What are the penalties and fines under the EU AI Act?
AI regulation: the EU AI Act
The EU AI Act has two main fine tracks. For most AI Act breaches, Member States impose penalties under Article 99, with headline ceilings of up to EUR 35 million or 7 percent of worldwide turnover for prohibited practices, EUR 15 million or 3 percent for certain key obligations, and EUR 7.5 million or 1 percent for misleading information. Separately, the Commission can fine general-purpose AI model providers under Article 101, up to EUR 15 million or 3 percent, from 2 August 2026.
What this means
The short version is that the EU AI Act does not create one single universal fine. It creates a penalty architecture. Article 99 sets the main penalty tiers for Member State enforcement, while Article 101 gives the European Commission a separate fining power for providers of general-purpose AI models, or GPAI models.
The practical catch is timing. A fine can only bite once the underlying rule is actually applicable. That means some exposures are already live, especially prohibited AI practices, while others do not become live until 2 August 2026. As at 21 July 2026, the separate Digital Omnibus on AI has been adopted and signed, but was still awaiting Official Journal publication, so the original AI Act dates still formally govern until that amending regulation enters into force.
This matters because many teams hear the headline numbers and assume they apply to every AI use case right now. They do not. You need to know which rule you are dealing with, who enforces it, and whether that rule is already in force.
Why it matters
For founders, operators, product teams, procurement leaders and advisers, penalties are where AI governance stops being abstract. The EU AI Act links different kinds of exposure to different authorities, dates and fine ceilings. If you get the timing wrong, you can either overreact to risks that are not yet live or miss risks that already are.
The amounts are large enough to matter at board level. So is the structure behind them. A prohibited practice can attract the top tier. A transparency failure under Article 50 moves into the middle tier once that article applies. A GPAI provider can face direct Commission proceedings, with its own fine regime and procedures. Smaller businesses also need to understand that the AI Act contains a real mitigation feature for SMEs and start-ups, because under Article 99 their fine ceiling is the lower of the amount or percentage, not the higher.
This is also not just about money. National regimes can include warnings and non-monetary measures, the Commission can require GPAI providers to cooperate, and enforcement outcomes can trigger procurement, contractual, audit and reputational consequences well before a final fine is imposed.
How it works
The EU AI Act has two different fine engines
Article 99 is the main national penalties provision. It requires Member States to lay down rules on penalties and other enforcement measures for infringements of the AI Act. Those penalties must be effective, proportionate and dissuasive. This is the route for most AI systems, providers, deployers, importers, distributors and notified bodies.
Article 101 is different. It is not a Member State penalty rule. It gives the European Commission direct fining power over providers of GPAI models. So when readers ask "what are the penalties under the EU AI Act?", the correct answer is not one number but two tracks: national Article 99 fines and Commission Article 101 fines.
This is also why penalties should be distinguished from the broader EU AI Act enforcement architecture. Penalties are one part of enforcement, not the whole system.
The three Article 99 tiers are real, but they are not universal
The top tier is for prohibited AI practices under Article 5. The ceiling is up to EUR 35 million, or if the offender is an undertaking, up to 7 percent of its total worldwide annual turnover for the preceding financial year, whichever is higher. This is the tier most people have heard about. It is the harshest because it is tied to uses the Act treats as unacceptable.
The middle tier is up to EUR 15 million or 3 percent of worldwide annual turnover, whichever is higher. But it is not a catch-all for every other AI Act obligation. It applies to a listed set of provisions: provider obligations in Article 16, authorised representative obligations in Article 22, importer obligations in Article 23, distributor obligations in Article 24, deployer obligations in Article 26, certain notified-body obligations, and transparency obligations under Article 50. As adopted in the Digital Omnibus on AI, once that amending regulation enters into force, this middle tier also captures the specific value-chain obligations in Article 25(2) and 25(4).
The lower headline tier is up to EUR 7.5 million or 1 percent of worldwide annual turnover, whichever is higher, for supplying incorrect, incomplete or misleading information to notified bodies or national competent authorities in reply to a request.
That structure matters because not every breach sits neatly inside one of those three ceilings. Article 99 obliges Member States to create penalty rules for any infringement of the Regulation, but only some infringements are tied to those explicit headline caps. So teams should not assume that every AI Act breach automatically maps to the familiar 35 million, 15 million or 7.5 million ladder.
The SME and start-up rule is a genuine mitigation, not a waiver
For SMEs, including start-ups, Article 99 says each fine is up to the percentage or the amount referred to in the relevant paragraph, whichever is lower. That is an important reduction from the usual rule, which uses whichever is higher.
