AITENCY — Custom AI Systems
Back to Blog
·9 min read

EU AI Act Penalties: What Non-Compliance Actually Costs

S
EU AI ActAI ComplianceAI Regulation

TL;DR

The EU AI Act sets out a three-tier penalty regime with maximum fines of €7.5 million, €15 million, and €35 million — or 1%, 3%, and 7% of global annual turnover, whichever is higher. The harshest tier targets prohibited AI practices like social scoring or untargeted facial recognition scraping. Enforcement begins August 2026 through national authorities, supervised by the EU AI Office. But the bigger threat for most businesses is not the fine itself: it’s procurement exclusion, lost contracts, and the reputational hit when your AI system gets named in an enforcement action. This guide breaks down each tier, explains what actually triggers a penalty, and gives you a self-assessment to check where you stand today.

If you assume the EU AI Act penalties only apply to Big Tech, read the fine print again.

The Act covers any business that develops, deploys, or uses AI systems with effect in the EU — regardless of where the company is headquartered. A 40-person SaaS company in Cyprus selling to German enterprises is in scope. A US firm running a customer-facing AI assistant for European users is in scope. The penalty thresholds were not designed to scare large corporations only.

EU AI Act penalties are administrative fines imposed under Article 99 of Regulation (EU) 2024/1689, structured in three tiers based on the severity of the violation, with maximum amounts ranging from €7.5 million to €35 million or a percentage of global annual turnover — whichever is higher.

This article breaks down what each penalty tier actually costs, what triggers them, how enforcement will work in practice, and the hidden consequences most compliance briefings skip entirely.

Key Takeaways:

  • AI Act fines come in three tiers: €7.5M / €15M / €35M maximum — or 1% / 3% / 7% of global turnover, whichever is higher.
  • The top tier (€35M or 7%) is reserved for prohibited AI practices under Article 5: social scoring, manipulative systems, untargeted facial recognition scraping, real-time biometric surveillance.
  • The middle tier (€15M or 3%) covers most operational violations: high-risk system obligations, transparency rules, GPAI model duties.
  • The lowest tier (€7.5M or 1%) targets businesses that supply false or misleading information to authorities.
  • Enforcement is decentralized: each EU member state designates a national authority, with the EU AI Office handling general-purpose AI models directly.
  • For most businesses, the financial penalty is not the biggest risk — procurement exclusion, contract loss, and public enforcement registers cause longer-term damage.

The Three-Tier Penalty Structure

Article 99 of the EU AI Act establishes three escalating fine tiers, each calculated as the higher of a fixed amount or a percentage of the preceding financial year’s worldwide annual turnover.

The structure mirrors GDPR’s logic but with sharper teeth at the top end. Here is the full schedule.

TierMaximum FinePercentage of TurnoverTriggers
Tier 1 (highest)€35 million7% of global annual turnoverViolations of Article 5 (prohibited AI practices)
Tier 2€15 million3% of global annual turnoverMost other obligations: high-risk systems, GPAI, transparency
Tier 3€7.5 million1% of global annual turnoverSupplying incorrect, incomplete, or misleading information to authorities

For SMEs and start-ups, the rule flips: the lower of the two amounts applies, not the higher. This is one of the few concessions in the Act for smaller businesses, and it matters for any company under €50 million in turnover.

Authorities consider mitigating and aggravating factors when setting the actual fine: nature and duration of the violation, intent or negligence, prior infringements, cooperation with regulators, and the technical and organizational measures the business had in place. A first-time, good-faith violation rarely lands at the maximum. A repeat offense by a company that ignored regulator inquiries can.

What Triggers Each Tier

The penalty tier depends entirely on which obligation you violate — not on the size of your business or the impact of the breach.

Tier 1: Prohibited AI Practices (€35M / 7%)

Article 5 lists practices the EU has decided are unacceptable in any context. These took effect February 2, 2025 — they are already enforceable. Examples that trigger the top-tier penalty:

  • Social scoring systems that classify people based on social behavior or predicted personality traits, leading to detrimental treatment.
  • AI systems that exploit vulnerabilities of specific groups (age, disability, social or economic situation) to materially distort behavior.
  • Untargeted scraping of facial images from the internet or CCTV footage to build facial recognition databases.
  • Emotion recognition in workplaces and educational institutions (with narrow medical and safety exceptions).
  • Real-time remote biometric identification in public spaces by law enforcement, outside narrow exceptions.
  • Predictive policing based solely on profiling.

