AI is moving fast. See how Whisperly helps you get control back and reduce risk.See how →
    AI Governance 12 min read

    EU AI Act Penalties: What Non-Compliance Will Cost You

    The EU AI Act imposes significant penalties for non-compliance, with fines exceeding even those foreseen by the GDPR. Learn about the tiered penalty system and how to prepare.

    Jelena Djukanovic
    Jelena Djukanovic| Jelena Djukanovic is an Attorney at Law specialising in Data Protection, IT Law, and AI Law
    Published: · Last reviewed: · Reviewed by: Tamara Zavisic, AI Governance Specialist
    EU AI Act penalties reach up to €35M or 7% of global turnover. Understand the EU AI Act penalties framework, fine tiers and how to reduce your exposure.

    The EU AI Act is a brand-new regulation introduced by the European Union that has the potential to reshape our daily lives and steer the future development of artificial intelligence (AI) technologies.

    Although it is crucial for companies to adjust their operations to meet the EU AI Act's requirements to avoid fines, there is no need to panic. The regulation will not be fully enforced immediately: its provisions will gradually become mandatory over the span of three years, with full enforcement by August 2027. For the complete phased schedule, including Digital Omnibus changes, see our EU AI Act timeline.

    As advised by the EU authorities, it is best for companies both within and outside the Union (if the EU AI Act applies to them) to prepare on time for its implementation and confirm compliance to avoid the steep fines that exceed even those foreseen by the GDPR. According to the European Commission's AI regulatory framework overview, organisations operating AI systems that affect EU citizens must begin compliance planning well before enforcement deadlines take effect (European Commission, 2024).

    Organizations that adhere to the obligations under the EU AI Act are sure to avoid the penalties. A crucial question arises, however: which organizations need to confirm compliance, and does the AI Act apply to all AI models? Understanding who must comply and the extent of the Act's reach is essential for companies to navigate these new regulations and prevent potential fines.

    <nav class="toc-block" aria-label="Table of contents">

    In this guide:

    </nav>

    Responsible entities under the EU AI Act

    TL;DRThe EU AI Act assigns compliance obligations to three groups: developers and providers who build or market AI systems, users who deploy them within the EU, and importers or distributors who bring AI products into the EU market. Each role carries specific duties around safety, transparency, and documentation. The Act also applies to organisations outside the EU if their AI systems affect people within the Union.

    The EU AI Act defines specific roles and responsibilities for various stakeholders:

    Developers and Providers are responsible for creating, supplying, or marketing AI systems. They must verify their systems meet all regulatory requirements related to safety, transparency, and documentation.

    Users of AI systems within the EU must adhere to transparency requirements and manage associated risks, confirming that end-users are informed about their interactions with AI.

    Importers and Distributors play a critical role in verifying that AI systems entering the EU market comply with regulations. They are tasked with maintaining documentation, verifying compliance, and reporting any issues to national authorities.

    Each stakeholder has specific obligations that must be met to avoid significant fines. Understanding these responsibilities helps organizations mitigate the risk of non-compliance and its associated penalties.

    The Act also extends its jurisdiction beyond EU borders. Organizations outside the EU that aim to market their AI models within the Union are subject to the Act's requirements and must confirm compliance.

    Understanding the Risk Classification System

    TL;DRThe EU AI Act sorts AI systems into four risk tiers. Unacceptable-risk systems are banned outright. High-risk systems face strict requirements around data quality, documentation, and human oversight. Limited-risk systems carry transparency obligations. Minimal-risk systems follow voluntary codes of conduct only. The tier determines which obligations apply and what penalties attach to non-compliance.

    The Act categorizes AI systems into four risk tiers:

    • Unacceptable Risks: Outright banned. These include social scoring by governments and real-time biometric identification in public spaces, as defined in Article 5 of the EU AI Act.
    • High Risks: Subject to stringent regulations covering data governance, technical documentation, transparency, and human oversight.
    • Limited Risks: Transparency obligations apply, particularly for chatbots and emotion-recognition systems.
    • Minimal Risks: Voluntary codes of conduct.

    To illustrate: consider a small EU-based company creating an AI system to assess candidates for admission to a law school in an EU member state. Due to its potential impact on applicants' rights, this system is classified as a high-risk AI system under Annex III of the EU AI Act. The company must comply with rigorous regulations, including transparency and accuracy requirements. This includes conducting AI Conformity Assessments and implementing effective monitoring systems. As a developer of a high-risk AI system, the company must meet most of the Act's provisions, which will incur substantial costs for a small firm.

