NO AI ACT.

Penalties · Amounts · Authorities · Dates

AI Act penalties: amounts, who is exposed, from when

The figures in circulation — “up to €35 million”, “up to 7% of turnover” — are real, but they cover one kind of breach only. The AI Act builds three separate tiers, applies to small companies the opposite arithmetic from large ones, and hands enforcement to different authorities depending on who is being fined.

01Three tiers, not one

Article 99 grades penalties by what was breached, not by how large the harm was. The highest figure is reserved for the practices the regulation bans outright: the ones no procedure, no documentation and no oversight can make admissible.

The Article 99 ceilings, simplified
What is breachedCeilingExample situation
The Article 5 ban (prohibited practices)up to €35 million or 7% of total worldwide annual turnover for the preceding financial yearA generalised social score deciding access to essential services in unrelated contexts.
Most other obligationsup to €15 million or 3%A high-risk system used without effective human oversight, or without informing the people affected.
Incorrect, incomplete or misleading information to authoritiesup to €7.5 million or 1%An answer to an authority's request that leaves out the system's known limits.

“Or” means whichever is higher: for a company with substantial turnover, the percentage far exceeds the fixed figure. That is why headlines always quote the €35 million and the actual fine can be much larger.

02For SMEs the arithmetic runs the other way

For small and medium-sized enterprises, start-ups included, the lower of the fixed amount and the percentage applies, not the higher. It is the one place where the regulation reverses the calculation, and it changes the risk considerably for a company with modest turnover.

It is not an exemption, though: the ceiling stays high in absolute terms, and proportionality is assessed case by case — gravity, duration, previous breaches, cooperation, measures taken. A small company using a prohibited system is not sheltered by being small.

03Who imposes the penalties

There is no single authority. Who fines depends on who is being fined and which kind of rule was broken.

  • Member States lay down the national penalty regime and designate the competent authorities. Penalties must be effective, proportionate and dissuasive, and the rules are notified to the Commission.
  • The European Commission, through the AI Office, can fine providers of general-purpose AI models directly (up to €15 million or 3%).
  • The European Data Protection Supervisor fines Union institutions, bodies and agencies, under its own, lower ceilings.

National arrangements — which authority, and how it sits alongside existing data-protection and sectoral supervision — are still settling in several Member States. The official sources at the foot of this page are where to check.

04From when they can be applied

The penalty provisions apply from 2 August 2025; the Article 5 bans were already applicable from 2 February 2025, and since 2 August 2026 general application has brought with it most of the obligations a penalty can rest on.

Put differently: the penalty calendar does not coincide with the obligation calendar. An obligation that does not yet apply cannot be fined — but once it applies, it applies from day one. The application timeline keeps the full sequence.

05The fine is not the only consequence

Focusing on the amount hides the consequences that arrive earlier and often cost more.

  • The system stops. Market surveillance authorities can require corrective action, restrict the system's availability, withdraw it or recall it.
  • The service has to be redone. If the system decided priorities, selections or access, those decisions have to be revisited — and with them the procedures that depended on them.
  • The other laws still apply. The same episode can engage data protection, non-discrimination, employment law and civil liability, each with its own machinery.
  • Trust is not restored by a bank transfer. For a public body, or a company serving people directly, this is usually the larger damage.

06What actually reduces exposure

None of these is an insurance policy: they matter because they make an organisation able to notice, explain and correct. That is also what an authority looks at when weighing proportionality.

  • Knowing which risk category each system in use falls into, and having written it down somewhere.
  • Knowing whether you are a provider or a deployer, because the obligations — and therefore the possible breaches — are not the same.
  • Having people who know what the system does and where it fails: that is the AI literacy obligation, and the first one to become applicable.
  • Keeping logs and documentation that let a decision be reconstructed months later.
  • Human oversight with real power to stop the output, not just a name on a procedure.

The full operational picture is on AI Act for business; for public bodies, on AI Act in public administration.

07What happens when nobody fines anyone

NO AI ACT turns the question around: its 2032 city is a world where the AI Act never entered into force, so none of these penalties exists. “The city of scores” stages exactly the practice that today sits in the top tier — a generalised score deciding who gets access to services — and shows where it ends up when nothing stops it.

08Official sources and transparency

  • Content responsibility: the NO AI ACT project (Matteo Angeloni); internal editorial review, no third-party legal review.
  • First published: September 2026 · Last reviewed: September 2026 (site v2.3.0).
  • Official sources: Regulation (EU) 2024/1689 on EUR-Lex (Article 99 for Member State penalties, Article 100 for EU institutions, Article 101 for GPAI models, Article 113 for the dates); the EU regulatory framework for AI; the European AI Office.
  • Caveat: this page is a simplified educational reading of the amounts and the mechanisms. It is not legal advice, it does not calculate anyone's exposure, and it does not replace the regulation or a professional's opinion.

Glossary · High-risk systems · The AI Act and the GDPR