Penalties GuideEU AI Act

EU AI Act penalties and fines

Map AI Act penalty exposure to the exact infringement tier: banned practices, high-risk operator duties, transparency duties, incorrect information, and GPAI model obligations.

Use Article 99 as the starting point, then separate Member State penalty rules, SME and startup proportionality, Union-body fines, and Commission fines for general-purpose AI model providers.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 26, 2026
Sections
6

Structured answer sets in this page tree.

Primary sources
8

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 26, 2026
Overview

The EU AI Act has three main maximum fine tiers: EUR 35 million or 7%, EUR 15 million or 3%, and EUR 7.5 million or 1%, with turnover alternatives for undertakings and a lower-cap rule for SMEs and startups. These are maximums, not automatic fines. Member State rules determine national enforcement, Article 100 covers Union bodies, and Article 101 creates a separate Commission route for general-purpose AI model providers.

Section 1

Article 99 fine tiers

Start every penalties review by identifying the relevant AI Act obligation and actor. applies to operators and notified bodies, while Article 101 separately addresses providers of general-purpose AI models.

For undertakings, each tier uses the greater of the fixed euro amount or the applicable percentage of total worldwide annual turnover for the preceding financial year. For SMEs, including startups, Article 99 uses the lower of the fixed amount or turnover percentage for the relevant tier.

Chapter XII, including and Article 100, has applied since 2 August 2025, but Article 101 is expressly excluded from that early date and applies from 2 August 2026. A penalty provision being in force does not make an underlying obligation applicable earlier than its own staged date.

The turnover percentages use total worldwide annual turnover for the preceding financial year. Do not substitute EU turnover, revenue for the affected product, or the current partial year. Keep the legal-entity and undertaking analysis used for the calculation, the financial source, the relevant year, and any SME or startup evidence with the exposure record.

  • Article 5 prohibited practices: up to EUR 35,000,000 or up to 7% of total worldwide annual turnover, whichever is higher for undertakings.
  • Specified operator and notified-body obligations, including provider, authorised representative, importer, distributor, deployer, notified-body, and Article 50 transparency duties: up to EUR 15,000,000 or up to 3% of worldwide annual turnover, whichever is higher for undertakings.
  • Supplying incorrect, incomplete, or misleading information to notified bodies or national competent authorities in response to a request: up to EUR 7,500,000 or up to 1% of worldwide annual turnover, whichever is higher for undertakings.
  • For SMEs and startups, the relevant fine is capped at the lower of the fixed euro amount or the turnover percentage.
Section 2

Highest exposure: prohibited AI practices

The largest tier is tied to non-compliance with Article 5 prohibited AI practices. Ordinary high-risk AI non-compliance falls outside this tier unless the conduct also meets an Article 5 prohibition.

Penalty triage should therefore begin with an Article 5 screen before moving to high-risk, transparency, or GPAI duties. If the system, feature, deployment context, or customer use case could fall into Article 5, escalate before launch or continued use.

Regulation (EU) 2026/1744 adds Article 5 prohibitions for specified non-consensual intimate material and child sexual abuse material. Those additions apply from 2 December 2026. Once applicable, non-compliance falls within the same (3) maximum tier because Article 99(3) covers non-compliance with Article 5.

  • Screen for manipulative or deceptive techniques that materially distort behaviour and cause or are reasonably likely to cause significant harm.
  • Screen for exploitation of age, disability, or social or economic vulnerability that materially distorts behaviour and causes or is reasonably likely to cause significant harm.
  • Screen for social scoring, certain criminal-offence risk prediction based solely on profiling or personality traits, untargeted facial-image scraping, workplace or education emotion inference, and sensitive biometric categorisation.
  • Treat real-time remote biometric identification by law enforcement in publicly accessible spaces as a specialised Article 5 issue with strict conditions, safeguards, and national-law dependencies.
  • From 2 December 2026, screen provider-side intended or reasonably foreseeable and reproducible generation of the specified prohibited material, the adequacy of technical safeguards, and deployer use for the prohibited purpose.
Section 3

Other operator duties and incorrect information

Under itself, the EUR 15,000,000 or 3% tier covers only the obligations listed in Article 99(4), including duties for key high-risk value-chain actors and Article 50 transparency duties for certain AI systems. For operators under the AI Office's exclusive competence, Article 75c applies that tier to infringement of any applicable AI Act provision, including provisions not listed in Article 99(4).

