AI Act Fines: Up to €35 million — who, how much and for what
Penalties for breaching the EU AI Act are among the highest in the history of European legislation — up to €35 million or 7% of global annual turnover. That's almost double the GDPR maximum. Let's look at who fines, how much and for what.
Three Tiers of Fines (Article 99)
Article 99 of Regulation (EU) 2024/1689 sets three tiers of maximum fines. The higher of the two amounts always applies — euros or percentage of turnover — unless the entity is a small or medium-sized enterprise (SME), in which case the lower of the two applies.
for prohibited AI practices under Article 5 — social scoring, manipulation, biometric categorisation of sensitive attributes, untargeted face scraping, emotion recognition in workplaces and schools.
for breaches of other obligations — high-risk systems without documentation, missing labelling of chatbots and AI content (Art. 50), breach of provider, deployer, importer or distributor obligations.
for supplying incorrect, incomplete or misleading information to notified bodies or supervisory authorities in response to a request.
Who Can Impose Fines
The AI Act delegates fines to three types of authorities — depending on who the breach concerns:
Each Member State designates its own market surveillance authorities and a notifying authority. They fine companies in that country — providers, deployers, importers and distributors of AI systems. In Slovakia no new central AI authority will be created: according to a MIRRI announcement of 13 August 2026, oversight rests with existing structures headed by MIRRI as the general market surveillance authority and single point of contact, with the national law still in the legislative process. In several other Member States the designation is still being prepared.
Fines providers of GPAI models (general-purpose AI — e.g. ChatGPT, Gemini, Claude). Under Article 101, it can impose fines of up to €15M or 3% of global annual turnover. Targets are Big Tech providers of foundation models, not their users.
Fines EU institutions, agencies and bodies. Maxima are lower — up to €1.5M for prohibited practices and up to €750K for other breaches (Art. 100).
Examples: How Much Specific Companies Would Pay
Maximum fines are ceilings — the actual amount depends on severity, duration of the breach, the company's cooperation and its size. Here are five realistic scenarios:
Tier 1 (prohibited practice under Art. 5). Ceiling: 7% of €2B = up to €140M. For large companies the higher of the two amounts applies.
Tier 1 — Art. 5 prohibits emotion recognition in the workplace. SME regime: the lower of the two amounts. 7% of €5M = €350K — less than €35M, so the fine is up to €350K.
Tier 2. AI in healthcare is high-risk under Annex III. Without documentation, FRIA and registration the fine can reach 3% of turnover — at a hospital with €30M turnover that's a ceiling of €900K.
Tier 2 — breach of Art. 50 (transparency). At €10M turnover the ceiling is 3% = €300K. With repeated breaches and lack of cooperation the fine can reach half the maximum.
Tier 3 — lowest ceiling, 1% of turnover or €7.5M. This is also a separate fine on top of the main breach. With non-cooperation the fines compound.
AI Act vs. GDPR Fines
AI Act fines are significantly higher than under GDPR. For companies processing personal data through AI, the fines can compound — a single breach can be punishable under both regulations.
GDPR (max)
AI Act (max)
How to Avoid Fines
Applies now (since Feb. 2025)
By 2 December 2027
Conclusion: AI Act fines are designed to bite even Big Tech. For small companies, 7% of turnover is an existential threat. Compliance — register, policy, training — costs in the order of thousands of euros. An inspection after a breach costs in the order of hundreds of thousands. Start now, while it's cheap.
Find Out What Your Company Actually Risks
Our checker tells you in 5 minutes which risk category your AI tools fall into and what fines you would face for a breach.
Start Free Check