EU AI Act Fines: How Article 99 Sets €35M / €15M / €7.5M Tiers and Who Pays Each One
Article 99 of the EU AI Act sets three penalty tiers. €35 million or 7% of global turnover for prohibited practices. €15 million or 3% for the obligations listed in Article 99(4). €7.5 million or 1% for supplying incorrect or misleading information. The higher of the absolute figure and the percentage applies to undertakings, and the lower of the two applies to SMEs and start-ups under Article 99(6). This piece walks the exact article list behind each tier, the crossover turnover where the percentage starts to bind, and which obligations are actually live after the July 2026 omnibus deferral.

TL;DR
- Article 99’s middle tier is the main live risk for enterprise deployers, with Article 50 transparency duties enforceable from 2 August 2026.
- Standalone Annex III high-risk obligations move to 2 December 2027, while product-embedded Annex I obligations move to 2 August 2028.
- Today’s practical exposure includes failing to disclose AI interaction, mark synthetic content, or disclose deepfakes and AI-generated news text.
- Article 101 separately lets the Commission fine general-purpose AI model providers for specified breaches, document failures, or denied evaluations.
Article 99 of the EU AI Act sets three penalty tiers, and the structure of the article matters more than the headline numbers. The top tier reaches €35 million or 7% of total worldwide annual turnover for the preceding financial year, whichever is higher. The middle tier sits at €15 million or 3%. The incorrect-information tier sits at €7.5 million or 1%. Two clauses do most of the work and most summaries skip both. First, "whichever is higher" means a €2 billion enterprise faces a €60 million ceiling at the middle tier rather than €15 million. Second, Article 99(6) inverts that rule for SMEs and start-ups: for them each fine is capped at the percentage or the amount, whichever is lower. A great many compliance decks have this backwards.
The calendar moved too. Regulation (EU) 2026/1744, the digital omnibus on AI, entered into force on 27 July 2026 and pushed the standalone Annex III high-risk obligations to 2 December 2027 and the product-embedded Annex I ones to 2 August 2028. The transparency duties in Article 50 did not move and have applied since 2 August 2026. So the tier that can actually be assessed against a deployer today is not the record-keeping one everybody prepared for.
I want to walk through the exact article list behind each tier, the turnover at which the percentage starts to bind, which obligations are live right now, and which architectural failures map to a finding under each tier.
Mandate
Article 99 codifies three categories of conduct and assigns a maximum fine to each.
The €35 million / 7% tier (prohibited practices)
The top tier applies to conduct prohibited under Article 5. Examples include social scoring by public authorities, real-time biometric identification for law enforcement outside narrow exceptions, and exploitation of vulnerabilities of specific groups. Most enterprise AI deployments do not sit in this tier. A regulated enterprise running a copilot for back-office finance, a healthcare summarization tool, or a customer-service LLM is not engaging in Article 5 prohibited practice. The Commission flagged this tier primarily at sovereigns and at the small set of vendors who build AI systems with social-scoring or biometric-surveillance use cases.
The €15 million / 3% tier (Article 99(4))
The middle tier is the one most enterprise deployers should plan around. Article 99(4) does not say "the high-risk obligations" in general terms. It enumerates a specific list: 16 for providers, 22 for authorised representatives, 23 for importers, 24 for distributors, 26 for deployers, then 31, 33(1), 33(3), 33(4) and 34 for notified bodies, and finally 50 for transparency.
Note which numbers are absent. Article 12 record-keeping and Article 13 and Article 14 are not enumerated in Article 99(4), and people read that as good news more often than they should. Those duties sit in Chapter III Section 2, and Article 16(a) obliges the provider to ensure the high-risk system complies with that entire section. A record-keeping failure therefore reaches the €15 million tier through Article 16, not directly. For a deployer the route is Article 26(6), which requires the deployer to keep the logs the system generates automatically, for a period appropriate to the intended purpose and at least six months, to the extent those logs are under its control. That is the clause an enterprise deployer gets assessed against, and the deployer obligations are covered in more depth in our Article 26 walkthrough.
A finding here can be triggered by a single auditable failure. The audit visit asks: produce the logs for AI request 47832 against your high-risk system. If the deployer cannot produce a per-decision record containing identity, data classification, policy state, and decision outcome, that is an Article 26(6) problem regardless of how good the model documentation looks. The fine ceiling is €15 million or 3% of worldwide turnover, whichever is higher.
