What the AI Act says about penalties
The general framework is mainly in Chapter XII of Regulation (EU) 2024/1689. Article 99 requires penalties to be effective, proportionate and dissuasive. Member States must establish rules to enforce them and may provide for warnings and other non-monetary measures.
Non-compliance therefore does not automatically produce the same outcome in every case. The facts and the date on which the relevant obligation applies must be assessed.
Which infringements can attract €35 million or 7%?
The highest tier concerns breaches of the prohibition of AI practices listed in Article 5. An administrative fine can reach €35 million or, for an undertaking, 7% of its total worldwide annual turnover in the preceding financial year, whichever is higher.
Article 5 prohibits specific AI practices. Before asking whether a system is high-risk, an organisation should check that its intended use is not prohibited under the AI Act.
Which infringements can attract €15 million or 3%?
Another tier can reach €15 million or, for an undertaking, 3% of its total worldwide annual turnover in the preceding financial year, whichever is higher.
It covers breaches of specified obligations relating to, among others, providers, authorised representatives, importers, distributors, deployers and notified bodies. It also covers certain transparency duties under Article 50.
The organisation’s role in the AI value chain therefore matters.
What if information is incorrect or misleading?
Providing incorrect, incomplete or misleading information to a notified body or a competent national authority in response to a request can attract a fine of up to €7.5 million or, for an undertaking, 1% of its total worldwide annual turnover in the preceding financial year, whichever is higher, subject to the SME rule discussed below.
Having documents is not enough. Information must be accurate, consistent, current, traceable and supported by evidence.
How are fines calculated for undertakings?
The Regulation pairs fixed maximum amounts with percentages of worldwide turnover. For undertakings other than SMEs, the higher applicable ceiling is used in the relevant category. This prevents a fixed amount from being insignificant to a very large business.
These amounts are maximum ceilings, not automatic fines. The authority must consider the circumstances of the infringement.
What about SMEs and start-ups?
Article 99 provides a specific rule for small and medium-sized enterprises, including start-ups. For each fine under that article, the maximum is the lower of the relevant percentage and fixed amount.
When imposing a fine, the authorities must also take account of the interests and economic viability of SMEs. This is not an exemption from the AI Act. It reflects proportionality in the penalty regime.
Which factors determine the amount?
Identifying the breached duty is only the beginning. Article 99 calls for consideration of relevant circumstances, including:
- the nature, gravity and duration of the infringement and its consequences
- the purpose of the AI system, the number of affected people and the damage suffered
- the degree of responsibility
- cooperation with the authorities and corrective measures
- previous infringements
- financial gains or losses avoided.
Two apparently similar breaches may therefore lead to different outcomes.
Which operators can be fined?
The AI Act distinguishes providers, deployers, authorised representatives, importers and distributors. Their obligations are not identical.
An organisation using a third-party system does not necessarily take on all the provider’s obligations. Nor does buying an external tool remove every responsibility.
A sound review starts with system → intended purpose → role → classification → obligation.
What about high-risk AI systems?
High-risk AI systems are subject to significant requirements, including risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy, robustness and cybersecurity. Different operators also have their own duties.
A mistaken classification can start a chain: incorrect classification → missed duties → absent controls → inadequate evidence → possible non-compliance. Classification is an early control point. Always check when the relevant high-risk rules apply to the system concerned.
What about deployers?
Organisations that use AI systems can also have duties. Article 26 sets specific obligations for deployers of high-risk systems. Depending on the case, these can include using the system according to instructions, assigning human oversight, meeting conditions for input data, monitoring operation, retaining certain logs and reporting risks or serious incidents.
Buying a tool from a supplier does not make its deployer a passive bystander. Its use needs governance too.
Penalties for general-purpose AI model providers
The Regulation has a separate regime for providers of general-purpose AI models. Under Article 101, the Commission may impose fines of up to €15 million or 3% of total worldwide annual turnover in the preceding financial year, whichever is higher, in the circumstances specified there.
These include certain breaches of the Regulation, failures to respond properly to information requests, incorrect information and failures to comply with measures required by the Commission. General-purpose AI models have their own supervision and enforcement arrangements.
What is the role of national authorities?
Enforcement is not solely a matter for the European Commission. Member States designate competent national authorities and establish surveillance and enforcement arrangements.
Authorities may investigate, request information, require corrective measures, restrict or withdraw systems and apply the relevant penalties.
An organisation should be able to answer an authority’s request with a coherent trail of decisions and evidence, rather than unrelated documents.

How can an organisation reduce non-compliance risk?
The point of AI governance is broader than avoiding a fine. It is to know and control how AI is used across the organisation.
Step 1. Inventory AI systems
Identify AI systems and uses.
Step 2. Determine the organisation’s role
Establish whether it is a provider, deployer or another operator.
Step 3. Classify each system
Determine the applicable regime.
Step 4. Identify obligations
Map classification and role to the relevant requirements.
Step 5. Assess risks
Consider risks to people, processes and the organisation.
Step 6. Put controls in place
Define technical, organisational and oversight measures.
Step 7. Assign owners
Every control needs someone responsible for it.
Step 8. Produce evidence
Record what was done and when.
Step 9. Monitor
Check that the controls continue to work.
Step 10. Manage change
Reassess when the system, its purpose or context changes.
Compliance belongs throughout the lifecycle.
What evidence should an organisation retain?
Depending on its duties and risks, useful evidence may include:
- an AI system inventory and regulatory classification
- risk and impact assessments
- technical documentation and records of decisions
- implemented controls and test results
- logs and human oversight records
- supplier documentation and training records
- incidents, corrective actions and periodic reviews
- records of system changes.
The same set is not required of every organisation. Evidence should follow the applicable obligations and risks: obligation → control → owner → evidence.
Common mistakes
Looking only at the maximum fine
First identify the actual obligations.
Assuming every infringement has the same outcome
The AI Act sets different penalty tiers.
Failing to establish the organisation’s role
Providers and deployers do not have identical duties.
Classifying a system only once
Its purpose or context may change.
Assuming third-party AI removes responsibility
Deployers can have duties too.
Creating documents only when asked
Traceability should accompany the system throughout its lifecycle.
Having policies without evidence
A policy alone does not prove a control works.
Ignoring system changes
A modification can alter risks, classification or obligations.
A penalty can be the end of a chain of failures
The headline figures attract attention. Yet the first question for an organisation is not how much a fine might cost. It is: can we show that we know which AI we use, which obligations apply and how we manage its risks?
Governance connects inventory → classification → obligations → risks → controls → evidence → monitoring.
That chain helps reduce exposure to non-compliance and gives the organisation something more useful: control over the AI it uses.
References
- Regulation (EU) 2024/1689 — Artificial Intelligence Act.
- Chapter XII and Article 99 — Penalties.
- Article 5 — Prohibited AI practices.
- Article 16 — Obligations of providers of high-risk AI systems.
- Article 26 — Obligations of deployers of high-risk AI systems.
- Article 50 — Transparency obligations.
- Article 100 — Administrative fines on Union institutions, bodies and agencies.
- Article 101 — Fines for providers of general-purpose AI models.
Do you know your organisation’s exposure under the AI Act?
Before thinking about penalties, identify your AI systems, how they are classified, which duties apply and what evidence you hold.
Start the diagnostic →
Céntrika’s diagnostic can help you establish that starting point.
