EU AI Act Penalties: How Much Can Non-Compliance Actually Cost You

SEO & GEO for WordPress websites

The EU AI Act is now in active enforcement. Prohibited AI practices have been banned since February 2025, penalty powers became applicable in August 2025, and the AI Office formally began exercising its investigative authority over general-purpose AI providers in August 2026. For any business operating in the EU or serving EU customers, EU AI Act penalties are no longer a future concern. They are a present legal reality.

The headline fine numbers are striking enough to demand attention. But the full cost of EU AI Act non-compliance extends well beyond the statutory maximum. Understanding the penalty structure, which AI use cases carry the greatest risk, and how enforcement actually works in practice gives you the foundation to make informed decisions before a regulator makes them for you.

The EU AI Act’s three-tier penalty structure explained

Article 99 of Regulation (EU) 2024/1689 establishes three tiers of administrative fines, each calibrated to the severity of the violation. Fines are calculated as the higher of a fixed euro amount or a percentage of total worldwide annual turnover, whichever produces the larger number.

Tier 1: Prohibited AI practices

The most serious violations, involving AI systems that fall under the Article 5 prohibited practices list, carry fines of up to €35,000,000 or 7% of global annual turnover. This exceeds GDPR’s top tier (4% / €20 million), making it the second-highest percentage-based penalty in EU digital regulation. There is no compliance pathway for prohibited AI. A system that falls within Article 5 cannot be remediated through documentation or conformity assessments. Immediate cessation is the only legal option.

Tier 2: High-risk AI and GPAI obligations

Non-compliance with high-risk AI system obligations, general-purpose AI (GPAI) model requirements, or violations by notified bodies carries fines of up to €15,000,000 or 3% of global annual turnover. This tier covers the majority of regulated AI in commercial use, including AI used in hiring, credit scoring, and critical infrastructure.

Tier 3: Misleading information

Supplying incorrect, incomplete, or misleading information to notified bodies or national competent authorities triggers fines of up to €7,500,000 or 1% of global annual turnover, per the official EU AI Act Article 99 text. Some secondary sources have cited 1.5% for this tier, but the official Commission text specifies 1%.

The SME exception

For small and medium-sized enterprises and start-ups, the calculation is inverted. The fine is the lower of the fixed amount or the turnover percentage, not the higher. A start-up with €500,000 in annual revenue facing a Tier 1 violation would face a maximum fine of €35,000 (7% of turnover), not €35 million. This proportionality protection is significant, though it does not eliminate exposure entirely. Each non-compliant AI system can attract a separate penalty, so organisations running multiple systems face cumulative risk.

For EU institutions and agencies, a separate mechanism applies under Article 100. The European Data Protection Supervisor can impose fines of up to €1,500,000 for prohibited practice violations and €750,000 for other non-compliance.

Which AI use cases trigger the highest fines

The highest fine tier (€35 million / 7%) applies to AI systems that fall under Article 5’s outright prohibitions. These are not grey areas. They represent practices the EU legislature determined carry risks so severe that no compliance framework can make them acceptable.

Article 5 bans eight categories of AI practice. These include subliminal or manipulative techniques designed to cause significant harm, AI that exploits the vulnerabilities of children or people with disabilities, social scoring systems that lead to disproportionate detrimental treatment, and purely profiling-based criminal risk prediction. The list also covers untargeted scraping of facial images from the internet or CCTV to build recognition databases, emotion recognition systems in workplaces and educational institutions, biometric categorisation that infers sensitive traits such as race or sexual orientation, and real-time remote biometric identification in publicly accessible spaces for law enforcement purposes (with narrow exceptions). Article 5 prohibitions became enforceable in February 2025.

The Digital Omnibus, adopted by the European Parliament in June 2026 and by the Council in late June 2026, adds two further prohibitions to Article 5: AI systems generating non-consensual intimate imagery and AI-generated child sexual abuse material. These new prohibitions apply from December 2026.

High-risk AI under Annex III

The Tier 2 fine (€15 million / 3%) applies to high-risk AI systems listed in Annex III. This category includes AI used in biometric identification, critical infrastructure management, education and vocational training, employment decisions (including recruitment, performance evaluation, and termination), access to essential services such as credit scoring and insurance pricing, law enforcement, migration and asylum processing, administration of justice, and democratic processes.

