⭐ Star on GitHub

Summary: Three fine tiers topping out at 7% of global turnover, split enforcement between national market surveillance authorities and the Commission (for GPAI), plus complaint and alert routes that let third parties trigger action.

Sources: raw/AI-regulations/Regulation - EU - 2024_1689.md (Article 99); raw/Laws/Enforcement of Chapter V under the EU AI Act...md

Last updated: 2026-07-28


The fine tiers

TierCapApplies to
1€35M or 7% of total worldwide annual turnover, whichever is higherBreach of Article 5 prohibited practices (Art 99(3))
2€15M or 3%Provider (Art 16), authorised representative (Art 22), importer (Art 23), distributor (Art 24), deployer (Art 26) obligations; notified body requirements (Arts 31, 33(1)(3)(4), 34); Article 50 transparency (Art 99(4))
3Lower tierSupplying incorrect, incomplete or misleading information to authorities

(source: Regulation - EU - 2024_1689.md, Article 99)

The 7% top tier exceeds GDPR’s 4%. Note it is a ceiling on administrative fines — Art 99(1) allows Member States to add “warnings and non-monetary measures.”

Member States set the rules, the Commission sets the ceiling

Art 99(1) — Member States “shall lay down the rules on penalties and other enforcement measures… The penalties provided for shall be effective, proportionate and dissuasive. They shall take into account the interests of SMEs, including start-ups, and their economic viability.”

Art 99(2) — Member States must notify the Commission of those rules “at the latest by the date of entry into application,” and of any later amendment.

So the actual exposure in any given Member State is set by national law within the Act’s caps, with an explicit SME-proportionality instruction. See ai-act-and-smes.

Split enforcement

High-risk systems — national market surveillance authorities, under the Regulation (EU) 2019/1020 market surveillance machinery (Chapter IX Section 3).

GPAI models — the Commission directly, via the AI Office. The Commission’s powers include “the power to request documentation and information, the power to conduct evaluations, the power to request measures (concerning compliance, risk mitigation and market restriction, recall and withdrawal), and the power to impose fines” (source: Enforcement of Chapter V…md).

Art 94 (as recorded in the source) applies Art 18 of Regulation (EU) 2019/1020 mutatis mutandis to GPAI model providers, “without prejudice to more specific procedural rights provided for in this Regulation.”

The enforcement gap for GPAI

GPAI providers “have been subject to these obligations since 2 August 2025,” but Commission “supervision and enforcement powers against GPAI model providers will only come into force on 2 August 2026” (source: Enforcement of Chapter V…md).

Twelve months of binding obligations with no Commission enforcement power behind them. See ai-act-timeline.

Routes to enforcement other than the Commission acting alone

The Chapter V analysis identifies three (source: Enforcement of Chapter V…md):

  1. National market surveillance authorities “may request that the Commission exercises its enforcement powers against GPAI model providers.”
  2. Downstream providers “may lodge a complaint against GPAI model providers.” This is the significant one for security researchers embedded at integrators — a downstream provider that discovers a defect in an upstream model has a formal channel.
  3. The scientific panel “may alert the AI Office to a systemic or a concrete identifiable risk posed by a GPAI model” — the qualified alert mechanism under Art 90. A qualified alert can also trigger systemic-risk designation under Art 51(1)(b). See governance bodies.

Whistleblowing

From 2 August 2026, “whistleblowing protections explicitly cover violations of the EU AI Act, though some AI-related issues may already fall under existing protections” via the EU Whistleblowing Directive (2019/1937) (source: raw/Laws/Whistleblowing and the EU AI Act...md).

Protection covers “employees, contractors, suppliers, job applicants, and former workers,” with internal, external and — in limited circumstances — public reporting channels. See Whistleblowing and the AI Act.

The Code of Practice separately requires signatories to protect whistleblowers as part of promoting “a healthy risk culture” (source: raw/Laws/Overview of the Code of Practice...md, Measure 8.3).

The sandbox shield

Providers following the guidance of a national competent authority inside an AI regulatory sandbox “will not face administrative fines for infringements of the Act.” They “remain liable for damages to third parties caused by experimentation” (source: raw/Laws/AI Regulatory Sandbox Approaches...md). See Regulatory sandboxes.