EU AI Act — penalties for companies, sized and dated
EU AI Act penalties for companies: the fines, sized and dated.
The caps are public and the penalty regimes have been in force since 2 August 2025. The timing is what most companies size wrong: Regulation (EU) 2026/1744 moved the high-risk regime to 2 December 2027 and 2 August 2028, so the fines a company can actually incur this quarter come from the duties already live — Article 5's bans, Article 50's transparency rules, and the other live obligations. Here are the three tiers, the live exposure, the exposure that moved, and the SME arithmetic that changes the number.
The caps
The three tiers.
Article 99 sets the ceilings. The tier depends on which duty you breached, not on how much harm resulted.
-
Tier one — breach the bans. €35 million or 7%, whichever is higher.
Violating Article 5's prohibited practices exposes an undertaking to administrative fines of up to €35 million or 7% of total worldwide annual turnover, whichever is higher (Article 99(3)). This is the tier that beats GDPR's headline, and the bans have applied to users as well as builders since 2 February 2025 — building a banned tool and buying one sit in the same tier.
-
Tier two — breach most other obligations. €15 million or 3%, whichever is higher.
Up to €15 million or 3% of total worldwide annual turnover, whichever is higher (Article 99(4)). The tier covers most of the Act's obligations — the verified examples are provider duties under Article 16, high-risk deployer duties under Article 26, and the transparency duties under Article 50. Transparency is the newest of the three: live since 2 August 2026, and it lands on the workflows most companies already run. For a company whose staff use AI tools, this is the tier the daily work actually touches.
-
Tier three — mislead the authorities. €7.5 million or 1%, whichever is higher.
Supplying incorrect, incomplete or misleading information to notified bodies or authorities costs up to €7.5 million or 1% of total worldwide annual turnover, whichever is higher (Article 99(5)). The smallest tier and the most avoidable: answer authority requests accurately, and keep the records that make your answers checkable.
-
The fourth regime — enforced from Brussels.
Providers of general-purpose AI models answer to the Commission directly, with fines of up to €15 million or 3% of annual worldwide turnover, whichever is higher (Article 101), with Commission enforcement active from 2 August 2026. Most companies will never meet this regime — it binds model providers, not the businesses deploying tools. It is on the map because “who fines whom” is part of sizing the risk.
All four figures are ceilings, not tariffs — member-state rules must make penalties effective, proportionate and dissuasive, and the cap is the worst case, not the quote.
Fineable now
What a company can be fined for right now.
Penalty regimes in force since 2 August 2025, enforcement powers activated 2 August 2026. The fineable surface is the live-duty surface.
-
The bans — tier-one exposure, since 2 February 2025.
Article 5 breaches are the top-tier kind, and the bans bind deployers as much as providers. The closest-to-home trap for a 50–500 person company is emotion inference in the workplace — an HR tool or people-analytics script inferring feelings from staff. A banned practice cannot be papered over; it has to stop.
-
Transparency — tier-two exposure, since 2 August 2026.
Article 50 duties sit squarely in the €15 million tier. On the deployer side: disclose deepfakes you publish, and disclose AI-generated text published to inform the public on matters of public interest — human-reviewed editorial content (with a natural person holding editorial responsibility) is exempt outright, and evidently artistic, creative, satirical or fictional work owes a lighter-touch disclosure, not zero. That lands on the marketing team's workflow, not on legal's abstraction. Provider-side duties — chatbot disclosure and machine-readable marking — attach if you ship your own bot.
-
The other live obligations — and the record that defends you.
Member-state penalty regimes cover infringements of the whole Regulation, not just the headline duties. The literacy duty under Article 4 has been live since 2 February 2025; skipping it is an infringement like any other, and which cap it lands under is a question no company should need answered — the duty costs less to satisfy than any fine is to dispute. Write the inventory, run the ban screen, keep the training records: the file is the defense.
The correction
What cannot be fined yet.
One regulation moved the exposure that was supposed to arrive this quarter. Budget against the new dates, not the pre-Omnibus ones.
-
The high-risk fines moved, twice.
Regulation (EU) 2026/1744 was adopted by Parliament on 16 June 2026, by Council on 29 June 2026, published in the Official Journal on 24 July 2026, and in force from 27 July 2026. It pushed the standalone high-risk package (Annex III — recruitment screening, credit scoring, insurance pricing, education, biometrics) to 2 December 2027 and product-embedded high-risk (Annex I) to 2 August 2028. Until those dates, the high-risk obligations are not applicable, so their paperwork cannot be a fineable breach.
-
The tiers did not change — the dates under them did.
