The EU AI Act Penalty Structure
Article 99 of Regulation EU 2024/1689 establishes a three-tier administrative penalty framework. Penalties are calculated as the higher of a fixed euro amount or a percentage of global annual worldwide turnover, meaning the fine scales with the organisation's economic capacity and always applies the more severe outcome.
Three Penalty Tiers
Prohibited Practice Violations (Article 5)
Applies to violations of the eight Article 5 prohibited practices: social scoring AI, real-time biometric ID in public spaces, subliminal manipulation AI, exploitation of vulnerabilities, emotion inference in workplaces, facial image scraping, biometric categorisation for sensitive attributes, and criminal prediction from profiling. Active since 2 February 2025.
High-Risk AI and GPAI Non-Compliance
Applies to non-compliance with high-risk AI provider and deployer obligations (Chapter III, Arts. 8–15), GPAI model obligations (Chapter V, Arts. 51–56), and violations by notified bodies. This is the penalty tier for high-risk and GPAI obligation non-compliance.
Incorrect or Misleading Information
Applies to incorrect, incomplete, or misleading information provided to notified bodies or competent authorities during conformity assessment or market surveillance. Note: violations of Article 50 transparency obligations are penalised separately under Article 99(4) at €15M / 3%, not under this tier.
Penalty Exposure Calculator
EU AI Act Penalty Calculator
Maximum Penalty Exposure
Factors That Affect Penalty Determination
Regulators must consider these factors when determining the appropriate fine within the permitted range:
- Nature and gravity of the violation and harm caused or potential harm
- Scope and purpose, number of persons affected and the AI system's purpose
- Duration of the infringement
- Prior violations by the same provider or deployer
- Cooperation with the competent authority and corrective measures taken
- Intent, whether the violation was intentional or negligent
- Financial capacity of the organisation, particularly SMEs and startups (Article 99(6))
- Benefits gained from the violation (financial or otherwise)
Who Enforces the EU AI Act?
Primary enforcement sits with national competent authorities, designated in each EU member state. For GPAI models with systemic risk, the European AI Office has direct supervisory and enforcement powers at EU level. Where the AI Act intersects with GDPR violations, Data Protection Authorities may also have jurisdiction. Organisations operating across member states should anticipate supervision from multiple authorities.
Yes. The EU AI Act and GDPR can both apply to the same AI system processing personal data. A data breach or discriminatory outcome from a high-risk AI system could trigger penalties under both regimes simultaneously. The regulations do not contain double-jeopardy provisions, though regulators are expected to coordinate. Seek legal counsel for any incident with cross-regime implications.
Article 99(6) permits competent authorities to impose penalties proportionate to the size and economic capacity of SMEs and startups, while still ensuring deterrence. This does not create an exemption, it means the actual fine imposed may be below the stated maximum. The proportionality principle gives regulators discretion to account for smaller organisations' capacity without reducing the fundamental legal obligation.