EU AI Act fines: what a violation actually costs
The EU AI Act's fines live in Article 99, and they are tiered: the ceiling depends on which obligation was breached. For the transparency duties in Article 50 (the chatbot-disclosure, marking, and labelling rules that have applied to ordinary websites since 2 August 2026) the ceiling is €15 million or 3% of total worldwide annual turnover, whichever is higher.
Those two numbers are quoted everywhere. What gets quoted far less often is the rest of the mechanics: the rule that caps fines for small companies at the lower of the two figures, the fact that the fining is done by national authorities in 27 capitals rather than by Brussels, and what an inspection of an Article 50 duty physically consists of. This page walks through the mechanics as the regulation states them, with the statute text linked where it matters.
The penalty tiers, as the regulation sets them
Article 99 defines three ceilings for administrative fines, plus a separate route for general-purpose AI model providers. Where your website sits: the Article 50 transparency duties are named explicitly in Article 99(4)(g), in the middle tier.
| What was breached | Ceiling | Basis |
|---|---|---|
| Prohibited AI practices (Article 5) | €35,000,000 or 7% of total worldwide annual turnover, whichever is higher | Art. 99(3) |
| Operator obligations, including the Article 50 transparency duties for providers and deployers | €15,000,000 or 3% of total worldwide annual turnover, whichever is higher | Art. 99(4)(g) |
| Supplying incorrect, incomplete or misleading information to authorities | €7,500,000 or 1% of total worldwide annual turnover, whichever is higher | Art. 99(5) |
| SMEs and start-ups: each ceiling above becomes… | …the same amount or percentage, whichever is lower | Art. 99(6) |
| General-purpose AI model providers (fined by the Commission, not member states) | €15,000,000 or 3% of total worldwide annual turnover, whichever is higher | Art. 101 |
The statutory wording for the Article 50 tier, in full: fines of "up to 15 000 000 EUR or, if the offender is an undertaking, up to 3 % of its total worldwide annual turnover for the preceding financial year, whichever is higher" for non-compliance with, among other operator obligations, "the transparency obligations for providers and deployers pursuant to Article 50."
These are ceilings, not schedules. Article 99 requires penalties to be effective, proportionate and dissuasive, and Article 99(7) lists the factors that set the actual amount: the nature, gravity and duration of the infringement, whether it was intentional or negligent, what the operator did to fix it and mitigate harm, prior fines, the operator's size and market share, and any financial benefit gained from the breach. A first-time gap that was fixed promptly and documented sits at one end of that scale; a sustained, knowing breach that continued after an authority pointed it out sits at the other.
The SME rule most summaries omit
Article 99(6) is one sentence and changes the arithmetic completely for small companies: for SMEs and start-ups, each fine is capped at the amount or the percentage, whichever is lower. The big-company logic runs in reverse.
- A large enterprise with €2 billion turnover faces the higher of €15M and 3% (€60M), so its Article 50 ceiling is €60 million.
- An SME with €2 million turnover faces the lower of €15M and 3% (€60,000), so its ceiling is €60,000.
Two things follow. The "€15 million fine" headline is misleading for a ten-person company: its realistic statutory exposure is a percentage of its own turnover, further scaled by the Article 99(7) proportionality factors. And the rule is a cap, not an exemption: there is no small-business carve-out from Article 50 itself. The duty applies at every size; only the ceiling bends.
Who actually fines you
Not the European Commission, with one exception. Fines for Article 50 breaches are imposed under national law by each member state's market-surveillance authorities, which member states were required to designate (along with their penalty rules) by 2 August 2025. The exception is providers of general-purpose AI models, whom the Commission can fine directly under Article 101, a power it has held since 2 August 2026. A website running an undisclosed chatbot answers to its national authority, not to Brussels.
The map is uneven. Some member states are operational: Finland was among the first, with Traficom coordinating enforcement under a dedicated national act in force since 1 January 2026; Italy assigned the role to its cybersecurity agency ACN; Spain built a dedicated AI supervision agency, AESIA; Germany designated the Federal Network Agency (Bundesnetzagentur) as its main market-surveillance authority, with sectoral regulators keeping their own patches; Malta uses its digital-innovation authority MDIA. Others had, as of a March 2026 European Parliament briefing, notified nothing: only eight of 27 member states had registered their single points of contact with the Commission by then, seven months past the deadline. One law-firm survey counts roughly 2,000 authorities across the EU with some AI Act surveillance competence once sectoral regulators are included.
Our country-by-country guides track who holds the pen in each member state, including Germany, France, and the Netherlands.
What triggers enforcement
Market-surveillance authorities act on their own sweeps, on referrals from other regulators, and, most cheaply for everyone involved, on complaints. Anyone can file one: a consumer, a consumer-protection NGO, a journalist, or a competitor who noticed your chatbot answers "I'm a member of the support team" when asked if it is AI. What makes Article 50 different from most of the AI Act is that a complaint can arrive fully formed, screenshots attached, because the breach is visible from outside. No whistleblower, no document request, no audit: the evidence is your own public website on an ordinary afternoon.
That visibility cuts both ways, which is the next section.