Deployer non-compliance carries the same Tier 2 exposure as provider non-compliance. Failure to assign human oversight, inform affected persons, or complete a Fundamental Rights Impact Assessment (FRIA) puts deployers in the same penalty bracket as the developers who built the system. Under the Digital Omnibus, standalone Annex III high-risk obligations have been deferred from August 2026 to December 2027. The penalty tiers themselves remain unchanged.

Hidden costs beyond the headline fine

The statutory fine is the number that gets attention, but for most organisations the indirect costs of AI Act non-compliance exceed the fine itself. Understanding the full cost picture is what makes compliance investment decisions rational rather than reactive.

Market withdrawal and procurement exclusion

National authorities have the power under Article 79 to order mandatory market withdrawal of non-compliant AI systems across all 27 EU Member States. Withdrawing a system does not retroactively cure past violations. For software businesses with EU revenue, losing market access is often more commercially damaging than the fine. EU public sector procurement increasingly includes AI compliance requirements, and a non-compliance finding can disqualify an organisation from government tenders at national, regional, and local level.

Civil liability and reputational damage

Article 86 of the EU AI Act grants individuals who have suffered harm from a high-risk AI system the right to an explanation and the right to seek redress. This creates civil litigation exposure that runs alongside regulatory fines. Non-compliance findings are public. National authorities maintain enforcement records, and significant cases attract media coverage. Industry research suggests reputational damage from AI misuse can trigger meaningful customer churn, and EU-based business partners increasingly require compliance documentation from AI vendors before entering contracts.

Compound regulatory exposure

AI Act violations frequently overlap with GDPR violations, particularly where AI systems process personal data. Article 99(8) prevents double punishment for the exact same factual violation (only the higher fine applies), but distinct violations arising from the same AI system can be penalised separately. A biometric recognition system that also violates GDPR data minimisation requirements could attract penalties under both frameworks for different aspects of the same deployment.

Conformity assessments for high-risk AI systems typically cost between €5,000 and €50,000 per system, according to compliance cost analysis published in 2026. Retrofitting documentation for systems already in production is significantly more expensive than building compliance into development workflows from the start. Companies that underestimate this consistently overlook the indirect costs of compliance reviews, which delay AI deployment timelines and consume engineering resources that would otherwise ship product.

How enforcement works in practice

EU AI Act enforcement is divided among three bodies. The European Commission’s AI Office supervises GPAI models and certain AI systems. National competent authorities and market surveillance authorities handle most other AI systems. The European Data Protection Supervisor enforces rules for AI systems used by EU institutions.

The AI Office formally began exercising its investigative and enforcement powers over GPAI model providers on 2 August 2026. Prior to this date, the AI Office focused on implementation support and “technical compliance dialogues,” its preferred initial tool for assessing compliance and clarifying questions. Where those dialogues do not adequately resolve concerns, the AI Office can escalate to formal enforcement powers: sending Requests for Information, conducting evaluations, demanding source code access, and ultimately imposing fines.

How investigations begin

Enforcement is triggered by complaints, serious incident reports, proactive market surveillance, referrals from sector-specific regulators, and whistleblower protections under Article 87. Multiple investigations into prohibited practices, including workplace emotion recognition systems in multinational corporations and predictive policing algorithms, were reportedly underway in late 2025 and early 2026. As of mid-2026, national market surveillance authorities in Germany, France, and the Netherlands had opened formal inquiries, though no officially confirmed penalty decisions with specific fine amounts had been publicly documented in primary EU sources at the time of writing.

As of March 2026, only 8 of 27 Member States had established their single contact points on the Commission’s list, per the European Parliament Think Tank’s enforcement review. Enforcement capacity is still uneven across Member States, but the regulatory architecture is clearly being built. The GDPR enforcement precedent suggests regulators will open with a small number of high-profile cases in sectors like HR, finance, and healthcare to establish precedent before broadening enforcement activity.

What mitigates a fine

Article 99(7) lists ten factors that affect the actual fine amount within the statutory maximum. These include the nature and duration of the infringement, documented compliance efforts, corrective measures taken before or after detection, degree of cooperation with authorities, proactive disclosure, and whether the infringement was intentional or negligent. Organisations that have documented governance frameworks and respond constructively to regulatory contact are treated materially differently from those that do not.

Compliance steps that reduce penalty exposure

Strong compliance frameworks can significantly reduce actual fine exposure within the statutory ranges. The steps below are sequenced to address the most common gaps first.

Build an AI inventory

Start by mapping every AI system used within the organisation, including tools that staff adopt informally without IT approval (sometimes called “shadow AI”). Document the purpose, provider, department, and stakeholders for each system. Over half of organisations lack systematic inventories of AI systems currently in production or development, which means they cannot accurately assess their own exposure.

