Three Article 99 tiers, and exactly which breaches land in each
Article 99 fixes the ceiling by which obligation you broke, not by the harm your system caused. The harm still matters to the amount an authority imposes inside that ceiling, but it cannot move a breach from one tier to another. There are three ceilings, and a breach falls into one of them by category. A prohibited practice under Article 5 sits at the top. Almost everything else substantive, including the entire high-risk regime and every Article 50 transparency duty, sits in the middle. Giving an authority bad information sits at the bottom, and is still worth up to €7.5 million.
| Tier | Fixed ceiling | Turnover ceiling | What lands here | Percentage overtakes the fixed sum above |
|---|---|---|---|---|
| Prohibited practices | €35,000,000 | 7% of total worldwide annual turnover | Article 5 prohibited practices, and nothing else | €500 million turnover |
| Most obligations | €15,000,000 | 3% of total worldwide annual turnover | The high-risk regime in Articles 9 to 15 and 43, registration under Article 49, Article 50 transparency, and provider, deployer, importer and distributor duties | €500 million turnover |
| Information to authorities | €7,500,000 | 1% of total worldwide annual turnover | Supplying incorrect, incomplete or misleading information to authorities | €750 million turnover |
The top tier is Article 5 and only Article 5
Nothing outside the prohibitions reaches €35 million or 7%. That matters for how you sequence compliance work: the eight prohibitions are a short, closed list, they have been binding since 2 February 2025, and screening against them is a bounded exercise rather than a programme. They cover subliminal or purposefully manipulative techniques causing significant harm, exploitation of vulnerabilities of age, disability or social and economic situation, social scoring leading to disproportionate or detrimental treatment, individual predictive criminal-risk assessment based solely on profiling, untargeted scraping of facial images, emotion recognition in the workplace and in education, biometric categorisation inferring sensitive traits, and real-time remote biometric identification in public spaces for law enforcement.
The Digital Omnibus adds a ninth: AI systems generating child sexual abuse material or non-consensual intimate imagery. Because it is an Article 5 prohibition, the conservative reading is that it carries the top tier once it applies on 2 December 2026. The provider test is broad, extending to any system where such generation is a reasonably foreseeable and reproducible outcome without significant technical modification, and, like several of the original eight, it binds deployers as well as providers, since Article 5 catches the use of a prohibited system and not only its placing on the market. The Digital Omnibus changes to the AI Act set out what else moved.
The middle tier is where most businesses actually sit
€15 million or 3% covers the bulk of the regulation. Every high-risk obligation is here: the Article 9 risk management system, data governance, technical documentation, logging, transparency to deployers, human oversight, accuracy and robustness, conformity assessment under Article 43 and registration under Article 49. So is all of Article 50 transparency, which is the tier most companies will meet first, because 2 August 2026 arrives long before the high-risk dates. So are the role-specific duties, which is why the Article 25 flip from deployer to provider is a penalty question and not just a paperwork question: inheriting the Article 16 obligation set means inheriting the exposure attached to it.
The information tier is not a technicality
€7.5 million or 1% for supplying incorrect, incomplete or misleading information to authorities is the tier that catches organisations after the fact. Picture a provider that assembled its Annex IV file before market placement, then shipped four model updates without revising it, and hands the original file to a market surveillance authority on request. The documentation duty was breached in the middle tier. Handing over a file that no longer describes the system risks a second, independent finding in this tier. Annex IV has to be kept up to date for a reason, and what each Annex IV block has to contain is worth reading before you are asked for it.
The higher-of rule for companies, and the Article 99(6) reversal for SMEs
Each tier carries two numbers, and they are not alternatives you get to choose between. For a company, the higher of the fixed sum and the turnover percentage applies. Article 99(6) reverses this for SMEs and start-ups, which pay the lower of the two. Art 99(6)
The arithmetic is worth doing once. In the top tier, 7% of turnover exceeds €35 million only above €500 million of total worldwide annual turnover. The middle tier crosses over at exactly the same point, because 3% of €500 million is €15 million. The information tier crosses over at €750 million. Below those thresholds the fixed sum is the operative ceiling for a company; above them, the percentage is, and it keeps climbing with no upper bound in the article.
Article 99(6) caps the number, not the duty. An SME with €4 million of turnover faces at most €280,000 in the top tier rather than €35 million, which is a real protection. It owes exactly the same obligations. Where it provides an Annex III system it still has to document its Article 6(4) assessment before placing that system on the market and still has to register it in the EU database even where it self-assesses as not high-risk, and in every case it still has to answer a market surveillance authority accurately. Article 11(2) gives SMEs a simplified form of technical documentation, not an exemption from having it.
Penalties have been enforceable since 2 August 2025
The penalty provisions applied on 2 August 2025, together with the general-purpose AI model obligations and the governance framework. That is a real date with a real effect, but it does not mean every obligation in the regulation became fineable that day. A tier can only attach to a duty that has already started to apply, and the application dates are staggered across three and a half years.
Read the two columns together and the live exposure as of today is narrower than the headline suggests, and sharper. What is fineable now under Article 99: an Article 5 prohibited practice at the top tier, and inaccurate, incomplete or misleading information given to an authority. The general-purpose AI model obligations in Articles 53 and 55 have applied since 2 August 2025, but the AI Office only gains its enforcement powers on 2 August 2026. The Article 4 AI-literacy duty has applied since 2 February 2025 and is supervised nationally; it does not carry one of the three Article 99 ceilings. What is not yet fineable is the thing most compliance programmes are built around, namely the high-risk obligations. The full sequence is laid out on the AI Act timeline as amended.
