ISHIGHRISK AI
Enforcement

Penalties and enforcement

Three Article 99 tiers, enforceable since 2 August 2025. Which breach lands in which tier, and why SMEs pay the lower of the two figures, not the higher.

Reviewed 22 July 2026Regulation (EU) 2024/1689, as amended by the Digital Omnibus
In short

Article 99 sets three ceilings: €35 million or 7% of total worldwide annual turnover for Article 5 prohibited practices, €15 million or 3% for most other duties including Article 50 transparency and the whole high-risk regime, and €7.5 million or 1% for giving authorities incorrect, incomplete or misleading information. Companies pay the higher of the fixed sum or the percentage; under Article 99(6) SMEs and start-ups pay the lower. The penalty provisions have applied since 2 August 2025. Enforcement is split between national market surveillance authorities, the AI Office for general-purpose AI models, and the EDPS for EU institutions, and only 8 of 27 member states met the 2 August 2025 deadline to name their authority.

Three Article 99 tiers, and exactly which breaches land in each

Article 99 fixes the ceiling by which obligation you broke, not by the harm your system caused. The harm still matters to the amount an authority imposes inside that ceiling, but it cannot move a breach from one tier to another. There are three ceilings, and a breach falls into one of them by category. A prohibited practice under Article 5 sits at the top. Almost everything else substantive, including the entire high-risk regime and every Article 50 transparency duty, sits in the middle. Giving an authority bad information sits at the bottom, and is still worth up to €7.5 million.

TierFixed ceilingTurnover ceilingWhat lands herePercentage overtakes the fixed sum above
Prohibited practices€35,000,0007% of total worldwide annual turnoverArticle 5 prohibited practices, and nothing else€500 million turnover
Most obligations€15,000,0003% of total worldwide annual turnoverThe high-risk regime in Articles 9 to 15 and 43, registration under Article 49, Article 50 transparency, and provider, deployer, importer and distributor duties€500 million turnover
Information to authorities€7,500,0001% of total worldwide annual turnoverSupplying incorrect, incomplete or misleading information to authorities€750 million turnover

The top tier is Article 5 and only Article 5

Nothing outside the prohibitions reaches €35 million or 7%. That matters for how you sequence compliance work: the eight prohibitions are a short, closed list, they have been binding since 2 February 2025, and screening against them is a bounded exercise rather than a programme. They cover subliminal or purposefully manipulative techniques causing significant harm, exploitation of vulnerabilities of age, disability or social and economic situation, social scoring leading to disproportionate or detrimental treatment, individual predictive criminal-risk assessment based solely on profiling, untargeted scraping of facial images, emotion recognition in the workplace and in education, biometric categorisation inferring sensitive traits, and real-time remote biometric identification in public spaces for law enforcement.

The Digital Omnibus adds a ninth: AI systems generating child sexual abuse material or non-consensual intimate imagery. Because it is an Article 5 prohibition, the conservative reading is that it carries the top tier once it applies on 2 December 2026. The provider test is broad, extending to any system where such generation is a reasonably foreseeable and reproducible outcome without significant technical modification, and, like several of the original eight, it binds deployers as well as providers, since Article 5 catches the use of a prohibited system and not only its placing on the market. The Digital Omnibus changes to the AI Act set out what else moved.

The middle tier is where most businesses actually sit

€15 million or 3% covers the bulk of the regulation. Every high-risk obligation is here: the Article 9 risk management system, data governance, technical documentation, logging, transparency to deployers, human oversight, accuracy and robustness, conformity assessment under Article 43 and registration under Article 49. So is all of Article 50 transparency, which is the tier most companies will meet first, because 2 August 2026 arrives long before the high-risk dates. So are the role-specific duties, which is why the Article 25 flip from deployer to provider is a penalty question and not just a paperwork question: inheriting the Article 16 obligation set means inheriting the exposure attached to it.