    EU AI Act Penalties: The Cost of Non-compliance

    TL;DRFines under the EU AI Act follow a three-tier structure that exceeds GDPR penalty levels. Prohibited AI violations carry fines up to EUR 35 million or 7% of global annual turnover. General compliance breaches reach EUR 15 million or 3%. Supplying misleading information to regulators can cost EUR 7.5 million or 1.5%. SMEs pay the lower of the two amounts in each tier.

    These penalties are designed to enforce compliance and uphold the integrity of AI technologies used across the EU.

    For organizations, especially small and medium-sized enterprises (SMEs), the financial impact of failing to adhere to these regulations can be severe. This section covers the specifics of these penalties and what organizations can expect if they do not comply with the Act's provisions.

    EU AI Act three penalty tiers explained — Whisperlywhisperly.ai/eu-ai-act-penaltiesEU AI Act — 3 penalty tiers.The cost of non-compliance is real.VIOLATION TYPEMAXIMUM FINEProhibited practices€35M or 7% turnoverHigh-risk breaches€15M or 3% turnoverMisleading authorities€7.5M or 1.5% turnoverSMEs pay the lower of percentage or fixed amount

    Tiered Penalty System

    TL;DRThree penalty tiers apply based on violation severity. Prohibited AI practices attract fines up to EUR 35 million or 7% of turnover. Non-compliance with high-risk or limited-risk requirements triggers fines up to EUR 15 million or 3%. Providing false information to authorities costs up to EUR 7.5 million or 1.5%. SMEs always pay the lower amount, reflecting their financial constraints.

    **Types and Severity of Violations****Maximum Penalty****% of the Annual Turnover**
    Prohibited AI ViolationsEUR 35 million7%
    General Compliance BreachEUR 15 million3%
    Information Accuracy ViolationEUR 7.5 million1.5%

    Similar to the GDPR, the EU AI Act employs a tiered penalty system. The fines are determined based on the type of AI system, the seriousness of the violations, and the size of the company. Penalties may reach a specified maximum amount or a percentage of annual turnover, whichever is higher. The penalty framework surpasses even the GDPR fines, which can reach as high as EUR 20 million.

    Any entity required to adhere to the AI Act's stipulations may face penalties if they fail to meet these obligations. This includes providers, authorities, institutions, and other entities involved in developing, placing on the market, or operating AI systems. Developers, importers, traders, and deployers may also incur fines.

    Prohibited AI Practices: Deploying or developing AI systems that pose unacceptable risks can result in fines of up to EUR 35 million or 7% of total global annual turnover from the previous fiscal year, whichever is higher.

    Non-Compliance with High-Risk and Limited-Risk Requirements: Entities failing to meet requirements around data quality, technical documentation, transparency, human oversight, and system resilience may face fines of up to EUR 15 million or 3% of total global annual turnover, whichever is greater.

    False or Misleading Information: Delivering false, incomplete, or misleading information to notified bodies and competent authorities can result in fines up to EUR 7.5 million or 1.5% of total global annual turnover, whichever is higher.

    The EU AI Act acknowledges the varying financial capacities of different organizations. Unlike the GDPR, which applies uniform penalties regardless of company size, the AI Act adjusts fines for SMEs by applying the lower of the two amounts (the fixed maximum or the turnover percentage), reflecting their financial constraints.

    To illustrate: if the small company in the law school example fails to comply with transparency and accuracy requirements, it falls under category II penalties. As an SME, it pays the lower of the two amounts. If 3% of its consolidated annual revenue amounts to EUR 150,000, which is below the EUR 15 million fixed maximum, the company pays EUR 150,000.

    The penalties are designed to promote strict adherence to the Act's standards, promoting safe and reliable AI across the EU. By imposing substantial fines, the Act holds all parties accountable for maintaining safety and transparency.

    Extension of Penalty Provisions to EU Authorities

    TL;DREU institutions that use AI systems are also subject to the Act, though their fines are significantly lower than those for private companies. Prohibited AI violations by EU bodies carry penalties up to EUR 1.5 million; other breaches up to EUR 750,000. The European Data Protection Supervisor enforces these fines and reports collected amounts annually to the European Commission.

    EU institutions that fail to comply will also face penalties, though significantly lower:

    **EU Bodies and Institutions****Maximum Penalty**
    Prohibited AI ViolationsEUR 1.5 million
    General Compliance BreachEUR 750,000

    The EU AI Act uses a decentralized enforcement approach: each Member State must appoint at least one national authority responsible for overseeing compliance and conducting market surveillance.

