Vigilis

EU AI Act

Fines and penalties, by scenario

The EU AI Act fines scale with the severity of the breach, and at the top they exceed the GDPR. Here is every fining regime, mapped to the exact Article, so you can see which one a given failure falls under.

The three Article 99 tiers

For AI systems, national market-surveillance authorities can fine up to the higher of a fixed figure or a percentage of total worldwide annual turnover.

€35Mor 7%

whichever is higher (worldwide annual turnover)

Prohibited practices

Placing on the market, putting into service, or using an AI system in a way banned under Article 5 (for example manipulative AI, social scoring, or untargeted facial scraping).

Art. 5 · penalty Art. 99(3)

€15Mor 3%

whichever is higher (worldwide annual turnover)

Most other obligations

Non-compliance with the high-risk provider requirements (Art. 9–15, Art. 16), deployer duties (Art. 26–27), transparency (Art. 50), and the importer, distributor, authorised-representative and notified-body obligations.

penalty Art. 99(4)

€7.5Mor 1%

whichever is higher (worldwide annual turnover)

Incorrect information to authorities

Supplying incorrect, incomplete, or misleading information to notified bodies or national competent authorities in reply to a request.

penalty Art. 99(5)

Two regimes people miss

Article 99 is not the whole story. Two other fining powers sit outside it.

General-purpose AI model providers

GPAI models are policed by the European Commission, not national authorities. The Commission can fine a model provider up to €15 million or 3% of worldwide annual turnover (whichever is higher) for breaching the GPAI obligations or failing to cooperate.

Art. 101 · duties Art. 53, 55

EU institutions and bodies

Union institutions, bodies and agencies are fined by the European Data Protection Supervisor: up to €1.5 million for a prohibited-practice breach and up to €750,000 for other non-compliance.

Art. 100

A softer rule for SMEs and startups

For SMEs, including startups, each cap applies as whichever amount is lower, the fixed euro figure or the turnover percentage, not higher. It is a deliberate softening, but it does not exempt smaller organisations from the obligations themselves.

Art. 99(6)

How the amount is decided

The figures are ceilings, not fixed fines. Authorities weigh the nature, gravity and duration of the breach, whether it was intentional or negligent, the harm caused, any prior infringements, and how far the organisation cooperated.

Art. 99(7)

Worldwide turnover, not just EU revenue

Like the GDPR, the percentage is calculated on the organisation’s total worldwide annual turnover, not only revenue earned in the EU. A global company with a small EU footprint can still face a fine measured against its entire global revenue, which is why classifying your systems correctly, and documenting the obligations that follow, is worth far more than the cost of getting it wrong.

Check your exposure, free

Based on the EU AI Act (Regulation (EU) 2024/1689), Articles 99, 100 and 101. Compliance support, not legal advice.