EU AI Act
EU AI Act penalties and fines: the three tiers and who enforces them
Article 99 sets three fine tiers: up to EUR 35 million or 7% of worldwide turnover for prohibited practices, up to EUR 15 million or 3% for most other operator duties including Article 50 and deployer duties, and up to EUR 7.5 million or 1% for misleading information. For SMEs the lower of the two figures applies. Commission fines on GPAI providers sit in Article 101.
Who this applies to
- Providers and deployers
- Penalties attach to the operator that breaches the duty: providers (Art. 16), authorised representatives, importers, distributors, deployers (Art. 26) and notified bodies.
- Anyone using a prohibited practice
- The top tier covers Article 5 prohibited practices.
- GPAI model providers
- The Commission can fine GPAI providers under Article 101.
- SMEs and start-ups
- Each fine is capped at the lower of the percentage and the amount. The Omnibus extends the lower-of rule to small mid-cap enterprises for the second and third tiers.
The three tiers in Article 99
Per Article 99 on the AI Act Service Desk, maximum fines for undertakings are the higher of the amount or the percentage of total worldwide annual turnover in the preceding financial year.
| Tier | Maximum | Covers |
|---|---|---|
| Article 99(3) | EUR 35,000,000 or 7% | Non-compliance with the Article 5 prohibited practices. |
| Article 99(4) | EUR 15,000,000 or 3% | Operator obligations: providers (Art. 16), authorised representatives (Art. 22), importers (Art. 23), distributors (Art. 24), Art. 25(2) and (4), deployers (Art. 26), notified bodies, and Article 50 transparency. |
| Article 99(5) | EUR 7,500,000 or 1% | Supplying incorrect, incomplete or misleading information to notified bodies or national authorities in reply to a request. |
Two details readers often miss. First, Article 50 transparency failures sit in the middle tier, not the lowest. Second, deployer duties under Article 26 sit in the middle tier too, so deployers of high-risk systems carry real exposure.
SMEs, start-ups and small mid-caps
For SMEs, including start-ups, each fine is capped at the percentage or the amount, whichever is lower (Article 99(6)). The Digital Omnibus adds Article 99(6a), applying the same lower-of rule to small mid-cap enterprises for fines under the second and third tiers. See AI Act for startups.
Fines on GPAI providers
The Commission, not national authorities, supervises GPAI model providers. Under Article 101 it can fine up to 3% of worldwide turnover or EUR 15 million, whichever is higher, for intentional or negligent breaches including supplying misleading information to the AI Office. Per the Commission's GPAI guidelines page, its enforcement powers, including fines, start on 2 August 2026, and providers of models placed on the market before 2 August 2025 have until 2 August 2027 to comply. See GPAI obligations.
What regulators weigh
Article 99(7) lists the circumstances an authority takes into account. Several of them turn on what you can show.
- The nature, gravity and duration of the infringement and its consequences, including the number of people affected and the damage suffered.
- Fines already imposed by other authorities for the same infringement or the same activity.
- The operator's size, annual turnover and market share.
- The degree of cooperation with national authorities to remedy the infringement.
- The operator's degree of responsibility, given the technical and organisational measures it has in place.
- How the authorities learned of the infringement, in particular whether the operator notified it.
- Whether the infringement was intentional or negligent, and any action taken to mitigate harm.
"Technical and organisational measures in place" and "notified it" are the factors you control. Records that show what controls existed, and when you detected and reported a problem, are the practical content of those factors.
Who enforces, and what is known about enforcement so far
Member States set penalty rules and designate national authorities, which enforce Article 99. The AI Office and Commission enforce against GPAI providers. As of mid-July 2026, a tracker reported that no AI Act fine had been publicly confirmed, and only nine Member States had designated both required authorities by 17 June 2026 (tracker, secondary source). Neither fact is a reason to delay: the prohibitions and Article 4 have applied since February 2025, and national fines can stack with other regimes such as GDPR.
