Non-compliance with the EU AI Act costs up to €35 million or 7% of global annual turnover. The fine level depends entirely on the type of violation. Banned AI practices under Article 5 carry the highest fine. High-risk AI system failures sit in the middle and information breaches attract the lowest penalties. This article covers all three tiers, how fines are calculated, who enforces the act and when enforcement applies. For full context on the regulation, see the complete guide to the EU AI Act.
€35M
Maximum fine for prohibited AI practices, or 7% of global turnover, whichever is higher
3
Violation tiers, each with a distinct fine ceiling and enforcement date
Feb 2025
Date the highest fine tier became enforceable
Disclaimer
This article is for informational purposes only and does not constitute legal advice. The fine amounts and compliance guidance contained in this article are based on Regulation (EU) 2024/1689 as published. Organisations should consult qualified legal counsel before making compliance decisions.
1. EU AI Act Fines at a Glance: 2026 Update
The EU AI Act fines and penalties for various violations as per EU Artificial Intelligence Act are listed below.
| Violation type | Maximum fine (€) | Maximum fine (% of global turnover) | Effective from |
|---|---|---|---|
| Non-Compliance with the prohibited AI practices Article 5 violations | €35,000,000 | 7% of global annual turnover for preceding financial year | 2 August 2025 |
| High-risk and other obligation breaches | €15,000,000 | 3% of global annual turnover for preceding financial year | 2 December 2027 |
| Supply of incorrect or misleading information to authorities | €7,500,000 | v1% of global annual turnover for preceding financial year | 2 August 2026 |
Two Critical Notes
Whichever is Higher applies: The euro cap and the % of global turnover are not alternatives. The fine under the regulation takes the figure that produces the larger fine among the two.
Small and Medium-sized Enterprises will receive lower fines: For SMEs and startups, the fine shall be the lower of the % of global turnover or the Euro cap, not the higher figure.
Additional Fine Categories
| Violation type | Maximum fine (€) | Maximum fine (% of global turnover) | Effective from |
|---|---|---|---|
| Violations by providers of General-purpose AI models | €15,000,000 | 3% of global annual turnover for preceding financial year | 2 August 2026 |
| Non-Compliance with prohibited AI practices by EU Institutions | €1,500,000 | Fixed Amount | 2 August 2025 |
| High-risk and other obligation breaches by EU Institutions | €750,000 | Fixed Amount | 2 August 2025 |
EU AI Act fines for prohibited practices are the most severe under the regulation, reaching up to €35 million or 7% of global annual turnover, whichever is higher.
JAGGAER AI
JAI is a secure AI built for the procurement world
JAI brings ISO 42001-certified AI governance and GDPR alignment to Source-to-Pay and procurement.
2. How EU AI Act Fines Are Calculated
The Dual Cap Mechanism
The EU AI Act penalties are dependent on two figures. The fixed euro ceiling and the percentage of global annual turnover of the preceding year. The regulation takes whichever is higher. Additionally, the percentage applies to the worldwide revenue and not limited to annual revenue from the European Union. Non-EU companies are not exempted from this calculation. See how the EU AI Act applies to non-EU businesses for a full breakdown of how the act applies.
Example 1
For violation of a prohibited AI practice under Article 5, the fixed euro ceiling is €35M and the percentage is 7% of the global annual turnover of the preceding financial year. So, for any company with global annual revenue above €500M, the percentage will always produce the larger figure. Thus, 7% of their global annual revenue will be the fine charged under the EU AI Act.
Example 2
A US company that generates €1 billion globally but only €20 million in the EU has its fine calculated on the €1 billion figure.
Mitigating Factors Supervisory Authorities May Consider
Authorities consider various factors while calculating the actual penalty. Factors that supervisory authorities weigh in your favour:
- Nature, gravity and duration of violation
- Size, market share and annual turnover of the operator
- Degree of cooperation with authorities
- The manner in which the violation became known to national authorities
- Whether administrative fines have been imposed by other market surveillance authorities
- Whether the operator acted intentionally or negligently
- Previous violations by the same operator
- Actions taken by the operator to mitigate the damage
3. Which EU AI Act Violations Attract Which Fines in 2026
Related Reading
For a full list of prohibited, high risk and information breach practices under the EU AI Act, refer to the EU AI Act risk categories and prohibited practices guide.
4. Who Enforces the EU AI Act in 2026 and When
National market surveillance authorities and the AI Office supervise and enforce the EU AI Act. Alongside, the AI Office enforces requirements for general purpose AI models. Each EU member state must appoint at least one market surveillance authority. When multiple authorities are appointed, the member state must designate a Single Point of Contact. Member States were required to designate their competent authorities and single points of contact by 2 August 2025.
The European Data Protection Supervisor (EDPS) is the market surveillance authority for EU institutions and agencies. It monitors the implementation of AI Act in EU institutions and agencies. If they fail to comply with the regulation, EDPS has the authority to impose fines under certain conditions.
EU AI Act Enforcement Timeline
The EU AI Act effective date was 1 August 2024, with obligations rolling out in phases through 2027 as per European Commission AI Act. Each EU AI Act enforcement date below marks when a specific set of obligations becomes binding.
The EU AI Act came into force.
