PENALTIES & ENFORCEMENT

The cost of EU AI Act non-compliance

Understand EU AI Act fines, turnover-based caps, non-monetary enforcement and the wider business risks of non-compliance.

9 min readReviewed October 2026
In brief

The headline figures are maximum fine thresholds, not automatic invoices. The applicable cap depends on the breach, the organisation's status and worldwide turnover, while the actual sanction must be proportionate to the facts.

Maximum fines at a glance

Articles 99 and 101 set maximum administrative-fine thresholds. For an undertaking that is not an SME, Article 99 generally uses the higher of the fixed euro amount or the percentage of total worldwide annual turnover for the preceding financial year. These are ceilings: an authority must still decide whether to fine and determine a proportionate amount.

The legal category matters. Article 99 covers AI-system operators and notified bodies, while Article 101 creates a separate regime for providers of general-purpose AI models. Confirm the applicable article and the organisation's role before estimating exposure.

Prohibited AI practices€35 millionor 7% of worldwide annual turnover

The highest Article 99 tier applies to non-compliance with the prohibitions in Article 5.

Listed operator obligations€15 millionor 3% of worldwide annual turnover

Covers listed duties for providers, deployers, importers, distributors, authorised representatives, notified bodies and Article 50 transparency.

Incorrect or misleading information€7.5 millionor 1% of worldwide annual turnover

Applies when incorrect, incomplete or misleading information is supplied in response to an authority or notified-body request.

General-purpose AI model providers€15 millionor 3% of worldwide annual turnover

Article 101 covers intentional or negligent breaches, failures to cooperate, requested measures or model-access obligations.

For Article 99 fines, SMEs including start-ups use the lower of the fixed amount and percentage. Small mid-cap companies receive the lower cap for the €15 million/3% and €7.5 million/1% tiers. Article 101 for GPAI providers has its own rules.

What the percentages can mean in practice

Turnover percentages can produce very different ceilings. The examples below apply the Article 99 formula only; they do not predict the fine an authority would impose and do not determine whether an organisation qualifies as an SME.

  • Qualifying SME with €10 million worldwide turnover: the percentage caps would be €700,000, €300,000 and €100,000 because Article 99 uses the lower amount for SMEs.
  • Non-SME undertaking with €100 million worldwide turnover: the fixed caps are higher, so the three ceilings would be €35 million, €15 million and €7.5 million.
  • Non-SME undertaking with €1 billion worldwide turnover: the percentage caps are higher, producing ceilings of €70 million, €30 million and €10 million.

Do not budget from revenue alone. The meaning of an ‘undertaking’, the relevant worldwide turnover and SME or small mid-cap status can require a fact-specific legal and corporate analysis.

How an authority decides the actual fine

A maximum cap is not the amount automatically payable. Article 99 requires consideration of the circumstances of the case, and penalties must be effective, proportionate and dissuasive. The applicable national penalty rules and enforcement procedure also matter.

  • Nature, gravity and duration of the infringement and its consequences.
  • Number of affected people and the level of damage they suffered.
  • Organisation size, market share and the economic benefit gained or loss avoided.
  • Cooperation with the authority, mitigation, reporting and corrective action.
  • Previous infringements and penalties already imposed for the same conduct under other EU or national law.

The risk is wider than the fine

Member States may use warnings and non-monetary measures as well as administrative fines. Supervisors can investigate, request information and require corrective action. Depending on the case, a non-compliant system or model can face restricted availability, withdrawal, recall or prohibition, which may be more disruptive than the financial penalty itself.

One AI use can also engage other regimes, including data protection, consumer protection, employment, product-safety and equality law. The AI Act does not replace those rules, so the same underlying conduct can create parallel regulatory, contractual or litigation exposure.

  • Suspension, redesign or removal of an AI-enabled product or workflow.
  • Investigation costs, management time and urgent evidence collection.
  • Customer claims, procurement exclusions, contract disputes and remediation costs.
  • Loss of trust with customers, employees, partners and investors.

Who enforces the rules and when

National competent authorities generally supervise AI systems. The European Commission's AI Office enforces GPAI-model obligations and has powers for a limited subset of AI systems, while the European Data Protection Supervisor supervises EU institutions, bodies and agencies.

The Act applies in stages. Penalty provisions do not make a substantive obligation enforceable before that obligation's own application date. As of 2 August 2026, the AI Office and national authorities exercise the relevant enforcement powers, while some high-risk-system rules apply later under the amended timetable.

Check the current consolidated Regulation, the application date for the specific duty and the rules of the competent Member State before reaching a conclusion.

Reduce exposure before an authority asks

The strongest response is a documented compliance process that finds and corrects problems early. Prioritise prohibited-practice screening and currently applicable duties, then plan ahead for obligations that enter into application later.

  • Maintain an AI inventory with owner, purpose, role, geography and application date.
  • Document scope, classification and prohibited-practice decisions with source evidence.
  • Map each duty to a control, accountable person, record and review date.
  • Create escalation, incident, complaint and regulator-response procedures.
  • Verify all information supplied to authorities and preserve a review trail.
  • Reassess after changes to the model, purpose, users, integration or law.

Official sources

Use the official text and current Commission guidance for decisions about a specific system.