“Up to €35 million” probably does not describe you
The figure appears in every summary; the exception that reverses it appears in almost none. For SMEs and start-ups each ceiling is the lower of the two figures, not the higher. Reading only the headline overstates the exposure by orders of magnitude — and distracts from what actually decides the amount.
The three tiers of Article 99
Prohibited practices
Article 5- General case
- €35M or 7 % of worldwide annual turnover, whichever is higher
- SMEs and start-ups
- whichever is lower
The highest ceiling in the Regulation. Covers the eight prohibited applications — of which one turns up in ordinary business software: emotion inference in the workplace.
Provider and deployer obligations
Articles 16, 26, 50 and others- General case
- €15M or 3 % of worldwide annual turnover, whichever is higher
- SMEs and start-ups
- whichever is lower
The tier that actually reaches deploying organisations: missing transparency under Article 50, absent human oversight, missing documentation for high-risk systems.
Incorrect information to authorities
in the course of proceedings- General case
- €7.5M or 1 % of worldwide annual turnover, whichever is higher
- SMEs and start-ups
- whichever is lower
Incorrect, incomplete or misleading information supplied to a market surveillance authority. The lowest tier — and the most easily avoided.
What decides the amount
A ceiling is not an expectation. Article 99 obliges authorities to take into account the nature and gravity of the infringement, the size of the undertaking, the duration, and the measures taken — and that final factor carries more weight than the category of infringement does.
The distance between “we assessed this, documented it, and reached a reasoned conclusion” and “nobody here ever considered it” is wider in outcome than the distance between two tiers. Which is why a documented inventory is not paperwork but the actual risk provision: it takes days and it changes the starting position entirely.
The second thing worth knowing is how proceedings begin. Routine inspection is the exception; complaints, incidents and tip-offs are the rule, and several Member States have deliberately built low-threshold complaint channels. An unsuccessful applicant, a rejected customer or a competitor reaches the authority with little effort. The timing is unpredictable, which argues for having the file ready — not against it.
Who enforces it
Germany: the Bundesnetzagentur. The national implementing act — the KI-MIG — entered into force on 29 July 2026 and concentrates market surveillance, the central contact point and the complaints body there, with a coordination and competence centre alongside. Sectoral competences remain: BaFin for AI tied to supervised financial activities, existing product authorities for Annex I, state authorities for state bodies.
Austria: the AI Service Desk at the telecoms regulator RTR is the central contact point, while market surveillance stays distributed across sectoral authorities.
For a company selling across both, that means one regulation and two sets of counterparties. The obligations are identical; the correspondence is not.
Frequently asked
How large are the fines under the EU AI Act?+
Article 99 sets three tiers: up to €35 million or 7 % of total worldwide annual turnover for prohibited practices under Article 5; up to €15 million or 3 % for breaches of provider, deployer and transparency obligations; up to €7.5 million or 1 % for supplying incorrect information to authorities. For undertakings other than SMEs the higher of the two figures applies.
Is the calculation different for a small company?+
It is reversed, and this is the part almost every summary omits. For SMEs, including start-ups, each ceiling is the lower of the two figures rather than the higher. A company with €20 million turnover facing an Article 50 breach is looking at 3 % of that — €600,000 as the ceiling of the range, not €15 million, and not as the expected fine either.
Since when can fines be imposed?+
The penalty provisions have applied since 2 August 2025. A fine can only follow a breach of an obligation that was itself applicable at the relevant time — so since February 2025 for the prohibitions and AI literacy, since August 2026 for transparency. The high-risk requirements cannot be breached before December 2027 because they do not yet apply.
Who imposes the fine?+
The market surveillance authority designated by each Member State. In Germany that is the Bundesnetzagentur, under the KI-MIG implementing act in force since 29 July 2026, which also makes it the central contact and complaints body. In Austria the AI Service Desk at the telecoms regulator RTR is the central contact point while market surveillance remains distributed across sectoral authorities.
What determines the actual amount?+
Article 99 requires authorities to take into account the nature and gravity of the infringement, the size of the undertaking, its duration, and the measures taken. That last factor is where most of the variance lives. The distance between "we assessed this, documented it and reached a reasoned conclusion" and "nobody here ever considered it" is wider in practice than the distance between two categories of infringement.
How do proceedings usually start?+
Rarely through routine inspection. Complaints, incidents and tip-offs are the common trigger — and several Member States have built deliberately low-threshold complaint channels. The timing is therefore unpredictable, which is an argument for having the file ready rather than against it.
Is there civil liability on top?+
The Regulation itself creates no standalone damages claim. The practical routes are the familiar ones: GDPR claims where personal data is involved, unfair-competition actions over missing disclosure in jurisdictions that allow them, and contractual liability towards customers who were given conformity assurances. The last of these increasingly appears as an express clause in supplier agreements.