- Prohibitions on certain AI systems and regulatory requirements came into effect
- Rules for general-purpose AI (GPAI) models, governance, confidentiality and penalties came into effect
EU AI Act obligations for general-purpose AI models
- Remaining rules under the act including high-risk AI system obligations and transparency rules will come into effect
- Member States should have established at least one AI regulatory sandbox at national level
- Rules for AI systems that are products or safety components of products regulated under Article 6(1) of act will apply
- Providers of GPAI models that were placed on the market before 2 August 2025 must comply with rules for GPAI models by this date
This regulatory timeline will be updated with any new key dates announced by official European Union bodies.
JAGGAER AI
JAI: Procurement AI that holds up to AI governance standards of the EU AI Act
JAI operates across sourcing, contracts, and supplier management. One platform incorporated into your existing procurement workflows.
5. EU AI Act Enforcement in 2026: What to Expect
The enforcement for high-risk systems has been delayed from 2nd August 2026 to 2nd December 2027. Additionally, AI systems that generate child sexual abuse material have been added to the list of prohibited AI systems. Investigations are underway, but as of June 2026, no public fines have been issued under the EU AI Act.
This does not mean that risk is low. It means that formal fines are rare in the early enforcement period, but supervisory activity is increasing.
GDPR followed the same pattern:
- Came into effect in May 2018 and initially focused on compliance and awareness.
- By 2019 and 2020, enforcement actions increased noticeably, including a €50 million penalty against Google for inadequate data consent policies.
- The trend accelerated in 2021. Amazon was penalised for €746 million for non-compliance with data processing standards. Meta had fines of €225 million for WhatsApp’s privacy policy issues.
The EU AI Act will follow the same trajectory
As of March 2026, only 8 of 27 EU member states had designated a national market surveillance authority. Enforcement infrastructure is still being built but the legal authority to fine is already active for Article 5 violations. See what the EU AI Act is and how it works to get a brief on what these violations are and how the act is structured.
EU AI Act penalties are not limited to fines and financial damage. Additional costs like reputation damage are harder to contain. A formal finding is public record, and it lands in procurement due diligence, triggers contract warranty clauses, and attracts press. On top of that, authorities can order a product withdrawn from the EU market. There is no ceiling on what that costs.
6. Practical EU AI Act Compliance Checklist for 2026
These are general starting points to ensure compliance. Get legal counsel involved before making decisions.
Disclaimer
This checklist is general guidance, not legal advice. Your specific obligations depend on your AI systems and role under the EU AI Act. Consult qualified legal counsel before making compliance decisions.
7. Frequently Asked Questions
The EU AI Act fines for non-compliance has three tiers: €35M or 7% of global annual turnover for banned AI systems, €15M or 3% of global annual turnover for high-risk failures, and €7.5M or 1% of global annual turnover for information breaches.
EU AI Act fines have a dual cap: a fixed euro ceiling and a percentage of global annual turnover of the preceding year. The higher of the two figures applies. The lower figure applies for SMEs and startups.
The maximum EU AI Act fines amount to €35 million or 7% of global annual turnover, whichever is higher, for AI practices and systems banned under Article 5.
8 Banned AI practices under Article 5 carry the highest fines of €35M or 7% of global annual turnover. These include social scoring, real-time biometric identification, and workplace emotion recognition.
EU AI Act fine amount is calculated on global annual turnover and are not limited to revenue from the European Union.
There is no single EU AI Act enforcement date. Enforcement started in phases: banned AI practices from 2 February 2025, GPAI obligations from 2 August 2025, and high-risk system obligations from 2 December 2027.
National market surveillance authorities enforce obligations for AI systems, and the EU AI Office enforces obligations for general-purpose AI models.
No public EU AI Act penalties have been issued as of June 2026.
Yes. For SMEs and startups, the lower amount of the fixed euro amount or the percentage of global annual turnover applies.
GDPR maximum fines are €20M or 4% of global annual turnover. Maximum fine under the EU AI Act are €35M or 7% of global annual turnover, nearly double the GDPR percentage for the most serious violations.
JAGGAER
Secure AI-Powered Intelligent Procurement Workflows
JAI deploys secure autonomous agents across sourcing, contracts, and supplier management within a unified Source-to-Pay platform.
Next Steps
Understanding the EU AI Act fines amount is one part of the compliance picture. These articles cover what to work through next.
Pillar Guide
EU AI Act: The Complete Guide for 2026
This guide provides an overview and explanation of the EU AI Act, the four risk tiers, the fines, the deadlines, compliance obligations and what compliance actually involves.
Risk Classification
EU AI Act Risk Categories: The 4 Tiers Explained
Learn what each risk tier means and which obligations apply to each level.
Read More
Deadlines
EU AI Act Compliance Deadlines: Key Dates and Obligations
The EU AI Act applies in phases. This guide covers every key compliance deadline with dates and what each means.
Read More
Talk to a procurement expert.
Tell us your challenge. We will show you exactly where JAGGAER One fits into your current setup — with specifics, not a generic demo.
- Direct or indirect?
We handle both — on one platform. - Already have an ERP?
JAGGAER Link connects to 1,000+ systems, no rip-and-replace. - Need to show ROI fast?
We define outcomes and KPIs before you sign. - Vertical-specific?
Manufacturing, higher ed, public sector — configured, not customized.