Under itself, the EUR 7,500,000 or 1% tier is specifically about supplying incorrect, incomplete, or misleading information to notified bodies or national competent authorities in reply to a request. Article 75c applies the same tier to incorrect, incomplete, or misleading information supplied to the AI Office. Do not describe this as a general paperwork fine; the trigger is the requested information response.

  • Provider duties under Article 16 belong in the 15 million euro or 3% tier when applies.
  • Authorised representative, importer, distributor, deployer, and specified notified-body duties also sit in the 15 million euro or 3% tier.
  • Article 50 transparency duties for providers and deployers are expressly included in the 15 million euro or 3% tier.
  • Authority-response workflows should preserve the request, legal basis, supplied information, reviewer approvals, and correction history because incorrect, incomplete, or misleading responses have their own tier.
Section 4

Member State rules and proportionality factors

requires Member States to lay down rules on penalties and other enforcement measures. Those measures may include warnings and non-monetary measures, and Member States must notify the Commission of their rules and later amendments.

does not set one EU-wide rule for fines on national public authorities and bodies. Each Member State must decide the extent to which those entities may receive administrative fines, and national legal systems may assign fine decisions to competent courts or other bodies.

requires authorities to assess the circumstances of each case, including nature, gravity, duration, consequences, affected persons, damage, prior fines for the same activity or omission, operator size, turnover, market share, financial benefit, cooperation, responsibility, notification, intent or negligence, and mitigation.

  • Check the applicable Member State rules before stating who imposes a fine or whether public authorities can be fined.
  • Distinguish national public authorities from Union institutions, bodies, offices, and agencies; Article 100 gives the European Data Protection Supervisor the Union-body route.
  • Record whether the issue affects one Member State, several Member States, or EU-level GPAI supervision.
  • Keep mitigation evidence close to the infringement record: containment steps, affected-person remediation, authority cooperation, corrective actions, and governance changes.
  • Avoid unsupported claims that a specific national authority will fine a company unless the relevant Member State rule or authority action is actually sourced.
Section 5

GPAI model provider fines are separate

General-purpose AI model providers need a separate Article 101 assessment. The Commission may impose fines of up to 3% of annual total worldwide turnover in the preceding financial year or EUR 15,000,000, whichever is higher.

Article 101 covers intentional or negligent infringements, failures to comply with Commission requests for documents or information, incorrect, incomplete, or misleading information, failures to comply with requested measures, and failures to provide model access for evaluations. The Commission must communicate its preliminary findings and give the provider an opportunity to be heard before adopting a fine decision.

Article 101 applies from 2 August 2026. The SME lower-cap formula does not appear in Article 101, so do not import it into a GPAI calculation; Article 101 instead requires proportionality and appropriateness and directs the Commission to consider relevant commitments.

  • Separate AI system operator duties from GPAI model provider duties in the enforcement register.
  • For GPAI documentation, track Article 53 technical documentation, downstream-provider information, copyright policy, and public training-content summary obligations.
  • For GPAI models with systemic risk, track Article 55 risk assessment, mitigation, serious-incident, cybersecurity, and reporting obligations separately from ordinary GPAI documentation duties.
  • Preserve Commission and AI Office requests, response deadlines, supplied documents, access decisions, and model-evaluation correspondence because Article 101 directly covers failures around these requests.
Section 6

Penalty exposure checklist

This checklist is relevant when a launch, incident, authority request, supplier change, model update, or customer deployment raises AI Act penalty questions.

The goal is to classify the exposure without overstating enforcement. Record what is known, what is not sourced yet, and which authority route is relevant.

For Union institutions, bodies, offices, and agencies, Article 100 creates a separate route handled by the European Data Protection Supervisor: up to EUR 1,500,000 for Article 5 prohibited practices and up to EUR 750,000 for other requirements or obligations. These caps do not answer whether a national public authority may be fined; that question remains subject to the relevant Member State's rules.

