"Fines up to €35 million or 7% of global turnover" is the most quoted line about the EU AI Act, and the least useful. The figure is real — it sits in Article 99(3) — but it is a statutory maximum for the most serious category of violation, not a price list. Actual penalties are set case by case by national authorities, within tiered ceilings, using factors the Regulation spells out. And the obligations that carry the headline numbers are not all applicable yet.
This guide walks through the three fine tiers, the caps for SMEs, who enforces what, the factors that move a penalty up or down, and — with the deflation the topic needs — what exposure realistically looks like for a mid-market B2B SaaS company in 2026. It pairs with our enforcement timeline guide.
The three fine tiers under Article 99
Article 99 sets maximum administrative fines in three tiers, scaled to the severity of the violation. For undertakings, each tier is the fixed amount or the percentage of total worldwide annual turnover for the preceding financial year, whichever is higher:
| Provision | Covers | Maximum fine |
|---|---|---|
| Article 99(3) | Violations of the Article 5 prohibited practices | €35M or 7% of turnover |
| Article 99(4) | Non-compliance with listed operator obligations, including the Article 50 transparency duties | €15M or 3% of turnover |
| Article 99(5) | Supplying incorrect, incomplete, or misleading information to notified bodies or national competent authorities | €7.5M or 1% of turnover |
Three things to hold onto. First, these are ceilings — the Regulation instructs authorities to impose penalties that are effective, proportionate, and dissuasive in the individual case, not to default to the maximum. Second, the tier that matters for most SaaS transparency questions is Article 99(4), the €15M / 3% tier, because that is where Article 50 non-compliance sits — and those duties apply from 2 August 2026. Third, the third tier is easy to overlook and should not be: giving an authority incorrect, incomplete, or misleading information during an inquiry is its own violation, which is one more reason answers to regulators need to come from records rather than recollection.
For completeness: providers of general-purpose AI models sit under a separate regime. Article 101 allows the Commission to fine GPAI model providers up to €15 million or 3% of total worldwide annual turnover, whichever is higher. Unless you train and supply models, that tier belongs to your upstream vendors, not to you.
The SME caps: whichever is lower
The whichever-is-higher rule reverses for smaller companies. Under Article 99(6), for SMEs — including start-ups — each fine tier is capped at whichever is lower of the fixed amount or the turnover percentage. A company with €20 million in annual turnover therefore faces a lower effective ceiling under the percentages than the headline euro figures suggest.
That is a deliberate design choice, and it cuts against the way the €35M number is usually marketed to smaller companies. The maximums are real; the framing that a 200-person SaaS company is facing the same exposure as a global platform is not. The honest statement is narrower: the ceilings scale with size, the floors are set case by case, and the cheapest position at every size is a documented one.
Who enforces what
There is no single EU AI Act regulator for AI systems. Each member state designates national market surveillance authorities to enforce the rules for AI systems in its territory, and each member state lays down its own penalty regime within the Article 99 maximums. The Commission's AI Office supervises general-purpose AI models and holds the Article 101 fining power over model providers.
Two practical consequences follow. A company operating across the EU can face questions from more than one national authority, so a single, consistent set of records beats per-market improvisation. And because national penalty regimes differ in procedure, the portable asset is not a prediction of any authority's behaviour — it is evidence: an AI inventory, a recorded role analysis, and documentation of the transparency measures you implemented. Our enforcement guide covers the supervisory structure in more detail.
What moves a penalty up or down: the Article 99(7) factors
Article 99(7) lists the circumstances authorities must take into account when deciding whether to impose a fine and at what level. The list includes, among other factors:
- Nature, gravity, and duration of the infringement and of its consequences, including the number of people affected and the level of damage.
- Intent or negligence — whether the infringement was deliberate or careless.
- Mitigation and cooperation — actions taken to mitigate harm, and the degree of cooperation with the authorities.
- History — relevant previous infringements, and whether other authorities have already fined the same operator for the same infringement.
- Size and market share of the operator, including its annual turnover.
- How the infringement came to light — including whether the operator reported it itself.
Read as a whole, the list rewards exactly the things a governance program produces: early detection, documented mitigation, and a cooperative, evidence-backed response. An organisation that can show when it assessed its Article 50 duties, what it implemented, and how it responded when something was wrong is arguing about the bottom of a range. An organisation with nothing on file is arguing about the top. That is reasoning from the Regulation's structure, not a prediction of any authority's practice — but it is the structure the Regulation chose.
