Fines under the EU AI Act: how Article 99 works, who enforces it and what applies today

Compliance8 min read·
K

Kees van der Vlies

Partner | IT Auditor

Also available in:Nederlands

Almost every presentation on the EU AI Act features the same slide: fines up to 35 million euros or 7% of worldwide annual turnover. The figure is correct, but it is the ceiling of one tier, for one type of violation. To understand what your organization actually risks, you have to look at the structure of Article 99: three penalty tiers, a separate rule for SMEs, a list of factors that determine the amount and a division of enforcement between national supervisors and the European Commission. This article lays that out, as of August 2026.

The three penalty tiers of Article 99

Article 99 divides violations into three tiers, each with its own ceiling. The heaviest tier (paragraph 3) concerns the prohibited AI practices of Article 5, such as social scoring, manipulative systems and the banned forms of biometrics. These carry a fine of up to 35 million euros or, for undertakings, up to 7% of total worldwide annual turnover for the preceding financial year, whichever is higher.

The middle tier (paragraph 4) covers most other obligations. It concerns the obligations of providers of high-risk systems (Article 16), authorised representatives (Article 22), importers (Article 23), distributors (Article 24) and deployers (Article 26), the requirements for notified bodies, and the transparency obligations of Article 50. Ceiling: 15 million euros or 3% of worldwide annual turnover, again whichever is higher.

The third tier (paragraph 5) is the least known: supplying incorrect, incomplete or misleading information to notified bodies or national competent authorities. This carries up to 7.5 million euros or 1% of turnover. For audit practice this one matters: an organization that paints too rosy a picture in response to a supervisor's information request creates a separate ground for a fine by doing so.

The SME rule: lower instead of higher

For large undertakings, the higher of the two ceilings always applies. For SMEs and startups, paragraph 6 reverses this: each fine is capped at the lower of the fixed amount and the turnover percentage. A startup with two million euros in revenue therefore faces a ceiling of 3% of that revenue for a middle-tier violation, not 15 million euros. The regulation also states explicitly that penalties must take into account the interests of SMEs and their economic viability.

A caveat belongs here: these are maximums, not price lists. Nothing in Article 99 obliges a supervisor to reach for the ceiling at every violation. Member states may also use warnings and non-monetary measures alongside fines, and in the early years that will probably be the common picture.

Which factors determine the amount

Paragraph 7 lists the circumstances that weigh in deciding whether a fine is imposed and how high it will be. The nature, gravity and duration of the infringement come first, including the purpose of the AI system and the number of affected persons and the damage they suffered. Also relevant: earlier fines for the same or related infringements, the size and market share of the offender, financial gains obtained, the degree of cooperation with the authorities, the technical and organisational measures in place, the way the infringement became known (including self-reporting), and whether it was intentional or negligent.

For practice, that list is good news for organizations with their governance in order. An organization that can show a working AI management system, that reported incidents itself and that cooperated with the investigation has something to point to under each of those factors. That is exactly the role an ISO 42001 certification plays in this story: no immunity, but demonstrable diligence.

Who enforces: member states and the Commission

Enforcement is divided. For AI systems it sits with the member states: under Article 99(1) they lay down the penalty rules themselves and under Article 70 they designate national competent authorities. In the Netherlands this runs through national implementing legislation; in its preparation, a coordinating role is foreseen for the Dutch Data Protection Authority and the Dutch Authority for Digital Infrastructure, with sectoral supervisors covering their own domains. Depending on the member state's legal system, fines can be imposed by a supervisor or by a court (paragraph 9), and each member state decides for itself to what extent public authorities can be fined (paragraph 8).

For providers of general-purpose AI models, enforcement sits not with the member states but with the European Commission, in practice the AI Office. Article 101 gives the Commission the power to fine those providers up to 3% of worldwide annual turnover or 15 million euros, whichever is higher.

What is enforceable in August 2026

The penalties chapter has formally applied since 2 August 2025, with the exception of Article 101. But a fine requires a violation, and thus an obligation that already applies. That produces the following picture. The prohibition of certain AI practices has applied since February 2025 and is therefore the first real ground for fines, immediately in the heaviest tier. The GPAI obligations have applied since August 2025. The transparency obligations of Article 50 and the AI literacy duty have been enforceable since August 2026. The high-risk obligations, including the deployer obligations of Article 26, follow after the Digital Omnibus on 2 December 2027 (Annex III) and 2 August 2028 (Annex I).

For most organizations this means: today's fine risk does not sit with the high-risk requirements, but with the questions of whether a prohibited practice is happening somewhere in the organization, whether chatbots and AI content are properly disclosed under Article 50, and whether staff are sufficiently AI literate.

What you can do now

The basis is the same as for any supervisory question: know what you have and in which role. A current AI inventory with the risk classification and your own role (provider or deployer) per system is the starting point. Then build demonstrability: policy, oversight and records, for example along the structure of ISO 42001. And treat information requests from supervisors with the same care as an audit request, because answering incorrectly or incompletely is a separate violation under paragraph 5.

Source: Regulation (EU) 2024/1689 (AI Act), Article 99, consulted via EUR-Lex: https://eur-lex.europa.eu/eli/reg/2024/1689/oj

Frequently asked questions

How high can fines under the EU AI Act get?+

Article 99 has three tiers. Violating the prohibited AI practices of Article 5: up to 35 million euros or 7% of worldwide annual turnover, whichever is higher. Breaching obligations as a provider, deployer, importer, distributor or notified body: up to 15 million euros or 3%. Supplying incorrect or misleading information to authorities: up to 7.5 million euros or 1%.

Do the fines also apply to organizations that only use AI?+

Yes. Article 99(4) explicitly lists the obligations of deployers under Article 26 as grounds for a fine, alongside those of providers, importers and distributors. The transparency obligations of Article 50 fall into this tier as well.

Is there a separate rule for SMEs?+

Yes. For SMEs and startups, each fine is capped at the lower of the two ceilings: the fixed amount or the turnover percentage. For large undertakings the higher of the two applies.

Since when can fines be imposed?+

The penalties chapter has applied since 2 August 2025, with the exception of Article 101 on GPAI models. Fines require an obligation that itself already applies: the Article 5 prohibitions since February 2025, the GPAI obligations since August 2025 and the Article 50 transparency obligations since August 2026. After the Digital Omnibus, the high-risk obligations follow in late 2027 and mid 2028.

Who imposes the fines?+

For AI systems: the national market surveillance authorities of the member states, in the Netherlands assigned through the national implementing legislation that designates the supervisors. For providers of GPAI models, enforcement sits with the European Commission, through the AI Office, under Article 101.

Need help with compliance?

Need to comply with ISO 27001, ISO 42001, NEN 7510, NIS2 or DORA, or do you need a SOC 2 report? We guide you through the entire process: from gap analysis to implementation.

Explore Compliance Services

About the author

K
Kees van der Vlies

Partner | IT Auditor

Back to knowledge base

Have a question?

Get in touch for advice on IT audit, compliance and information security.

Contact us