EU AI Act penalties: fines up to €35M or 7% of turnover
The EU AI Act backs its rules with some of the largest fines in technology regulation — deliberately, to make compliance a board-level issue. This guide breaks down the penalty structure, who enforces it, and how to reduce your exposure. Part of our guide to the EU AI Act.
AramGRC Team·AI Compliance & Assurance·September 11, 2026·7 min read
The EU AI Act penalty structure
The Act sets three tiers of maximum fines, each the higher of a fixed amount or a percentage of worldwide annual turnover:
Prohibited practices — up to €35 million or 7% of total worldwide annual turnover.
Other obligations — breaches of high-risk, transparency, GPAI or deployer duties — up to €15 million or 3%.
Incorrect, incomplete or misleading information to authorities or notified bodies — up to €7.5 million or 1%.
For SMEs and startups, the fine is the lower of the fixed amount or the percentage, to keep penalties proportionate.
Who enforces the EU AI Act, and how
Enforcement is shared: national market-surveillance authorities in each member state oversee most systems, while the European AI Office supervises general-purpose AI models. Authorities can investigate, conduct inspections, demand documentation, require corrective action, and impose fines. Penalties consider the nature and gravity of the breach, whether it was intentional, and any mitigating action.
Why the turnover link matters
Like the GDPR, the Act ties its top fines to a percentage of global turnover — so the real exposure scales with company size, and for a large multinational the 7% figure dwarfs the €35 million headline. It's designed so that compliance is cheaper than the risk of ignoring it.
How EU AI Act fines compare to the GDPR
The EU AI Act's top tier (7% of turnover) is actually higher than the GDPR's (4%), reflecting how seriously the EU treats prohibited AI. Many organisations will be subject to both regimes at once, since AI systems usually process personal data.
How to reduce your penalty exposure
Classify every AI system correctly — misclassifying a high-risk system is the costliest mistake.
Exit prohibited practices immediately — that's the €35 million / 7% tier.
Document everything — technical documentation and evidence are your defence.
Complete conformity assessment for high-risk systems before the deadlines.
AramGRC helps you close the gaps that lead to the largest fines — classification, high-risk conformity and documentation — with an EU AI Act readiness audit. See EU AI Act compliance.
Frequently asked questions
What are the penalties under the EU AI Act?+
Up to €35 million or 7% of worldwide annual turnover for prohibited practices, up to €15 million or 3% for other breaches, and up to €7.5 million or 1% for supplying incorrect information — each the higher of the amount or percentage (the lower, for SMEs).
What is the maximum fine under the EU AI Act?+
€35 million or 7% of total worldwide annual turnover, whichever is higher, for engaging in prohibited AI practices.
Are EU AI Act fines based on turnover?+
Yes — the top fines are the higher of a fixed amount or a percentage of global annual turnover, so exposure scales with company size (SMEs pay the lower of the two).
Who enforces the EU AI Act?+
National market-surveillance authorities enforce most systems, and the European AI Office supervises general-purpose AI models. They can investigate, inspect and impose fines.