LinkedInInstagramXTikTok

EU AI Act penalties: how big are the fines and who enforces them?

The EU AI Act is often described in terms of what businesses must do. Just as important is what happens if they do not. The Act carries some of the largest fines in EU digital law, and the penalty provisions have been in force since August 2025. This guide sets out the tiers, who enforces them, how the size of a fine is decided, and what companies can do now to limit their exposure.

The three main penalty tiers

The Act scales penalties to the seriousness of the breach. The headline figures are ceilings; actual fines are set case by case.

Prohibited practices — up to €35 million or 7%

Breaching the ban on prohibited AI practices — such as certain social scoring or manipulative systems — carries fines of up to €35 million or 7% of total worldwide annual turnover for the preceding year, whichever is higher.

Other obligations — up to €15 million or 3%

Most other breaches, including failures around high-risk system obligations or the transparency rules, are subject to fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher.

Incorrect information — up to €7.5 million or 1%

Supplying incorrect, incomplete or misleading information to notified bodies or competent authorities can be fined up to €7.5 million or 1% of turnover, whichever is higher.

A break for smaller companies

For SMEs and start-ups, each ceiling applies as the lower of the fixed sum and the percentage, rather than the higher. This tempers the impact on smaller businesses while keeping the regime meaningful.

Separate rules for general-purpose AI

Providers of general-purpose AI models sit under a distinct enforcement track. The European Commission can impose fines of up to €15 million or 3% of worldwide annual turnover on GPAI providers that breach their obligations or fail to comply with its requests.

Who enforces the rules

Enforcement is shared. Each member state designates one or more market surveillance authorities responsible for most of the Act, while the European Commission’s AI Office oversees general-purpose AI models. A European Artificial Intelligence Board coordinates consistent application across the Union. In Sweden, national authorities are being designated to supervise and enforce the rules domestically.

How the size of a fine is decided

Penalties must be effective, proportionate and dissuasive. In setting an amount, authorities weigh the nature, gravity and duration of the breach, whether it was intentional or negligent, the size and market share of the operator, any action taken to mitigate harm, and the degree of cooperation with authorities. A company that self-identifies a problem and moves quickly to fix it is in a very different position from one that ignores it.

Fines are not the only consequence

Beyond financial penalties, authorities can order that a non-compliant system be brought into conformity, withdrawn or recalled from the market. There is also reputational damage, potential civil liability to those harmed, and contractual fallout with customers who require compliance. For many businesses these knock-on effects matter as much as the fine itself.

How to reduce your exposure

The most effective protection is preparation. Build an inventory of the AI systems you provide or deploy, classify each against the Act’s risk categories, document how you meet the relevant obligations, and put clear internal governance and vendor due diligence in place. Good records not only lower the chance of a breach — they demonstrate good faith if a regulator ever comes calling.

How Lawgent can help

Lawgent helps businesses assess their AI Act exposure and put proportionate compliance measures in place before problems arise. Contact us for a practical review of where you stand and what to prioritise.

0Varukorg0,00 

Inga produkter i varukorgen.

Gå tillbaka till butiken