The three numbers you need to know

The AI Act's sanctions regime sits in Article 99 of Regulation (EU) 2024/1689, and it defines three fine tiers, each calculated two ways: a fixed euro amount or a percentage of total worldwide annual turnover for the preceding financial year. For companies, whichever figure is higher applies; for SMEs and startups, the rule flips.

InfringementCompaniesSMEs / startups
Prohibited practices (Article 5)Up to €35,000,000 or up to 7% of total worldwide annual turnover for the preceding financial year, whichever is higherWhichever of the two — fixed amount or percentage — is lower applies
Non-compliance with other obligations (providers, importers, distributors, deployers, transparency — Arts. 16, 22-26, 31, 34, 50)Up to €15,000,000 or up to 3% of total worldwide annual turnover, whichever is higherWhichever of the two is lower applies
Incorrect, incomplete or misleading information to notified bodies or competent authoritiesUp to €7,500,000 or up to 1% of total worldwide annual turnover, whichever is higherWhichever of the two is lower applies

The "SMEs and startups" category now also covers the SMC (small mid-cap), a new category added by the Digital Omnibus. For these companies, the Regulation deliberately inverts the logic: instead of taking the higher figure, it takes the lower of the two, specifically to stop a percentage applied to a small turnover from producing a disproportionate amount relative to the fixed cap.

In one line: €35,000,000 or 7% of global turnover for prohibited practices is the highest ceiling of any EU regulation to date, above even GDPR's maximum (€20,000,000 or 4%).

Not just the manufacturer: who can actually be on the hook

Article 99 doesn't say "manufacturers." It says operators, an umbrella term the Regulation defines to cover the provider, the authorised representative, the importer, the distributor and the deployer — that is, whoever simply uses the AI system, even if they never built or sold it.

In practice, this means a company that buys a high-risk AI system from a third party and puts it into operation internally can be fined as a deployer if it fails to meet its own obligations (Article 26) — for example, failing to have qualified staff oversee the system, failing to inform affected people where required, or failing to keep the logs the system generates automatically. The provider that built the system has its own obligations and its own exposure, but it isn't the only one who can be fined.

The separate regime for ChatGPT, Gemini and other large models

The AI Act keeps two things apart that are easy to conflate. On one side, AI systems in general, covered by Article 99 and enforced by each Member State's market surveillance authority. On the other, general-purpose AI models (GPAI) — the kind of model behind ChatGPT, Gemini or Claude — covered by a separate regime under Article 101.

Article 101 fines reach up to €15,000,000 or up to 3% of total worldwide annual turnover, whichever is higher, and they're imposed directly by the European Commission's AI Office — not a national authority. It's a centralized, EU-level regime aimed specifically at the model provider.

The distinction matters in practice: if a company uses GPT via API to build its own product, the one exposed to an Article 101 fine for a failure in the model itself is OpenAI, not the customer company. That customer company is still exposed under Article 99 as a deployer if it fails its own obligations, but that's a different liability, for a different failure, before a different authority.

Since when it's actually enforceable

This is where a lot of people get it wrong. The Article 99 sanctions framework — together with governance and the GPAI model regime — has applied since August 2, 2025. Article 5's prohibitions have been enforceable even earlier, since February 2, 2025. In that sense, the sanctions regime already exists and can already be applied.

But the bulk of the high-risk obligations — the ones that in practice carry the most real risk of landing in the €15,000,000 / 3% tier — were pushed back by the Digital Omnibus, in force since July 27, 2026: Annex III high-risk systems aren't enforceable until December 2, 2027, and Annex I systems (safety components of already-regulated products, like medical devices) not until August 2, 2028.

The practical takeaway: the sanctions framework has existed since 2025 and prohibited practices are already enforceable today, but full enforcement against most high-risk systems doesn't arrive until 2027-2028. "The Regulation already allows fines" is not the same statement as "every obligation that carries the most weight is already enforceable."

Has anyone actually been fined under the AI Act yet?

No. As of this research (September 2026), there is no reliable confirmation of any real fine imposed under the AI Act. Unverified stories about supposed "first fines" circulate on low-quality blogs, but no official source — not a national market surveillance authority, not the Commission's AI Office — confirms an actual sanction to date.

To get a sense of the scale European authorities are willing to impose when they do apply a turnover-based percentage, it's worth looking at GDPR — a different regime from the AI Act, but with a similar sanctions logic. The largest GDPR fine in history was imposed on Meta Platforms Ireland in May 2023: €1,200,000,000, for illegal international data transfers. In Spain, the AEPD fined Iberdrola €6,500,000 in 2024 over a security breach. These are figures from a different regime than the AI Act, but they show the order of magnitude these authorities have already proven willing to impose once the calculation is based on a percentage of turnover.

What to do with this

Don't wait for 2027 to start

The Annex III delay buys time, not a reason to postpone. Building real classification, a system registry and actual documentation takes months, not weeks — and Article 5's prohibited practices are already enforceable today.

Check whether you act as a provider or a deployer

It fundamentally changes what you can be fined for. If you buy or license AI systems from third parties, you're the deployer of those systems — and you carry your own obligations (Article 26), separate from whatever the provider does.

Document as if you'll be inspected tomorrow

Article 99 weighs, among other factors, the nature and duration of the infringement and whether it was intentional. Having a documented trail — classification, decisions, human oversight — is the strongest defense in an inspection.

Start with what's already enforceable

Article 5's prohibitions (certain social scoring or manipulation systems, for example) have been enforceable since February 2025. Confirm none of your systems fall there before worrying about the 2027 timeline.

AI Act Starter Kit Classification checklist, system registry, and the starter policies that reduce your real exposure to a fine — built to do without a consultant. €29, VAT incl.
Buy →

Frequently asked questions

Can we be fined even if we don't build AI, just use it?

Yes. Article 99 also applies to "deployers" (whoever uses the system), not only providers or manufacturers. If you fail to meet your obligations as a deployer (Article 26), you're exposed to fines of up to €15,000,000 or up to 3% of total worldwide annual turnover, whichever is higher.

Are AI Act fines higher than GDPR fines?

Yes, at the top tier: up to €35 million or 7% of turnover, versus GDPR's maximum of €20 million or 4%. Even so, as of September 2026 there is no confirmed real fine under the AI Act yet, while GDPR has already imposed fines exceeding €1 billion (the Meta case, 2023).

If we're an SME or startup, is the risk lower?

For SMEs and startups, the Regulation applies whichever of the fixed cap and the turnover percentage is lower — the opposite rule from large companies — but a percentage applied to a small turnover can still be proportionally severe.

Since when can we actually be fined?

The Article 99 legal framework has applied since August 2025, but the 2026 Digital Omnibus pushed enforceability of Annex III high-risk obligations to December 2027 and Annex I obligations to August 2028. Article 5's prohibited practices, by contrast, have been enforceable since February 2025.