Back to Blog Listing

EU AI Act Fines and Penalties Explained

EU AI Act Fines and Penalties Explained
Digital Colliers Oct 6, 2026 7 min read

EU AI Act Fines and Penalties

The headline number is well known: up to €35 million or 7% of worldwide annual turnover. What gets less attention is how the AI Act actually decides the size of a fine, which obligations sit in which tier, and why most companies are far more likely to face a fine for missing documentation or transparency duties than for a prohibited practice.

This guide explains the three penalty tiers, how authorities calculate fines, the rules for SMEs and start-ups, when each obligation becomes enforceable and what you can do now to reduce your exposure.

The three penalty tiers

Article 99 of the AI Act sets three tiers of administrative fines. In each tier, the maximum is a fixed amount or a percentage of the company's total worldwide annual turnover in the preceding financial year, whichever is higher.

Tier What it covers Maximum fine
1 Prohibited AI practices (Article 5) €35 million or 7% of worldwide annual turnover
2 Most other obligations: providers, deployers, importers, distributors, authorised representatives and notified bodies, including the high-risk requirements and the transparency duties in Article 50 €15 million or 3% of worldwide annual turnover
3 Supplying incorrect, incomplete or misleading information to notified bodies or national authorities €7.5 million or 1% of worldwide annual turnover

Tier 1 applies to the practices the Act bans outright, such as manipulative techniques that cause significant harm, social scoring, untargeted scraping of facial images to build recognition databases, emotion recognition at work and in education (with narrow exceptions) and certain uses of real-time remote biometric identification in public spaces. From 2 December 2026, two further practices are banned: AI that generates non-consensual intimate imagery of real people, and AI-generated child sexual abuse material.

Tier 2 is where most companies' real exposure sits. It covers the duties of deployers under Article 26, such as using a high-risk system according to its instructions, assigning human oversight and keeping logs, as well as the transparency duties for chatbots, deepfakes and AI-generated content.

Tier 3 punishes misleading regulators. It is a reminder that what you tell an authority during an investigation has to be accurate and complete.

Providers of general-purpose AI models are fined separately under Article 101, by the European Commission rather than national authorities, up to €15 million or 3% of worldwide annual turnover. The Commission can impose these fines from 2 August 2026.

How fines are calculated

The maximums are ceilings, not starting points. Article 99(7) lists the factors authorities must consider when deciding whether to fine a company and how much:

  • the nature, gravity and duration of the infringement and its consequences, taking into account the purpose of the AI system,
  • the number of people affected and the level of damage they suffered,
  • whether other authorities have already fined the same company for the same infringement,
  • the size, annual turnover and market share of the company,
  • any financial benefit gained or loss avoided through the infringement,
  • the degree of cooperation with the authority to remedy the infringement and reduce its effects,
  • the degree of responsibility, taking into account the technical and organisational measures the company had in place,
  • how the authority learned of the infringement, in particular whether the company reported it,
  • whether the infringement was intentional or negligent, and
  • any action taken to mitigate the harm to affected people.

Two of these factors are directly in your control: the measures you had in place before something went wrong, and how you behave once it does. A company that can show a documented AI inventory, a risk classification, working human oversight and a quick, transparent response to an incident is in a very different position from one that cannot.

Each Member State sets out its own detailed penalty rules within these limits and designates the market surveillance authorities that enforce them. Expect differences in enforcement style between countries, much as with GDPR.

Rules for SMEs and start-ups

The AI Act softens the rules for smaller companies in two ways.

First, for SMEs, including start-ups, the fine is capped at whichever of the two amounts is lower, not higher. For a company with €20 million turnover, a Tier 2 infringement is therefore capped at €600,000 (3% of turnover), not €15 million.

Second, the Digital Omnibus amendment (Regulation (EU) 2026/1744, in force since 27 July 2026) introduced a new category of small mid-cap companies, with fewer than 750 employees and an annual turnover of up to €150 million or a balance sheet total of up to €129 million. They also benefit from reduced penalty caps, simplified technical documentation and more proportionate quality management requirements.

Member States must also take the interests and economic viability of SMEs into account when setting their penalty rules. None of this exempts smaller companies from the obligations themselves. It only reduces the financial consequences.

When enforcement starts

The penalty provisions have applied since 2 August 2025. Which fines are possible today depends on which obligations already apply:

Since / from Enforceable obligations
2 August 2025 Prohibited practices (banned since February 2025)
2 August 2026 Transparency duties under Article 50, most remaining provisions, and Commission fines for providers of general-purpose AI models
2 December 2026 New prohibitions on non-consensual intimate imagery and AI-generated abuse material. Machine-readable marking for generative AI systems already on the market before August 2026
2 December 2027 High-risk systems listed in Annex III
2 August 2028 High-risk AI in products covered by Annex I

The high-risk dates were moved by the Digital Omnibus. The original deadline for Annex III systems was 2 August 2026.

For most companies, the obligations that can be enforced right now are the ban on prohibited practices and the transparency duties: telling people when they talk to a chatbot, labelling deepfakes and marking AI-generated content.

How to reduce your risk

You cannot remove regulatory risk completely, but you can cut it down substantially with a few steps that also make your AI systems easier to run.

  1. Build an AI inventory. List every AI system in use, including AI features inside standard software and tools employees use on their own. You cannot classify what you do not know about.
  2. Classify each system. Check it against the prohibited practices, the Annex III high-risk areas and the transparency duties. Write down the reasoning, especially when you decide a system is not high-risk.
  3. Fix transparency now. Add AI disclosures to chatbots and voice assistants, label deepfakes and set up machine-readable marking for generated content. These duties already apply.
  4. Plan the high-risk work. For systems in scope, start on risk management, logging, technical documentation and human oversight early. December 2027 leaves less time than most conformity projects need.
  5. Assign responsibility. Name an owner for each system and a central contact for AI compliance, and set up an incident process.
  6. Support AI literacy. Article 4 requires providers and deployers to take measures that support the AI literacy of their staff. Documented training shows those measures.
  7. Review vendor contracts. Make sure providers of the AI systems you use give you the instructions, documentation and logs you need to meet your deployer duties.

These measures are also exactly what Article 99(7) rewards: they show the technical and organisational measures you had in place and make it easier to respond quickly if something goes wrong.

Our EU AI Act compliance team helps companies build the inventory, classify their systems and close the gaps before the deadlines.

FAQ

Q: How much is the maximum EU AI Act fine? A: Up to €35 million or 7% of worldwide annual turnover, whichever is higher, for prohibited AI practices. Most other violations, including high-risk and transparency duties, are capped at €15 million or 3%.

Q: How are EU AI Act penalties calculated? A: Authorities weigh the nature, gravity and duration of the infringement, the number of people affected, the company's size and turnover, any financial benefit, whether it was intentional or negligent, the measures in place and the company's cooperation.

Q: Do the same fines apply to small companies? A: The tiers are the same, but for SMEs and start-ups the lower of the two amounts applies. Small mid-cap companies also benefit from reduced caps since the Digital Omnibus amendment.

Q: Can we be fined today? A: Yes, for prohibited practices, for breaches of the transparency duties that apply since 2 August 2026, and, for providers of general-purpose AI models, for their obligations. High-risk obligations follow from 2 December 2027.

Related Posts