deniz.in

Markets

Weather

Loading weather

· via dev.to (home feed)

EU AI Act fines up to €35 million or 7% of turnover: the penalty tiers explained

A dev.to breakdown maps the EU AI Act's three penalty tiers, from €35 million or 7% of turnover for banned practices down to €7.5 million for misleading regulators, and the factors that adjust fines.

EU AI Act fines up to €35 million or 7% of turnover: the penalty tiers explained

The three penalty tiers

A detailed breakdown published on dev.to maps out how the EU AI Act punishes non-compliance, and the short version is that the stakes sit at the very top of EU digital regulation. Under Article 99 of the Act, the harshest tier — breaching the prohibition on banned AI practices — carries a maximum fine of €35 million or 7% of a company's global annual turnover, whichever is higher. A middle tier, capped at €15 million or 3% of turnover, covers failures around high-risk systems, transparency obligations under Article 50, and operator duties such as cooperation with authorities and corrective action. The lowest tier, €7.5 million or 1%, applies to supplying incorrect, incomplete or misleading information to regulators.

For companies, the dev.to piece explains, regulators apply the larger of the fixed cap or the turnover percentage. The turnover figure used is global annual revenue from the preceding financial year, and for corporate groups the ultimate parent's turnover can be used if the parent controls the subsidiary's AI activities.

How fine amounts are calculated

According to the breakdown, the European AI Office works from a base amount set by the severity of the violation and the applicable tier ceiling, then adjusts it. Aggravating factors that can push a fine higher include repeat violations within the previous five years, intentional or reckless non-compliance, refusal to cooperate during an investigation, breaches that cause actual harm to individuals, and concealment or destruction of evidence.

The list of mitigating factors is arguably the most actionable part for developers: voluntarily disclosing non-compliance before enforcement begins, taking corrective action within 30 days of notification, cooperating effectively with investigators, having no prior enforcement history, and implementing compliance measures that go beyond minimum requirements can all reduce the final amount.

Enforcement timeline and stated priorities

The dev.to article dates the start of AI Office enforcement to 2 August 2026 and says the office has signalled a graduated approach — information requests and corrective-action orders come first, with financial penalties as a later step. Intentional non-compliance or failure to cooperate, however, can trigger penalty proceedings directly.

The piece lays out a phased set of priorities: in late 2026, general-purpose AI models with systemic risk (above the 10²⁵ FLOPs threshold) and GPAI providers that have ignored information requests. In the first half of 2027, attention shifts to prohibited-practice investigations, guidance on classifying high-risk systems, and preparation for what the article describes as a December 2027 high-risk deadline. From the second half of 2027, high-risk obligations become fully enforceable, with early enforcement expected to concentrate on critical infrastructure, law enforcement and employment — areas where misclassification is most consequential.

How the ceilings compare

Placed next to other EU regimes, the AI Act's penalty ceiling exceeds GDPR (€20 million or 4%, in force since May 2018) in both absolute and relative terms, and sits above the Digital Services Act's 6% of global turnover, though below the Digital Markets Act's 10%. Data Act fines, effective from September 2025, are set individually by member states under Article 40.

Reach, double jeopardy and appeals

The framework applies extraterritorially, per the breakdown: non-EU providers whose AI system outputs are used in the EU face the same penalties, with cross-border enforcement coordinated between the AI Office, national supervisory authorities and third-country regulators. An organisation cannot be fined twice for the same violation, but distinct violations arising from one incident — a transparency breach plus non-cooperation, for example — can each carry independent penalties. Appeals reportedly run first to the European AI Board and then to the Court of Justice of the European Union.

Why it matters

For AI developers, the tiered structure turns compliance into a concrete checklist: classify systems correctly and early, since treating a prohibited or high-risk system as low-risk is the single most expensive mistake available; respond promptly to AI Office information requests, which the piece flags as an early enforcement priority; and keep documentation that supports voluntary disclosure and fast correction, the two mitigating factors most within a team's control.

One caveat: this is a secondary, AI-assisted explainer published on dev.to — it self-labels under Article 50's AI-origin transparency rules — rather than official guidance, and specific dates such as the high-risk deadline it cites should be verified against Regulation (EU) 2024/1689 itself. Even so, the penalty architecture it describes is a useful planning baseline for anyone shipping AI into the EU market.

  • #eu-ai-act
  • #compliance
  • #ai-regulation
  • #fines
  • #enforcement