What are the fines under the EU AI Act?
EU AI Act penalties fines are set in tiers, with maximums scaled to the seriousness of the breach. The top tier — up to €35 million or 7% of total worldwide annual turnover for the preceding financial year, whichever is higher — applies to the prohibited AI practices listed in Art. 5. Most other infringements, including breaches of provider and deployer obligations for high-risk systems and the transparency duties in Art. 50, carry up to €15 million or 3% of turnover; supplying incorrect or misleading information to authorities or notified bodies carries up to €7.5 million or 1%.
These are ceilings, not tariffs. National authorities set the actual amount, and the Regulation directs them to weigh the nature and gravity of the infringement, its duration, whether the operator is an SME, any prior penalties, and whether the operator cooperated or self-reported.
- Identify which AI systems you provide or deploy, and in what role.
- Screen every system against the Art. 5 prohibitions first — that is where the 7% exposure sits.
- Classify the remainder: high-risk under Annex III or Art. 6, limited-risk transparency, or minimal risk.
- Check whether you meet the SME definition, which changes how the caps are calculated.
- Assemble the evidence an authority would ask for: inventory, classification rationale, technical documentation, and human-oversight arrangements.
EU AI Act fine tiers as set out in the Regulation's penalties provisions.: Tier | Type of infringement | Maximum fine Highest | Prohibited AI practices (Art. 5) | €35m or 7% of total worldwide annual turnover, whichever is higher Standard | Breach of provider, deployer, importer, distributor, or notified-body obligations, including high-risk requirements and Art. 50 transparency | €15m or 3% of worldwide annual turnover Information | Incorrect, incomplete, or misleading information supplied to notified bodies or national competent authorities | €7.5m or 1% of worldwide annual turnover GPAI models | Infringements by providers of general-purpose AI models, enforced by the Commission | €15m or 3% of worldwide annual turnover
Note that the Regulation also addresses penalties for Union institutions, bodies, and agencies separately, with fines imposed by the European Data Protection Supervisor at lower fixed amounts. For the article-by-article detail, see the EU AI Act guide or the text of Regulation (EU) 2024/1689 itself.
What triggers the highest EU AI Act fines?
Only one category attracts the top tier: the practices prohibited by Art. 5. Prohibited AI practices penalties are the Act's sharpest instrument because these systems are considered incompatible with fundamental rights rather than merely risky. The prohibitions have applied since 2 February 2025 — earlier than most of the Act.
- Subliminal, manipulative, or deceptive techniques that materially distort behaviour and cause or are likely to cause significant harm.
- Exploitation of vulnerabilities due to age, disability, or a specific social or economic situation.
- Social scoring by public or private actors leading to detrimental or disproportionate treatment.
- Predicting the risk of a person committing a criminal offence based solely on profiling or personality traits.
- Untargeted scraping of facial images from the internet or CCTV to build or expand facial recognition databases.
- Inferring emotions in the workplace or in education, except for medical or safety reasons.
- Biometric categorisation to deduce race, political opinions, trade union membership, religious beliefs, sex life, or sexual orientation.
- Real-time remote biometric identification in publicly accessible spaces for law enforcement, subject to narrow exceptions.
- •If you are unsure which of your systems could touch a prohibition, a free exposure scan is a reasonable place to triage before you commit engineering time.
Are there reduced penalties for SMEs and startups?
Yes — though it is a cap-calculation rule rather than a discount. SME AI Act proportionality works like this: for SMEs, including startups, each of the fine ceilings is set at the lower of the percentage figure and the fixed euro figure. For every other undertaking, the top tier takes the higher of the two. In practice, a small company with modest turnover is capped by the percentage; a very large company is capped by the euro figure only when that is higher.
"SME" follows the EU definition in Commission Recommendation 2003/361/EC: fewer than 250 staff and either turnover of no more than €50 million or a balance-sheet total of no more than €43 million, with partner and linked enterprise data consolidated. That consolidation rule matters — a small subsidiary of a large group is generally not an SME.
How the fine caps are calculated by organisation size.: Organisation size | How the cap is applied | Conditions SME or startup (per the EU definition) | The lower of the percentage of turnover and the fixed euro amount | Headcount and financial thresholds met, including partner and linked enterprise data Large undertaking | The higher of the percentage and the fixed euro amount, in the top tier | Standard treatment under the penalties provisions Subsidiary of a large group | Generally treated as a large undertaking | Linked-enterprise data is consolidated, so group figures apply Union institution, body, or agency | Separate fixed-amount regime | Fines imposed by the European Data Protection Supervisor
Beyond the caps, the Regulation asks Member States to take SME interests into account, and it obliges national authorities to provide regulatory sandboxes with priority access for SMEs. The Commission's AI Act Service Desk is the official first stop for small-business guidance.
Who enforces these fines — and how?