Do not read the 2 August 2025 date as an amnesty for the six months before it. The prohibitions bound you from 2 February 2025 even though the penalty provisions applied later. More importantly, a prohibited practice you have not stopped is not a historic breach at all: it is a continuing one, happening now, inside the penalty regime. The conservative posture is to treat any Article 5 exposure as live rather than grandfathered.
Who enforces the AI Act: market surveillance authorities, the AI Office and the EDPS
There is no single AI Act regulator. Supervision is split by what you have and who you are, and the split determines who can open a file on you.
| What you have | Who supervises it | Basis |
|---|---|---|
| Most AI systems placed on the market or put into service in the EU | The national market surveillance authority of the member state concerned | Designated by each member state under Article 70 |
| General-purpose AI models, and systems from the same provider | The AI Office | Enforcement powers begin 2 August 2026 |
| AI used by EU institutions, bodies, offices and agencies | The European Data Protection Supervisor | EU-level supervision, not national |
The second row carries a trap for model providers. If you provide a general-purpose AI model and you also ship systems built on that model, both the model and those systems fall to the AI Office rather than to a national authority. If a customer builds on your model, that customer system is supervised nationally. The same technology can therefore be supervised by two different bodies depending on whose name is on the system, which is one more reason role determination is worth getting right early.
The Article 70 designation gap: 8 of 27 member states made the deadline
Article 70 required each member state to designate its national competent authorities by 2 August 2025, the same day the penalty provisions started to apply. Only 8 of the 27 met it, a figure that surfaced in the European Parliament debates on the Digital Omnibus. Nineteen of the twenty-seven member states entered the penalty era without a fully named enforcer.
The states that moved early took visibly different routes. France routed supervision to the DGCCRF, its consumer-protection and fraud-control enforcement body. Spain stood up AESIA, a dedicated agency for supervising artificial intelligence. Germany placed it with the Bundesnetzagentur, its established federal network regulator. Three institutional cultures, three different instincts about what AI supervision resembles: consumer protection, a bespoke AI regulator, and sectoral network regulation. Expect their opening questions to differ accordingly.
A missing authority is not a missing obligation. Designation determines who supervises you. It does not determine whether the duty binds you, when it starts, or what a breach is worth. States that designate late will still be supervising conduct that predates the designation, and nothing about the delay narrows Article 99. Treat the gap as a delay in attention, not a defence.
What an uneven enforcement map means if you operate across several member states
Market surveillance is organised nationally. If you place the same system on the market in twelve member states, you are exposed to the supervisory posture of twelve authorities, some of which are fully staffed and some of which do not yet exist by name. You cannot maintain twelve compliance postures for one product, so in practice you will hold one, and the only safe one is the strictest you plausibly face.
Plan to the front-runners, not to the median
The rational baseline is not the average member state. It is the state that designated early, has an enforcement culture, and is likely to publish its expectations first. A product that satisfies a designated, resourced authority satisfies a late one. The reverse is not true, and rebuilding a documentation set under time pressure after an authority opens a file is the expensive path.
Documentation is the portable asset
Whichever authority arrives, the questions come from the same articles. Annex IV technical documentation, the Article 6(4) record of why you concluded a system is not high-risk, the EU database registration entry, the conformity assessment route you chose, and the post-market monitoring plan. None of that is jurisdiction-specific. Building it once answers every authority, and it is the part of the work that does not get faster if you start late.
The ambiguity gap makes divergence more likely, not less
The Commission missed its February 2026 statutory deadline for the Article 6 high-risk classification guidelines. That means national authorities are approaching the Article 6(3) derogation without a common set of worked examples, at exactly the moment they are standing up new teams. A derogation argument that convinces one authority may not convince another, and until the guidelines land there is no authoritative tiebreaker. The conservative posture follows from the structure rather than from pessimism: document the assessment thoroughly, register the system even where you self-assess as not high-risk, and assume that profiling of natural persons forecloses the derogation entirely.
Cutting your exposure before the high-risk tiers bite
Penalty exposure is not evenly distributed across the work, so the sequence matters more than the volume. In descending order of what a euro of effort buys you:
- Screen for Article 5 first. It is the only route to 7%, the list is closed, and it has been enforceable since 2 August 2025. If anything in your estate touches emotion recognition at work, biometric categorisation, social scoring or scraped facial images, that is the first conversation.
- Fix Article 50 before 2 August 2026. Middle tier, broadest population, and usually the cheapest remediation in the regulation. A disclosure line in a chatbot interface is not an engineering programme.
- Decide your role before you decide your obligations. A deployer that rebrands a purchased high-risk system, substantially modifies it, or repurposes a general tool into a high-risk use becomes the provider under Article 25 and inherits the full Article 16 set.
- Start the Annex IV pack now for anything that might be Annex III. The obligations apply from 2 December 2027 for standalone systems and 2 August 2028 for embedded products. The documentation, conformity assessment and registration work does not compress into the final quarter.
- Answer authorities carefully. The bottom tier exists precisely for organisations that handle the request worse than they handled the underlying duty.
If you are not sure which of those apply to a given system, the free AI Act triage classifier runs the same tests in order and tells you which tier your answers put you in, with the article each determination rests on. The primary text is on EUR-Lex, and the Commission maintains its own overview of the regulatory framework for AI.