EU AI Act Penalties and Enforcement Timeline
Penalty tiers under the EU AI Act, verified against the final Digital Omnibus text.
| Tier | Maximum administrative fine | Note |
|---|---|---|
| Prohibited-practice violations | Up to €35M or 7% of global annual turnover | Unchanged by the Digital Omnibus. |
| Most other obligations | Up to €15M or 3% of global annual turnover | Unchanged by the Digital Omnibus. |
| Supplying incorrect information | Up to €7.5M or 1% of global annual turnover | Unchanged by the Digital Omnibus. SME caps apply at the lower of the amounts. |
What the obligation actually requires
The penalties page is not a separate product obligation. It explains the enforcement exposure attached to the other AI Act duties. The table above uses the penalty tiers stored in the deadline data; the tiers were verified as unchanged by the final Digital Omnibus text. Treat those figures as a planning signal, not as a substitute for legal confirmation.
For a business, penalties matter because they change prioritization. A prohibited-practices issue is not just another compliance task. Other obligations still need their own scoping against the relevant application dates and company roles. The practical requirement is to know which obligations apply, which systems are involved, and which gaps are serious enough to escalate before a regulator, customer, or partner asks for evidence.
Who usually triggers it
A company deploying AI in hiring, credit, education, or essential-services workflows may need to think about penalty exposure because the underlying system can affect people in high-impact settings. A provider of general-purpose AI models may need to track exposure through documentation, downstream information, copyright-policy work, and systemic-risk questions. A generative media company may need to connect transparency, machine-readable marking, and prohibited-practices review rather than treating them as separate silos.
The common misunderstanding
The common mistake is reading the penalty table first and then trying to reverse-engineer the business risk. That usually produces noise. Penalties follow the obligation. If the company has not mapped its systems to GPAI, transparency, high-risk, or prohibited-practices exposure, the fine amounts alone do not tell it what to fix.
What to do next
Use the checker and timeline to identify the obligations that may apply. Then build a short risk register: system name, business owner, likely role, relevant obligation page, deadline status, and open evidence gaps. Keep the penalty table close enough to inform prioritization, but do not let it replace the real work of classifying systems and assigning owners.