How a check actually happens
There is no forensic mystery to an Article 50 inspection. The duties are worded from the visitor's point of view, so checking them means being a visitor: an official (or complainant) opens the site in a browser, starts the chat and asks whether it is AI, looks at published images and articles for marks and labels, and saves dated screenshots of what appeared. That is the whole procedure. It takes minutes, it needs no access to your systems, and nothing about it requires a regulator to schedule anything with you first.
The burden then runs the other way: authorities expect documented evidence that the disclosure was in place (configurations, screenshots, timestamps), not a verbal assurance that it usually is. The strongest answer to "your chatbot did not disclose on 14 October" is a sealed, dated record of the same visit performed earlier, showing that it did.
What the first wave will look like
As of this page's last review, no market-surveillance authority anywhere in the EU has published a fine under Article 50. The duties took effect on 2 August 2026; the machinery is days old and, in many member states, still being assembled. Treat any claim of "first Article 50 fines already issued" with suspicion until a national authority publishes one.
The realistic opening sequence, based on how EU market surveillance historically starts (GDPR's first year looked the same), is not a wave of maximum fines. It is information requests and corrective-action orders: an authority writes, points at the gap, and sets a deadline to fix it. Fines enter when an operator ignores the letter, cannot show remediation, or is caught misleading the authority, and that last one carries its own tier (€7.5M / 1%). The member states with operational regimes are the plausible first movers, and visible, easy-to-verify breaches (an undisclosed customer-facing chatbot on a sizeable consumer site) are the plausible first targets, precisely because the check costs an afternoon.
The earlier consequences are not regulatory at all: procurement questionnaires now ask about Article 50, enterprise customers ask their vendors, and journalists run the nudge test on consumer brands. Being demonstrably checkable, with dated records either way, matters before any authority is involved.
The one date that moved
Regulation (EU) 2026/1744 (the "Digital Omnibus on AI," in force since 27 July 2026) delayed the Act's high-risk regime but left Article 50 in place, with one narrow carve-out: the machine-readable marking duty in Article 50(2), for generative systems already on the market before 2 August 2026, applies from 2 December 2026. Chatbot disclosure, deepfake labels, and AI-text labels have no grace period; their penalty exposure began 2 August 2026. What the December date does and does not cover →
Common questions
Have any fines been issued under Article 50 yet?
As of early August 2026, no. The Article 50 duties only began to apply on 2 August 2026, and no national market-surveillance authority has published an Article 50 fine so far. That is normal for a new EU regime: the opening moves are typically information requests and orders to fix the problem, with fines reserved for operators who ignore them or cannot show remediation. The exposure is real from day one, though — there is no separate enforcement grace period.
What is the maximum fine for an Article 50 violation?
Up to EUR 15 million or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher (Article 99(4)(g)). For SMEs and start-ups the same two figures apply but capped at whichever is lower (Article 99(6)), which for a genuinely small company means a percentage of its own turnover, not EUR 15 million.
Who issues the fines — the EU or my country?
National market-surveillance authorities in each member state, under national penalty rules — not the European Commission. Italy assigned the role to its cybersecurity agency ACN, Spain to AESIA, Finland to Traficom, Germany to the Federal Network Agency. The one exception is providers of general-purpose AI models, whom the Commission can fine directly under Article 101.
Do the fines apply to small businesses?
Yes — there is no small-business exemption from Article 50 itself. What SMEs and start-ups get is a kinder ceiling: under Article 99(6) the fine is capped at the amount or the percentage, whichever is lower, so in practice at 3% of the company's own worldwide turnover. Proportionality factors in Article 99(7), including the operator's size and what it did to fix the breach, scale the actual amount further.
Can a company outside the EU be fined?
Yes. The AI Act covers providers and deployers located outside the EU when the system's output is used in the Union, and the penalty provisions do not distinguish by headquarters. Enforcement against a company with no EU establishment is slower in practice, but a US or UK site with EU visitors and an undisclosed chatbot is inside the regime, not outside it.
Is there a grace period before fines can start?
Not a general one. Article 50's duties and the penalty exposure both began on 2 August 2026. The single carve-out, confirmed by Regulation (EU) 2026/1744, is the machine-readable marking duty in Article 50(2) for generative systems already on the market before 2 August 2026, which applies from 2 December 2026. Chatbot disclosure and visible deepfake and AI-text labels have no grace period.
Sources and further reading
- Article 99: penalties, full statute text — the tiers, the SME rule, and the proportionality factors
- Regulation (EU) 2026/1744 (EUR-Lex) — the Digital Omnibus amendment, source of the 2 December 2026 marking carve-out
- European Commission: Guidelines on the Article 50 transparency obligations (final, 20 July 2026) — the reference document authorities will assess against
- European Parliament research briefing: enforcement of the AI Act (March 2026) — source of the eight-of-27 designation figure
- Article 50, explained — the four duties the fines attach to
- The free printable Article 50 checklist — the manual version of the visitor's-eye check
This page summarises the penalty provisions for orientation. It is not legal advice; the statute text linked above is the authority, and actual fine amounts are set case by case by national authorities. Where your exposure is non-obvious, involve qualified counsel.