Enforcement
What are the penalties under the EU AI Act?
Three tiers, turnover-based, and applied by the authority that already supervises your sector.
Short answer
The EU AI Act sets administrative fines in tiers. Breach of the prohibited-practice provisions attracts fines up to EUR 35 million or 7% of total worldwide annual turnover, whichever is higher. Breach of most other obligations, including high-risk requirements for providers and deployers, attracts up to EUR 15 million or 3% of turnover. Supplying incorrect, incomplete or misleading information to authorities attracts up to EUR 7.5 million or 1%, with proportionate lower caps for SMEs and start-ups.
Reviewed 2026-08-02. General information for governance planning, not legal advice.
Key points
- Up to EUR 35 million or 7% of global turnover for prohibited practices
- Up to EUR 15 million or 3% for most other obligations
- Up to EUR 7.5 million or 1% for incorrect or misleading information to authorities
- Lower caps apply proportionately to SMEs and start-ups
- Irish enforcement runs through designated sectoral authorities
- Penalty exposure sits alongside GDPR exposure, not instead of it
The exposure that is easiest to underestimate
The third tier is the one organisations overlook. Providing incorrect, incomplete or misleading information to an authority is itself sanctionable, which means an inaccurate AI inventory is not merely an internal weakness. It is a compliance exposure in its own right.
This is why evidence quality matters as much as control design. An organisation that cannot substantiate what it told a regulator is in a materially worse position than one that reported a gap honestly.
How fines are assessed
Authorities take account of the nature, gravity and duration of the infringement, whether it was intentional or negligent, action taken to mitigate harm, cooperation with the authority, and whether penalties have already been applied for the same conduct.
Cooperation and mitigation are evidence-driven. They are demonstrated by records created before contact with the authority, not by explanations offered afterwards.
Reducing exposure in practice
- Complete prohibited-practice screening across the estate first
- Close inventory gaps before making any statement to an authority
- Version classification reasoning so historic decisions can be reproduced
- Record oversight and incident handling contemporaneously
- Separate assessment from approval so decisions are challengeable
- Retain an append-only audit trail of who decided what, and when
Frequently asked questions
- What is the maximum EU AI Act fine?
- Up to EUR 35 million or 7% of total worldwide annual turnover, whichever is higher, for infringement of the prohibited AI practice provisions.
- Are smaller companies treated differently?
- Yes. For SMEs, including start-ups, the applicable cap is the lower of the fixed amount and the turnover percentage, so the ceiling is proportionate to size.
- Can one incident trigger both AI Act and GDPR penalties?
- The regimes are separate and can apply to the same system for different failings, so AI Act exposure should be assessed alongside, not instead of, data protection exposure.
Primary sources
How AIRAS Cloud supports this
Related answers
Turn the regulation into an operating record
AIRAS Cloud gives Irish and EU organisations one accountable place to discover AI, determine scope, classify defensibly, assign controls and evidence every decision.
No pricing commitment. No confidential information required.