The AI Act introduces financial sanctions of up to €35 million or 7% of global turnover for major infractions. Small and medium-sized enterprises benefit from a lighter treatment. Prohibited practices will be sanctioned starting February 2, 2025, while most other obligations will become sanctionable in 2026.
In brief
- Three levels of financial sanctions: caps up to €35M or 7% of turnover depending on severity, €15M / 3%, or €7.5M / 1% for minor breaches
- All parties involved in the AI chain (providers, deployers, importers, distributors, notified bodies) can be subject to a sanction
- SMEs and start-ups benefit from a specific rule: the lower amount between the percentage and the fixed threshold applies (Art. 99§6)
- Ten adjustment factors for fine amounts are provided: severity, duration, cooperation, size, benefits obtained, corrective actions, etc.
- Authorities designated by each Member State manage controls and issue sanctions, in collaboration with the European AI Office
- Beyond fines, risks include market exclusion, public warnings, and significant reputational impact
Chapter XII of the regulation (Articles 99 to 101) defines a structured set of financial sanctions, divided into three levels. Specific rules apply to European Union institutions and providers of General Purpose AI (GPAI) models. This framework, inspired by the GDPR but with stricter caps, aims to ensure firm and homogeneous application.
Overview of the AI Act Sanctions System
Three fundamental principles guide this regime:
- **Proportionality**: Sanctions are calculated based on the severity of the breach and the size of the company.
- **Effectiveness**: Member States must ensure that sanctions are effectively implemented.
- **Deterrence**: Amounts are designed so that the fine never becomes a mere operating cost, even for the largest organizations.
With the August 2, 2026 deadline approaching, mastering this framework is essential to anticipate risks.
The Three Levels of Fines Provided by Article 99
The European regulation's Article 99 details a progressive scale of sanctions based on the nature and severity of the breach. For each category, the amount retained is the higher of the percentage of global turnover or the fixed sum, except for SMEs and start-ups, which benefit from the reverse rule.
First Level – Major Infractions: Up to €35M or 7% of Turnover
This level concerns violations of the prohibitions set out in **Article 5**, applicable from February 2, 2025. This includes:
- **Subliminal manipulation techniques** aimed at influencing a person's behavior in a harmful way.
- **Exploitation of vulnerabilities** (age, disability, social situation) to alter individual choices.
- **Social scoring systems** leading to disproportionate discrimination.
- **Real-time biometric recognition in public spaces** for law enforcement purposes, excluding strictly listed exceptions.
- **Emotion recognition** in the workplace or educational sector, excluding medical or security necessities.
- **Biometric categorization** allowing the inference of sensitive elements such as ethnic origin, political opinions, or sexual orientation.
Second Level – Non-compliance with Main Obligations: Up to €15M or 3% of Turnover
This tier concerns the majority of the regulation's requirements outside of prohibited practices. Specifically targeted are:
- **Provider obligations** (Article 16): technical documentation, CE marking, risk management, data governance, quality system.
- **Deployer obligations** (Article 26): human oversight, monitoring, incident notification, traceability.
- **Importer obligations** (Article 23) and **distributor obligations** (Article 24): compliance and documentation checks before any commercialization.
- **Transparency obligations** (Article 50): user information, labeling of AI-generated content, mention of deepfakes.
- **Notified body obligations** (Articles 31, 33, 34): independence, competence, assessment procedures.
This level concerns the majority of companies developing or integrating high-risk AI systems or subject to transparency requirements.
Third Level – Misleading Information: Up to €7.5M or 1% of Turnover
This category applies to the deliberate or negligent transmission of inaccurate, incomplete, or misleading information to notified bodies or national competent authorities during an audit or procedure. Lying or omitting essential elements during an audit, information request, or incident report exposes the company to this specific sanction, regardless of the severity of the main infraction.
Special Cases: GPAI and EU Institutions
Regime Applicable to GPAI Model Providers (Article 101)
Providers of General Purpose AI models fall under a sanction regime managed directly by the European Commission via the AI Office. Fines can reach **€15 million or 3% of global turnover** in the following cases:
- **Non-compliance with GPAI obligations** (Articles 51 to 56): documentation, copyright policy, transparency, systemic risk management.
- **Refusal to cooperate**: failure to respond to a Commission request (Article 91).
- **Non-execution of a Commission injunction** (Article 93).
- **Obstruction of access to the model** (Article 92).