The information tier is not a technicality

€7.5 million or 1% for supplying incorrect, incomplete or misleading information to authorities is the tier that catches organisations after the fact. Picture a provider that assembled its Annex IV file before market placement, then shipped four model updates without revising it, and hands the original file to a market surveillance authority on request. The documentation duty was breached in the middle tier. Handing over a file that no longer describes the system risks a second, independent finding in this tier. Annex IV has to be kept up to date for a reason, and what each Annex IV block has to contain is worth reading before you are asked for it.

The higher-of rule for companies, and the Article 99(6) reversal for SMEs

Each tier carries two numbers, and they are not alternatives you get to choose between. For a company, the higher of the fixed sum and the turnover percentage applies. Article 99(6) reverses this for SMEs and start-ups, which pay the lower of the two. Art 99(6)

The arithmetic is worth doing once. In the top tier, 7% of turnover exceeds €35 million only above €500 million of total worldwide annual turnover. The middle tier crosses over at exactly the same point, because 3% of €500 million is €15 million. The information tier crosses over at €750 million. Below those thresholds the fixed sum is the operative ceiling for a company; above them, the percentage is, and it keeps climbing with no upper bound in the article.

Article 99(6) caps the number, not the duty. An SME with €4 million of turnover faces at most €280,000 in the top tier rather than €35 million, which is a real protection. It owes exactly the same obligations. Where it provides an Annex III system it still has to document its Article 6(4) assessment before placing that system on the market and still has to register it in the EU database even where it self-assesses as not high-risk, and in every case it still has to answer a market surveillance authority accurately. Article 11(2) gives SMEs a simplified form of technical documentation, not an exemption from having it.

Penalties have been enforceable since 2 August 2025

The penalty provisions applied on 2 August 2025, together with the general-purpose AI model obligations and the governance framework. That is a real date with a real effect, but it does not mean every obligation in the regulation became fineable that day. A tier can only attach to a duty that has already started to apply, and the application dates are staggered across three and a half years.

2 Feb 2025Article 5 prohibitions and the Article 4 AI-literacy duty applied.
2 Aug 2025GPAI model obligations, governance provisions and the penalty provisions applied.
2 Aug 2026Article 50 transparency applies. AI Office enforcement begins.
2 Dec 2026Article 50(2) marking reaches generative systems placed on the market before 2 August 2026. The CSAM and non-consensual-imagery prohibition applies.
2 Dec 2027High-risk obligations apply to standalone Annex III systems.
2 Aug 2028High-risk obligations apply to Annex I embedded-product systems.

Read the two columns together and the live exposure as of today is narrower than the headline suggests, and sharper. What is fineable now under Article 99: an Article 5 prohibited practice at the top tier, and inaccurate, incomplete or misleading information given to an authority. The general-purpose AI model obligations in Articles 53 and 55 have applied since 2 August 2025, but the AI Office only gains its enforcement powers on 2 August 2026. The Article 4 AI-literacy duty has applied since 2 February 2025 and is supervised nationally; it does not carry one of the three Article 99 ceilings. What is not yet fineable is the thing most compliance programmes are built around, namely the high-risk obligations. The full sequence is laid out on the AI Act timeline as amended.

Do not read the 2 August 2025 date as an amnesty for the six months before it. The prohibitions bound you from 2 February 2025 even though the penalty provisions applied later. More importantly, a prohibited practice you have not stopped is not a historic breach at all: it is a continuing one, happening now, inside the penalty regime. The conservative posture is to treat any Article 5 exposure as live rather than grandfathered.

Who enforces the AI Act: market surveillance authorities, the AI Office and the EDPS

There is no single AI Act regulator. Supervision is split by what you have and who you are, and the split determines who can open a file on you.

What you haveWho supervises itBasis
Most AI systems placed on the market or put into service in the EUThe national market surveillance authority of the member state concernedDesignated by each member state under Article 70
General-purpose AI models, and systems from the same providerThe AI OfficeEnforcement powers begin 2 August 2026
AI used by EU institutions, bodies, offices and agenciesThe European Data Protection SupervisorEU-level supervision, not national

The second row carries a trap for model providers. If you provide a general-purpose AI model and you also ship systems built on that model, both the model and those systems fall to the AI Office rather than to a national authority. If a customer builds on your model, that customer system is supervised nationally. The same technology can therefore be supervised by two different bodies depending on whose name is on the system, which is one more reason role determination is worth getting right early.

