EU AI Act guide · updated 2 August 2026

EU AI Act fines: the complete penalty guide

The EU AI Act borrows GDPR’s enforcement design and raises the ceiling. Article 99 sets three penalty tiers, each expressed as a fixed amount or a share of worldwide annual turnover — whichever is higher. Since 2 August 2026 the tiers are live for Annex III high-risk systems, which moves AI compliance from a policy discussion to a board-level number.

The three tiers

€35M or 7%

Prohibited practices (Article 5)

Manipulative or exploitative techniques causing harm, social scoring, untargeted facial-image scraping, emotion recognition in workplaces and schools, banned biometric categorisation and real-time remote biometric ID outside narrow exceptions. Banned since February 2025.

€15M or 3%

Obligation breaches — the tier most companies risk

Provider duties for high-risk systems (documentation, oversight, conformity), deployer duties under Article 26, transparency duties under Article 50, importer/distributor duties, and GPAI model-provider duties. Enforceable for Annex III systems since 2 August 2026.

€7.5M or 1%

Misleading information

Supplying incorrect, incomplete or misleading information to notified bodies or national authorities in reply to a request.

For a company with €500M global turnover, the middle tier alone is a €15M exposure per breach category — against remediation work that is typically a few weeks of structured documentation and process. The asymmetry is the business case.

How authorities size a fine

Article 99 requires proportionality: the nature, gravity and duration of the infringement, whether it was intentional or negligent, actions taken to mitigate, degree of cooperation, and prior findings all count. Two practical consequences follow. First, a documented compliance effort is itself mitigation — an inventory, dated classifications and a remediation plan materially change how an authority reads you. Second, obstruction is its own tier: answering an information request badly can cost €7.5M / 1% on top of the underlying issue.

Where exposure actually concentrates

  • Unclassified inventories.You cannot show an authority your posture if you don’t know which of your systems are high-risk in the first place. This is the cheapest gap to close and the worst one to be caught with.
  • Missing Annex IV documentation — the first document requested, and a per-system provider breach if absent. See the Annex IV guide.
  • Deployer blindness.Companies using vendor AI for hiring or credit assume the fine risk is the vendor’s. Article 26 breaches sit in the €15M / 3% tier and attach to the deployer.
  • Silent Article 50 gaps — undisclosed chatbots and unmarked synthetic content: trivial to fix, embarrassing to be fined for.

Get your fine-exposure picture per system, free

The free AnnexWise assessment classifies a system in about 10 minutes — risk tier, open obligations and a gap report, with article references throughout. It runs in your browser; answers never leave your device.

Run the free assessment →

The rational response to a penalty regime this asymmetric is not panic-buying a consultancy engagement — it is producing, this month, the paper trail that turns any future authority conversation into a short one: inventory, classification, gap report, remediation plan, documentation. That is exactly the sequence the compliance checklist walks through.

Frequently asked questions

Are EU AI Act fines higher than GDPR fines?

The top tier is. GDPR caps at €20M or 4% of global turnover; the AI Act's prohibited-practices tier reaches €35M or 7%. The middle tier — €15M or 3% — is where most real-world exposure sits, covering breaches of high-risk, transparency and GPAI obligations.

Who actually imposes the fines?

National market-surveillance authorities designated by each member state impose fines for most breaches; the European Commission (through the AI Office) can fine general-purpose AI model providers up to €15M or 3%. Which authority moves first will vary by country, exactly as it did under GDPR.

Do smaller companies pay the same fines?

The percentages and amounts are ceilings, and authorities must weigh proportionality — nature, gravity, duration, cooperation. For SMEs and startups the Act caps each tier at the lower of the fixed amount or the percentage, rather than the higher. What small companies cannot do is assume they're invisible: GDPR enforcement reached small firms within two years.

Fines aside, what else can authorities do?

Order corrective action, mandate withdrawal or recall of a system from the market, and demand documentation and access. For many businesses a forced market withdrawal is a bigger number than any fine — it stops revenue, not just adds cost.

Where does your AI system actually stand?

The free AnnexWise assessment classifies a system in about 10 minutes — risk tier, open obligations and a gap report, with article references throughout. It runs in your browser; answers never leave your device.

Run the free assessment →

Keep reading

AnnexWise is compliance software, not a law firm; this guide is general information about Regulation (EU) 2024/1689, not legal advice for your situation. Verdict logic is documented on the methodology page.