EU AI Act penalty tiers under Article 99Three penalty tiers drawn to scale. Prohibited practices: 35 million euro or 7 percent of worldwide annual turnover. Most other operator obligations: 15 million euro or 3 percent. Supplying incorrect information: 7.5 million euro or 1 percent. In each case the fine is the higher of the two figures.Prohibited AI practicesArticle 5€35 millionor 7% of turnoverOther operator obligationsArticles 16, 22–27, 48–51€15 millionor 3% of turnoverIncorrect informationArticle 99(5)€7.5 millionor 1% of turnoverFines are the higher of the fixed sum or the percentage of total worldwide annual turnover for the preceding financial year.
Penalty ceilings under Article 99, drawn to scale. The prohibited-practice tier is more than four times the information tier.
7%Of group worldwide turnover, top tier
5%Of average daily turnover, per day
3Separate enforcement bodies
5 yrsLimitation period, Article 75c

The three penalty tiers

Article 99 sets three ceilings. In each, the fine is the higher of a fixed sum or a percentage of total worldwide annual turnover for the preceding financial year.

Article 99 penalty tiers
BreachProvisionCeilingWhat it covers
Prohibited AI practicesArticle 5€35 million or 7%Deploying or placing on the market an AI system that falls within one of the ten Article 5 bans.
Most other operator obligationsArticles 16, 22–27, 48–51€15 million or 3%Failures by providers, importers, distributors, deployers, authorised representatives or notified bodies, including the high-risk and transparency duties.
Supplying incorrect or misleading informationArticle 99(5)€7.5 million or 1%Giving notified bodies or national competent authorities information that is incorrect, incomplete or misleading in reply to a request.

Two things about the structure matter more than the numbers. First, the percentage limb is calculated on group worldwide turnover, which decouples exposure from the size of the entity that actually committed the breach. Second, the tiers are set as ceilings for Member States, not as tariffs: each Member State legislates its own penalty regime within them, so the same breach can be priced differently in different jurisdictions.

Who enforces what

Enforcement is split three ways, and the split turns on what your system is built on rather than where your company sits.

Articles 74, 99

National market surveillance authorities

The default supervisor for everything not reallocated: high-risk systems, the Article 5 prohibitions, and the Article 50 transparency duties, in each Member State where the system is on the market.

Ceiling

€35m / 7%, €15m / 3% or €7.5m / 1% depending on the breach

Articles 75, 75a–75d, 101

The AI Office

Exclusive supervision of AI systems built on a general-purpose AI model where the model and the system come from the same provider, and of AI systems integrated into very large online platforms and search engines under the DSA. Also the sole enforcer against general-purpose AI model providers.

Ceiling

Article 99(3)–(7) amounts apply correspondingly, plus periodic penalties up to 5% of average daily turnover per day

Article 100

European Data Protection Supervisor

Fines against Union institutions, bodies, offices and agencies that fall within the scope of the Regulation.

Ceiling

€1.5m for a prohibited practice, €750,000 for other breaches

Three enforcers with different remits and different ceilings. Which one supervises your system depends on what the system is built on, not on where your company is.

The reallocation to the AI Office is the significant change. Before the Omnibus, supervision of AI systems was essentially national, with the AI Office focused on general-purpose models. Article 75(1) now gives it exclusive competence over two categories of AI system: those built on a general-purpose model where the model and the system come from the same provider or undertaking, and those integrated into very large online platforms or search engines under the Digital Services Act.

For a vertically integrated AI company, one that trains a model and ships the product on top of it, that means a single EU-level supervisor rather than 27 national ones. Whether that is better or worse depends on your view of consistency versus proximity, but it is certainly different: the AI Office has investigative powers modelled on competition procedure, not on product safety inspection.