Administrative fines do not replace other consequences. allows warnings and non-monetary measures under Member State rules, and the Act's market-surveillance provisions can require correction, restriction, withdrawal, recall, or disabling. Contractual claims, liability, employment consequences, data-protection enforcement, and sector-specific remedies arise under their own legal bases and are outside the Article 99 tier calculation.

What is the maximum AI Act fine for prohibited AI practices?

Under , non-compliance with Article 5 prohibited AI practices can be fined up to EUR 35,000,000 or, for undertakings, up to 7% of total worldwide annual turnover for the preceding financial year, whichever is higher. For SMEs and startups, the Article 99 lower-cap rule applies.

Is the incorrect-information fine 1% or 1.5% under ?

(5) of Regulation (EU) 2024/1689 states EUR 7,500,000 or, for undertakings, up to 1% of total worldwide annual turnover for supplying incorrect, incomplete, or misleading information to notified bodies or national competent authorities in reply to a request.

Do Member States set their own AI Act penalty rules?

Yes. requires Member States to lay down rules on penalties and other enforcement measures, which may include warnings and non-monetary measures, and to notify the Commission of those rules and later amendments.

Are GPAI model provider fines handled under the same table?

No. From 2 August 2026, GPAI model providers have a separate Article 101 route under which the Commission may impose fines of up to 3% of annual total worldwide turnover for the preceding financial year or EUR 15,000,000, whichever is higher, for intentional or negligent failures covered by that article. Article 101 does not repeat 's SME lower-cap formula.

What are the AI Act fine caps for EU institutions and bodies?

Article 100 allows the European Data Protection Supervisor to fine Union institutions, bodies, offices, and agencies up to EUR 1,500,000 for non-compliance with Article 5 prohibited practices and up to EUR 750,000 for other AI Act requirements or obligations. National public authorities are different: each Member State sets the extent to which administrative fines may apply to public authorities and bodies established in that Member State.

  • Identify the actor: provider, deployer, product manufacturer, authorised representative, importer, distributor, notified body, public authority, Union body, or GPAI model provider.
  • Classify the trigger: Article 5 prohibited practice, (4) listed obligation, Article 99(5) authority-response information issue, Article 75c AI Office-supervised operator issue, Article 100 Union-body issue, or Article 101 GPAI model provider issue.
  • Calculate only the sourced maximum tier and label it as a maximum, not an expected fine.
  • Apply the SME or startup lower-cap rule where the entity qualifies, and keep evidence of the SME/startup status used for the calculation.
  • Collect proportionality evidence: harm, number of affected persons, duration, intent or negligence, cooperation, mitigation, prior authority actions, turnover, market share, and benefit gained or loss avoided.
  • Check Member State penalty rules before naming a national authority, public-sector fine exposure, court route, warning route, or non-monetary measure.
Primary sources

References and citations

ai-act-service-desk.ec.europa.eu
Referenced sections
  • Official AI Act Service Desk source URL for Article 50, which Article 99 includes in the 15 million euro or 3% penalty tier.
"Transparency obligations for providers and deployers of certain AI systems"
ec.europa.eu
Referenced sections
  • Code of Practice transparency chapter describing model documentation and downstream-provider information commitments for GPAI providers using the Code.
"drawing up and keeping up-to-date model documentation"
eur-lex.europa.eu
Referenced sections
  • Primary source for market-surveillance corrective measures, Article 99 penalties, Article 100 Union-body fines, Article 101 GPAI model provider fines, and SME lower-cap treatment.
"whichever is higher"
eur-lex.europa.eu
Referenced sections
  • Articles 53, 55, 88 to 93, and 101 ground GPAI model provider obligations, Commission supervision powers, and GPAI fine exposure.
"Fines for providers of general-purpose AI models"
eur-lex.europa.eu
Referenced sections
  • Supports the added content-related prohibitions and their 2 December 2026 application date; Article 99(3) supplies the maximum fine tier for Article 5 non-compliance.
eur-lex.europa.eu
Referenced sections
  • Binding amendment used for the added Article 5 content prohibitions, their 2 December 2026 application date, and the Article 75c penalty route for operators under the AI Office's exclusive competence.
Related guides