The Article 70 designation gap: 8 of 27 member states made the deadline

Article 70 required each member state to designate its national competent authorities by 2 August 2025, the same day the penalty provisions started to apply. Only 8 of the 27 met it, a figure that surfaced in the European Parliament debates on the Digital Omnibus. Nineteen of the twenty-seven member states entered the penalty era without a fully named enforcer.

The states that moved early took visibly different routes. France routed supervision to the DGCCRF, its consumer-protection and fraud-control enforcement body. Spain stood up AESIA, a dedicated agency for supervising artificial intelligence. Germany placed it with the Bundesnetzagentur, its established federal network regulator. Three institutional cultures, three different instincts about what AI supervision resembles: consumer protection, a bespoke AI regulator, and sectoral network regulation. Expect their opening questions to differ accordingly.

A missing authority is not a missing obligation. Designation determines who supervises you. It does not determine whether the duty binds you, when it starts, or what a breach is worth. States that designate late will still be supervising conduct that predates the designation, and nothing about the delay narrows Article 99. Treat the gap as a delay in attention, not a defence.

What an uneven enforcement map means if you operate across several member states

Market surveillance is organised nationally. If you place the same system on the market in twelve member states, you are exposed to the supervisory posture of twelve authorities, some of which are fully staffed and some of which do not yet exist by name. You cannot maintain twelve compliance postures for one product, so in practice you will hold one, and the only safe one is the strictest you plausibly face.

Plan to the front-runners, not to the median

The rational baseline is not the average member state. It is the state that designated early, has an enforcement culture, and is likely to publish its expectations first. A product that satisfies a designated, resourced authority satisfies a late one. The reverse is not true, and rebuilding a documentation set under time pressure after an authority opens a file is the expensive path.

Documentation is the portable asset

Whichever authority arrives, the questions come from the same articles. Annex IV technical documentation, the Article 6(4) record of why you concluded a system is not high-risk, the EU database registration entry, the conformity assessment route you chose, and the post-market monitoring plan. None of that is jurisdiction-specific. Building it once answers every authority, and it is the part of the work that does not get faster if you start late.

The ambiguity gap makes divergence more likely, not less

The Commission missed its February 2026 statutory deadline for the Article 6 high-risk classification guidelines. That means national authorities are approaching the Article 6(3) derogation without a common set of worked examples, at exactly the moment they are standing up new teams. A derogation argument that convinces one authority may not convince another, and until the guidelines land there is no authoritative tiebreaker. The conservative posture follows from the structure rather than from pessimism: document the assessment thoroughly, register the system even where you self-assess as not high-risk, and assume that profiling of natural persons forecloses the derogation entirely.

Cutting your exposure before the high-risk tiers bite

Penalty exposure is not evenly distributed across the work, so the sequence matters more than the volume. In descending order of what a euro of effort buys you:

  1. Screen for Article 5 first. It is the only route to 7%, the list is closed, and it has been enforceable since 2 August 2025. If anything in your estate touches emotion recognition at work, biometric categorisation, social scoring or scraped facial images, that is the first conversation.
  2. Fix Article 50 before 2 August 2026. Middle tier, broadest population, and usually the cheapest remediation in the regulation. A disclosure line in a chatbot interface is not an engineering programme.
  3. Decide your role before you decide your obligations. A deployer that rebrands a purchased high-risk system, substantially modifies it, or repurposes a general tool into a high-risk use becomes the provider under Article 25 and inherits the full Article 16 set.
  4. Start the Annex IV pack now for anything that might be Annex III. The obligations apply from 2 December 2027 for standalone systems and 2 August 2028 for embedded products. The documentation, conformity assessment and registration work does not compress into the final quarter.
  5. Answer authorities carefully. The bottom tier exists precisely for organisations that handle the request worse than they handled the underlying duty.

If you are not sure which of those apply to a given system, the free AI Act triage classifier runs the same tests in order and tells you which tier your answers put you in, with the article each determination rests on. The primary text is on EUR-Lex, and the Commission maintains its own overview of the regulatory framework for AI.

