EU AI Act Article 99: Fines and Penalty Tiers
Article 99 of the EU AI Act sets three penalty tiers reaching 35M EUR or 7% of global turnover for prohibited practices, 15M EUR or 3% for high-risk non-compliance, and 7.5M EUR or 1% for supplying misleading information. Article 99 has applied since August 2, 2025; the Digital Omnibus deferred most of the Tier 2 obligations it backs to December 2027 and August 2028.

Article 99 of the EU AI Act sets three penalty tiers. The highest, €35 million or 7% of total worldwide annual turnover for the preceding financial year (whichever is higher), applies to violations of the prohibited practices in Article 5. The middle tier caps at €15 million or 3%, for non-compliance with the high-risk obligations under Articles 8 to 27 and the transparency obligations under Article 50. Supplying incorrect, incomplete, or misleading information to notified bodies and national authorities draws the lowest tier, €7.5 million or 1%. Article 99 itself has applied since August 2, 2025. What it enforces moved: the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force July 27, 2026) deferred the Tier 2 high-risk obligations behind most of this exposure to December 2, 2027 for standalone Annex III systems and August 2, 2028 for AI embedded in regulated products. Article 5's prohibited practices and Article 50's transparency duties kept their original dates, February 2, 2025 and August 2, 2026.
I want to walk through what each tier covers, how the tiers interact with the operational obligations elsewhere in the Act, and what evidence holds up under enforcement.
TL;DR
Article 99 fines run 35M EUR or 7% of global turnover for Article 5 violations, 15M EUR or 3% for high-risk non-compliance, and 7.5M EUR or 1% for misleading a regulator. The penalty framework itself has applied since August 2, 2025, but the Digital Omnibus on AI pushed most of the Tier 2 obligations behind it to December 2, 2027 for standalone Annex III systems and August 2, 2028 for Annex I systems embedded in regulated products. Article 5's prohibited-practices duties and Article 50's transparency duties stayed on their original dates.
Mandate
Article 99 establishes the penalty regime that backs the substantive obligations of the EU AI Act. Member States are required to lay down national penalty rules consistent with the Article 99 framework and to ensure those rules are effective, proportionate, and dissuasive.
The penalties apply to providers, deployers, importers, distributors, and authorized representatives of AI systems. Member States may apply lower penalties for SMEs and start-ups. The Commission retains a separate penalty regime for general-purpose AI model providers under Article 101, which can reach €15 million or 3% of total worldwide annual turnover.
Tier 1: prohibited practices (€35M / 7%)
The highest tier applies to violations of Article 5, which prohibits certain AI practices outright. The prohibited list includes systems that deploy subliminal techniques to materially distort behavior, systems that exploit vulnerabilities of specific groups, social scoring by public authorities, predictive policing based solely on profiling, untargeted scraping of facial images for facial recognition databases, emotion inference in workplaces and educational settings, biometric categorization based on sensitive attributes, and real-time remote biometric identification in publicly accessible spaces for law enforcement purposes. Most enterprise AI deployments do not fall under Tier 1.
Tier 2: high-risk non-compliance (€15M / 3%)
The middle tier covers the bulk of operational AI compliance work. It applies to non-compliance with provider obligations under Articles 16 to 22 and deployer duties at Article 26. Transparency (Articles 13 and 50), record-keeping (Article 12 and Article 19), human oversight (Article 14), and the conformity assessment step (Article 43) round out the list. For most enterprise deployments, Tier 2 is the relevant exposure, though most of that list sits inside the high-risk Chapter III obligations the Digital Omnibus deferred to December 2, 2027 for standalone Annex III systems and August 2, 2028 for Annex I embedded systems. Article 13 and Article 50 transparency duties did not move; those still landed August 2, 2026.
Tier 3: supplying misleading information (€7.5M / 1%)
The lower tier applies to supplying incorrect, incomplete, or misleading information to notified bodies and national competent authorities in reply to a request. The tier sits separately from the substantive compliance obligations. A deployer that fails Article 26 monitoring and then misrepresents the failure to the authority faces both the Tier 2 penalty for the substantive failure and the Tier 3 penalty for the misrepresentation.
Compliance gap
Tier 1 is the headline number, and I see most compliance posture built around it for that reason. The operational exposure sits in Tier 2.
The Tier 2 exposure is per obligation, not per system
A single high-risk deployment can incur multiple Tier 2 penalties across distinct obligations. A deployer that fails Article 12 record-keeping, Article 13 transparency, and Article 26 monitoring faces three distinct compliance findings. National authorities can aggregate, but the substantive basis for each finding stands independently. Treating Tier 2 as a single €15 million exposure misreads the structure.
