Non-compliance with the EU AI Act carries some of the highest administrative fines in EU tech regulation, structured in three tiers based on the severity of the violation. Engaging in a prohibited practice, such as social scoring or exploiting the vulnerabilities of a specific group, carries fines up to 35 million euros or 7 percent of a company's total worldwide annual turnover, whichever is higher. Violating other obligations, including the rules for high-risk systems or a general-purpose AI provider's duties, carries fines up to 15 million euros or 3 percent of global turnover, and supplying incorrect or misleading information to a regulator or notified body carries fines up to 7.5 million euros or 1 percent of turnover. For small and medium enterprises, the lower of the two figures in each tier applies rather than the higher one, softening the exposure for smaller companies. Enforcement sits with national market surveillance authorities in each member state, coordinated by the EU AI Office for general-purpose AI models specifically. These figures are current as of 2026 and companies should verify enforcement guidance for their sector, since this is general information rather than legal advice. Nanobase AI, headquartered in Silicon Valley, builds the documentation and monitoring controls that reduce exposure to these penalties.

Three tiers, and the gap between them is large

The EU AI Act's penalty structure is not a single fine amount scaled to severity; it is three distinct tiers with a wide gap between the top and bottom. Understanding which tier a given failure falls into matters more than knowing the headline number, because most compliance failures land in the lower tiers, not the tier that generates the alarming headlines.

Violation typeMaximum fine
Prohibited AI practices (Article 5)35 million euros or 7% of global annual turnover, whichever is higher
Other obligations (high-risk requirements, GPAI provider duties, transparency)15 million euros or 3% of global annual turnover, whichever is higher
Supplying incorrect, incomplete, or misleading information to authorities7.5 million euros or 1% of global annual turnover, whichever is higher

The turnover-based calculation, not the flat euro figure, is what makes the top tier severe for large companies, since 7% of global revenue can dwarf 35 million euros for any company doing meaningful business.

Who actually issues these fines

Enforcement is not centralized the way the maximum figures might suggest. Each EU member state designates its own national market surveillance authority responsible for supervising the Act within its territory, while a new EU-level AI Office handles enforcement specifically for GPAI model providers, including the systemic-risk tier. This dual structure means a company's day-to-day compliance relationship runs through its national authority for most obligations, with the AI Office stepping in specifically for model-provider-level issues at the frontier end of the market. Smaller and medium-sized enterprises benefit from proportionality provisions that allow authorities to weigh company size and economic viability when calculating an actual fine within the maximum bounds. Enforcement runs mostly through national authorities for day-to-day compliance, with the EU-level AI Office reserved specifically for GPAI model provider issues.

The realistic sequence before a fine is issued

  1. A national authority identifies a potential violation, often through a complaint, an audit, or a serious incident report.
  2. The authority requests documentation and an explanation from the company, which is where clear technical documentation and a defensible risk classification matter most.
  3. If the response is inadequate, the authority can order corrective action, such as withdrawing a system from the market, before penalties escalate.
  4. Fines are typically reserved for confirmed violations, particularly repeated or willful ones, rather than issued as a first response to a good-faith gap.

Companies that can show a documented, if imperfect, compliance effort are in a materially different position than those with no risk classification or documentation at all.

Why the deployer side is not immune

A recurring assumption is that penalties mainly target the companies that build AI systems. Deployer obligations carry their own enforcement exposure: a deployer that ignores a high-risk system's monitoring and incident-reporting duties, or that uses a system for a prohibited practice regardless of who built it, faces the same tiered penalty structure. Deployer obligations carry the same tiered penalty exposure as provider obligations, so buying rather than building an AI system does not remove enforcement risk. This is general information, not legal advice, and actual exposure depends on the specific violation and jurisdiction involved.

Frequently asked questions

Are these fines retroactive to before the relevant obligation applied?

No. Enforcement follows the phase-in schedule, so a company cannot be fined for a high-risk system obligation before 2 August 2026, or for a GPAI obligation before 2 August 2025, even though the Act itself entered into force in August 2024.

Can a single violation trigger multiple fine tiers at once?

Yes, if a company both engages in a prohibited practice and separately misleads an authority during an investigation, each violation is assessed under its own tier, and the totals can compound rather than being capped at the single highest tier.

Do startups face the same fine structure as large enterprises?

The maximum caps apply broadly, but proportionality provisions let authorities account for a company's size and financial capacity when setting the actual fine within those caps, which in practice tends to produce smaller absolute penalties for smaller companies.

How does this compare to GDPR fines?

The structure is deliberately similar: GDPR's two-tier system caps at 20 million euros or 4% of global turnover, while the AI Act's top tier goes further at 35 million euros or 7%, reflecting the EU's view that certain AI harms warrant a higher ceiling than data protection violations alone.

How Nanobase AI helps

Nanobase AI helps companies build the documented risk classifications, technical files, and monitoring processes that materially change how an enforcement conversation goes if a national authority does come asking. This is core to our AI security and compliance work, and it pairs with the broader roadmap in our EU AI Act, GDPR, and KVKK compliance checklist. We are an accepted member of the NVIDIA Inception Program and work across both cloud and on-premise AI deployments.

Ready to discuss your project? Contact Nanobase AI or email hello@bumu.tech.