EU AI Act · July 2026

EU AI Act Fines and Enforcement: What €35M Penalties Actually Mean

6 min readTarget keyword: EU AI Act fines enforcement penalties €35 million

The EU AI Act's penalty framework is structured to be proportionate to the severity of the infringement and the size of the infringing organisation. Understanding the three tiers of fines — and what triggers each — is essential context for any enterprise compliance programme.

More importantly: the Act's enforcement architecture is built around documented evidence. The enterprises that will pay maximum fines are not necessarily those that built the worst AI systems. They are the ones that cannot prove their systems were compliant.


The Three Tiers of Fines

Tier 1: €35 Million or 7% of Global Annual Turnover

The highest penalty tier applies to the most serious violations: deploying prohibited AI systems (those classified as unacceptable risk under Article 5), or providing materially incorrect, incomplete, or misleading information to notified bodies and competent authorities. For a global enterprise with €10 billion in annual turnover, this ceiling is €700 million.

Tier 2: €15 Million or 3% of Global Annual Turnover

Mid-tier penalties apply to infringements of any of the requirements applicable to high-risk AI systems — including failures in risk management, data governance, technical documentation, automatic logging, transparency, human oversight, or accuracy obligations. For most enterprises, this is the relevant tier: Article 12 logging failures, inadequate technical documentation, or insufficient human oversight mechanisms.

Tier 3: €7.5 Million or 1.5% of Global Annual Turnover

The lowest tier applies to supplying incorrect, incomplete, or misleading information to national competent authorities in the context of an investigation, or failing to respond to information requests.


Who Enforces the Act?

Enforcement is primarily carried out by national market surveillance authorities — bodies designated by each EU member state to supervise the Act's implementation within their jurisdiction. The European AI Office has supervisory authority over GPAI model providers and can directly investigate and sanction them.

Market surveillance authorities have broad investigative powers: they can require access to training data, technical documentation, and the AI systems themselves. They can conduct inspections. They can impose interim measures — including suspending an AI system's operation — pending investigation. And they can share information with other national authorities across the EU.

National data protection authorities also have a role where AI system violations intersect with GDPR compliance — which is particularly relevant for AI systems processing personal data in high-risk contexts such as credit scoring or employment decisions.


Evidence Is the Central Variable

In almost every enforcement scenario, the question is not only whether a violation occurred — it is whether the organisation can demonstrate that it didn't. The EU AI Act creates a documentary accountability framework in which the absence of evidence is itself treated as evidence of non-compliance.

Consider a market surveillance authority investigating whether an enterprise's AI credit scoring system complied with Article 12's automatic logging requirement. The authority will request the logs. If those logs:

...the authority has grounds to find a violation, regardless of what the enterprise's technical documentation says the system was supposed to do.

Conversely, an enterprise that can produce a complete, cryptographically-verified, externally-witnessed evidence trail of its AI decision-making — pre-mapped to Article 12's specific requirements — has the strongest possible position in an enforcement context. Not because the evidence proves perfection, but because it demonstrates that the enterprise took its obligations seriously and built accountability infrastructure rather than relying on assertion.


What Triggers an Investigation

Enforcement investigations are most likely to be triggered by:

The practical implication is that enforcement risk is concentrated in organisations with public-facing AI in high-risk domains — particularly financial services, employment technology, and healthcare AI — where individual adverse outcomes create natural complaint pathways.

The compliance strategy that minimises enforcement risk is not primarily about policy. It is about evidence. The organisation that can demonstrate, on request, a complete and integrity-verified record of its AI decision-making is the organisation that can defend itself in an investigation. And that capability is built years before the regulator calls, not in response to the call.

Transform your AI logs into regulatory evidence.

Provara seals every AI decision into a tamper-evident, cryptographically-chained ledger — producing signed evidence packets pre-mapped to EU AI Act, ISO 42001, NIST AI RMF, and SOC 2 requirements.

Request a 30-minute technical demo →