Classify each system against the risk tiers

Misclassifying a high-risk system as low-risk leaves an organisation exposed to Tier 2 penalties. Recruitment tools, CV screening software, credit scoring AI, insurance pricing models, and diagnostic support systems are all high-risk under Annex III. Classification should be done by someone with legal and technical input, not assumed by the team using the tool.

Build technical documentation from the start

Annex IV requires structured technical records including system architecture, training data provenance, intended purpose, and risk mitigation measures. Retrofitting documentation for existing systems is exponentially more difficult than embedding documentation into development workflows from the start. Documentation preparation accounts for a substantial share of total conformity assessment costs.

Establish AI governance with cross-functional ownership

Effective AI governance requires legal, security, product, and engineering representation. Integrate risk-based AI checkpoints into existing development pipelines rather than treating compliance as a one-time audit. For GPAI providers, signing the GPAI Code of Practice (published in July 2025, with signatories including Amazon, Anthropic, IBM, Microsoft, and OpenAI) provides a presumption of conformity with GPAI obligations and is treated as a mitigating factor in fine calculations.

Align AI Act and GDPR compliance

Where AI systems involve personal data, align AI Act and GDPR governance rather than running parallel processes. A combined Data Protection Impact Assessment (DPIA) and Fundamental Rights Impact Assessment (FRIA) approach is more efficient and reduces the risk of gaps that create separate regulatory exposure under both frameworks.

High-risk AI compliance implementation typically takes 12 to 18 months for complex organisations. Starting now, even ahead of the December 2027 Annex III deadline, creates the documented compliance record that Article 99(7) treats as a mitigating factor if a violation is ever investigated.

What the EU AI Act means for AI-powered tools you already use

The EU AI Act’s scope is broader than most business leaders realise. Any organisation whose teams use Microsoft Copilot, ChatGPT, Google Gemini, or any AI-powered tool in a professional context is a “deployer” under the Act, and deployers carry specific legal obligations.

Large language models underlying ChatGPT, Claude, Microsoft Copilot, and Google Gemini fall under the GPAI rules, which have been in force since August 2025. Any company allowing employees to use these tools must meet AI literacy obligations under Article 4, which became applicable in February 2025. This means ensuring that staff who use AI tools have a sufficient understanding of how those tools work and where they may fail.

Transparency obligations that apply now

Article 50 transparency obligations came into force in August 2026. Chatbots must now disclose that they are AI. AI-generated content, including text, images, audio, and deepfakes, must be labelled in machine-readable format. These obligations were not deferred by the Digital Omnibus. The delay under the Omnibus applies only to high-risk Annex III and Annex I obligations, not to transparency requirements.

Extraterritorial reach

The EU AI Act has extraterritorial reach that mirrors the GDPR. Any organisation, regardless of location, must comply if its AI systems are used within the EU or produce outputs affecting EU residents. A US-based company using AI for loan approvals serving European customers falls within scope even if the AI models run on servers outside Europe. There is no size exemption. A two-person start-up selling an AI hiring tool to a single German client has the same core legal obligations as a large enterprise, though SME penalty calculations are more favourable.

The practical implication for most SMBs is that approximately 85% of AI systems they use, including spam filters, recommendation engines, and AI-assisted content tools, fall into the minimal-risk category with no specific AI Act obligations beyond general product safety. The compliance burden concentrates on specific high-risk use cases. Knowing which tools you use and how they are classified under the Act is the first and most important step. Producing content at scale with AI tools, for example, sits in the minimal-risk category, which is why services like AI-powered content scaling fall outside the high-risk framework entirely. The risk exposure that matters most is in HR, finance, and any system making consequential decisions about individuals.

The EU AI Act is not a compliance checkbox exercise. It is a structural shift in how AI is governed across the EU and, through its extraterritorial reach, across much of the global economy. The organisations that treat compliance as an ongoing governance capability rather than a one-time project will be better positioned both to avoid penalties and to demonstrate trustworthy AI use to customers, partners, and regulators. The penalty framework is designed to make non-compliance more expensive than compliance. The numbers in Article 99 exist precisely to make that calculus clear.

This content was generated with the help of AI and it may contain mistakes

Your customers are asking AI. Are you part of the answer?

In a quick demo, we show how WP SEO AI tracks your AI visibility, finds content gaps, and helps your website appear in ChatGPT, Google AI Overviews and more.

Dive deeper in