EU AI Act
Fines and penalties, by scenario
The EU AI Act fines scale with the severity of the breach, and at the top they exceed the GDPR. Here is every fining regime, mapped to the exact Article, so you can see which one a given failure falls under.
The three Article 99 tiers
For AI systems, national market-surveillance authorities can fine up to the higher of a fixed figure or a percentage of total worldwide annual turnover.
whichever is higher (worldwide annual turnover)
Prohibited practices
Placing on the market, putting into service, or using an AI system in a way banned under Article 5 (for example manipulative AI, social scoring, or untargeted facial scraping).
Art. 5 · penalty Art. 99(3)
whichever is higher (worldwide annual turnover)
Most other obligations
Non-compliance with the high-risk provider requirements (Art. 9–15, Art. 16), deployer duties (Art. 26–27), transparency (Art. 50), and the importer, distributor, authorised-representative and notified-body obligations.
penalty Art. 99(4)
whichever is higher (worldwide annual turnover)
Incorrect information to authorities
Supplying incorrect, incomplete, or misleading information to notified bodies or national competent authorities in reply to a request.
penalty Art. 99(5)
Two regimes people miss
Article 99 is not the whole story. Two other fining powers sit outside it.
General-purpose AI model providers
GPAI models are policed by the European Commission, not national authorities. The Commission can fine a model provider up to €15 million or 3% of worldwide annual turnover (whichever is higher) for breaching the GPAI obligations or failing to cooperate.
Art. 101 · duties Art. 53, 55
EU institutions and bodies
Union institutions, bodies and agencies are fined by the European Data Protection Supervisor: up to €1.5 million for a prohibited-practice breach and up to €750,000 for other non-compliance.
Art. 100
A softer rule for SMEs and startups
For SMEs, including startups, each cap applies as whichever amount is lower, the fixed euro figure or the turnover percentage, not higher. It is a deliberate softening, but it does not exempt smaller organisations from the obligations themselves.
Art. 99(6)
How the amount is decided
The figures are ceilings, not fixed fines. Authorities weigh the nature, gravity and duration of the breach, whether it was intentional or negligent, the harm caused, any prior infringements, and how far the organisation cooperated.
Art. 99(7)
Worldwide turnover, not just EU revenue
Like the GDPR, the percentage is calculated on the organisation’s total worldwide annual turnover, not only revenue earned in the EU. A global company with a small EU footprint can still face a fine measured against its entire global revenue, which is why classifying your systems correctly, and documenting the obligations that follow, is worth far more than the cost of getting it wrong.
Check your exposure, freeBased on the EU AI Act (Regulation (EU) 2024/1689), Articles 99, 100 and 101. Compliance support, not legal advice.