Penalties for Non-Compliance
What violations cost under Article 99.
The EU AI Act carries some of the highest penalties in EU digital regulation — deliberately in the GDPR tradition, and higher at the top end.
The three tiers (Art. 99)
| Violation | Maximum fine |
|---|---|
| Prohibited AI practices (Art. 5) | €35 million or 7% of global annual turnover, whichever is higher |
| Most other obligations (high-risk requirements, transparency, GPAI duties) | €15 million or 3% of global turnover |
| Supplying incorrect or misleading information to authorities | €7.5 million or 1% of global turnover |
For SMEs and startups, each cap applies as the lower of the percentage or the fixed amount — still existential for most companies.
Beyond fines
- Market surveillance authorities can force products off the EU market.
- Non-compliance surfaces in due diligence — it can stall enterprise sales, funding rounds, and acquisitions.
- Deployers face claims from affected individuals under national law.
The realistic risk for software teams
Early enforcement will focus on prohibited practices and clearly high-risk systems without documentation. The cheapest insurance is being able to show your homework: an inventory, classifications with reasoning, and Annex IV documentation for anything high-risk. That's precisely the evidence trail Guardia AI generates.