Check your own system

The free classifier walks the same tests in order and tells you which of them your system actually trips, with the article each answer rests on.

Run the triage →

Frequently asked questions

What is the maximum fine under the EU AI Act?

For a company the maximum is 35 million EUR or 7% of total worldwide annual turnover, whichever is higher, and it applies only to the Article 5 prohibited practices; an SME or start-up pays the lower of the two under Article 99(6). Every other substantive breach sits in the middle tier at 15 million EUR or 3%, which is where the high-risk regime and all of the Article 50 transparency duties land. Supplying incorrect, incomplete or misleading information to an authority carries 7.5 million EUR or 1%. The figures are ceilings for their category rather than fixed tariffs, so the amount an authority actually imposes turns on the facts of the case.

When did EU AI Act penalties become enforceable?

The penalty provisions applied from 2 August 2025, alongside the general-purpose AI model obligations and the governance framework. That date does not make every obligation fineable, because a tier can only attach to a duty that has already started to apply. The Article 5 prohibitions and the Article 4 AI-literacy duty have applied since 2 February 2025. Article 50 transparency applies from 2 August 2026. High-risk obligations for standalone Annex III systems apply from 2 December 2027, and for Annex I embedded products from 2 August 2028.

Do SMEs and start-ups pay lower AI Act fines?

Yes. Article 99(6) reverses the usual rule for SMEs and start-ups: where a company pays the higher of the fixed sum or the turnover percentage, an SME or start-up pays the lower of the two. In practice that means the percentage usually governs, because a smaller business will rarely reach the turnover at which 7% exceeds 35 million EUR. The reversal caps the number, not the duty. An SME still owes the same obligations, still has to document its assessments and still has to answer a market surveillance authority.

Who issues EU AI Act fines?

Enforcement is split three ways. National market surveillance authorities designated under Article 70 supervise most AI systems placed on their market. The AI Office supervises general-purpose AI models and systems from the same provider, with its enforcement beginning on 2 August 2026. The European Data Protection Supervisor covers EU institutions, bodies and agencies. For a business selling into several member states, the practical answer is that more than one national authority can take an interest in the same system, because market surveillance is organised nationally.

Can I be fined now if my high-risk AI system is not compliant?

Not for the high-risk obligations themselves, because they do not apply yet. Standalone Annex III systems come into scope on 2 December 2027 and Annex I embedded products on 2 August 2028. What is live today is different: the Article 5 prohibitions, the Article 4 AI-literacy duty, the general-purpose AI model obligations, and the duty to give authorities accurate information. A system that is high-risk and non-compliant is not yet a penalty exposure, but the conformity work behind Articles 9 to 15, Annex IV and registration takes far longer than the time left.

My member state has not named an AI Act authority. Does that help me?

No. Only 8 of the 27 member states met the 2 August 2025 Article 70 deadline to designate their authorities, but designation controls who supervises you, not whether the obligation binds you. The duties apply from their application dates regardless of national administrative readiness, and states that designate late will still be supervising conduct that predates the designation. Treat the gap as a delay in attention rather than a defence, and assume every member state has a functioning authority well before the high-risk deadlines in December 2027 and August 2028.

What fine applies to an Article 50 transparency breach?

Article 50 breaches sit in the middle tier: 15 million EUR or 3% of total worldwide annual turnover, whichever is higher for a company and whichever is lower for an SME or start-up. That covers failing to tell people they are interacting with a chatbot under 50(1), failing to notify people exposed to emotion recognition or biometric categorisation under 50(3), and failing to disclose a deepfake or AI-generated public-interest text under 50(4). Most of these duties apply from 2 August 2026, with the 50(2) machine-readable marking duty reaching pre-existing systems on 2 December 2026.

This page is triage guidance, not legal advice. It reflects Regulation (EU) 2024/1689 as amended by the Digital Omnibus, reviewed 22 July 2026, when the Omnibus was adopted and signed but awaiting Official Journal publication. Final classification for ambiguous cases needs qualified counsel.