Article 75(1)Stays with national authorities even where the AI Office would otherwise have exclusive competence

  • Systems covered by the Annex I, Section A harmonisation legislation
  • Certain Annex III high-risk systems
  • Law enforcement, border management and financial institution systems falling under Article 74(6)
  • Systems used in the administration of justice

The penalty that outruns the fine

Article 75c lets the AI Office impose periodic penalty payments of up to 5% of average daily income or worldwide annual turnover in the preceding financial year, per day, for as long as a breach continues.

This is the provision least represented in coverage of the Act, and arithmetically it is the largest number in the Regulation. A one-off fine is bounded. A daily charge is not: it compounds until the operator complies.

Periodic penalty at the Article 75c ceiling: arithmetic, not prediction
Annual worldwide turnoverPer day30 days90 daysOne year
€100m€14k€411k€1.2m€5.0m
€1bn€137k€4.1m€12m€50m
€10bn€1.4m€41m€123m€500m

Read the final column against the €35 million top tier. At the ceiling, sustained non-compliance costs a mid-sized operator more in periodic penalties over a year than the maximum one-off fine for a prohibited practice. These are of course maxima, and the Court of Justice has unlimited jurisdiction to cancel, reduce or increase them, but the shape of the incentive is deliberate. The Regulation is built to make continued non-compliance more expensive than remediation.

How the amount is actually set

Article 99(7) lists nine factors authorities must take into account. Some are fixed by the facts; several are determined by how the organisation behaves once it knows.

  1. The nature, gravity and duration of the infringement and of its consequences, taking into account the purpose of the system and, where appropriate, the number of people affected and the level of damage
  2. Whether the same operator has already been fined by other market surveillance authorities for the same infringement
  3. The size, annual turnover and market share of the operator
  4. Any other aggravating or mitigating factor applicable to the circumstances, such as financial benefits gained or losses avoided
  5. The degree of cooperation with the national competent authorities
  6. The degree of responsibility of the operator, taking into account the technical and organisational measures it implemented
  7. The manner in which the infringement became known to the authority: in particular whether the operator notified it, and if so to what extent
  8. Whether the infringement was intentional or negligent
  9. Any action taken to mitigate the harm suffered by the affected persons

Four of these are within your control after the breach has happened: the technical and organisational measures you had implemented, the degree of cooperation, whether you notified the authority yourself, and what you did to mitigate harm to the people affected. That is the practical argument for having an incident process before you need one, not because it prevents a fine, but because it changes four of the nine inputs.

Smaller firms get the lower figure

For SMEs including start-ups, Article 99(6) inverts the general rule: each fine is up to the percentage or the fixed amount, whichever is lower. The Omnibus extended comparable treatment to small mid-cap enterprises for the Article 99(4) and (5) tiers.

How the same breach is priced for different operators
OperatorRuleArticle 99(4) exposure
Large enterprise, €2bn turnoverHigher of the two€60m: the 3% limb exceeds the €15m fixed sum
SME or start-up, €4m turnoverLower€120,000: the 3% limb, not the €15m fixed sum
Small mid-capLowerThe lower of 3% or €15m, per Article 99(6a)

Without the inversion, a €4 million start-up committing a high-risk breach would face the €15 million fixed sum: roughly four times its annual revenue, and a straightforwardly terminal outcome. Article 99(6) is what makes the regime survivable at the small end, and it is worth knowing about before you accept a vendor’s risk framing or price indemnities into a contract.

Union bodies and GPAI providers

Two populations sit outside the Member State regime entirely: Union institutions are fined by the European Data Protection Supervisor under Article 100, and general-purpose AI model providers by the Commission under Article 101.

The two regimes outside Article 99
PopulationEnforcerProvisionCeiling
Union institutions, bodies, offices and agenciesEuropean Data Protection SupervisorArticle 100€1.5m for a prohibited practice, €750,000 otherwise
Providers of general-purpose AI modelsEuropean CommissionArticle 101Up to 3% of worldwide annual turnover or €15m, whichever is higher

The Article 101 ceiling is notably lower than the Article 99(3) tier, which surprises people who assume foundation model providers face the largest exposure. They do not, unless the model is used for a prohibited practice, in which case the prohibition and its tier apply on their own terms.

