | Lower of the two amounts |
| Tier 3 — Misleading Information | Supplying incorrect, incomplete or misleading information to notified bodies or national competent authorities in reply to a request | €7,500,000 OR 1% of total worldwide annual turnover — whichever is HIGHER | Lower of the two amounts |
Tier 1: Prohibited Practices (Article 5)
Non-compliance with the Article 5 prohibitions is subject to administrative fines of up to €35,000,000 or, if the offender is an undertaking, up to 7% of its total worldwide annual turnover for the preceding financial year, whichever is higher. The prohibited practices include social scoring by public authorities, AI systems that exploit the vulnerabilities of specific groups (children, people with disabilities, those in economic hardship), real-time remote biometric identification in publicly accessible spaces for law enforcement outside narrow exceptions, untargeted scraping of facial images to build recognition databases, emotion recognition in workplaces and educational institutions, and predictive policing based solely on profiling.
The "whichever is higher" clause is the critical detail. For a company with €5 billion in annual revenue, a Tier 1 violation could result in a fine of €350 million - ten times the nominal €35 million cap. The percentage calculation applies to the entire corporate group, not just the subsidiary operating the AI system.
Tier 2: High-Risk and Transparency Obligations
This is the tier most organisations will encounter in day-to-day compliance work. It covers the substantive obligations on providers of high-risk AI systems - risk management, technical documentation, data governance, logging, transparency, human oversight, and cybersecurity - as well as the transparency obligations under Article 50 (disclosing to users when they interact with AI systems, chatbots, and AI-generated content).
A practical note: failing to produce technical documentation under Article 11, failing to register a high-risk system, or failing to implement a quality management system all fall under Tier 2 at €15M / 3%.
Tier 3: Misleading Regulators
Supplying incorrect, incomplete or misleading information to notified bodies or national competent authorities in reply to a request is subject to administrative fines of up to €7,500,000 or 1% of total worldwide annual turnover, whichever is higher. This tier is deliberately lower because the offence is procedural rather than substantive - but it is still material. Incomplete training-data documentation provided during an investigation, for example, can trigger Tier 3 on top of any underlying Tier 2 violation.
Double exposure is real. Incomplete or inaccurate technical documentation can simultaneously trigger Tier 2 (non-compliance with provider obligations) and Tier 3 (misleading information to authorities). And if the same AI system also processes personal data unlawfully, GDPR fines can stack on top — Article 99 fines do not replace GDPR penalties.
The SME and Start-up Carve-Out
For SMEs and start-ups, Article 99(6) reverses the "whichever is higher" rule: the fine is capped at the lower of the fixed euro amount and the percentage of turnover - the more favourable figure applies. This is a meaningful concession. A start-up with €2 million in annual revenue faces a maximum Tier 1 fine of €140,000 (7% of €2M) rather than €35 million.
That said, proportionality has limits. A €140,000 fine for a seed-stage company could still be existential. And the SME carve-out applies to the calculation of the fine, not to the underlying obligation - a small company that deploys a prohibited AI practice is still in breach.
The Digital Omnibus provisional agreement (see below) also extends simplified compliance frameworks - including proportionate penalties - to "small mid-cap" companies with up to 750 employees and €150 million in annual revenue, a new category that goes beyond the traditional SME definition.
GPAI Providers: A Separate Regime Under Article 101
General-purpose AI model providers - think foundation model developers - operate under a parallel enforcement regime. Under Article 101, the European Commission can fine GPAI model providers up to €15,000,000 or 3% of their total worldwide annual turnover in the preceding financial year, whichever is higher, for intentionally or negligently infringing the AI Act's GPAI obligations, failing to comply with information requests, or refusing access for model evaluations.
The structural difference from Article 99 is significant: GPAI fines are imposed by the Commission directly (through the AI Office), not by national market surveillance authorities. The AI Office's formal enforcement powers against GPAI model providers come into force on 2 August 2026. Until that date, the AI Office can engage informally with providers; after it, the office can compel.
Who Enforces the AI Act?
Enforcement is split across three distinct bodies, and knowing which one has jurisdiction over your organisation matters.
MSAs have broad investigative powers. They can request documentation, conduct on-site inspections, carry out technical testing of AI systems, and take interim measures - including ordering market withdrawal or recall of non-compliant systems - where there is a serious risk. Member States can appoint any type of public entity (competition authority, data protection authority, cybersecurity agency) to perform MSA functions, so the specific regulator you face will vary by country and sector.
The Enforcement Timeline - and the Omnibus Caveat
The AI Act does not land all at once. Here is where things currently stand:
| Date | What Became Enforceable |
|---|---|
| 2 February 2025 | Article 5 prohibited practices - already enforceable |
| 2 August 2025 | GPAI model obligations (Chapter V) - already enforceable |
| 2 August 2026 | MSA enforcement powers; Article 50 transparency obligations; Article 101 GPAI fines |
| 2 December 2027 (if Omnibus adopted) | High-risk Annex III obligations (biometrics, critical infrastructure, employment, education, migration, etc.) |
| 2 August 2028 (if Omnibus adopted) | High-risk Annex I obligations (AI embedded in regulated products - medical devices, lifts, toys, etc.) |
