See how Trussed maps to EU AI Act in minutes

    No generic demo, just the controls relevant to your program.

    Book a session
    Compliance Guide

    EU AI Act Penalties Explained: Fine Tiers and Calculations

    A structured breakdown of EU AI Act penalty tiers under Articles 99 and 101, how turnover-based ceilings work, who enforces them, and which records organizations should prepare when assessing exposure.

    Direct answer. The EU AI Act establishes three penalty tiers under Article 99: up to €35 million or 7% of global annual turnover for prohibited AI practices; up to €15 million or 3% for violations of high-risk system and other compliance obligations; and up to €7.5 million or 1% for supplying incorrect or misleading information to authorities. A separate tier under Article 101 applies to general-purpose AI model providers, enforced directly by the European Commission’s AI Office. In each case, the applicable maximum is whichever figure is higher for large organizations, or lower for SMEs and startups.

    Fine tiers at a glance

    Maximum penalties are tied to the category of violation. For most organizations, the higher of the fixed euro ceiling or the percentage of global annual turnover applies.

    Category Maximum fine Notes
    Prohibited practices Up to €35 million or 7% of global annual turnover Whichever is higher for large organizations; lower of the two for SMEs and startups
    High-risk and other compliance obligations Up to €15 million or 3% of global annual turnover Covers high-risk system duties and related compliance failures under Article 99
    Information failures Up to €7.5 million or 1% of global annual turnover Applies to supplying incorrect or misleading information to authorities
    GPAI model providers Up to €15 million or 3% Enforced by the EU AI Office under Article 101

    How the penalty structure is built

    Regulation (EU) 2024/1689, commonly known as the EU AI Act, sets out its penalty framework primarily in Article 99, with a separate provision in Article 101 for general-purpose AI model providers. Rather than a single fine schedule, the Act ties maximum penalties to the category of violation. Each tier defines a fixed euro ceiling and a percentage-of-turnover ceiling, and the higher of the two applies to the calculation for most organizations.

    This means the actual financial exposure for any single violation depends on two separate factors: which obligation was breached, and the size of the organization’s global revenue. Understanding both factors is a prerequisite for any internal risk assessment, since a small fixed-amount violation can still translate into a very large fine once turnover is applied.

    Fine tiers by violation category

    Article 99 groups penalties into three practical bands. The top tier targets prohibited AI practices and carries the highest ceilings (€35 million or 7%). The mid tier addresses high-risk system and other compliance obligations (€15 million or 3%). The lower tier covers incorrect or misleading information supplied to authorities (€7.5 million or 1%). General-purpose AI model providers face a parallel track under Article 101, with ceilings aligned to the mid tier and direct oversight by the European Commission’s AI Office.

    Turnover calculation and the SME exception

    Turnover for these calculations is defined as total worldwide annual turnover for the preceding financial year, not turnover limited to EU operations. Organizations with significant non-EU revenue should model exposure against consolidated global figures rather than EU-derived revenue alone, since the Act does not draw that distinction.

    A separate rule applies to SMEs and startups: rather than the higher of the fixed amount or the percentage figure, these organizations are subject to the lower of the two. This changes the calculation materially for smaller entities and makes accurate verification of SME status a relevant step in any exposure assessment, since misclassification could lead to an inaccurate estimate of maximum liability.

    Practical modeling note

    When estimating exposure, classify each system by obligation category first, then apply the correct higher-or-lower rule based on confirmed SME or startup status. Global consolidated turnover is the base figure, not EU-only revenue.

    Who enforces these penalties

    Enforcement authority under the Act is distributed rather than centralized. Member States are required to designate national competent and market surveillance authorities responsible for investigating non-compliance and imposing penalties within their jurisdiction for most obligations, including high-risk system requirements and prohibited practice violations.

    A separate enforcement track exists for general-purpose AI model providers, where the European AI Office, established within the European Commission, holds specific investigatory and enforcement powers under Article 101. Organizations operating across multiple Member States should expect that more than one national authority may have jurisdiction over different deployments, and that the AI Office’s role is limited to the GPAI provider category rather than general high-risk or prohibited-practice enforcement.

    Where runtime controls intersect with documented risk factors

    The Act’s mid-tier penalties for high-risk obligations, and its lower-tier penalties for information failures, are both connected to an organization’s ability to produce accurate, complete, and retrievable records during a regulatory review. Audit trails, access controls, and change-management documentation are referenced in the Act’s technical and procedural expectations for demonstrating that risk management obligations were actually operationalized, not just documented on paper.

    Runtime governance capabilities that generate consistent audit logging, enforce least-privilege access for AI agents, and maintain records of tool and permission approvals can support the evidentiary record an organization needs when responding to a market surveillance authority. This does not change the underlying obligations set out in the Act, but it can reduce the risk that a documentation gap becomes the basis for a lower-tier information-failure finding on top of a substantive violation.

    Documentation organizations should be prepared to produce

    The following records help support exposure assessment and responses to competent authorities.

    • An inventory of AI systems classified against Article 5 prohibited-practice criteria and Annex III high-risk criteria
    • Risk management files and technical documentation supporting high-risk system obligations
    • Conformity assessment records and post-market monitoring logs where applicable
    • Records distinguishing provider versus deployer role for each system, since obligations differ by role
    • Documented verification of SME or startup status where that classification is claimed
    • A record of which national competent authority has jurisdiction over each deployment

    Frequently asked questions

    Which figure applies if both the fixed amount and the percentage exceed the organization’s actual liability capacity?

    For most organizations, the higher of the fixed euro amount or the turnover percentage applies. SMEs and startups are the exception, where the lower of the two figures applies instead.

    Can penalties from multiple tiers apply to the same organization for the same AI system?

    Available sources do not confirm whether fines across multiple violation categories can be applied cumulatively to a single system or organization. This should be treated as an open question pending regulatory clarification or enforcement precedent.

    Does the EU AI Office enforce penalties for high-risk system violations generally?

    No. The AI Office’s enforcement role under Article 101 is specific to general-purpose AI model providers. High-risk system and prohibited-practice enforcement is handled by national competent and market surveillance authorities in each Member State.

    Assess your AI Act exposure before an investigation does

    Understanding which fine tier applies to each of your AI systems is the first step. Maintaining the audit trails and access records to support that assessment is the next.

    Talk to an Expert