Managing the exposure

Exposure is a function of three things you can measure: which tier a system’s worst plausible breach sits in, how long a breach would run before you noticed, and how well you could evidence the Article 99(7) mitigating factors.

Reducing exposure, by the mechanism it actually acts on
ActionReducesBecause
Screen every system against Article 5 firstTierMoves worst-case exposure from the 7% tier to the 3% tier, or out of scope
Monitoring that detects a breach in days, not quartersDurationArticle 99(7) weighs duration, and periodic penalties accrue daily
A documented incident and notification processAmountSelf-notification, cooperation and mitigation are three of the nine factors
Contemporaneous records of technical and organisational measuresAmountDegree of responsibility is assessed on the measures you had in place
Knowing which authority supervises each systemResponse timeThe AI Office and national authorities have different powers and procedures

Frequently asked questions

What is the maximum fine under the EU AI Act?
€35 million or 7% of total worldwide annual turnover for the preceding financial year, whichever is higher. That top tier under Article 99(3) is reserved for the Article 5 prohibited practices. Most other operator breaches, including the high-risk and transparency duties, carry up to €15 million or 3%, and supplying incorrect or misleading information to authorities carries up to €7.5 million or 1%.
Is the AI Act fine based on group turnover or local turnover?
Total worldwide annual turnover for the preceding financial year. That means a small EU subsidiary's exposure is set by the size of its group, not by its own revenue. It is the same basis the GDPR uses, and it is why the percentage limb usually bites harder than the fixed sum for large operators.
Are EU AI Act fines lower for small companies?
Yes, and the mechanism is easy to miss. For SMEs including start-ups, Article 99(6) provides that each fine is up to the percentage or the fixed amount, whichever is lower: the opposite of the general rule. Regulation (EU) 2026/1744 extended comparable treatment to small mid-cap enterprises for the Article 99(4) and (5) tiers.
Who enforces the EU AI Act?
It depends on the system. National market surveillance authorities are the default. The AI Office has exclusive competence over AI systems built on a general-purpose AI model where the model and system come from the same provider, and over systems integrated into very large online platforms and search engines, and it is the sole enforcer against GPAI model providers. The European Data Protection Supervisor fines Union institutions and bodies.
What is a periodic penalty payment under the AI Act?
A recurring daily charge the AI Office can impose under Article 75c to compel compliance, capped at 5% of average daily income or worldwide annual turnover in the preceding financial year, per day. It is separate from a one-off fine and accrues for as long as the breach continues, so over a sustained period it can exceed the headline ceilings.
Can the AI Office inspect our premises?
Yes. Article 75a gives it market surveillance powers including remote and on-site inspections, examining records on any medium and taking copies, requesting explanations, and sealing premises, books and records for the duration of an inspection. Judicial authorisation follows national law; a court checks the measure is not arbitrary or excessive but does not review whether the investigation is necessary.
How long do authorities have to act?
Article 75c sets a five-year limitation period for the AI Office both to exercise its powers and to enforce its decisions. Note that exposure accrues from the moment a breach begins, so for the Article 5 prohibitions, enforceable since 2 February 2025, a practice still running today has been in breach throughout.
Does self-reporting reduce the fine?
It can. Article 99(7) directs authorities to weigh the manner in which the infringement became known, and in particular whether the operator notified it and to what extent, alongside the degree of cooperation and any action taken to mitigate harm to affected people. None of that is a safe harbour, but the factors are explicit in the text.

Sources and verification

Every date and provision cited here was checked against the consolidated text on 11 August 2026. The EU AI Act is being amended as it is implemented; where this page and EUR-Lex disagree, EUR-Lex governs.

This page is an independent information resource. It is not legal advice, and it does not create a lawyer–client relationship. Take advice on your own facts before making a compliance decision.

Next: screen for the highest tier in the ten prohibited practices, work out whether Chapter III applies with the high-risk classification guide, or read Article 99 in full.