EU AI Act Penalties and Enforcement Timeline

Penalty tiers under the EU AI Act, verified against the final Digital Omnibus text.

Verification note. The Digital Omnibus on AI defers certain deadlines but does not amend the Article 99 penalty tiers. Figures below were verified against the final Omnibus text on .
TierMaximum administrative fineNote
Prohibited-practice violationsUp to €35M or 7% of global annual turnoverUnchanged by the Digital Omnibus.
Most other obligationsUp to €15M or 3% of global annual turnoverUnchanged by the Digital Omnibus.
Supplying incorrect informationUp to €7.5M or 1% of global annual turnoverUnchanged by the Digital Omnibus. SME caps apply at the lower of the amounts.

What the obligation actually requires

The penalties page is not a separate product obligation. It explains the enforcement exposure attached to the other AI Act duties. The table above uses the penalty tiers stored in the deadline data; the tiers were verified as unchanged by the final Digital Omnibus text. Treat those figures as a planning signal, not as a substitute for legal confirmation.

For a business, penalties matter because they change prioritization. A prohibited-practices issue is not just another compliance task. Other obligations still need their own scoping against the relevant application dates and company roles. The practical requirement is to know which obligations apply, which systems are involved, and which gaps are serious enough to escalate before a regulator, customer, or partner asks for evidence.

Who usually triggers it

A company deploying AI in hiring, credit, education, or essential-services workflows may need to think about penalty exposure because the underlying system can affect people in high-impact settings. A provider of general-purpose AI models may need to track exposure through documentation, downstream information, copyright-policy work, and systemic-risk questions. A generative media company may need to connect transparency, machine-readable marking, and prohibited-practices review rather than treating them as separate silos.

The common misunderstanding

The common mistake is reading the penalty table first and then trying to reverse-engineer the business risk. That usually produces noise. Penalties follow the obligation. If the company has not mapped its systems to GPAI, transparency, high-risk, or prohibited-practices exposure, the fine amounts alone do not tell it what to fix.

What to do next

Use the checker and timeline to identify the obligations that may apply. Then build a short risk register: system name, business owner, likely role, relevant obligation page, deadline status, and open evidence gaps. Keep the penalty table close enough to inform prioritization, but do not let it replace the real work of classifying systems and assigning owners.

Use the deadline checker View full timeline