EU AI Act penalties and fines explained
- Penalties are tiered: up to 35M euro / 7% (prohibited), 15M / 3% (most obligations), 7.5M / 1% (false information).
- For larger firms the fine is the higher of the sum or percentage; SMEs benefit from the lower cap.
- Providers of general-purpose AI models face a separate Article 101 fining regime enforced by the European Commission (up to 15M euro or 3%).
- As of mid-2026 no fine has yet been imposed under the AI Act by any authority, mirroring the quiet opening years of GDPR enforcement.
- Authorities can also order corrective measures or withdrawal from the EU market, not just fines.
- Current as of June 2026. This is general information, not legal advice.
The three penalty tiers
The Act's fines are structured in three main tiers:
- Up to 35 million euro or 7 percent of global annual turnover for breaching the prohibitions on unacceptable-risk AI practices. This is the most serious tier.
- Up to 15 million euro or 3 percent of worldwide annual turnover for breaches of the listed operator and notified-body obligations, including provider, importer, distributor and deployer duties and the Article 50 transparency obligations.
- Up to 7.5 million euro or 1 percent of global annual turnover for supplying incorrect, incomplete, or misleading information to authorities.
In each case, the fine is the higher of the fixed sum or the percentage for larger companies.
How SMEs and startups are treated
For large organisations each cap applies as the higher of the fixed sum or the percentage of worldwide annual turnover; for SMEs and startups the same caps apply as whichever of the two is lower, a deliberate proportionality mechanism.
Two regimes people miss
Providers of general-purpose AI models face a separate fining regime under Article 101, enforced directly by the European Commission, with fines up to 15 million euro or 3 percent of worldwide turnover. EU institutions and bodies face reduced caps, up to 1.5 million euro for prohibited-practice breaches and 750,000 euro otherwise, imposed by the European Data Protection Supervisor. And a fact worth knowing when calibrating risk: as of mid-2026 no fine has yet been imposed under the AI Act by any authority, a pattern that mirrors the quiet opening years of GDPR enforcement rather than an absence of intent.
Beyond fines
Penalties are not the only enforcement tool. Authorities and the AI Office can request information, require access to systems, order corrective measures, and in some cases require a system to be withdrawn from the EU market. For many organisations, the operational disruption of a withdrawal or a forced remediation can matter as much as a fine.
When penalties apply
The penalties framework took effect alongside the phased obligations, with rules for penalties to be laid down by Member States from 2 August 2025. The fines attach to the obligations as they come into force, so prohibited-practice and GPAI breaches are already exposed, while high-risk penalties track the high-risk obligations as they apply.
The constructive way to read this
Fines make the headlines, but the more useful framing is that the Act rewards organisations that can demonstrate good governance. The same evidence that protects you from penalties (a clear inventory, documented risk decisions, and current records) is exactly what enterprise buyers and partners increasingly ask to see. Building that evidence is both a shield against penalties and an enabler of trust and sales.
Key terms
- Article 99
- The EU AI Act article that sets the penalty framework and tiered fines for breaches.
- Unacceptable-risk practices
- The prohibited AI uses, breaches of which attract the highest tier of fine.
- Proportionate cap
- The lower of the fixed amount or percentage applied to SMEs and startups, instead of the higher.
- AI Office
- The European Commission body overseeing implementation and enforcement of the AI Act.
- Corrective measures
- Remedial steps an authority can require, including withdrawal of a system from the EU market.