Regulation EU 2024/1689, Post-Omnibus Edition

EU AI Act Fines and Penalties: The Complete Guide

The EU AI Act imposes penalties up to €35 million or 7% of global annual turnover, the 'whichever is higher' mechanism means large enterprises face exposure far above the fixed caps.

Find your risk tier, 5 min → Skip to penalty calculator
Not sure if your AI system triggers €35M / 7% exposure?

The Risk Classifier maps your use case to Article 5 (prohibited), Annex III (high-risk), Article 50 (limited), or minimal, with article-grounded scoring. 12 questions, 5 min, no login.

Run the classifier →

The EU AI Act Penalty Structure

Article 99 of Regulation EU 2024/1689 establishes a three-tier administrative penalty framework. Penalties are calculated as the higher of a fixed euro amount or a percentage of global annual worldwide turnover, meaning the fine scales with the organisation's economic capacity and always applies the more severe outcome.

⚖️
How penalties are calculated: For each violation tier, regulators calculate both the fixed maximum (e.g. €35M) and the turnover-based maximum (e.g. 7% of global annual revenue). The higher of the two figures is the applicable maximum. A company with €10B global revenue faces up to €700M for the most severe violations.

Three Penalty Tiers

TIER 1, HIGHEST

Prohibited Practice Violations (Article 5)

€35,000,000
or 7% of global annual turnover
whichever is higher, Art. 99(3)

Applies to violations of the eight Article 5 prohibited practices: social scoring AI, real-time biometric ID in public spaces, subliminal manipulation AI, exploitation of vulnerabilities, emotion inference in workplaces, facial image scraping, biometric categorisation for sensitive attributes, and criminal prediction from profiling. Active since 2 February 2025.

TIER 2, STANDARD

High-Risk AI and GPAI Non-Compliance

€15,000,000
or 3% of global annual turnover
whichever is higher, Art. 99(4)

Applies to non-compliance with high-risk AI provider and deployer obligations (Chapter III, Arts. 8–15), GPAI model obligations (Chapter V, Arts. 51–56), and violations by notified bodies. This is the penalty tier for high-risk and GPAI obligation non-compliance.

TIER 3, INFORMATION

Incorrect or Misleading Information

€7,500,000
or 1% of global annual turnover
whichever is higher, Art. 99(5)

Applies to incorrect, incomplete, or misleading information provided to notified bodies or competent authorities during conformity assessment or market surveillance. Note: violations of Article 50 transparency obligations are penalised separately under Article 99(4) at €15M / 3%, not under this tier.

Penalty Exposure Calculator

EU AI Act Penalty Calculator

Maximum Penalty Exposure

Factors That Affect Penalty Determination

Regulators must consider these factors when determining the appropriate fine within the permitted range:

  • Nature and gravity of the violation and harm caused or potential harm
  • Scope and purpose, number of persons affected and the AI system's purpose
  • Duration of the infringement
  • Prior violations by the same provider or deployer
  • Cooperation with the competent authority and corrective measures taken
  • Intent, whether the violation was intentional or negligent
  • Financial capacity of the organisation, particularly SMEs and startups (Article 99(6))
  • Benefits gained from the violation (financial or otherwise)

Who Enforces the EU AI Act?

Primary enforcement sits with national competent authorities, designated in each EU member state. For GPAI models with systemic risk, the European AI Office has direct supervisory and enforcement powers at EU level. Where the AI Act intersects with GDPR violations, Data Protection Authorities may also have jurisdiction. Organisations operating across member states should anticipate supervision from multiple authorities.

Yes. The EU AI Act and GDPR can both apply to the same AI system processing personal data. A data breach or discriminatory outcome from a high-risk AI system could trigger penalties under both regimes simultaneously. The regulations do not contain double-jeopardy provisions, though regulators are expected to coordinate. Seek legal counsel for any incident with cross-regime implications.

Article 99(6) permits competent authorities to impose penalties proportionate to the size and economic capacity of SMEs and startups, while still ensuring deterrence. This does not create an exemption, it means the actual fine imposed may be below the stated maximum. The proportionality principle gives regulators discretion to account for smaller organisations' capacity without reducing the fundamental legal obligation.

← Complete EU AI Act Guide

Free Resource

Where Does Your AI Stand Against the New Phased Timeline?
Find Out in 5 Minutes

Download our EU AI Act 5-Point Express Compliance Check, a structured self-assessment covering risk classification, Annex III applicability, documentation gaps, and board-level exposure. Delivered as a PDF immediately after submit.

No spam. No marketing lists. PDF delivered immediately after submit. Privacy Policy

✓   Your checklist is downloading now. Check your inbox for a copy.