Most commercial businesses will not encounter these. But "social scoring" has been interpreted broadly in early guidance — a tenant screening system, an insurance pricing model, or a credit assessment tool that combines unrelated personal data could fall in scope if not designed carefully.

Tier 2: High-Risk and General Obligations (€15M / 3%)

This is where most enforcement against ordinary businesses will land. Tier 2 covers violations of:

  • Obligations for high-risk AI systems (Article 16 onwards): risk management, data governance, technical documentation, human oversight, accuracy, robustness, cybersecurity.
  • Transparency obligations under Article 50: failing to inform users they are interacting with AI, missing AI-generated content disclosures, failing to label deepfakes.
  • General-purpose AI model obligations under Articles 53-55: insufficient documentation, copyright policy gaps, systemic risk assessment failures.
  • Conformity assessment failures and CE marking violations.

If you deploy AI for hiring, credit decisions, education access, essential services, or law enforcement, you are operating high-risk systems under Annex III and the Tier 2 obligations apply directly.

Tier 3: Misleading Authorities (€7.5M / 1%)

The lowest tier exists to keep businesses honest in their dealings with regulators. Supplying incomplete documentation, false answers to information requests, or misleading statements during an investigation triggers this tier — even if the underlying AI system was compliant. The lesson: do not treat regulator inquiries casually.

For deeper context on what the law actually requires, the EU AI Act 2026 preparation guide and the complete EU AI Act compliance guide cover the operational obligations in detail.

How Enforcement Will Actually Work

Enforcement is decentralized: each EU member state designates a national competent authority, while the EU AI Office handles general-purpose AI models centrally from Brussels.

By August 2, 2026, every member state must designate at least one notifying authority and one market surveillance authority. Some are reusing existing data protection regulators (the obvious move); others are setting up dedicated AI authorities. The national authority where the AI system is placed on the market or used has primary jurisdiction.

For general-purpose AI (GPAI) models — think foundation models — the EU AI Office, established within the European Commission, takes the enforcement lead. The European AI Board coordinates between national authorities to keep enforcement consistent across the bloc.

What enforcement looks like in practice:

  1. Information requests. Authorities can demand technical documentation, training data summaries, and risk management records.
  2. On-site inspections. Market surveillance authorities can audit AI systems already in deployment.
  3. Corrective measures first. For most violations, authorities will require correction before issuing fines. Compliance is the goal, not revenue.
  4. Public register. Enforcement actions are publishable. A named-and-shamed listing damages procurement prospects long after the fine is paid.
  5. Cross-border coordination. A breach in one member state can trigger investigations in others.

First Expected Enforcement Actions

Late 2026 and 2027 will see the first major AI Act fines, almost certainly targeting either prohibited practices or transparency violations — the easiest categories to prove.

Based on how GDPR enforcement evolved, expect this trajectory:

  • Q3-Q4 2026: Warning letters and corrective orders against transparency violations. Companies with chatbots that do not disclose AI involvement, deepfake content without labels, AI-generated marketing without disclosure.
  • Early 2027: First substantive fines under Tier 2, likely targeting high-profile public-facing systems where harm is visible.
  • Mid-2027 onwards: Tier 1 enforcement around prohibited practices, particularly any case touching biometric surveillance or workplace emotion recognition.

The pattern from GDPR is instructive: regulators picked symbolic cases first, then built precedent. Expect the same here. The question is not whether the AI Office will issue a major fine — it is which industry gets the example made of it.

AI Act Fines vs. GDPR Fines in Practice

The AI Act’s headline figures exceed GDPR’s, but real-world fines will likely follow GDPR’s scaling pattern — most stay well below the maximum.

AspectGDPREU AI Act
Max fine (top tier)€20M or 4% of turnover€35M or 7% of turnover
In force sinceMay 2018Phased through 2025-2027
Largest fine to date€1.2 billion (Meta, 2023)TBD
Median fine (per Enforcement Tracker)€50K-€500K rangeTBD
Enforcement styleReactive, complaint-drivenMixed: proactive market surveillance + reactive

GDPR taught regulators a clear lesson: maximum fines exist as deterrent, but most enforcement targets the operational layer with smaller, targeted penalties. AI Act enforcement will likely follow the same playbook — except with higher ceilings and more proactive market surveillance built into the structure.