Explore more topics

Are industry AI use cases high-risk under EU AI Act Annex III?
FAQ answer on when an industry AI use case falls under EU AI Act Annex III, how Article 6 classification works, when Article 6(3) can support a non-high-risk conclusion, and what evidence providers should keep.
EU AI Act AI System Classification Edge Cases FAQ
Answers for EU AI Act edge cases: AI system definition, inference versus simple rules, GPAI models, embedded products, territorial scope, roles, and classification evidence.
EU AI Act Applicability and Roles: Scope, Actor Map, and Evidence
Determine whether the EU AI Act applies to an AI system or GPAI model, map provider, deployer, importer, distributor, and product manufacturer roles, and record evidence for classification.
EU AI Act applicability test: scope, role, and risk classification
Stepwise EU AI Act applicability test for AI-system status, exclusions, territorial scope, operator role, prohibited uses, high-risk systems, GPAI models, transparency duties, and evidence records.
EU AI Act Article 5 Prohibited AI Practices Screening Guide
Screen AI systems against EU AI Act Article 5, including manipulation, social scoring, biometrics, law enforcement, and the new prohibited-content category.
EU AI Act Article 50 transparency disclosures FAQ
Article 50 FAQ for EU AI Act transparency duties covering chatbot notices, synthetic content marking, biometric and emotion notices, deepfakes, public-interest text, timing, accessibility, and exceptions.
EU AI Act Article 50 transparency, labeling, and user disclosures
Source-backed guide to EU AI Act Article 50 duties for user interaction notices, synthetic content marking, deepfake labels, emotion recognition notices, biometric categorisation notices, and related high-risk AI instructions for use.
EU AI Act Article 73 serious incident FAQ
FAQ on EU AI Act serious incident handling for high-risk AI systems, including Article 73 reporting, deployer escalation, corrective action, and GPAI systemic-risk distinctions.
EU AI Act Compliance Checklist by Risk Class
A practical EU AI Act checklist for classifying AI systems, assigning operator roles, screening prohibited practices, and collecting evidence for high-risk, GPAI, transparency, monitoring, and incident duties.
EU AI Act Compliance Program: roles, high-risk evidence, GPAI and incidents
Build an EU AI Act compliance program around provider, deployer, importer, distributor, high-risk, GPAI, transparency, monitoring, and incident evidence duties.
EU AI Act conformity assessment and notified bodies for high-risk AI
Source-backed guide to EU AI Act high-risk AI conformity assessment routes, provider evidence, EU declaration of conformity, CE marking, and notified body involvement.
EU AI Act deadlines and compliance calendar | Article 113 dates
EU AI Act compliance calendar for Regulation (EU) 2026/1744, Article 113 dates, Article 111 transitions, GPAI enforcement, Article 50, and high-risk systems.
EU AI Act FAQ: scope, roles, high-risk AI, GPAI, FRIA, and dates
Source-backed EU AI Act FAQ covering scope, roles, risk classification, GPAI, transparency, AI literacy, rights and complaints, sandboxes, authorities, SME provisions, and current legal status.
EU AI Act FRIA FAQ: Article 27 Scope, Contents, and Notification
Source-backed FAQ on when Article 27 requires a fundamental rights impact assessment, which deployers are covered, what the FRIA must contain, and how it relates to DPIAs and registration.
EU AI Act FRIA for high-risk AI systems: Article 27 scope and evidence
Source-backed guide to EU AI Act Article 27 fundamental rights impact assessments: who must run a FRIA, Article 6(2) triggers, Annex III carveouts, DPIA overlap, notification, and registration evidence.
EU AI Act GPAI and Systemic-Risk Duties: Article 53 and 55 FAQ
FAQ on EU AI Act duties for general-purpose AI model providers, including Article 53 documentation, copyright and training-summary duties, Article 55 systemic-risk duties, serious incidents, cybersecurity, and staged enforcement.
EU AI Act GPAI evidence pack checklist for Article 53 and 55