The Omnibus left every cap untouched; what it moved is the high-risk regime to 2 December 2027 and 2 August 2028. That makes penalty guidance unusually easy to go stale on: a page written before 24 July 2026 can quote all three tiers correctly and still carry the pre-Omnibus assumption that high-risk obligations arrive in 2026. Dated, calendar-anchored sources beat evergreen ones here — check any penalty guidance against Regulation (EU) 2026/1744 before you size a budget off its fear.
-
What did not move.
Article 4 and Article 5 kept their 2 February 2025 date. Article 50 kept 2 August 2026. The penalty regimes kept 2 August 2025. The live exposure has been live for months — which is why the cheap-to-close list and the fineable list are the same list.
Your cap
Your size changes the number.
The headline caps are multinationals' arithmetic. Article 99 has an SME clause, and the Omnibus added a mid-cap band.
-
The general formula.
For undertakings generally, each cap is the amount or the percentage, whichever is higher. That is how the €35 million figure is real arithmetic for a multinational — and why adopting it as a working assumption for a 200-person company is how vendors sell panic.
-
The SME inversion.
For SMEs and start-ups, Article 99(6) flips the formula: each fine is capped at the lower of the amount or the percentage. Worked example — an SME with €10 million in worldwide annual turnover: the tier-one cap is not €35 million, it is 7% of €10 million — €700,000. The tier-two cap is 3% — €300,000. Authorities must additionally weigh the interests of SMEs, including start-ups, and their economic viability. That is the number to put in the risk register, and it sits more than an order of magnitude below the headline.
-
The new mid-cap band.
The Omnibus extended SME-style relief — simplified documentation, sandbox priority, tailored penalty caps — to a new small mid-cap category: fewer than 750 employees and up to €150 million annual turnover (or ≤€129 million balance-sheet total). If your company sits between the SME definitions and the multinationals, check whether the band catches you before assuming the headline caps.
-
The fine is not the whole cost.
A banned practice has to stop — the tool goes, mid-workflow. Corrective orders, re-papering and disclosure duties carry weeks, not euros. One industry expert's year-one prediction, reported by Help Net Security: corrective orders will outnumber headline fines. Build the file before you need it.
The full duty-and-deadline picture behind these numbers — what is live, what moved, and what an SME doesn't have to buy — is the EU AI Act compliance checklist for SMEs.
Straight answers
Asked by operators, answered plainly.
What is the maximum fine under the EU AI Act?
Up to €35 million or 7% of total worldwide annual turnover, whichever is higher, for breaching Article 5's banned practices; up to €15 million or 3% for most other obligations, including Article 50 transparency; up to €7.5 million or 1% for supplying incorrect, incomplete or misleading information to notified bodies or authorities. SMEs and start-ups pay at the lower of the amount or the percentage (Article 99(6)).
Are EU AI Act fines actually in force?
Yes. Member states had to lay down their penalty regimes by 2 August 2025, and enforcement powers activated with the 2 August 2026 milestone. What the Digital Omnibus moved is the high-risk regime — that package applies from 2 December 2027 for standalone systems and 2 August 2028 for product-embedded ones, so its paperwork cannot be a fineable breach until then.
Can an SME be fined €35 million?
Not off a €10 million turnover. For SMEs and start-ups, Article 99(6) caps each fine at the lower of the amount or the percentage — 7% of €10 million is €700,000, and that is the tier-one cap. Authorities must additionally weigh the interests of SMEs, including start-ups, and their economic viability.
Which AI Act violations carry the biggest fines?
Breaching the Article 5 bans — the top tier. Then most other obligations under Article 99(4): provider duties (Article 16), high-risk deployer duties (Article 26), and the transparency duties (Article 50). Supplying incorrect, incomplete or misleading information to notified bodies or authorities sits in the smallest tier. General-purpose AI model providers face a separate Commission-enforced regime of up to €15 million or 3% (Article 101).
Who enforces the EU AI Act penalties?
Each member state's national competent authorities enforce the Regulation against companies on their territory, under penalty rules every member state had to have in force by 2 August 2025. The one exception is general-purpose AI model providers, whom the Commission polices directly under Article 101.
How does a company reduce its AI Act exposure this week?
Close the live duties, because they are the fineable surface: write the AI inventory, screen it against Article 5's bans, deliver tiered AI literacy measures with a record, and wire the Article 50 disclosure step into the content workflow. Days of work, not quarters. Our post-Omnibus compliance checklist for SMEs sorts every step by date.
Next
Size the fines. Close the cheap ones.
Fast path: the $30 self-serve courses — order tonight, start tonight, 30-day money-back. With your team: UpShift AI runs readiness snapshots, fluency audits, and hands-on bootcamps for EU companies of 10–500 — AI consulting and training for European teams, exposure closed before an authority asks for the file. The rest of the cluster: the Article 4 AI literacy field guide, the training requirements for employees, and the post-Omnibus compliance checklist for SMEs.