What this means for B2B SaaS: the realistic exposure
Here is the honest version for a mid-market SaaS company in 2026, and it is less cinematic than the headlines. The €35M / 7% tier attaches to the Article 5 prohibited practices — social scoring, specified manipulation and biometric uses — which a typical B2B SaaS product should not be anywhere near. Confirming that, in writing, is the first and cheapest control. The high-risk regime, where the heavy documentation duties live, was rescheduled to December 2027 and August 2028 pending adoption of the Digital Omnibus, so it grounds no penalty exposure today.
What remains current is the pairing we keep returning to: the Article 50 transparency duties, which apply from 2 August 2026 and sit under the €15M / 3% tier, and buyer scrutiny, which is not a fine at all but arrives earlier and more often than any regulator. Procurement teams are adding EU AI Act sections to security questionnaires, and a stalled enterprise deal is a loss your finance team records this quarter, not a ceiling in a regulation. The Article 50 guide covers the duties themselves; the point here is that the same evidence answers both audiences.
So the credible framing is not "you could be fined €35 million" — for most readers of this post, on current obligations, that is not the exposure. It is: the maximums are real, the near-term exposure is Article 50 plus buyer pressure, and both are addressed by the same modest set of records.
The one-week evidence plan
A week of work puts you on the right side of the Article 99(7) factors and gives procurement something better than reassurance. This mirrors the plan in our compliance checklist:
- Day 1 — inventory. List every AI-powered feature and third-party model API in the product and in internal operations.
- Day 2 — role analysis. Record provider or deployer status per system; the classification determines which duties, and therefore which fine tier, could ever be in play.
- Day 3 — Article 5 screen. Record the conclusion that nothing you ship touches a prohibited practice, and escalate anything ambiguous to counsel. This is the €35M tier — retire it explicitly.
- Day 4 — Article 50 mapping. Match in-scope systems to the transparency duties and record why each applies or does not.
- Days 5–7 — implement, evidence, assign. Ship missing disclosures, attach implementation evidence to the record, and assign an owner to track the Digital Omnibus adoption and national penalty regimes.
Start with the classification, not the fine math
The free assessment gives you a suggested provider/deployer classification and risk-exposure result in about three minutes — the day-2 step above, done for you.
Run the free assessmentEU AI Act fines and penalties FAQ
What is the maximum fine under the EU AI Act?
Article 99(3) provides the highest tier: for violations of the Article 5 prohibited practices, administrative fines of up to EUR 35 million or 7% of total worldwide annual turnover for the preceding financial year, whichever is higher. That is a statutory maximum, not a standard charge — national authorities set actual penalties case by case under the Article 99(7) factors.
What can an Article 50 transparency breach cost?
Non-compliance with the Article 50 transparency obligations falls under Article 99(4), which provides maximum administrative fines of EUR 15 million or 3% of total worldwide annual turnover, whichever is higher, subject to the Regulation’s rules for SMEs. The Article 50 duties themselves apply from 2 August 2026. Actual penalties are determined case by case by national market surveillance authorities.
Do smaller companies face smaller maximums?
Yes. For SMEs, including start-ups, Article 99(6) caps each fine tier at whichever is lower of the fixed amount or the turnover percentage — the reverse of the whichever-is-higher rule that applies to larger undertakings. The Article 99(7) factors, such as gravity, intent, and cooperation, then shape the actual figure within that ceiling.
Can a company be fined for high-risk obligations today?
The Annex III high-risk application date is scheduled for 2 December 2027 (product-integrated Annex I systems, 2 August 2028) under the May 2026 political agreement on the Digital Omnibus, pending legal adoption. Obligations that are not yet applicable cannot ground penalties, so high-risk penalty exposure is not current — but the preparation workload for a genuine high-risk system is long enough that the dates still matter now.
Who actually issues EU AI Act fines?
National market surveillance authorities designated by each member state enforce the rules for AI systems in their territory, applying penalty regimes each member state lays down within the Article 99 maximums. The European Commission, through the AI Office, enforces the general-purpose AI model obligations, with fines under Article 101 of up to EUR 15 million or 3% of total worldwide annual turnover, whichever is higher.
Build the record that argues for the bottom of the range
Govarna keeps your AI inventory, role analysis, Article 5 screen, transparency evidence, and change history together — the documentation the Article 99(7) factors reward, ready before anyone asks.