    Some EU institutions themselves use AI systems. The question of what happens when they fail to comply is addressed directly in the Act. Union institutions, bodies, offices, and agencies are subject to penalties, though the fines imposed on them are significantly lower than those for private companies. For violations related to prohibited AI systems, EU institutions can face fines up to EUR 1.5 million. Other breaches carry fines up to EUR 750,000.

    Institutions have the right to contest fines before they are finalized. Collected fines go to the EU's general budget. The European Data Protection Supervisor (EDPS) is responsible for enforcing these fines and reporting on collected amounts annually to the European Commission.

    GPAI and GPAISR Classification

    TL;DRGeneral-Purpose AI (GPAI) models and those with Systemic Risks (GPAISR) face separate obligations under the Act. GPAI providers can be fined up to 3% of global annual turnover or EUR 15 million for non-compliance, withholding documents, or obstructing evaluations. The European Commission has authority to designate models as GPAISR, with Court of Justice oversight providing judicial review of those decisions.

    The four risk tiers cover most AI systems. The Act also addresses a separate category: General-Purpose AI (GPAI) models and those designated as having Systemic Risks (GPAISR). GPAI models are versatile and used across many sectors. GPAISR models are identified based on high-impact capabilities, whether from technical capability or broad market reach. Both types impose additional obligations on providers.

    A concern with this designation system is that the European Commission has authority to designate certain AI models as GPAISR. This creates potential for inconsistent decision-making, as the criteria are currently defined in legal terms rather than through established practical standards.

    Despite these concerns, the Act provides penalties for this category. Companies providing GPAI models can face fines up to 3% of their annual global turnover or EUR 15 million, whichever is higher, if they fail to comply with regulations, withhold requested documents or information, or obstruct access to their AI models for evaluation. The severity depends on the nature and duration of the infringement. Companies receive notification of preliminary findings and have an opportunity to respond before a final decision is made.

    The Court of Justice of the European Union has unlimited jurisdiction to review Commission decisions on fines. The Court can cancel, reduce, or increase fines, providing a layer of oversight that is particularly relevant given the Commission's independent authority to designate AI systems as GPAISR.

    How to Properly Prepare and Avoid Penalties

    TL;DRPreparation starts with understanding which risk tier applies to each AI system your organisation operates. High-risk systems demand transparency safeguards, data privacy compliance, and regular conformity assessments. The three-year implementation window may appear generous, but compressed timelines and higher remediation costs await organisations that delay. Consulting AI governance professionals early reduces exposure significantly.

    Preparing for the EU AI Act starts with a thorough understanding of your obligations. This means staying current on the classification of your AI systems, implementing necessary safeguards, and running regular compliance checks. High-risk AI systems require particular attention: they carry strict requirements for transparency, data privacy compliance, and accountability.

    Consulting AI governance professionals is essential to proper alignment with regulatory demands. The three-year implementation window may appear generous, but organizations that wait until enforcement is imminent will face compressed timelines and higher remediation costs. Start now.

    Frequently Asked Questions

    What are the maximum fines under the EU AI Act?

    The highest fines reach EUR 35 million or 7% of global annual turnover for prohibited AI practices. General compliance breaches carry fines up to EUR 15 million or 3% of turnover. Providing false information to regulators can cost up to EUR 7.5 million or 1.5% of turnover.

    How do EU AI Act fines compare to GDPR penalties?

    The EU AI Act penalties significantly exceed GDPR levels. While GDPR fines cap at EUR 20 million or 4% of global turnover, the AI Act top tier reaches EUR 35 million or 7%. Both regulations apply the higher of the two amounts, except for SMEs under the AI Act, which pay the lower figure. Read more about GDPR enforcement mechanisms.

    Are SMEs treated differently under the penalty framework?

    Yes. The EU AI Act explicitly adjusts fines for small and medium-sized enterprises. SMEs always pay the lower of the fixed maximum amount or the turnover-based percentage, reflecting their financial constraints. This is a departure from the GDPR, which applies uniform penalty calculations regardless of company size.

    Do penalties apply to organisations outside the EU?

    Any organisation whose AI systems affect individuals within the EU is subject to the Act, regardless of where the organisation is headquartered. This extraterritorial reach mirrors the GDPR approach to data protection jurisdiction.

    What happens if an EU institution violates the AI Act?

    EU institutions, bodies, and agencies face lower penalties: up to EUR 1.5 million for prohibited AI violations and EUR 750,000 for other breaches. The European Data Protection Supervisor enforces these fines and reports collected amounts annually.

    What are the penalties for GPAI model providers?

    Providers of General-Purpose AI models face fines up to 3% of annual global turnover or EUR 15 million for non-compliance, withholding documents, or obstructing access to models for evaluation. The GPAI obligations apply regardless of the model specific risk classification.

