Short answer. The EU AI Act sets fines in three tiers. Prohibited AI practices carry up to EUR 35 million or 7% of total worldwide annual turnover, whichever is higher. Most other breaches, including duties on high-risk systems, carry up to EUR 15 million or 3%. Supplying authorities with incorrect or misleading information carries up to EUR 7.5 million or 1%. These penalty rules have applied since 2 August 2025.
The AI Act ranks fines by how serious the breach is, not by which company committed it. The ceiling that applies depends on the obligation that was broken. Article 99 sets the national penalty regime, and it defines three bands.
For a company, the higher of the fixed sum and the percentage applies. A firm with EUR 2 billion in turnover faces up to EUR 60 million in the top tier, because 7% of turnover exceeds the EUR 35 million floor. For small and medium enterprises and start-ups, the rule flips: the fine is capped at the lower of the two figures, so the same top-tier breach is limited to EUR 35 million rather than the percentage.
Banks and insurers already operate AI systems the Act classifies as high-risk. Annex III lists creditworthiness assessment and credit scoring of individuals, and risk assessment and pricing for life and health insurance. Firms that run these models sit squarely in the 3% penalty band. A banking group with EUR 1 billion in annual turnover faces up to EUR 30 million per breach category, on top of the remediation cost and the supervisory attention that follows.
The penalty regime does not arrive alone. DORA has applied to financial entities since 17 January 2025 and governs the resilience of the systems that run these models. The EU AI Act adds a separate accountability layer with its own fines. A bank that cannot show which AI systems it runs, how they are classified, and who owns each control now carries measurable financial exposure under two regulations at once.
The EU AI Act sets three penalty tiers: EUR 35 million or 7% for prohibited practices, EUR 15 million or 3% for most other breaches, and EUR 7.5 million or 1% for misleading authorities.
The three ceilings map to three levels of severity. The top tier of EUR 35 million or 7% is reserved for the practices Article 5 prohibits outright, the conduct the legislators judged most harmful. The middle tier of EUR 15 million or 3% covers the bulk of the Act, the operational duties that attach to high-risk systems and to general-purpose AI models. The lowest tier of EUR 7.5 million or 1% targets a specific failure: misleading the authorities or notified bodies that police the system.
Each tier states two numbers, a fixed amount and a percentage of worldwide annual turnover. For companies the supervisor takes the higher figure, which means the percentage governs large firms and the fixed sum governs smaller ones. The design makes the fine bite regardless of company size.
The penalty provisions have applied since 2 August 2025. By that date every Member State had to lay down its rules on penalties and enforcement and notify them to the Commission. The bans on prohibited practices came earlier, on 2 February 2025, so the conduct that triggers the highest tier was already unlawful before the fines switched on.
One part runs on a later clock. Fines against providers of general-purpose AI models, imposed by the European Commission rather than national authorities, apply from 2 August 2026. So a national authority can already fine a bank for a high-risk system today, while the Commission’s power to fine a foundation-model provider directly starts in 2026.
National market surveillance authorities impose the fines under Article 99, not the European Commission. Member States designate these authorities, and as of early 2026 most had done so. Germany named the Federal Network Agency, France named the CNIL, and Spain named its data protection authority.
For financial institutions there is a specific twist. Under Article 74(6), the market surveillance authority for high-risk AI systems placed on the market by regulated financial entities is the same national authority that supervises those firms under EU financial services law. In practice this means a bank’s existing financial supervisor also polices its high-risk AI. The regulator that already reviews capital and conduct gains authority over the bank’s AI systems, which raises the odds that AI governance gaps surface during routine supervision.
Article 99 lists the factors an authority weighs. They include the nature, gravity, and duration of the breach, the number of people affected, whether the same operator has already been fined by another authority for the same conduct, the size and market share of the operator, and whether the breach was intentional or negligent. Cooperation with the authority and steps taken to reduce the harm pull the figure down.
The ceilings are maximums, not defaults. An authority that finds a first breach, prompt disclosure, and active cooperation can set a fine well below the cap. A firm that hid the problem or repeated it invites the opposite. This is why a documented, observable governance trail matters: it is the evidence that turns a potential top-tier fine into a proportionate one.
Start with an inventory. List every AI system in use, note who built it and who deploys it, and classify each one against the Act’s risk tiers. Most fines trace back to a system nobody had mapped. An inventory turns an abstract regulation into a list a compliance team can act on.
Then assign an owner and a control to each high-risk system, and keep a log that shows what the control does and when it ran. The factors that reduce a fine, cooperation, mitigation, and a clean first record, are exactly the things a firm can only prove with records made before the breach. Governance that is written down and observable is what limits the downside when a supervisor calls.
The penalty regime rewards firms that run AI as accountable production infrastructure rather than as scattered pilots. That is the work Ableneo does. In 2025 Ableneo shipped 34 production AI projects across financial services, insurance, and other regulated sectors, and about 80% of the projects we start reach production, so the classification, ownership, and control questions Article 99 turns into financial exposure are the ones we resolve before a system ships. We map each AI system to its risk tier, its owner, and its evidence trail, so a supervisor’s question has a documented answer. See the Ableneo AI Transformation FAQ for related answers on EU AI Act and DORA obligations.
Key takeaways
Planning AI in a regulated business? Ableneo takes systems from classification to governed production.