The €7.5 million / 1% tier (incorrect, incomplete, or misleading information)
The third tier covers supplying incorrect, incomplete, or misleading information to notified bodies or to national competent authorities in reply to a request. The conduct here is a documentation failure during conformity assessment or post-market monitoring. The deployer represents the system as having capability X. The auditor finds capability X is absent. The finding is in this tier even if the underlying high-risk system is otherwise compliant.
The "higher of" rule and where the percentage starts to bind
Each tier is written as "X million euro or, if the offender is an undertaking, up to Y% of its total worldwide annual turnover for the preceding financial year, whichever is higher." The crossover points are worth computing once and remembering, because the published summaries get them wrong often enough to matter.
- Top tier: 7% of turnover exceeds €35 million above €500 million of turnover.
- Middle tier: 3% of turnover exceeds €15 million above €500 million of turnover.
- Third tier: 1% of turnover exceeds €7.5 million above €750 million of turnover.
The first two tiers cross over at exactly the same figure, which is a quiet piece of drafting symmetry and a useful mental anchor: at half a billion euro of group turnover, the absolute numbers stop being the operative cap on both of the tiers a deployer cares about. Below that line the euro figures bind. Above it, the percentage does, and it scales without limit.
The SME inversion in Article 99(6)
Article 99(6) reads: in the case of SMEs, including start-ups, each fine referred to in this article shall be up to the percentages or amount referred to in paragraphs 3, 4 and 5, whichever thereof is lower. The word is lower, and it reverses the rule that applies to everyone else.
The practical effect: a start-up with €5 million of turnover facing a middle-tier finding is capped at 3% of €5 million, which is €150,000, rather than at €15 million. The proportionality is built into the article rather than left to the authority's discretion. This also means the SME cap gets stricter as the company shrinks, which is the opposite of the intuition most founders arrive with.
Article 101 and general-purpose AI model providers
A fourth penalty regime sits outside Article 99 and gets missed. Article 101 lets the Commission itself fine providers of general-purpose AI models up to 3% of annual total worldwide turnover or €15 million, whichever is higher, where the provider intentionally or negligently infringed the regulation, failed to supply requested documents or supplied inaccurate information, refused to comply with a requested measure, or denied the Commission access to the model for evaluation. National competent authorities do not administer this one. The Commission does, directly.
What is enforceable today
Article 99 itself has been applicable since 2 August 2025, when Chapter XII of the regulation started to apply. The penalties framework is not waiting for anything. What has moved is the set of obligations it can be pointed at.
After the omnibus, the live exposure for a typical enterprise deployer breaks down like this. The Article 5 prohibitions and their €35 million tier date from 2 February 2025, and the omnibus added two more (generating or manipulating intimate imagery without freely given consent, and child sexual abuse material) that bite from 2 December 2026. Article 50 transparency became applicable on 2 August 2026 and sits squarely inside the €15 million tier, because Article 50 is named in the Article 99(4) list. The high-risk obligations that route to that same tier through Article 16 and Article 26 now wait until 2 December 2027 for standalone Annex III systems and 2 August 2028 for Annex I product-embedded ones.
The practical consequence is one most readiness programmes have not absorbed. The obligation an enterprise can be fined for today, at the €15 million or 3% level, is disclosing that a person is interacting with an AI system, marking synthetic content, and disclosing deepfakes and AI-generated text published as news. Not record-keeping. The record-keeping work still has to happen, and the extra sixteen months is a real gift for anyone who has not started, but a chatbot that never tells the user it is a chatbot is the version of this that carries live liability in August 2026. See the omnibus deferral and the Article 50 obligations for the detail.
The Article 99(7) factors
The ceiling is not the fine. Article 99(7) lists what the national authority weighs when setting the actual figure:
- The nature, gravity and duration of the infringement and its consequences.
- Whether other market surveillance authorities have already fined the same operator for the same conduct.
- The size, annual turnover and market share of the operator.
- Any financial benefit gained, or loss avoided, through the infringement.
- The degree of cooperation shown in remedying the infringement and mitigating its effects.
- The degree of responsibility, taking into account the technical and organisational measures already implemented.
- How the infringement came to light, and specifically whether the operator reported it.
- Whether the conduct was intentional or negligent.
- Any action taken to mitigate the harm suffered by affected persons.
