EU AI Act penalties
and fines under Article 99.
Three tiers, a reversal that works in favour of smaller companies, and a top rate higher than the GDPR's. Article 99, explained without the parts that do not affect you.
Last updated Published by TryTrustableNot legal advice
What is the maximum fine under the EU AI Act?
The maximum fine under the EU AI Act is €35 million or 7% of total worldwide annual turnover for the preceding financial year, whichever is higher, for breaching the Article 5 prohibited practices. For SMEs and start-ups, Article 99(6) applies whichever of the two figures is lower. Every other breach carries a lower ceiling.
Those figures are in Article 99 of the AI Act, and the Digital Omnibus (Regulation (EU) 2026/1744) left the ceilings unchanged. It did add one paragraph, covered below, that matters to companies just above SME size.
Article 99 sets maxima against categories of breach rather than against individual articles, so exposure is decided by which tier your failure falls into rather than by how many rules you broke.
| Tier | What triggers it | Maximum |
|---|---|---|
| Prohibited practicesArticle 99(3) | Social scoring, untargeted facial scraping, emotion inference at work or school, and the other unacceptable-risk practices in Article 5 | €35m or 7%of total worldwide annual turnover |
| Most other obligationsArticle 99(4) | Provider, authorised representative, importer, distributor and deployer duties, notified-body obligations, and Article 50 transparency | €15m or 3% |
| Incorrect informationArticle 99(5) | Supplying incorrect, incomplete or misleading information to notified bodies or national authorities in reply to a request | €7.5m or 1% |
| General-purpose AI providersArticle 101 | Breaching the GPAI model obligations, or failing to comply with a Commission request or measure. Imposed by the Commission rather than a national authority | €15m or 3% |
Percentages are of total worldwide annual turnover for the preceding financial year. For an ordinary undertaking the higher figure is the ceiling.
The SME reversal, which is reported backwards constantly
For an ordinary company the applicable ceiling is whichever is higher: the fixed sum or the percentage. Article 99(6) inverts that for SMEs, including start-ups: for them it is whichever is lower, on all three tiers.
The practical effect is large and asymmetric. An SME turning over €20 million faces a middle-tier ceiling of 3% (€600,000) rather than €15 million. A large company turning over €2 billion faces €60 million rather than €15 million. The regime is deliberately shaped so the ceiling scales with the ability to absorb it, which is the opposite of how India's DPDP Act works with its fixed-rupee maxima.
The Omnibus added Article 99(6a) for small mid-cap enterprises, the new category above SME size. They also get the lower-of rule, but only on the second and third tiers. For prohibited practices a small mid-cap is treated like any other company.
Article 99(1) also requires penalties to be effective, proportionate and dissuasive, and Article 99(7) lists what authorities weigh: the nature and gravity of the breach and its consequences, whether other authorities have already fined for the same conduct, the size and market share of the operator, any financial benefit gained, whether the breach was intentional or negligent, what was done to mitigate it, and the degree of cooperation.
When each tier becomes enforceable
A ceiling only matters once the obligation behind it applies, and the Omnibus moved the dates for the largest group of obligations. The prohibitions have been enforceable since 2 February 2025, with two new ones from 2 December 2026. Article 50 transparency and the Commission's GPAI fines apply from 2 August 2026. High-risk duties become enforceable on 2 December 2027 for Annex III systems and 2 August 2028 for Annex I products. The full table, with the article behind each date, is in the EU AI Act compliance guide.
Against the GDPR, and against DPDP
| EU AI Act | GDPR | DPDP Act 2023 | |
|---|---|---|---|
| Top tier | €35m or 7% of global turnover | €20m or 4% of global turnover | ₹250 crore (fixed) |
| Basis | Higher of the two; lower for SMEs | Higher of the two | Fixed maximum per obligation |
| Scales with size | Yes, both directions | Yes, upward | No |
| Enforcer | National market surveillance authorities; AI Office for GPAI | National supervisory authorities | Data Protection Board of India |
| Object regulated | The AI system, as a product | The processing of personal data | The processing of personal data |
One deployment can engage all three at once, which is the argument for one control set rather than three programmes. DPDP figures are set out in full on the DPDP penalties page.
What reduces the number
Article 99(7) is explicit that mitigation and cooperation count, and both are ordinary engineering and process work rather than legal work.
- Know which systems you have, and their tier. An inventory that predates the inquiry is worth more than any assessment written during one
- Keep the logs. Article 12 requires them for high-risk systems and they are how you establish what the system actually did rather than what you believe it did
- Document before deployment, not after. Annex IV documentation dated after a complaint reads as remediation
- Do not answer an authority from memory. The third tier exists specifically for incorrect or misleading information supplied in reply to a request
The first two are what the AI governance engine holds: a register of the models, prompts and MCP servers you run, a risk classification per system, and evaluation runs kept with their transcripts. If you want the same obligations scored rather than priced, the compliance readiness check covers governance, data mapping and security, and the EU AI Act guide sets out what each tier requires.
The things people ask us
What is the maximum fine under the EU AI Act?
The maximum fine under the EU AI Act is €35 million or 7% of total worldwide annual turnover for the preceding financial year, whichever is higher, for breaching the Article 5 prohibited practices. For SMEs and start-ups, Article 99(6) applies whichever of the two figures is lower. Every other breach carries a lower ceiling. The next tier, €15 million or 3%, covers most provider and deployer obligations.
How large are the EU AI Act fines?
Three tiers under Article 99. Up to €35 million or 7% of total worldwide annual turnover for breaching the Article 5 prohibitions; up to €15 million or 3% for most other obligations, including provider and deployer duties and Article 50 transparency; and up to €7.5 million or 1% for supplying incorrect, incomplete or misleading information to authorities or notified bodies.
Is it the higher or the lower of the two figures?
For most companies, whichever is higher. For SMEs and start-ups, Article 99(6) reverses it: whichever is lower applies, on all three tiers. The Digital Omnibus added Article 99(6a), which gives small mid-cap enterprises the same lower-of rule on the second and third tiers, but not on the prohibited-practices tier.
How do AI Act fines compare with the GDPR?
The top tier is higher. The GDPR caps at €20 million or 4% of global turnover; the AI Act's prohibited-practices tier reaches €35 million or 7%. The middle tier, €15 million or 3%, sits just below the GDPR's ceiling and is the one most companies are actually exposed to.
Can we be fined under both the AI Act and the GDPR for the same system?
They regulate different things (the AI Act regulates the system as a product, the GDPR regulates the processing of personal data) so the same deployment can engage both, enforced by different authorities. Whether a single set of facts can attract two fines is a question for counsel and for the ne bis in idem principle, not one to plan around.
Who actually enforces this?
National market surveillance authorities in each member state, coordinated through the European Artificial Intelligence Board, with the AI Office at the Commission responsible for general-purpose AI models directly. For GPAI providers the Commission can fine up to €15 million or 3% itself under Article 101.
Do the fines apply now?
The penalties regime has applied since 2 August 2025, but only to obligations that have themselves commenced. The Article 5 prohibitions and, since 2 August 2026, the Article 50 transparency duties are enforceable, as are the Commission's Article 101 fines for GPAI providers. High-risk obligations become enforceable when they apply: 2 December 2027 for standalone Annex III systems, 2 August 2028 for Annex I.
Exposure is a function of what you can show.
We connect a real model and show the risk classification, the evaluation record and the evidence behind both, in one pass.