Evidence drives the multiplier
The penalty figure is a cap. The actual penalty within the cap turns on the nature, gravity, and duration of the infringement, the intentional or negligent character, prior infringements, cooperation with the authority, and the size of the entity. Cooperation requires the entity to produce evidence on demand. A deployer that cannot produce the logs its own Article 26(6) retention duty requires (the provider's mirror obligation sits at Article 19) faces the structural failure of the record-keeping obligation and a worse multiplier on the penalty calculation, because the absence of evidence is treated as inability to cooperate.
Tier 3 is the audit-failure tier
Tier 3 is the supplying-misleading-information tier. The misleading information does not have to be intentional. Incomplete information supplied in good faith can trigger Tier 3 if the authority concludes the information was incomplete in a material way. The structural answer to Tier 3 exposure is to have the evidence to respond completely. Deployers who can produce the per-decision audit record do not have to estimate, paraphrase, or extrapolate when the authority asks.
What the architecture must produce
An architecture that minimizes Article 99 exposure produces, for every high-risk decision, evidence that the underlying obligations were satisfied at the time of the decision. The evidence is structured, signed, retained for the applicable period, and available to the deployer on demand.
The evidence has to map to specific obligations. Article 12 automatic recording produces its own record. Article 19 retention and content compliance produce another. The Article 13 instructions for use prove transparency, and human oversight under Article 26 gets its record when the monitoring event happens. Tier 2 enforcement against any individual obligation is rebutted by the corresponding evidence. Tier 3 exposure is reduced because the deployer can respond completely.
The architecture that produces this evidence is the same architecture that produces compliance under the rest of the Act. The penalty exposure is the financial restatement of the substantive obligations.
DeepInspect
This is the evidence infrastructure that backs the penalty rebuttal. DeepInspect sits as a stateless proxy between authenticated users and the LLM. Every request produces a signed per-decision record containing identity, role, policy version, data classification, outcome, and timestamp. The records are retained for the deployer's specified period, searchable across deployments, and produced on demand.
For Article 99, that record set is the evidence layer that rebuts Tier 2 findings and reduces Tier 3 exposure. Article 12's obligation is satisfied structurally, Article 19 retention runs automatically, and Article 26 monitoring evidence is generated per request. The deployer responding to an authority inquiry produces complete records rather than estimates.
If you are running AI in a high-risk category and your Article 99 exposure depends on the application's ability to produce records under inquiry, that exposure is open.
Book a demo today.
Frequently asked questions
- Does the percentage-of-turnover penalty apply to subsidiaries or to the global group?
Article 99 sets the penalty as €X million or Y% of total worldwide annual turnover for the preceding financial year, whichever is higher. The worldwide annual turnover is the group's consolidated turnover. A subsidiary that fails an obligation can be subject to a penalty calculated against the group's turnover, not the subsidiary's standalone turnover. The interaction with national procedural law varies by Member State, but the Commission's guidance treats consolidated turnover as the baseline.
- Are there reduced penalties for SMEs and start-ups?
Article 99 allows Member States to lay down lower penalties for SMEs and start-ups. The discretion sits with the national authority. The reduction is not automatic and depends on how the Member State has transposed the framework into national law. The Commission has signaled a preference for proportionate penalties for SMEs, and several Member States are expected to introduce specific SME tiers in their national implementation. The 7% / 3% / 1% percentage caps still apply, but the absolute caps may be reduced.
- Can a single incident trigger multiple penalty tiers?
Yes. A prohibited practice violation under Article 5 carries Tier 1 exposure. If the entity also fails the related transparency obligation and misrepresents the failure to the authority, Tier 2 and Tier 3 stack on top. Member State authorities can aggregate the penalties into a single sanctioning decision, but the substantive basis for each finding can be assessed independently. The aggregation rules vary by Member State and remain subject to the proportionality principle that governs the framework as a whole.
- How does Article 99 interact with the GDPR penalty regime?
GDPR and the EU AI Act run in parallel, a comparison covered in more depth in EU AI Act fines vs GDPR fines. A breach that violates both regimes can trigger penalties under each. GDPR's tier reaches €20 million or 4% of global turnover. A deployer that fails Article 12 record-keeping under the AI Act and also fails GDPR's records-of-processing obligation can face both penalties for the same underlying incident, on different substantive grounds. The ne bis in idem principle limits double-jeopardy within a single substantive basis, but the AI Act and GDPR are treated as distinct substantive regimes for penalty purposes.
- When does the Article 99 penalty regime begin to apply?
Article 99 and its enforcement mechanics have applied since August 2, 2025, the same date Tier 1 exposure for Article 5's prohibited practices went live (Article 5 itself took effect February 2, 2025). What changed is the substantive Tier 2 exposure behind it: the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force July 27, 2026) deferred the Chapter III high-risk obligations from August 2, 2026 to December 2, 2027 for standalone Annex III systems and August 2, 2028 for AI embedded in regulated products under Annex I. Article 50 transparency duties kept the original August 2, 2026 date, and general-purpose AI model provider obligations under Articles 53 to 56 (enforced separately under Article 101) have applied since August 2, 2025.