Enforcement is national, with one exception. AI Act supervisory authorities are designated by each Member State: at least one notifying authority and at least one market surveillance authority, collectively the national competent authorities. Market surveillance authorities carry the investigative and penalty powers. The exception is general-purpose AI models, where the European Commission's AI Office enforces directly.
Enforcement roles and where each one bites.: Role | Enforcement stage | What it does National market surveillance authority | Investigation and penalties | Requests documentation, orders corrective action, withdraws or recalls systems, imposes fines Notifying authority | Pre-market | Designates and monitors notified bodies for conformity assessment Notified body | Conformity assessment | Assesses certain high-risk systems before placing on the market Commission AI Office | GPAI models | Evaluates, requests information, and fines providers of general-purpose AI models European Artificial Intelligence Board | Coordination | Advises and coordinates consistent application across Member States Data protection authorities | Overlapping supervision | Supervise personal-data processing under the GDPR; designated market surveillance authority for certain high-risk uses in some Member States
In Ireland, national implementation and competent-authority designation sit with the Department of Enterprise, Tourism and Employment, and the Data Protection Commission remains the supervisory authority for the personal-data dimension of any AI system. Irish organisations should expect to deal with more than one regulator on the same system.
What will supervisory authorities look at first?
Market surveillance work usually starts with a documented request for information, not a raid. The fastest way to convert a routine enquiry into an escalation is to be unable to answer basic questions about what you deploy and why you classified it the way you did.
- An inventory of AI systems, with role stated for each: provider, deployer, importer, or distributor.
- The classification rationale — why a system is or is not high risk, and if Art. 6(3) exemptions are relied on, the assessment supporting that.
- Technical documentation and logging for high-risk systems, including data governance and accuracy, robustness, and cybersecurity measures.
- Evidence of human oversight arrangements: who reviews outputs, with what authority to override.
- Art. 50 transparency evidence — disclosure that users are interacting with an AI system, and marking of synthetic content.
- AI literacy measures for staff dealing with AI systems, which have applied since 2 February 2025.
- Records of instructions for use received from providers, and evidence that deployment stayed within them.
- Post-market monitoring and serious-incident reporting arrangements.
- •A structured free compliance tracker or a scored readiness assessment will surface which of these you cannot yet evidence. Software supports a compliance programme; it does not make an organisation compliant.
AI Act vs GDPR fines: how does enforcement compare?
Comparing AI Act vs GDPR fines is useful because most EU organisations already have GDPR muscle memory. The headline percentages differ — the AI Act's top tier is 7% against the GDPR's 4% — but the deeper difference is that the AI Act is product-safety law wearing fundamental-rights clothing. Its primary remedy is often not a fine at all, but an order to correct, withdraw, or recall a system from the market.
AI Act and GDPR enforcement compared.: Dimension | EU AI Act | GDPR Top fine ceiling | €35m or 7% of worldwide annual turnover | €20m or 4% of worldwide annual turnover Trigger for top tier | Prohibited practices (Art. 5) | Breaches of principles, lawful basis, data subject rights, transfers SME treatment | Caps calculated on the lower of euro or percentage figure | No equivalent statutory cap adjustment Primary regulator | National market surveillance authority; Commission AI Office for GPAI | National data protection authority; one-stop-shop lead authority Non-financial remedies | Withdrawal, recall, restriction of a system on the market | Processing bans, corrective orders Complaint route | Complaints to market surveillance authorities | Data subject complaints to a supervisory authority
There is no one-stop-shop mechanism in the AI Act equivalent to the GDPR's lead supervisory authority for cross-border processing, so an organisation active in several Member States can face several market surveillance authorities. Where an AI system processes personal data, both regimes apply at once — Regulation (EU) 2016/679 does not step aside, and the European Data Protection Board has been active on the overlap.
What should organisations do now to reduce exposure?
Penalty exposure under the AI Act is mostly a function of three things: whether you touch a prohibition, whether you can evidence your classifications, and whether you can answer an information request accurately and on time. All three are addressable before any enforcement contact.
- Screen for prohibitions now. The Art. 5 list has applied since 2 February 2025, carries the 7% ceiling, and is the shortest test to run against your system inventory.
- Write down classification decisions. Date them, name the decision-maker, and record the reasoning — particularly for any Annex III system where you argue an exemption applies.
- Fix the information-request path. The 1% tier exists specifically for incorrect or misleading answers to authorities. Decide now who owns responses and where the evidence lives.
- Map deadlines against your roadmap. High-risk obligations under Annex III generally apply from 2 August 2026, with certain product-embedded high-risk systems following on 2 August 2027.
- Keep vendor evidence. As a deployer you rely on provider documentation; if the provider cannot supply it, that is a procurement decision, not a documentation gap to absorb.
- •Start with the free EU AI Act tools to build the inventory, then move to the EU AI Act compliance handbook for templates and programme structure. Step-by-step guidance on setting each of these up is in the Veritome Help Center, and further analysis across the obligation set is on the Veritome blog.