EU AI Act Guide

EU AI Act Fines and Penalties: The Three Tiers, Explained

Last updated: 2026-07-09

The EU AI Act carries the largest fines in EU tech regulation — higher than GDPR at the top tier. Penalties are structured in three bands, and the number that applies is whichever is higher: the fixed amount or the percentage of total worldwide annual turnover.

Fines are also not the only exposure: market surveillance authorities can force products off the EU market, and enterprise buyers walk away from vendors with unresolved compliance questions long before any regulator does. Here is the actual structure.

Not sure which tier applies to you? Check your system in 2 minutes — free and rule-based.

Quick shortcut

Already know you need documents? Skip straight to the Doc Pack — your classification is done for you.

Get Doc Pack ($229$499)

Tier 1 — €35M or 7%: prohibited practices

Violations of Article 5 — manipulative techniques causing significant harm, exploitation of vulnerabilities, social scoring, untargeted facial-image scraping, emotion recognition in workplaces and schools, and the other prohibited practices — draw the top band: up to €35 million or 7% of total worldwide annual turnover, whichever is higher.

These provisions have applied since 2 February 2025, and penalty enforcement has been available since 2 August 2025. There is no transition period left: a prohibited practice running today is a live violation, not a future risk.

Tier 2 — €15M or 3%: most operational violations

Non-compliance with the operative obligations sits here: provider duties for high-risk systems (risk management, data governance, technical documentation, logging, oversight, accuracy), deployer duties, importer and distributor duties, notified-body obligations, and Article 50 transparency duties for chatbots and synthetic content.

This is the band that matters for most SaaS companies. Missing Annex IV documentation on a high-risk system, or an undisclosed chatbot, is a Tier 2 matter — up to €15 million or 3% of worldwide turnover.

Tier 3 — €7.5M or 1%: misleading information

Supplying incorrect, incomplete or misleading information to notified bodies or authorities draws up to €7.5 million or 1% of turnover. It exists so that paper compliance — documents describing processes that do not exist — is itself punishable, separately from the underlying violation.

SME cap, GPAI fines and who enforces

For SMEs and startups, each fine is capped at the lower of the two amounts rather than the higher — the percentages bite less, but €7.5–35M ceilings still apply. Providers of general-purpose AI models face a separate regime: up to €15M or 3%, enforced by the Commission’s AI Office.

Everything else is enforced nationally: each member state designates market surveillance authorities that investigate, order corrective action or market withdrawal, and fine. Factors that move the number: nature and duration of the infringement, intent or negligence, cooperation, mitigation taken, and whether the same operator was sanctioned before by another authority.

The exposure that arrives before any fine

Realistically, a mid-size SaaS is unlikely to be the first headline enforcement target — but three cheaper penalties arrive earlier. First, corrective-action orders: an authority can require withdrawal of a non-compliant system from the EU market, which for a SaaS is an existential order, not a fee. Second, procurement: enterprise buyers already ask AI Act questions in vendor reviews, and “we have not classified our systems” ends deals silently. Third, contract risk: EU customers pass their deployer duties through contractually, and a vendor who cannot support them is in breach before any regulator looks.

The rational response is proportionate: classify your systems, produce the core documents, and keep evidence — the same work that answers a buyer questionnaire is the work that mitigates a fine.

Where does your system land?

Check your AI system against the actual Annex I/III rules in 2 minutes. Free, rule-based, no signup.

Start the free risk check →

Frequently asked questions

Are fines already being issued?

Penalty provisions have been applicable since 2 August 2025, and member state authorities are standing up enforcement. Early activity focuses on prohibited practices and egregious cases — but corrective-action powers and buyer pressure operate regardless of headline fines.

Is 7% calculated on EU revenue or global revenue?

Total worldwide annual turnover of the preceding financial year — the same construction as GDPR, deliberately. EU-only revenue does not cap the calculation.

Can individuals like directors be fined personally?

The Act fines operators — companies — not individuals. Personal liability can still arise under national law (negligence, misrepresentation), and member states set some procedural rules, but the AI Act penalty bands target legal entities.

About these guides

Written by the TrustPacket team. We track Regulation (EU) 2024/1689, Commission guidance, and enforcement developments to keep these guides current. Not legal advice — when in doubt, consult qualified counsel.

Last updated: 2026-07-09 · Content review: 11 July 2026 · Questions? Email us

This is informational editorial content based on Regulation (EU) 2024/1689 and cited official implementation material. It is not legal advice, not a conformity assessment, and does not create a lawyer-client relationship. Application depends on facts this guide cannot verify. Consult qualified counsel for a binding assessment.