The three tiers

| Tier | Maximum | What triggers it |
|---|---|---|
| Prohibited practices | EUR 35,000,000 or 7% of total worldwide annual turnover, whichever is higher | Non-compliance with the prohibitions in Article 5 |
| Operator obligations | EUR 15,000,000 or 3%, whichever is higher | Most other obligations on providers, deployers, importers, distributors and notified bodies |
| Incorrect information | EUR 7,500,000 or 1%, whichever is higher | Supplying incorrect, incomplete or misleading information to notified bodies or national competent authorities |
Two details are worth reading carefully. The percentage is of total worldwide annual turnover for the preceding financial year, so a small European operation belonging to a large group is exposed on the group's number. And "whichever is higher" means the fixed sum is the floor for smaller undertakings while the percentage governs large ones.
The SME rule that inverts the formula
This is the part most summaries get wrong, and it works in your favour. For SMEs, including start-ups, each fine is capped at whichever of the percentage and the fixed amount is lower, rather than higher.
The practical effect is significant. A small company does not face a EUR 35,000,000 exposure on a turnover that would produce a much smaller percentage figure. If you are an SME and someone quotes you the headline number without this qualification, they have not read Article 99 to the end.

Which failures land in which tier
The top tier is narrow. It applies to the practices prohibited outright in Article 5: things like untargeted scraping of facial images to build recognition databases, emotion inference in workplaces and education outside narrow exceptions, social scoring, and certain manipulative or exploitative systems. Most organisations will never touch this tier, and those who might usually know it.
The middle tier is where ordinary compliance failures land. Missing technical documentation, an absent risk management system, no human oversight measures, failure to register a high-risk system, transparency failures, or a deployer using a system outside its instructions for use. This is the tier to budget your programme against. The document set that satisfies these obligations is set out in EU AI Act policies and documentation.
The bottom tier is about candour with authorities. Giving a notified body or a national competent authority incorrect, incomplete or misleading information is separately punishable, which means an inaccurate submission can cost you even where the underlying system was compliant.
Who enforces, and from when
Enforcement runs through national market surveillance authorities designated by each Member State, with the AI Office carrying specific responsibilities in relation to general-purpose AI models. Member States set the detailed rules on penalties and notify them to the Commission, so the exact procedure varies by country even though the ceilings come from the Regulation.
The Act applies in phases. The prohibitions and the AI literacy duty came into application first, transparency and general-purpose obligations follow, and the high-risk regime lands later still. Our guide to who has to comply and from when maps the tiers to the dates, including the shift of the high-risk deadline to December 2027.

How this compares to GDPR and NIS2
| Regime | Top administrative maximum | Measured against |
|---|---|---|
| EU AI Act | EUR 35,000,000 or 7% | Total worldwide annual turnover |
| GDPR | EUR 20,000,000 or 4% | Total worldwide annual turnover |
| NIS2, essential entities | At least EUR 10,000,000 or 2% | Total worldwide annual turnover, as a minimum ceiling in national law |
The AI Act's top tier is the highest of the three, which is a deliberate signal about the prohibited practices rather than a statement about ordinary compliance risk. For a typical organisation the middle tier is the realistic exposure. NIS2's ceilings work differently again, since the Directive sets minimums that national law may exceed, which we cover in NIS2 fines and penalties.

What reduces your exposure
- Classify every system and write down the reasoning. Penalties follow obligations, obligations follow classification, and a documented classification is the first thing an authority will ask for.
- Check nothing you run touches Article 5. This is a short exercise with a large payoff, because it is the only tier where the top number applies.
- Keep the Article 11 and Annex IV documentation current. Documentation gaps are the most common middle-tier failure.
- Be careful what you submit. The third tier exists specifically for inaccurate information given to authorities.
- Record your AI literacy measures. Article 4 already applies, and it is cheap to satisfy and cheap to evidence.

Do this in Venvera
Venvera holds the EU AI Act as a maintained control set: classify each system by risk tier, track the obligations that follow, generate the policy and documentation set, and keep evidence current. See the EU AI Act workspace or the free EU AI Act compliance checklist. Pricing is published and flat, from EUR 399 per month.
Frequently asked questions
What is the maximum EU AI Act fine?
Up to EUR 35,000,000 or 7% of total worldwide annual turnover, whichever is higher, for non-compliance with the prohibited practices in Article 5. Most other operator obligations carry up to EUR 15,000,000 or 3%, and supplying incorrect information carries up to EUR 7,500,000 or 1%.
Are the fines lower for small companies?
Yes. For SMEs, including start-ups, each fine is capped at whichever of the fixed sum and the percentage is lower, which inverts the general rule. This qualification is frequently omitted from summaries.
Is the AI Act fine higher than GDPR?
The top tier is: 7% of worldwide turnover against GDPR's 4%. That top tier applies only to the prohibited practices in Article 5. The tier most organisations should plan against is 3%.
Who issues EU AI Act fines?
National market surveillance authorities designated by each Member State, with the AI Office holding specific responsibilities for general-purpose AI models. Member States set the detailed penalty rules within the ceilings the Regulation fixes.
Can a company outside the EU be fined?
The Act reaches providers and deployers outside the EU in defined circumstances, including where the output of a system is used in the Union. We cover the triggers in does the EU AI Act apply outside the EU.



