The number that gets quoted most about the EU AI Act — “up to 7% of global turnover” — is real, but it only applies to the most serious category of violation. Article 99 actually sets out three separate fine tiers, each tied to a different type of infringement, plus a specific carve-out for SMEs. Knowing which tier your exposure sits in matters more than the headline number.

The Three Tiers

TierWhat it coversMaximum fine
1 — Prohibited practicesNon-compliance with Article 5 — the outright bans (social scoring, manipulative AI, unlawful biometric categorization, etc.)€35,000,000 or 7% of total worldwide annual turnover, whichever is higher
2 — Operator and notified-body obligationsProvider duties (Art. 16), authorised representative duties (Art. 22), importer/distributor duties (Art. 23–24), deployer duties (Art. 26), notified body requirements, and transparency obligations (Art. 50)€15,000,000 or 3% of total worldwide annual turnover, whichever is higher
3 — Incorrect or misleading informationSupplying incorrect, incomplete, or misleading information to notified bodies or national authorities€7,500,000 or 1% of total worldwide annual turnover, whichever is higher

Every figure is “whichever is higher” between the flat amount and the percentage — the mechanism is designed so that fines scale with company size rather than being capped at a fixed number for large enterprises.

Where Most Mid-Market Exposure Sits

For a typical mid-market company that isn’t running social scoring or biometric surveillance, Tier 2 is the practical concern. It covers the day-to-day operational failures that actually happen: a provider that doesn’t maintain Annex IV technical documentation, a deployer that doesn’t meet its Article 26 obligations, or a system that fails the transparency disclosure requirement in Article 50 (not telling users they’re interacting with AI, or not labeling AI-generated content).

That puts realistic exposure at up to €15 million or 3% of global turnover for gaps that are entirely preventable with a documented system inventory and classification process — not exotic prohibited-use scenarios.

The SME Fine Cap

Article 99(6) sets a specific rule for SMEs, including start-ups: each fine is capped at whichever is lower — the percentage or the flat amount — rather than whichever is higher. For a small company with modest turnover, that means the percentage figure (which scales down with turnover) applies instead of the flat multi-million-euro ceiling that would otherwise apply regardless of company size.

Article 99(1) also requires that penalties “take into account the interests of SMEs, including start-ups, and their economic viability” — meaning regulators are explicitly directed to consider proportionality for smaller operators, not just apply the maximum available. This is on top of the broader SME support measures built into the Act, including reduced conformity-assessment fees.

What Regulators Actually Weigh

Article 99(7) lists the factors a market surveillance authority must consider before setting a fine amount — this is where “the fine is €35M” gets replaced with “the fine reflects the actual situation”:

  • The nature, gravity, and duration of the infringement, including how many people were affected and how badly
  • Whether the same operator has already been fined for the same infringement elsewhere
  • The operator’s size, turnover, and market share
  • Whether the infringement was intentional or negligent
  • The degree of cooperation with authorities, and whether the operator self-reported
  • Any action already taken to mitigate harm to affected people

In practice, this means a company that has an AI system inventory, a documented classification process, and evidence of good-faith remediation is negotiating from a materially different position than one that has none of that and gets flagged cold by a regulator. Article 99(7)(g) specifically calls out “the technical and organisational measures implemented” as a mitigating factor — documentation isn’t just a compliance checkbox, it’s the evidence that reduces the fine if something does go wrong.

Enforcement Timing

Fines under Tier 2 (the one most mid-market companies should actually plan around) attach to obligations that phase in on the deferred timeline — most high-risk Annex III obligations now apply from 2 December 2027. But Tier 1 (prohibited practices) and the GPAI-related pieces of Tier 2 are enforceable now: prohibited practices since February 2025, GPAI provider obligations since August 2025. The Digital Omnibus deferred high-risk application dates — it did not touch the fine structure itself or reduce any already-active obligation.

Turning This Into a Plan

The fine structure rewards exactly the work compliance teams should be doing anyway: inventory every AI system, classify it correctly against Annex III and the Article 5 prohibitions, assign provider/deployer responsibility, and keep documentation current as systems change. None of that eliminates fine exposure outright, but it’s the single biggest lever both for avoiding Tier 2 infringements in the first place and for reducing the fine if a regulator does investigate.

Aikraft classifies systems, generates Annex IV-aligned documentation, and flags drift automatically as your systems or the regulation change — see how it works or take the free risk quiz to see where your own systems currently stand.