In practice, that means a small business does not escape the penalty regime, but its ceiling is capped in the more favourable direction. For a large undertaking, the turnover percentage can quickly exceed the fixed EUR amount. For an SME or start-up, Article 99 prevents that higher-of outcome and instead applies the lower figure.
As at 21 July 2026, this lower-of rule is current law for SMEs, including start-ups. The adopted Digital Omnibus on AI would extend a similar lower-of treatment to small mid-cap enterprises for the Article 99(4) and 99(5) tiers, but that extension is not yet in force because the amending regulation was still awaiting Official Journal publication at the time of research.
If you need the broader small-business implementation picture, including support measures and compliance simplifications, that sits better in eu-ai-act-small-business than on this page.
What is live now, and what starts later
The penalty chapter itself has applied since 2 August 2025, but exposure depends on whether the underlying obligation is already applicable. That point is easy to miss.
Under the law currently in force, Article 4 on AI literacy and Chapter II on prohibited AI practices have applied since 2 February 2025. That means prohibited-practice exposure is already live. If your system falls into a banned category, the top Article 99 tier is not theoretical. It is part of the live rulebook now. For the details of what counts as banned, see prohibited-ai-practice.
Chapter V on GPAI and Chapter VII on governance have applied since 2 August 2025. So GPAI obligations are already in force. However, Article 101, the Commission's fining power for GPAI providers, was carved out from that early application and instead starts with the Act's general application date, 2 August 2026.
Most of the remaining obligations, including Article 50 transparency duties, apply from 2 August 2026 under the current law. That is why many organisations will only face live middle-tier exposure for transparency failures from that date, even though the penalty chapter itself is already active.
The pending Digital Omnibus on AI matters here, but only conditionally. As at 21 July 2026 it had been adopted and signed, yet was still awaiting publication in the Official Journal. Until it enters into force, the current-law dates formally stand. Once it enters into force, it will not move the main Article 50 date or the GPAI dates, but it will create targeted changes around later high-risk milestones and a short transition for certain pre-2 August 2026 synthetic-content systems under Article 50(2).
For the full sequence of milestones, this page should point readers to eu-ai-act-timeline rather than restating the entire rollout.
Article 101 gives the Commission a separate GPAI fining power
Article 101 lets the Commission fine providers of GPAI models up to 3 percent of annual total worldwide turnover or EUR 15 million, whichever is higher, where the Commission finds intentional or negligent infringement. The same ceiling also covers failures to comply with Article 91 document and information requests, failures to comply with Article 93 measures, or failures to give the Commission access needed for an Article 92 evaluation.
This matters because GPAI providers do not wait for a Member State to set up an Article 99 route. The Commission itself becomes the fining authority here. The Commission's own guidance says GPAI obligations have applied since 2 August 2025, but its enforcement powers, including fines, enter into application on 2 August 2026. Providers of GPAI models already on the market before 2 August 2025 get until 2 August 2027 to comply.
There is also more procedural detail now than there was only weeks ago. On 21 July 2026, the Official Journal published Commission Implementing Regulation (EU) 2026/1755, which sets detailed arrangements for certain Commission proceedings under the AI Act, including proceedings linked to evaluations and Article 101 fines. That does not change the fine ceiling, but it does make the Commission's enforcement path more concrete as 2 August 2026 approaches.
If your organisation is dealing with foundation models or upstream model supply, the adjacent explainer is general-purpose-ai-model.
National penalty regimes still matter a lot
The AI Act sets the outer architecture, but Member States still decide key parts of Article 99 enforcement. National law determines the competent authority, the procedural route, what non-monetary measures are available, and to what extent public authorities and public bodies can be fined.
The Regulation expressly allows warnings and non-monetary measures. It also says Member States can structure administrative fines through courts or other bodies, depending on their legal system, provided the result has equivalent effect. In other words, the AI Act harmonises the ceilings and principles more than it harmonises every procedural detail.
That is why the same breach category may present differently across the Union. The headline amount is European. The route to getting there is partly national. For operators, that means two layers of analysis are needed: first, identify the EU obligation and fine tier; second, identify the relevant national enforcement law and authority.
The adopted Digital Omnibus on AI sharpens this point. It amends Article 99(1) so that Member States, when laying down and implementing penalties, must take account of Commission guidelines issued under Article 96. Once that amendment enters into force, national penalty design remains national, but it will have a stronger explicit link to Commission guidance.
