← Back to blog

AI Act Fines: Up to €35 million — who, how much and for what

Penalties for breaching the EU AI Act are among the highest in the history of European legislation — up to €35 million or 7% of global annual turnover. That's almost double the GDPR maximum. Let's look at who fines, how much and for what.

Three Tiers of Fines (Article 99)

Article 99 of Regulation (EU) 2024/1689 sets three tiers of maximum fines. The higher of the two amounts always applies — euros or percentage of turnover — unless the entity is a small or medium-sized enterprise (SME), in which case the lower of the two applies.

Tier 1 — highest up to €35M or 7% of turnover

for prohibited AI practices under Article 5 — social scoring, manipulation, biometric categorisation of sensitive attributes, untargeted face scraping, emotion recognition in workplaces and schools.

Tier 2 — middle up to €15M or 3% of turnover

for breaches of other obligations — high-risk systems without documentation, missing labelling of chatbots and AI content (Art. 50), breach of provider, deployer, importer or distributor obligations.

Tier 3 — lowest up to €7.5M or 1% of turnover

for supplying incorrect, incomplete or misleading information to notified bodies or supervisory authorities in response to a request.

Who Can Impose Fines

The AI Act delegates fines to three types of authorities — depending on who the breach concerns:

1
National supervisory authorities

Each Member State designates its own market surveillance authorities and a notifying authority. They fine companies in that country — providers, deployers, importers and distributors of AI systems. In Slovakia no new central AI authority will be created: according to a MIRRI announcement of 13 August 2026, oversight rests with existing structures headed by MIRRI as the general market surveillance authority and single point of contact, with the national law still in the legislative process. In several other Member States the designation is still being prepared.

2
European AI Office

Fines providers of GPAI models (general-purpose AI — e.g. ChatGPT, Gemini, Claude). Under Article 101, it can impose fines of up to €15M or 3% of global annual turnover. Targets are Big Tech providers of foundation models, not their users.

3
EDPS (European Data Protection Supervisor)

Fines EU institutions, agencies and bodies. Maxima are lower — up to €1.5M for prohibited practices and up to €750K for other breaches (Art. 100).

Examples: How Much Specific Companies Would Pay

Maximum fines are ceilings — the actual amount depends on severity, duration of the breach, the company's cooperation and its size. Here are five realistic scenarios:

1
Large AI provider (€2B turnover) deploys a social scoring system

Tier 1 (prohibited practice under Art. 5). Ceiling: 7% of €2B = up to €140M. For large companies the higher of the two amounts applies.

2
Medium-sized company (€5M turnover) uses emotion analysis on employees

Tier 1 — Art. 5 prohibits emotion recognition in the workplace. SME regime: the lower of the two amounts. 7% of €5M = €350K — less than €35M, so the fine is up to €350K.

3
Hospital deploys high-risk AI without technical documentation

Tier 2. AI in healthcare is high-risk under Annex III. Without documentation, FRIA and registration the fine can reach 3% of turnover — at a hospital with €30M turnover that's a ceiling of €900K.

4
E-shop fails to label its AI chatbot and deepfake ads

Tier 2 — breach of Art. 50 (transparency). At €10M turnover the ceiling is 3% = €300K. With repeated breaches and lack of cooperation the fine can reach half the maximum.

5
Company supplies misleading information during an inspection

Tier 3 — lowest ceiling, 1% of turnover or €7.5M. This is also a separate fine on top of the main breach. With non-cooperation the fines compound.

AI Act vs. GDPR Fines

AI Act fines are significantly higher than under GDPR. For companies processing personal data through AI, the fines can compound — a single breach can be punishable under both regulations.

GDPR (max)

€20M or 4% of global turnoverFor personal data onlyImposed by national DPA

AI Act (max)

€35M or 7% of global turnoverFor all AI systems regardless of personal dataImposed by national market surveillance authority, AI Office or EDPS

How to Avoid Fines

Applies now (since Feb. 2025)

No prohibited AI practices (Art. 5)Employee AI literacy (Art. 4)Audit of currently used AI tools

By 2 December 2027

AI systems register and internal policyLabelling of chatbots and AI content (Art. 50) — already in force since 2 Aug 2026Human oversight procedures for high-riskFRIA for high-risk systems

Conclusion: AI Act fines are designed to bite even Big Tech. For small companies, 7% of turnover is an existential threat. Compliance — register, policy, training — costs in the order of thousands of euros. An inspection after a breach costs in the order of hundreds of thousands. Start now, while it's cheap.

Find Out What Your Company Actually Risks

Our checker tells you in 5 minutes which risk category your AI tools fall into and what fines you would face for a breach.

Start Free Check

Blog content is written and reviewed before publication by Bc. Ferko Kiš, who holds editorial responsibility for the published texts.

AiComply asistent Automatizovaný AI asistent
EU AI Act
Dobrý deň! Som AiComply asistent — automatizovaný chatbot s umelou inteligenciou. Poradím vám s EU AI Act a súladom. Čo vás zaujíma? Spustiť bezplatnú kontrolu