EU AI Act resource · Last verified 2026-08-02

EU AI Act penalties and application timeline

The fines that keep compliance teams up at night, and the deadlines that decide when each obligation actually applies. Know both and you know what to prioritise.

1

The three fine tiers

Violations of prohibited practices (Art. 5): up to €35 million or 7% of global annual turnover. Violations of most provider and deployer obligations: up to €15 million or 3%. Supplying incorrect or misleading information to authorities: up to €7.5 million or 1.5%.

2

SME caps

For smaller providers and deployers (below 50 employees and €10 million turnover), the 7% and 3% tiers are capped at €7.5 million and €15 million respectively — but the percentages can still bite for larger SMEs.

3

Who gets fined

Providers and deployers established in the EU, and providers or deployers outside the EU whose AI output is used in the EU. National market surveillance authorities enforce, alongside the AI Office for systemic general-purpose models.

4

The timeline at a glance

1 August 2024 — the Act entered into force. 2 February 2025 — prohibited practices (Art. 5) and emotion/biometric transparency began applying. 2 August 2025 — general-purpose AI obligations. 2 August 2026 — most high-risk system obligations, including Article 50 transparency. 2 August 2027 — full application, including Annex III systems already placed on the market before 2026.

5

What this means for you now

With 2 August 2026 behind us, the high-risk obligations are live. If you deploy high-risk AI without the risk file, documentation, logs, and oversight, you are exposed to the 3% tier today — and the market surveillance machinery is scaling up across member states.

Go deeper

Related guides & tools

See where your AI actually lands

Describe your system in the free Risk Scanner for a preliminary classification and the obligations that likely apply.

Open the Risk Scanner

Preliminary EU AI Act clarity summary. Not legal advice.