Sanctions for EU Institutions and Bodies (Article 100)
European Union institutions are not exempt from the regime. The European Data Protection Supervisor (EDPS) can impose fines of up to **€1.5 million** for prohibited practices and **€750,000** for other types of infractions.
The Ten Adjustment Criteria for Fines (Article 99§7)
Each financial sanction is modulated according to ten detailed factors:
1. **Nature, severity, and duration of the breach** (purpose of the system, number of people affected)
2. **Existence of previous fines for the same facts** (ne bis in idem principle)
3. **Sanctions already imposed under other legislation** (e.g., GDPR)
4. **Size and turnover of the entity** (specific consideration for SMEs and start-ups)
5. **Financial benefits obtained**
6. **Degree of cooperation with authorities**
7. **Efforts deployed for compliance** (technical and organizational measures)
8. **Manner in which the infringement became known** (self-reporting or not)
9. **Intentional or negligent character**
10. **Corrective actions taken**
Proactive behavior, collaboration, and rapid correction of breaches can reduce the sanction amount. Conversely, opacity or obstruction aggravates the situation.
Derogatory Regime for SMEs and Start-ups (Article 99§6)
The text provides specific protection for smaller structures: the maximum sanction is calculated on the lower amount between the percentage of turnover and the fixed sum.
Example for a company with an annual turnover of €500,000:
- **Prohibited practices**: 7% × €500,000 = €35,000 (instead of €35M)
- **Main obligations**: 3% × €500,000 = €15,000 (instead of €15M)
- **Misleading information**: 1% × €500,000 = €5,000 (instead of €7.5M)
SMEs are therefore not exempt from AI Act requirements, but their economic viability is preserved, in accordance with the principle stated in Article 99.
Sanctions Beyond Fines: Other Business Risks
Financial sanctions are only one aspect of the framework. The regulation provides for other enforcement measures that can be mobilized by national authorities:
Non-financial Measures
Article 99 also authorizes:
- **Public warnings**: informing the public about the non-compliance of an AI system, with potentially strong reputational impact.
- **Market withdrawal or suspension**: obligation to withdraw an AI system or prohibit its operation until compliance is restored.
- **Correction obligations**: injunctions to correct within a specified timeframe.
Reputational and Commercial Risks
The European public register of high-risk AI systems (Article 71) makes compliance information accessible to all. A sanction published in this register can affect the trust of customers, partners, or investors, with major commercial consequences, particularly for companies positioned in the B2B market.
Cumulation with Other Regimes
Non-compliance can expose companies to cumulative sanctions under other texts such as the GDPR (for personal data processing), sector-specific regulations, or consumer law. Article 99 provides that authorities take into account fines already imposed to avoid double jeopardy, but the overall risk remains significant.
Who Are the Control and Sanction Actors?
The regulation's governance is structured around three levels:
National Supervisory Authorities
Each Member State will designate at least one entity responsible for supervision and sanctioning on its territory. In France, the official designation is pending. These authorities have investigative and sanctioning powers over all AI actors present or operating in the country.
The European AI Office
This office, attached to the European Commission, oversees the application of the regulation at the EU level. It intervenes directly to sanction GPAI model providers (Article 101), without going through national authorities, and coordinates policies between Member States.
The European Data Protection Supervisor
The EDPS ensures compliance with the regulation by the European Union's own institutions, bodies, and agencies (Article 100).
Member States are required to report annually to the European Commission on the details of fines and proceedings initiated, ensuring harmonized application of the text throughout the Union.
How to Limit the Risk of Sanction?
The best strategy is to anticipate and structure compliance:
1. **Identify and classify AI systems**: assess the risk level of each solution. The free compaia diagnostic facilitates this step and helps target applicable obligations.
2. **Build solid compliance documentation**: having a detailed technical file is a major asset in case of an audit, to prove good faith and limit the risk of maximum sanction.
3. **Implement continuous risk management**: a process compliant with Article 9, documented and monitored, is recognized as a mitigating factor in the fine calculation.
4. **Train teams**: mastery of AI requirements (Article 4) has been in effect since February 2025. A lack of training can be considered a lack of diligence.
5. **Prepare an incident management protocol**: reacting quickly and cooperating with authorities in the event of an incident reduces the severity of the sanction.
> Investing in compliance with the AI Act protects the company far beyond the simple financial aspect. Solutions like compaia support organizations in creating and managing their AI technical documentation, step by step.
Additional Resources