Regulators must weigh proportionality, not just the headline cap
The AI Act does not tell authorities to jump straight to the maximum. Article 99 lists a set of factors national authorities must weigh when deciding whether to impose an administrative fine and how large it should be. Those factors include the nature, gravity and duration of the infringement, its consequences, the number of affected people, earlier fines for the same operator, the operator's size, turnover and market share, financial benefit gained or losses avoided, the level of cooperation, the degree of responsibility, how the infringement became known, whether the conduct was intentional or negligent, and any steps taken to mitigate harm.
Article 101 uses a similar proportionality logic at Commission level for GPAI providers. When setting a fine, the Commission must consider the nature, gravity and duration of the infringement, proportionality and appropriateness. It must also take account of commitments made under Article 93 or in relevant codes of practice under Article 56.
Operationally, that means good behaviour after a problem is found can matter. Cooperation, remediation, mitigation and documented governance are not guaranteed shields, but they are legally relevant to sanction sizing. A company with weak controls and obstructive behaviour will look very different from one that identified an issue, preserved evidence, cooperated quickly and fixed the defect.
The pending Digital Omnibus on AI changes dates, but not the basic penalty ladder
As at 21 July 2026, the Digital Omnibus on AI had completed the legislative process and been signed on 8 July 2026, but it was still awaiting Official Journal publication. That means its changes are adopted but not yet in force.
Once it enters into force, it will not rewrite the basic Article 99 amount ladder. The core penalty architecture remains. What it does change is the wider timeline around which obligations are live. In particular, it adds new prohibited practices concerning certain non-consensual intimate imagery and child sexual abuse material generation, with application from 2 December 2026. It also gives providers of synthetic-content systems placed on the market before 2 August 2026 until 2 December 2026 to comply with Article 50(2). It moves the Annex III standalone high-risk obligations to 2 December 2027 as the outer limit, moves Annex I embedded-product high-risk obligations to 2 August 2028, and moves the national sandbox operational deadline to 2 August 2027.
So the practical question is not whether the Omnibus abolishes AI Act penalties. It does not. The real question is which obligations are live on which date, because that determines when each fine exposure becomes real in practice.
Examples
A company places on the EU market an AI system that falls within a prohibited practice under Article 5, for example a use case classified as banned in the Act and the Commission's prohibited-practices guidance. Because the prohibitions have applied since 2 February 2025, that exposure is already live. If national authorities enforce, the top Article 99 tier is available, up to EUR 35 million or 7 percent of worldwide annual turnover, with the SME and start-up lower-of rule where applicable.
A provider or deployer launches an in-scope transparency-risk system without the disclosures required by Article 50. Under the law currently in force, the key point is timing: Article 50 generally applies from 2 August 2026, not earlier. Once it applies, Article 99 places Article 50 breaches in the middle tier, up to EUR 15 million or 3 percent. If the pending Omnibus enters into force, pre-2 August 2026 synthetic-content systems get a limited transition for Article 50(2) until 2 December 2026, but the general Article 50 start date is not moved.
A GPAI provider fails to comply with a Commission request for documents or information under Article 91, or does not provide access needed for an Article 92 evaluation. That is not an Article 99 national fine question. It is Article 101 territory. The Commission can fine up to EUR 15 million or 3 percent of worldwide turnover, whichever is higher, once its fining powers enter into application on 2 August 2026.
Common misunderstandings
The AI Act has one universal fine. No. It has national Article 99 penalties for most actors and a separate Article 101 Commission fine regime for GPAI model providers.
All AI Act fines are already live. No. Prohibited-practice exposure is already live, but many other exposures depend on later application dates. Transparency exposure under Article 50, and Commission GPAI fines under Article 101, start on 2 August 2026 under the current law.
The EUR 15 million or 3 percent tier covers every non-prohibited breach. No. Article 99(4) lists specific obligations. Other infringements can still be sanctionable under national law, but they do not automatically slot into that middle-tier list.
The SME rule means small companies cannot be fined seriously. No. SMEs and start-ups are still sanctionable. The rule changes the maximum by using the lower of the fixed amount or percentage, which is a real mitigation but not an exemption.
The Digital Omnibus on AI is already in force. Not as at 21 July 2026. It has been adopted and signed, but official sources still showed it as awaiting Official Journal publication. Until it enters into force, the original AI Act dates formally remain in place.