    When do enforcement deadlines begin?

    The EU AI Act entered into force on August 1, 2024. Prohibited practices provisions apply from February 2025. AI literacy requirements apply from August 2025. High-risk system obligations become enforceable by August 2026, with full enforcement across all provisions by August 2027.

    How can organisations begin preparing for compliance?

    Start by mapping every AI system your organisation develops or deploys against the Act risk classification framework. Conduct a gap analysis against applicable requirements, begin building technical documentation, and consider conformity assessment readiness for any high-risk systems. Early investment in governance infrastructure reduces last-minute remediation costs.

    How Whisperly helps avoid EU AI Act penalties — compliance automationwhisperly.aiThe fines are real. The deadlines are now.Whisperly gets you compliant.WITHOUT WHISPERLYWITH WHISPERLYNo AI inventoryInventory auto-builtRisk classification missingDone automaticallyTechnical docs absentGenerated and versionedNo human oversightControls implementedEnforcement arrivesEvidence readyNo missing inventory. No unclassified systems.AI-powered. Human-reviewed.
    eu-ai-actpenaltiescompliancefinesnon-compliance

    Questions & Answers

    What are the maximum fines under the EU AI Act?+

    The highest fines reach EUR 35 million or 7% of global annual turnover for prohibited AI practices. General compliance breaches carry fines up to EUR 15 million or 3% of turnover. Providing false information to regulators can cost up to EUR 7.5 million or 1.5% of turnover.

    How do EU AI Act fines compare to GDPR penalties?+

    The EU AI Act penalties significantly exceed GDPR levels. While GDPR fines cap at EUR 20 million or 4% of global turnover, the AI Act top tier reaches EUR 35 million or 7%. Both regulations apply the higher of the two amounts, except for SMEs under the AI Act, which pay the lower figure. Read more about GDPR enforcement mechanisms.

    Are SMEs treated differently under the penalty framework?+

    Yes. The EU AI Act explicitly adjusts fines for small and medium-sized enterprises. SMEs always pay the lower of the fixed maximum amount or the turnover-based percentage, reflecting their financial constraints. This is a departure from the GDPR, which applies uniform penalty calculations regardless of company size.

    Do penalties apply to organisations outside the EU?+

    Any organisation whose AI systems affect individuals within the EU is subject to the Act, regardless of where the organisation is headquartered. This extraterritorial reach mirrors the GDPR approach to data protection jurisdiction.

    What happens if an EU institution violates the AI Act?+

    EU institutions, bodies, and agencies face lower penalties: up to EUR 1.5 million for prohibited AI violations and EUR 750,000 for other breaches. The European Data Protection Supervisor enforces these fines and reports collected amounts annually.

    What are the penalties for GPAI model providers?+

    Providers of General-Purpose AI models face fines up to 3% of annual global turnover or EUR 15 million for non-compliance, withholding documents, or obstructing access to models for evaluation. The GPAI obligations apply regardless of the model specific risk classification.

    When do enforcement deadlines begin?+

    The EU AI Act entered into force on August 1, 2024. Prohibited practices provisions apply from February 2025. AI literacy requirements apply from August 2025. High-risk system obligations become enforceable by August 2026, with full enforcement across all provisions by August 2027.

    How can organisations begin preparing for compliance?+

    Start by mapping every AI system your organisation develops or deploys against the Act risk classification framework. Conduct a gap analysis against applicable requirements, begin building technical documentation, and consider conformity assessment readiness for any high-risk systems. Early investment in governance infrastructure reduces last-minute remediation costs.

    Jelena Djukanovic

    Written by

    Jelena Djukanovic

    Jelena Djukanovic is an Attorney at Law specialising in Data Protection, IT Law, and AI Law. She has been recognised as a Global and Thought Leader in Data Privacy and Protection by Who's Who Legal in the "Data: 2022", "Data: 2023", and "Data: 2024" guides. Described by Legal 500 as an attorney whose "comprehensive understanding of the law gives clients the confidence to expand their business internationally", she advises domestic and international clients across the information technology, finance, cybersecurity, and e-commerce sectors on GDPR compliance, data protection procedures, IT contracts, and AI governance frameworks.

    Reviewed by: Tamara Zavisic, AI Governance Specialist

    Share
    Get Started

    Ready to make compliance
    feel effortless?

    Join 100+ companies automating GRC with Whisperly. Get audit-ready in weeks, not months.

    Stay ahead of compliance changes

    Practical compliance tips, delivered to your inbox every two weeks.