How the platform supports it
Each row maps a requirement to a platform control, the evidence artifact it produces, and the Trust & Governance Fabric facets involved. Swfte provides the controls and the evidence. You remain responsible for the decisions.
| Requirement | Platform control | Evidence artifact | Fabric facets |
|---|---|---|---|
| Show the technical and organisational measures in place (Art. 99(7)(g)) | Policy set per AI system, enforced at runtime, with decisions recorded. | Policy configuration history and decision log. | Policy, Compliance, Auditability |
| Detect and notify problems quickly (Art. 99(7)(h)) | Live monitoring of behaviour and policy denials; full action trace for reconstruction. | Alert records and reconstructable incident timeline. | Monitoring, Traceability |
| Avoid prohibited practices (Art. 5) | Deny and escalate rules for restricted actions and use cases; approved-model list. | Use-case approvals and denial records. | Policy, Risk, Human oversight |
| Accurate information to authorities (Art. 99(5)) | A single traceable record per AI system rather than documents assembled by hand. | Trust Profile and exported audit evidence with timestamps. | Evidence, Auditability |
Compliance-by-design. Swfte provides the technical controls, governance mechanisms and evidence to support deployment within applicable requirements. The exact posture depends on your use case, jurisdiction, deployment and configuration. This is not legal advice.
Hosting today: customer data is stored in AWS eu-west-1 (Ireland), as stated on the trust page. EU region, in-country, dedicated and on-prem options are the platform position: what it is designed to let you do, scoped with you through a dedicated deployment engagement, not self-serve.
What this does not cover
- Swfte does not predict whether or how an authority would fine you, and nothing here is an estimate of exposure.
- It does not pay, insure against or negotiate fines.
- National penalty rules and Member State enforcement practice differ. Consult counsel for your Member State.
- A control is not a defence by itself. Article 99(7) is a balancing exercise on all the circumstances.
Frequently asked questions
What is the maximum fine under the EU AI Act?
For prohibited practices, up to EUR 35 million or 7% of total worldwide annual turnover for the preceding financial year, whichever is higher (Article 99(3)).
What is the fine for breaching high-risk deployer or Article 50 duties?
Up to EUR 15 million or 3% of worldwide turnover, whichever is higher (Article 99(4)). That tier covers deployers under Article 26 and transparency under Article 50.
Do SMEs pay the same fines as large companies?
No. For SMEs, including start-ups, each fine is capped at the lower of the percentage and the amount. The Digital Omnibus extends that lower-of rule to small mid-cap enterprises for the 3% and 1% tiers.
Are fines already being imposed?
As of mid-July 2026 a tracker reported no publicly confirmed AI Act fine. Treat that as secondary information that can change. Commission enforcement powers over GPAI providers began on 2 August 2026.
Does Article 4 AI literacy have its own fine?
Article 4 contains no penalty provision itself. Enforcement runs through national authorities and national penalty rules, so check your Member State.
Can good records reduce a fine?
Article 99(7) tells authorities to consider your technical and organisational measures, cooperation, mitigation and whether you self-reported. Records help you show those facts. They do not guarantee any outcome, and this is not legal advice.
Sources
Last verified 2026-10-06. Primary sources are EUR-Lex and European Commission pages. Items marked as secondary are commentary or trackers; check the primary text before relying on them.
- AI Act Article 99, penalties (AI Act Service Desk)
- AI Act Article 101, fines on GPAI providers (AI Act Service Desk)
- Regulation (EU) 2026/1744, the Digital Omnibus on AI (EUR-Lex) (Adopted 8 July 2026, published 24 July 2026, in force 27 July 2026.)
- European Commission: guidelines for providers of general-purpose AI models
- Regulation (EU) 2024/1689, the AI Act (EUR-Lex)
- AI Act national implementation tracker (artificialintelligenceact.eu) (Secondary tracker, used for designation counts and the absence of confirmed fines.)
Across the platform
The controls on this page are part of the Trust & Governance Fabric that runs through every layer of the Sovereign Intelligence Platform.
AI governance
Governance that runs inside AI, not beside it.
AI sovereignty
Seven kinds of control over your AI estate.
Trust Profile
The record of what each AI system is and may do.
Trust centre
What Swfte can show today, and what it does not claim.
Build EU-first AI with the evidence already running
Start with one entry point. Add governance, in-region options and evidence as your requirements grow.