Risks and boundaries
This page is about penalties and exposure, not about the full compliance checklist. A fine analysis starts with the obligation, but it is not the same thing as classifying a system, designing controls, performing a conformity assessment, or mapping the full enforcement chain. Those sit better in eu-ai-act and eu-ai-act-enforcement.
It is also important not to overread the headline numbers. Article 99 sets maximum ceilings for certain categories and requires Member States to put an enforcement regime in place, but national law still matters for procedure, public-authority treatment, warnings, and other non-monetary measures. Two organisations with a similar breach profile may face different procedural pathways in different Member States.
There is also a live legal-status boundary at the time of writing. The Digital Omnibus on AI was adopted and signed, but official procedure sources still showed it as awaiting Official Journal publication on 21 July 2026. That means the date changes described above are adopted and likely imminent, but not yet legally operative until publication and entry into force. Readers should therefore distinguish carefully between current law and pending amending law.
Finally, none of this is a substitute for legal advice on a specific fact pattern. The AI Act's penalty architecture is clear in broad outline, but the exact exposure in a real case depends on the system type, operator role, Member State procedure, timing, available evidence, and how the authority applies the proportionality factors.
What to do next
First, build a simple exposure map rather than a generic "AI Act risk" list. Identify which of your systems or models could engage Article 5 prohibitions, Article 50 transparency duties, Chapter V GPAI obligations, or the listed operator duties in Article 99(4). If you cannot map the obligation, you cannot map the fine.
Second, split your timeline into live-now and live-later risks. As at 21 July 2026, prohibited-practice exposure is already live. Article 50 and Commission GPAI fining powers become much more immediate on 2 August 2026. If you are relying on the pending Omnibus date changes for planning, treat that as conditional until the amending regulation is published.
Third, if you are an SME or start-up, do not ignore the lower-of rule. It materially affects your ceiling, but it does not remove the need for controls, record-keeping and response planning. If you are near the small-business threshold, track whether the Omnibus extension for small mid-cap enterprises enters into force.
Fourth, prepare your incident and regulator-response playbook now. Article 99 and Article 101 both reward cooperation and remediation in sanction sizing. Decide who owns regulator correspondence, evidence preservation, corrective action and Board-level escalation before you need it.
Fifth, organisations touching GPAI should treat 2 August 2026 as an operational deadline, not just a legal date. The Commission has issued GPAI guidance, the Code of Practice is in place as a voluntary tool, and Implementing Regulation (EU) 2026/1755 now gives the Commission procedural machinery for Article 101 proceedings.
FAQs
What is the highest fine under the EU AI Act?
For Article 99 national enforcement, the highest headline ceiling is for prohibited AI practices under Article 5: up to EUR 35 million or, for an undertaking, 7 percent of worldwide annual turnover for the previous financial year, whichever is higher.
Does every AI Act breach fall into one of the three Article 99 tiers?
No. The three tiers cover prohibited practices, a listed group of operator and transparency obligations, and misleading information to notified bodies or national competent authorities. Other infringements can still be penalised under national rules even if they are not tied to one of those explicit ceilings.
Are SMEs and start-ups treated differently?
Yes. Under current law, Article 99 says that for SMEs, including start-ups, the fine ceiling is the lower of the fixed amount or the turnover percentage. That is more favourable than the standard rule, which uses whichever is higher.
Who fines GPAI providers, Member States or the Commission?
For Article 101, it is the Commission. That provision creates a separate EU-level fining power for providers of general-purpose AI models, including failures to comply with information requests, measures, or evaluation access requirements.
When do Article 50 transparency fines become a live issue?
Under the law in force on 21 July 2026, Article 50 generally applies from 2 August 2026. That is when the middle-tier Article 99 exposure for Article 50 breaches becomes live. The pending Omnibus does not move the general Article 50 date.
Does the Digital Omnibus on AI reduce the main fine amounts?
No. It changes parts of the timeline and some surrounding mechanics, but it does not replace the core Article 99 amount ladder or the Article 101 GPAI ceiling.
Can public authorities be fined under the AI Act?
Potentially, but the extent depends on Member State law for Article 99 cases. The Regulation requires each Member State to lay down rules on how far administrative fines may be imposed on public authorities and bodies established in that Member State.
Is misleading information only a low-tier issue?
Not always. Under Article 99, misleading information to notified bodies or national competent authorities falls into the EUR 7.5 million or 1 percent tier. But for GPAI providers, failures to comply properly with Commission information requests can fall under Article 101, which has a higher ceiling of EUR 15 million or 3 percent.
