EU AI Act fines and penalties — what's at stake
The EU AI Act's three-tier fine structure: €35M / 7% for prohibited practices, €15M / 3% for high-risk breaches, €7.5M / 1% for misinformation. SME perspective.
The EU AI Act’s penalty regime is designed to sting. The headline numbers — €35 million or 7% of global turnover — match GDPR-tier severity, and in some bands exceed it. This guide unpacks the three fine tiers, the SME-specific cap, who enforces what, and the practical incidents that are most likely to trigger a fine.
The three tiers (Article 99)
Article 99 establishes a tiered penalty regime. Whichever amount is higher — the absolute euro figure or the percentage of preceding global annual turnover — wins.
| Tier | Maximum | Triggers | |---|---|---| | Tier 1 (most severe) | €35 million or 7% | Non-compliance with the prohibited practices listed in Article 5 | | Tier 2 | €15 million or 3% | Most other infringements — high-risk obligations (Art. 9–15), transparency (Art. 50), conformity assessment violations, GPAI obligations | | Tier 3 | €7.5 million or 1% | Supplying incorrect, incomplete, or misleading information to notified bodies or national supervisory authorities |
The SME cap — important small print
Article 99(6) provides that for SMEs (including startups), the fine is capped at the lower of the absolute amount or the percentage. For everyone else, it’s the higher. The intent is to prevent a 50-person company from being fined into oblivion for a procedural slip, while still keeping the percentage threat real for large incumbents.
Practical effect for a Series A startup with €5M in revenue:
| Infringement | Large company fine | Startup fine (€5M turnover) | |---|---|---| | Prohibited practice | Higher of €35M or 7% (= €35M) | Lower of €35M or €350K (= €350K) | | High-risk breach | Higher of €15M or 3% (= €15M) | Lower of €15M or €150K (= €150K) | | Bad info to authority | Higher of €7.5M or 1% (= €7.5M) | Lower of €7.5M or €50K (= €50K) |
€350K is still meaningful — that’s a two-engineer year of runway. Don’t bank on the SME cap as a strategy. Bank on classifying correctly.
What actually triggers the fines
The fines are not theoretical. Here are the breach patterns supervisory authorities are most likely to act on:
Tier 1 — Article 5 violations:
- Deploying a workplace emotion-recognition system (banned)
- Using AI for social scoring of employees that leads to unjustified differential treatment
- Real-time biometric identification in publicly accessible spaces (with narrow law-enforcement exceptions)
- Manipulative AI that exploits vulnerable users
Tier 2 — most likely operational breaches:
- Placing a high-risk AI system on the market without registering it in the EU database (Art. 49)
- Shipping a high-risk system without a conformity assessment (Art. 43)
- Missing or inadequate technical documentation (Art. 11, Annex IV)
- Failure to inform users that they’re interacting with AI (Art. 50)
- Failure to label deepfakes or synthetic content (Art. 50)
- GPAI provider failing to publish the copyright training-data summary (Art. 53)
Tier 3:
- Misrepresenting capabilities or risks in your declaration of conformity
- Providing incomplete information to a notified body during conformity assessment
- Failing to cooperate with a supervisory authority’s inquiry
Who enforces — supervisory authorities and the AI Office
The Act creates a layered governance structure:
- National supervisory authorities — designated by each Member State. They handle individual cases against companies operating in their jurisdiction. For Sweden, the AI Act surveillance is likely to be split between IMY (data protection angle) and a designated competent authority for product safety. The exact division was finalised in 2025.
- The European AI Office — part of the European Commission. It oversees the GPAI provisions directly. If you provide a GPAI model, the AI Office is your direct counterparty.
- The European Artificial Intelligence Board — coordinates between national authorities, issues guidance, harmonises enforcement.
A typical penalty proceeding involves the national authority opening an inquiry, the company being given a chance to respond, a corrective order being issued, and only then — if the company fails to remediate — a fine.
When fines actually apply — the date matters
Penalties for high-risk breaches are expected to apply from 2 December 2027 (the general application date for high-risk obligations, postponed under the Digital Omnibus, agreed May 2026 and pending formal adoption). Article 5 prohibitions have been enforceable since 2 February 2025 — and fines for those apply from the same date. GPAI penalties apply from 2 August 2025.
If your audit catches a high-risk compliance gap before 2 December 2027 and you remediate before that date, you reduce the enforcement window. After 2 December 2027, the gap is a live liability.
Mitigating factors (Article 99(7))
The Act expects supervisory authorities to take several factors into account when setting the fine:
- The nature, gravity, and duration of the infringement
- The number of persons affected and the damage suffered
- Whether other authorities have imposed fines for the same conduct
- Annual turnover and market share
- Whether mitigating actions were taken (acceptance audit trail, prompt remediation)
- Degree of cooperation with the supervisory authority
- Previous infringements
- Whether the infringement was intentional or negligent
This is where your audit trail earns its keep. A company that can show: “we ran a classification, a named human reviewed it, we kept reviewer notes, we have evidence of our AI literacy programme” lands closer to the low end of the fine band than one that cannot.
The cheapest insurance is correct classification
The cheapest mitigation is to classify your systems correctly the first time, document the reasoning, and accept the classification with a named human. That gets you out of Tier 1 entirely (correct screening rules out prohibited practices) and gives you the documentation to argue for low-end fines if a Tier 2 question ever comes up.
That’s what platforms like Maditon are for — to keep the classification, the reasoning, the reviewer attribution, and the audit trail in one place so you can produce them when it matters.