The Digital Omnibus caveat: On 7 May 2026, the Council of the EU and the European Parliament reached a provisional political agreement that would defer high-risk Annex III obligations from 2 August 2026 to 2 December 2027, and Annex I obligations from 2 August 2027 to 2 August 2028. As of June 2026, the Digital Omnibus is a provisional political agreement - it is not yet formally adopted law. Formal adoption is expected before 2 August 2026, but the new deadlines only bind once the Omnibus is published in the Official Journal.
Critically, the Omnibus does not reduce or defer the penalty levels themselves. It also does not touch the prohibited-practices ban (in force since February 2025), the GPAI rules (in force since August 2025), or most Article 50 transparency obligations (proceeding as scheduled from 2 August 2026). The delay is a deferral, not a dismantling.
Plan against 2 December 2027 for Annex III high-risk systems, but confirm formal Omnibus adoption before treating it as settled law. The prohibited-practices ban and GPAI rules are already live and unchanged — enforcement exposure on those provisions exists today.
How Fines Are Actually Calculated
The figures above are maxima. Article 99(7) requires authorities to weigh all relevant circumstances when deciding whether to impose a fine and at what level. Key factors include:
- Nature, gravity, and duration of the infringement - including the number of affected persons and the level of harm suffered
- Intent or negligence - deliberate violations attract higher fines than good-faith compliance failures
- Self-reporting - how the infringement came to the authority's attention (self-reported vs. discovered during inspection)
- Cooperation - the degree to which the operator cooperated with the investigation
- Corrective action - steps taken to mitigate damage to affected persons
- Prior infringements - whether the same operator has been fined before, by any authority, for related conduct
- Size and market share - the operator's scale and economic position
- Double-counting protection - whether other authorities have already fined for the same infringement
Good-faith compliance efforts with documented gaps will be treated more favourably than systemic non-compliance. Documented evidence of a functioning AI governance programme - risk assessments, technical documentation, incident response procedures - is not just a compliance artefact; it is a mitigating factor in any enforcement proceeding.
Member States are required to report annually to the Commission on the administrative fines they have issued, along with any related litigation or judicial proceedings. This creates a public record that will, over time, reveal how different national MSAs are calibrating penalties - useful intelligence for compliance teams tracking enforcement trends.
Your Exposure, Calculated
Use this interactive tool to estimate your potential fine exposure across all three tiers based on your organisation's annual revenue.
Five Practical Steps to Reduce Your Exposure
The AI Act's penalty framework is designed to be dissuasive, not confiscatory. Authorities have discretion, and that discretion is exercised in favour of organisations that can demonstrate genuine compliance effort. Here is where to focus:
Map your AI systems now. You cannot classify risk, assign obligations, or build documentation for systems you have not inventoried. Start with a complete register of every AI system your organisation develops, deploys, or procures - standalone, embedded, internally built, and vendor-supplied.
Treat Article 5 as a hard line. The prohibited-practices ban has been enforceable since February 2025. If any system in your portfolio touches social scoring, emotion recognition in workplaces or schools, untargeted facial-image scraping, or subliminal manipulation, the exposure is live today - not in 2027.
Build your documentation trail. Technical documentation, risk assessments, conformity declarations, and quality management records are both a compliance requirement and a mitigating factor in enforcement. Automated logging, version control, and decision traceability provide the evidence base that demonstrates ongoing compliance.
Establish an incident-reporting process. Failure to report a serious incident within the required window is itself a Tier 2 violation that compounds the underlying incident. Define escalation pathways, assign responsibility, and template your regulatory notifications before you need them.
Self-report where appropriate. How an infringement comes to an authority's attention is an explicit factor in fine calculation. Proactive disclosure of a compliance gap - before an inspection surfaces it - is treated more favourably than discovery. Build internal processes that surface issues early enough to make that choice.
The Bottom Line
The EU AI Act's penalty regime is the most consequential AI compliance framework in force anywhere in the world. The prohibited-practices ban is already live. GPAI enforcement powers activate in August 2026. High-risk obligations are deferred - but only provisionally, and only for Annex III and Annex I systems. The fine levels themselves are not being reduced.
The organisations that will fare best in enforcement proceedings are those that started building governance infrastructure early, documented their decisions, and treated compliance as a continuous programme rather than a point-in-time exercise.
This post is for informational purposes only and does not constitute legal advice. Consult qualified legal counsel for advice specific to your organisation's situation.
Related reading

Harmonised Standards and Presumption of Conformity Under the EU AI Act: A Plain-English Guide to Articles 40 and 41
What "presumption of conformity" actually buys you under Articles 40 and 41, why the CEN-CENELEC standards are delayed, and what high-risk AI providers must do right now.

EU AI Act Article 9: A Plain-English Guide to the Risk Management System for High-Risk AI
Article 9 of the EU AI Act requires a continuous, lifecycle-wide risk management system for every high-risk AI system. Here's exactly what that means and how to build one.

Article 22 EU AI Act: The Plain-English Guide to Authorised Representatives for Non-EU Providers
If you build high-risk AI outside the EU and want to sell into the EU market, Article 22 requires you to appoint an EU authorised representative by written mandate - before you go live. Here's exactly what that means.