The European Union's Artificial Intelligence Act (AI Act) establishes a comprehensive regulatory framework for artificial intelligence, with fines serving as a key enforcement mechanism. The regulation, which entered into force on 1 August 2024, sets out graduated penalties for violations, ranging from bans on unacceptable-risk applications to transparency obligations for limited-risk systems. The fine structure is designed to deter non-compliance and ensure that providers and deployers of AI systems adhere to the Act's requirements.
The AI Act classifies AI applications into four risk categories - unacceptable, high, limited, and minimal - plus a separate category for general-purpose AI. Unacceptable-risk applications, such as those manipulating human behaviour or enabling social scoring, are banned outright. High-risk applications, including those used in health, education, recruitment, or law enforcement, must meet strict quality, transparency, and human oversight obligations. Limited-risk systems, such as deepfake generators, face only transparency duties, while minimal-risk applications like spam filters are unregulated. General-purpose AI models, including large language models, have additional requirements, with high-impact models subject to extra evaluations.
The fine structure under the AI Act is tiered according to the severity and type of infringement. For violations involving prohibited practices (unacceptable risk), fines can reach up to €35 million or 7% of the company's total worldwide annual turnover, whichever is higher. Non-compliance with obligations for high-risk AI systems or general-purpose models can result in fines up to €15 million or 3% of global turnover. Supplying incorrect, incomplete, or misleading information to notified bodies or national authorities can attract fines up to €7.5 million or 1% of turnover. These thresholds align with the EU's General Data Protection Regulation (GDPR) approach, which also uses turnover-based penalties to ensure proportionality.
Enforcement and Timeline
The AI Act's provisions are being phased in over 6 to 36 months from its entry into force. The ban on unacceptable-risk applications became applicable on 2 February 2025, six months after the regulation took effect. Obligations for general-purpose AI models, including transparency and copyright requirements, apply from 2 August 2025. High-risk AI systems covered by existing EU product safety legislation must comply by 2 August 2026, while high-risk systems in other sectors have until 2 August 2027. The European Commission is responsible for overseeing general-purpose AI models, while national authorities will enforce rules for other AI systems.
Fines for Prohibited Practices
Prohibited practices under the AI Act include AI systems that deploy subliminal techniques to distort behaviour, exploit vulnerabilities of specific groups, or evaluate individuals based on social scoring. Real-time remote biometric identification in publicly accessible spaces is also banned, with narrow exceptions for law enforcement under strict judicial oversight. For these most serious violations, the maximum fine is €35 million or 7% of global annual turnover, whichever is higher. This level is intended to have a deterrent effect on large technology companies, such as those developing large language models or generative AI systems.
Fines for High-Risk and General-Purpose AI Obligations
High-risk AI systems must undergo conformity assessments and, in some cases, a Fundamental Rights Impact Assessment before deployment. Providers must implement quality management systems, ensure technical documentation, and enable human oversight. General-purpose AI models, including those from providers like OpenAI or Anthropic, must publish training data summaries, adopt copyright policies, and provide technical documentation. Failure to meet these obligations can result in fines up to €15 million or 3% of global turnover. For systemic-risk models, additional requirements include model evaluations, adversarial testing, and incident reporting, with non-compliance subject to the same penalty tier.
Fines for Incorrect Information
Providing incorrect, incomplete, or misleading information to notified bodies or national authorities is a separate infringement. This includes failing to update documentation or misrepresenting the capabilities of an AI system during conformity assessments. Fines for such violations are capped at €7.5 million or 1% of global annual turnover. This lower tier acknowledges that the harm from misinformation is less severe than direct violations of substantive obligations, but still ensures accountability.
Extraterritorial Application
Like the GDPR, the AI Act has extraterritorial reach. Providers based outside the EU must comply if they place AI systems on the EU market or if their systems' outputs are used within the EU. This means companies such as Google DeepMind or Amazon Web Services offering AI services to EU users are subject to the same fines. The European Artificial Intelligence Board, established by the Act, coordinates national supervision and ensures consistent enforcement across member states.
Comparison with GDPR Fines
The AI Act's fine structure mirrors the GDPR's tiered approach. GDPR fines for serious violations can reach €20 million or 4% of global turnover, while less severe infringements attract up to €10 million or 2%. The AI Act's higher maximums - €35 million or 7% for prohibited practices - reflect the potential for AI systems to cause widespread harm. However, both regulations use turnover as a benchmark, ensuring that fines are proportionate to company size.
Impact on AI Industry
The fine structure has prompted AI developers to invest in compliance measures. For instance, OpenAI and Anthropic have established dedicated trust and safety teams, while Google DeepMind has published model cards and transparency reports. Smaller providers, such as AI21 Labs or Inflection AI, may face challenges meeting documentation requirements, but the Act provides for reduced obligations for open-source models. The voluntary General-Purpose AI Code of Practice, published on 10 July 2025, offers guidance on demonstrating compliance, potentially reducing the risk of fines.
Future Developments
The European Commission is expected to issue further guidance on fine calculations and enforcement priorities. As of 2025, no fines have been imposed under the AI Act, as the grace periods for most provisions are still running. However, national authorities are preparing enforcement mechanisms, and the European Artificial Intelligence Board is developing best practices. The Act's risk-based approach and fine structure are likely to influence AI regulation globally, as other jurisdictions consider similar frameworks.
In summary, the EU AI Act fines are a critical component of the regulation, designed to enforce compliance through graduated penalties. By aligning fines with the severity of violations and global turnover, the Act aims to hold AI providers accountable while fostering innovation. Companies operating in the EU must understand these penalties and implement robust compliance programs to avoid significant financial exposure.