Two of those are directly architectural. The degree of responsibility given the technical and organisational measures already in place, and the ability to cooperate by producing evidence, both depend on what an operator can show. An enterprise that can hand over signed per-decision records is arguing about mitigation from a different position than one reconstructing history from application logs.
Compliance gap
Most enterprise AI deployments today have no architecture that produces the records the middle tier presumes exist.
The application-controlled audit log fails the Article 12 test
When the application that calls the model also writes the compliance log, the audit record has three failure modes. Selective logging: the application logs successes and misses edge cases. Suppression: logs can be wiped by the same software that failed. Loss on crash: the application crashes after the model responds but before the log commits. A regulator reviewing a high-risk system that produced harm asks for an immutable record showing identity, classification, policy state, and decision outcome at the moment of the request. An application-controlled JSON log fails every part of that question.
Identity context is missing at the request layer
The explicit statutory demand for named humans is narrower than most summaries suggest, and worth stating precisely. Article 12(3) applies only to the systems in Annex III point 1(a), remote biometric identification, and for those it requires the logs to capture the period of each use, the reference database checked against, the input data that produced a match, and item (d), the identification of the natural persons involved in verifying the results under Article 14(5). Outside that category, Article 12(1) and (2) require automatic recording of events over the system's lifetime sufficient to identify risk situations, support post-market monitoring, and support the deployer's Article 26(5) monitoring duty.
That still lands in the same place operationally. A deployer cannot monitor operation, escalate a suspected risk, or reconstruct a serious incident from records that name only a service account. Most enterprise AI deployments call the model API with a static service credential or an application API key, and the credential identifies the calling application rather than the human or agent acting through it. Without identity attached at the HTTP request layer, the record either omits the person entirely or infers one from a session-cookie heuristic that will not survive being questioned. Article 19 then requires providers to keep those automatically generated logs for at least six months, and Article 26(6) puts the same six-month floor on deployers for the logs under their control. Retaining a record that cannot answer who did this is retention without evidence. The Article 19 logging obligation is worth reading alongside this.
Data classification is not evaluated at request time
Nothing in Article 12 uses the phrase "data classification," and it does not need to. The obligation is that the recording is automatic and contemporaneous with the event. A classification derived weeks later, by a batch job reading production traces, is a reconstruction rather than a record, and an auditor who understands the difference will ask when the field was written and not just whether it exists. The classification has to be present in the record at the moment of the decision, which means it has to be computed on the request path.
Vendor-embedded AI is invisible to the deployer
A material share of enterprise AI usage flows through SaaS vendors who embed model calls under the hood. The customer-service vendor uses an LLM to summarize tickets. The credit-decisioning vendor uses ML to flag high-risk applications. The deployer's environment never sees the prompt, the response, or the data classification. The Article 26 deployer obligation does not transfer to the vendor. The deployer owns the disclosure on demand.
Mandate vs Compliance
The text of Article 99 reads at one level of abstraction. The infrastructure that survives a regulatory review sits several levels lower. The gap between them is where most enterprises are exposed.
Disclosure test
A regulator asks: produce the audit record for AI request 47832 against your high-risk system, including the identity of the requester, the classification of the data in the prompt, the policy version that governed the decision, and the decision outcome. A compliant architecture produces this within minutes. A non-compliant architecture produces unstructured application logs, missing fields, and a workflow of engineers reconstructing context from production traces. The disclosure failure itself can trip the €7.5 million tier even if the underlying decision was correct.
Vendor liability
Microsoft and SAP declined to comment when The Register asked the major AI vendors how much liability they accept for AI agent decisions. Oracle, Salesforce, ServiceNow, and Workday did not respond. Under Article 26, the deployer obligation does not transfer through a contract clause. The deployer remains the regulated party.
Compliance gap
The compliance gap is architectural. The records the middle tier presumes exist are not produced by application logs, by network firewalls, or by model-side guardrails. They are produced by an inspection layer that sits inline on the AI request path and writes the per-decision record before the model response returns to the application.
DeepInspect
This is the architecture the EU AI Act requires the deployer to provide. DeepInspect sits at the AI request boundary as an external enforcement layer that operates as a stateless proxy between authenticated users or agents and the LLM endpoint. Every HTTP request is evaluated against per-route, per-role policies using identity context the application supplies. The per-decision record is committed by the proxy, independent of the application, before the model response returns to the calling system.