The Hidden Penalty: Lost Business

The financial fine is rarely the worst consequence. For most B2B companies, the bigger cost is procurement exclusion and contract loss.

Three patterns are already visible:

  1. Procurement clauses. Public sector and large enterprise tenders increasingly require AI Act compliance attestations. A pending enforcement action disqualifies you from the bid — no fine required.
  2. Customer due diligence. Enterprise buyers running their own compliance programs ask suppliers for AI risk documentation. Inability to provide it kills deals before they reach legal review.
  3. Insurance and financing. Cyber insurance carriers are starting to ask about AI governance. So are investors during due diligence.

Add reputational damage from a public enforcement register, and the actual cost of non-compliance often runs 5-10x the fine itself. This is the same lesson businesses learned the hard way with GDPR — why most AI projects fail often comes back to the governance and compliance gaps that surface only when a customer or regulator asks the hard questions.

Self-Assessment: Where Do You Stand Today?

A 10-minute self-assessment can tell you whether you are facing a Tier 1, Tier 2, or no exposure at all.

Answer honestly:

#QuestionIf yes...
1Do any of your AI systems perform tasks listed in Article 5 (social scoring, biometric scraping, emotion recognition at work)?Tier 1 exposure — stop immediately and seek legal review
2Do you operate AI in any Annex III area (employment, credit, education, essential services, law enforcement)?Tier 2 exposure — high-risk obligations apply
3Do you use AI in customer-facing interactions without clear disclosure?Tier 2 exposure — transparency violation risk
4Do you generate or distribute synthetic media (deepfakes, AI-generated images, voices)?Tier 2 exposure — labeling required
5Have you documented your AI systems’ purpose, training data sources, and risk controls?If no, you cannot demonstrate compliance under audit
6Do you have a designated person accountable for AI Act compliance?If no, you have no governance structure

Score: any "yes" to questions 1-4 means you are in the Act’s scope. Any "no" to questions 5-6 means you have no defensible compliance position. Most businesses we audit fall into this gap — they are in scope but undocumented.

If you are building AI systems and want them to pass compliance review by design, our approach to custom AI systems bakes governance and documentation into the implementation phase, not as an afterthought. Choosing the right AI implementation partner is one of the most direct levers you have on long-term compliance cost.

Frequently Asked Questions

Are EU AI Act penalties already in effect?

The prohibition on Article 5 practices and the Tier 1 penalties for them are enforceable as of February 2, 2025. Most other obligations — and the corresponding Tier 2 fines — take effect August 2, 2026. General-purpose AI model obligations followed in August 2025 with a one-year grace period for existing models.

Do AI Act fines apply to non-EU companies?

Yes. The Act applies extraterritorially. Any business placing AI systems on the EU market, or whose AI output is used in the EU, falls under the regulation regardless of where the company is registered. A US or UK company serving EU users is in scope.

Can a single AI system trigger multiple penalty tiers?

Yes. A high-risk AI system that also engages in a prohibited practice could face Tier 1 fines for the prohibited element and Tier 2 fines for separate documentation or transparency failures. Authorities can stack penalties for distinct violations.

What is the difference between AI Act fines and GDPR fines?

GDPR governs personal data processing; the AI Act governs AI systems specifically. Both can apply to the same product. AI Act fines reach higher (7% vs. 4% of global turnover) and explicitly target system design, not just data handling. A non-compliant AI system processing personal data risks fines under both regimes.

Where can I track EU AI Act enforcement?

The EU AI Office publishes guidance and decisions on the European Commission’s digital strategy site. National competent authorities maintain their own registers. By 2027, expect dedicated trackers similar to GDPR’s Enforcement Tracker to emerge.

The right time to address EU AI Act penalties exposure is before a regulator or procurement officer asks. Download our EU AI Act compliance checklist or book a free discovery call — we will walk through your AI systems against the Act’s obligations and tell you where you stand. No legalese. Just a clear picture of what is in scope, what is missing, and what to fix first.

Ready to Explore Automation for Your Business?

Start with a free process audit — we'll identify the highest-value automation opportunities in your operations.

Book a Discovery Call