EU AI Act Penalties: the Actual Fine Tiers
9 min read · updated August 11, 2026
Article 99 of the AI Act sets three ceilings for administrative fines, not one. The €35 million figure that appears in every headline attaches to a single article — the prohibited practices in Article 5 — and most infringements a normal provider might commit sit in a lower tier.
The three tiers
All three come from Article 99 of Regulation (EU) 2024/1689, as published in the Official Journal on 12 July 2024. Each is expressed as a fixed amount or a percentage of total worldwide annual turnover for the preceding financial year, whichever is higher where the offender is an undertaking.
- Up to €35,000,000 or 7% of total worldwide annual turnover. Article 99(3), for non-compliance with the prohibition of the AI practices in Article 5.
- Up to €15,000,000 or 3%. Article 99(4), for non-compliance with a defined list of operator and notified body obligations, other than Article 5.
- Up to €7,500,000 or 1%. Article 99(5), for the supply of incorrect, incomplete or misleading information to notified bodies or national competent authorities in reply to a request.
Which infringement lands where
The middle tier is the one worth reading closely, because Article 99(4) is a closed list rather than a catch-all. It covers non-compliance with: the obligations of providers under Article 16; of authorised representatives under Article 22; of importers under Article 23; of distributors under Article 24; of deployers under Article 26; the requirements and obligations of notified bodies under Article 31, Article 33(1), (3) and (4), and Article 34; and the transparency obligations for providers and deployers under Article 50.
Article 16 is doing most of the work in that list for a provider, because it is the provision that aggregates the high-risk duties: ensuring the Chapter III Section 2 requirements are met, having a quality management system under Article 17, keeping documentation and logs, conformity assessment, the EU declaration, CE marking, registration, corrective action, accessibility, and cooperation with authorities. A failure of any of those is an Article 16 failure and therefore a 3% tier exposure — including, for instance, a missing registration in the EU database or a post-market monitoring plan that was never written.
The bottom tier is narrower than it looks. It is specifically about answering a request from a notified body or a national competent authority with information that is incorrect, incomplete or misleading — not about record-keeping failures generally, which land in the tier above.
The SME rule that reverses the formula
Article 99(6) is the provision most often omitted from summaries, and for a small company it is the most important sentence in the article. For SMEs, including start-ups, each fine referred to in Article 99 is up to the percentage or the amount referred to in paragraphs 3, 4 and 5, whichever is lower.
So the formula inverts. For a large undertaking the fixed amount is a floor on the ceiling and the percentage can take it far higher; for an SME the fixed amount is a cap and the percentage will almost always be the operative, much smaller, number. A start-up with €2 million turnover faces an Article 5 ceiling of 7% of €2 million, not €35 million. This is not a discount on liability — the prohibition applies identically — but it removes the existential arithmetic that the headline figures suggest.
“SME” here follows the Union definition used elsewhere in Union law rather than a bespoke AI Act threshold, and eligibility is not purely a headcount question where ownership links exist. That is a determination to check rather than assume.
Two separate regimes
Article 99 is not the whole penalty picture, and two adjacent provisions catch different actors:
- General-purpose model providers. Article 101 empowers the Commission, not national authorities, to impose fines on providers of general-purpose AI models of up to €15,000,000 or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher — for intentional or negligent infringement of the relevant provisions, failure to comply with a request for documents or information, supplying incorrect or misleading information, failing to comply with a measure requested, or failing to give the Commission access to a model in order to conduct an evaluation. This is the tier that attaches to the Chapter V obligations.
- Union institutions, bodies and agencies. Article 100 gives the European Data Protection Supervisor power to impose administrative fines on them, with substantially lower ceilings than the commercial tiers.
When these became applicable
Chapter XII, which contains Article 99, has applied since 2 August 2025 under Article 113 — with the express exception of Article 101, which applies from 2 August 2026. That produces a sequence worth stating plainly, because it is frequently reported wrongly:
- From 2 February 2025, the Article 5 prohibitions were in force but no national penalty regime under Article 99 yet applied.
- From 2 August 2025, national penalty rules applied — Member States were required to lay down the rules and notify the Commission by that date — and the Commission’s power to fine general-purpose model providers under Article 101 did not.
- From 2 August 2026, Article 101 applies. The Regulation as adopted put the bulk of the high-risk obligations on that same date; they are no longer there.
- From 2 December 2027, the stand-alone Annex III high-risk obligations apply — moved from 2 August 2026 by Regulation (EU) 2026/1744, which was adopted on 8 July 2026, published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. For high-risk AI embedded in Annex I regulated products, the date moved from 2 August 2027 to 2 August 2028.
The consequence for exposure is direct, and it is the reason this sequence is worth carrying in your head rather than looking up. The Article 99(4) tier is a ceiling on a fine for breaching an obligation; an obligation that does not yet apply cannot be breached. Because most Article 16 duties now bind from 2 December 2027 rather than 2 August 2026, the 3% tier has very little to attach to for a high-risk system provider until then. What it does attach to in the meantime is unaffected by the postponement: the Article 50 transparency duties, which still apply from 2 August 2026 and are expressly listed in Article 99(4)(g), and the deployer and distributor obligations to the extent they bind on their own timetable.
What sets the amount inside the ceiling
Article 99(1) requires penalties to be effective, proportionate and dissuasive, and to take into account the interests of SMEs and start-ups and their economic viability. Article 99 also lists the factors an authority weighs when deciding whether to impose a fine and how much: among them the nature, gravity and duration of the infringement and its consequences; whether fines have already been applied by other market surveillance authorities for the same infringement; the size, annual turnover and market share of the operator; any financial benefit gained or loss avoided; the degree of cooperation with authorities; the degree of responsibility taking into account the technical and organisational measures implemented; the intentional or negligent character of the infringement; and any action taken to mitigate the harm.
Two of those are directly actionable. Cooperation and mitigation are both in your control after an incident, and the record of technical and organisational measures is in your control before one — which is the quiet argument for the Article 17 quality management system being an artefact you can produce rather than a policy you can describe. See what compliance evidence looks like in practice.