The record contains a verified identity, the role and authorization context, the data classification applied to the prompt, the policy version that governed the decision, the decision outcome, and a cryptographic signature that prevents post-hoc modification. The record is the artifact a regulator accepts under Article 12 and Article 19. Production latency stays under 50 ms in internal testing, which keeps the enforcement layer outside the model inference budget.
If you are facing the 2 December 2027 high-risk deadline, let's talk.
Beyond the EU AI Act
The same architecture satisfies adjacent regimes. DORA Article 19 requires log retention and contemporaneous records for digital operational resilience in financial services. Fannie Mae Lender Letter LL-2026-04 takes effect August 6, 2026 and requires disclosure on demand for AI and ML decisions in mortgage origination. Texas TRAIGA, the Texas Responsible AI Governance Act, took effect January 1, 2026 with civil penalties and AG enforcement, and we have mapped its control requirements in TRAIGA controls mapping. Each regime uses its own vocabulary and its own filing deadlines, and each one ends up asking for the same artifact: a record of what happened on a specific request, written by something other than the software being audited. Build it once, on the AI request path, and the mapping exercise for each new regime becomes paperwork rather than engineering.
Frequently asked questions
- How are EU AI Act fines actually calculated?
Each tier specifies an absolute cap and a percentage of total worldwide annual turnover for the preceding financial year. For an undertaking the ceiling is the higher of the two, so a €2 billion enterprise faces a €60 million ceiling at the middle tier rather than €15 million. Below roughly €500 million of turnover the euro figure is the operative cap on both the top and middle tiers. National competent authorities then set the actual fine within that ceiling using the Article 99(7) factors: gravity, duration, whether the conduct was intentional or negligent, cooperation, measures already in place, self-reporting, and prior findings.
- Who decides which tier applies?
The national competent authority in the member state where the deployer is established or where the conduct occurred. Each member state designates its own competent authority. For multi-state deployers, the EU AI Office coordinates cross-border enforcement and handles the general-purpose AI category directly. Member state authorities cooperate through the AI Board.
- Does the deployer pay or the vendor pay?
Under Article 26, the deployer of a high-risk AI system bears the deployer obligations regardless of who developed or supplied the system. Contractual indemnification clauses with vendors do not transfer the regulatory obligation. The deployer is the regulated party in any audit visit. A finding against the deployer cannot be cured by pointing at a vendor contract.
- When do these fines start being assessed?
Article 99 itself became applicable on 2 August 2025, when Chapter XII started to apply. The Article 5 prohibitions date from 2 February 2025, joined by the two the omnibus added, which bite from 2 December 2026. General-purpose AI model obligations started on 2 August 2025, with the Commission's Article 101 fining power against GPAI providers running from 2 August 2026. Article 50 transparency became enforceable on 2 August 2026. The high-risk obligations moved to 2 December 2027 for standalone Annex III systems and 2 August 2028 for Annex I product-embedded ones. Enforcement maturity varies across member states, but legal exposure begins on each respective date.
- What about SMEs and startups?
Article 99(6) states that for SMEs, including start-ups, each fine is up to the percentage or the amount referred to in paragraphs 3, 4 and 5, whichever thereof is lower. That is the reverse of the rule for other undertakings, and it is a hard cap rather than a discretionary factor. A start-up with €5 million of turnover facing a middle-tier finding is capped at 3% of €5 million, so €150,000, not €15 million. Article 99(1) separately tells member states to take SME viability into account when laying down their national penalty rules, so the size consideration appears in two places. Neither obliges the authority to issue a token penalty within that cap.
- Does Article 99 cover general-purpose AI model providers?
No, and this trips people up. Article 99 is administered by national competent authorities. Fines against providers of general-purpose AI models are imposed by the European Commission under Article 101, up to 3% of annual total worldwide turnover or €15 million, whichever is higher. The grounds include infringing the regulation intentionally or negligently, failing to supply requested documents or supplying inaccurate information, refusing a requested measure, and denying the Commission access to the model for evaluation. An enterprise that fine-tunes and distributes a general-purpose model may find itself a provider for these purposes.
- Which obligation carries live fine exposure in August 2026?
Article 50 transparency. It is enumerated in Article 99(4), so it carries the €15 million or 3% ceiling, and it was not deferred by the omnibus. Disclosing that a person is interacting with an AI system, marking synthetic content in a machine-readable form, and disclosing deepfakes and AI-generated news text are the duties in force now. The record-keeping obligations most readiness programmes prioritised are not enforceable against a deployer until 2 December 2027.