Build a source-backed evidence pack for EU AI Act GPAI model obligations: technical documentation, downstream information, copyright policy, training-content summary, and systemic-risk records where applicable.
EU AI Act GPAI Provider Obligations: Articles 53 and 55
Source-backed guide to EU AI Act duties for general-purpose AI model providers: Article 53 documentation, copyright policy, training-content summary, downstream information, and Article 55 systemic-risk controls.
EU AI Act High-Risk AI Requirements: Articles 8-16 and 26
Map the EU AI Act requirements for high-risk AI systems: risk management, data governance, technical documentation, logs, transparency, human oversight, accuracy, robustness, cybersecurity, and deployer duties.
EU AI Act high-risk AI use cases by industry | Article 6 and Annex III guide
Industry-by-industry guide to EU AI Act high-risk classification under Article 6, Annex III, Annex I product safety routes, exclusions, and provider/deployer boundaries.
EU AI Act high-risk conformity assessment route selector
Select the EU AI Act Article 43 conformity assessment route for a high-risk AI system, including Annex I product legislation, Annex III categories, notified body triggers, standards, declaration, CE marking, registration, and evidence.
EU AI Act high-risk requirements checklist: Articles 8-15
Checklist for EU AI Act high-risk AI system requirements in Articles 8-15: risk management, data governance, documentation, logs, transparency, human oversight, accuracy, robustness, and cybersecurity.
EU AI Act post-market monitoring and serious incident reporting
Source-backed guide to EU AI Act Articles 72 and 73 for high-risk AI: monitoring plans, serious incident reporting, deployer escalation, corrective action, and GPAI distinctions.
EU AI Act post-market monitoring FAQ for high-risk AI systems
Answer to how providers and deployers should handle EU AI Act post-market monitoring for high-risk AI systems under Article 72, with serious-incident, log, corrective-action, and lifecycle-change triggers.
EU AI Act provider vs deployer role boundaries: Article 3 and Article 25 FAQ
FAQ on EU AI Act provider, deployer, operator, importer, distributor, authorised representative, product manufacturer, downstream provider, and GPAI model provider boundaries.
EU AI Act risk classification intake workflow
A source-based intake structure for classifying EU AI Act scope, prohibited practices, high-risk routes, Annex III use cases, GPAI model status, roles, and reassessment triggers.
EU AI Act serious incident reporting triage workflow: Article 73 and Article 55
Triage EU AI Act serious incidents by definition, actor, reporting route, deadline, deployer escalation, corrective action, and separate GPAI systemic-risk reporting.
EU AI Act Technical Documentation and Provider Evidence Templates
Build AI Act evidence templates for high-risk AI providers: Article 11 technical documentation, Annex IV fields, quality management, conformity, CE marking, registration, logs, and post-market monitoring.
EU AI Act technical documentation FAQ | Article 11 and Annex IV
What Article 11 and Annex IV require in high-risk AI technical documentation: system identity, intended purpose, architecture, data, testing, oversight, cybersecurity, conformity, and post-market monitoring.
EU AI Act Timeline Roadmap: Dates, Legal Status, Owners, and Evidence
Turn EU AI Act milestones into an implementation roadmap by separating enacted dates, political agreements, draft guidance, consultations, and voluntary codes, then assigning actions and evidence.
EU AI Act vs ISO/IEC 42001: legal duties, controls, and evidence limits
Compare the EU AI Act and ISO/IEC 42001:2023, including legal status, Article 17 quality management, high-risk duties, GPAI, evidence reuse, and assurance limits.
EU AI Act vs NIST AI RMF: legal duties, risk controls, and evidence boundaries
Compare the EU AI Act with NIST AI RMF 1.0 across legal status, GOVERN-MAP-MEASURE-MANAGE, high-risk duties, GPAI, evidence reuse, and revision limits.
FAQ: EU AI Act conformity assessment procedures and notified body selection
cited FAQ on EU AI Act Article 43 conformity assessment routes, Annex VI internal control, Annex VII notified-body review, CE marking, declarations, and registration.