Governance · 5 minute read
EU AI Act Penalties Explained: Tiers and Exposure
EU AI Act penalties are tiered by seriousness, with the highest tier for prohibited practices, a middle tier for breaches of most other obligations, and a lower tier for supplying incorrect information to authorities. Caps are set as fixed amounts or percentages of global turnover, whichever is higher.
Penalty figures attract attention, and they are rarely the right thing to plan against. For most organisations the realistic exposure is being told to remediate a live system on a schedule they did not choose. This guide covers how the tiers work and what actually reduces exposure, drawing on FISTA Solutions' AI enablement work. This article is general guidance, not legal advice.
How are penalties structured?
| Tier | Covers | Cap basis |
|---|---|---|
| Highest | Prohibited AI practices | Higher of fixed sum or turnover percentage |
| Middle | Most other obligations, including high-risk duties | Higher of fixed sum or turnover percentage |
| Lower | Incorrect or misleading information to authorities | Higher of fixed sum or turnover percentage |
Each tier sets a maximum rather than a tariff, and the caps use the higher of a fixed amount or a percentage of total worldwide annual turnover for the preceding financial year.
Who enforces the Act?
National authorities designated by member states, operating within a market surveillance structure, with EU-level bodies coordinating and handling general-purpose model matters.
Sector regulators remain relevant where they already supervise an industry, which means a financial services firm can face both its existing supervisor and an AI market surveillance authority on the same system.
Does good-faith compliance help?
Yes, materially. Authorities are directed to consider factors including the nature, gravity, and duration of the breach, whether it was intentional or negligent, actions taken to mitigate harm, cooperation, and whether the organisation had relevant measures in place.
That is precisely why contemporaneous evidence matters. An organisation that can show it classified its systems, assessed them, tested them, and documented its decisions is in a different position from one reconstructing after the fact.
What is the realistic exposure for most organisations?
Remediation under deadline. Being told to change a live system on a schedule you did not choose, while customers depend on it, is expensive regardless of whether a fine follows.
There is also the record: a finding documents that the organisation was not meeting a requirement, which affects future examinations and, in regulated sectors, relationships with existing supervisors. See AI compliance audit cost.
What about smaller organisations?
Proportionality considerations apply, with attention to the interests of small and medium enterprises including start-ups, and caps operating so that smaller organisations are exposed on the fixed figures rather than on turnover percentages.
That reduces the headline exposure without removing the obligations, and the remediation cost lands the same way.
What reduces exposure in practice?
Classification done honestly and early. Evidence produced during the build. A named owner per system. Documented decisions about what the system may do unsupervised. And an incident process that works.
Those five are also what makes the systems better, which is the argument for doing them regardless of the penalty regime.
What increases exposure?
Policies without mechanisms. A policy that requires impact assessments, with no assessments performed, evidences that the organisation knew what was required and did not do it.
Shadow deployments increase exposure similarly: systems nobody inventoried cannot have been assessed. See what is shadow ai.
How do prohibited practices differ?
They are not a compliance question but a hard line: certain uses are not permitted regardless of documentation or safeguards. They carry the highest penalty tier and, unlike other obligations, cannot be met by doing the work properly.
Check proposed uses against the prohibitions before designing anything. Discovering that a planned system is not permissible after building it is the most avoidable loss available.
How does timing affect exposure?
The Act applies in phases, and penalty provisions attach as the relevant obligations take effect. Confirm current dates rather than relying on a summary.
Transitional arrangements for systems already on the market also affect the position, and they differ by category.
What should you document?
Classification decisions with reasoning, assessments, evaluation evidence with dates and versions, approvals, oversight design, and incidents with what changed afterwards.
The reasoning matters as much as the conclusion, because a defensible position taken carefully is a different thing from a conclusion someone assumed.
Who owns this internally?
Legal and compliance for interpretation, engineering and product for the evidence. Organisations where compliance owns everything produce documents; organisations where engineering owns everything miss the interpretation.
What should you do first?
Check your proposed and live uses against the prohibitions. That is a short exercise, it is the highest-consequence tier, and most organisations have never done it explicitly.
Then build the inventory, because nothing else is possible without it. See what is an ai inventory.
How does this interact with other regimes?
Badly, if managed separately. The same system can attract attention from a data protection authority, a sector supervisor, and an AI market surveillance authority, and each will ask overlapping questions from a different starting point.
One evidence base mapped to several requirements answers all of them. Three separate programmes produce three sets of documents describing the same systems, and inconsistencies between them are themselves a problem.
What about supply chain exposure?
A system built on a third-party model or bought from a vendor still carries your obligations as provider or deployer. Contractual assurances from a supplier reduce commercial risk and do not transfer regulatory duty.
Ask suppliers for the documentation your own obligations require, and treat inability to produce it as a procurement finding rather than a minor gap.
How FISTA Solutions helps
FISTA Solutions builds AI systems so the evidence of good-faith compliance exists by default: classification checked against prohibitions before design, assessments tied to specific use, evaluation results dated and versioned, oversight design documented, and incident handling that produces a record of what changed. Delivery runs through AI enablement, AI agents, and forward deployed engineers. The record is 150+ projects for 50+ companies across 12+ countries.
To reduce regulatory exposure on live systems, message FISTA on WhatsApp, or read EU AI Act high-risk obligations.
Share-ready article cover
Download the generated social format.
Clear answers
Questions raised by this field note.
Straightforward guidance for evaluating scope, fit, and the next step.
01How are penalties structured?
In tiers by seriousness. Prohibited practices carry the highest exposure, breaches of most other obligations a middle tier, and supplying incorrect, incomplete or misleading information to authorities a lower tier. This is general guidance, not legal advice.
02How are the caps calculated?
As the higher of a fixed amount or a percentage of total worldwide annual turnover for the preceding financial year, which means large groups are exposed on turnover and smaller organisations on the fixed figure.
03Who enforces the Act?
National authorities designated by member states, working within a market surveillance structure, with EU-level bodies coordinating and handling general-purpose model matters. Sector regulators remain relevant where they already supervise.
04Does good-faith compliance help?
Yes. Authorities are directed to consider factors including the nature and gravity of the breach, whether it was intentional or negligent, actions taken to mitigate, and cooperation, which makes contemporaneous evidence genuinely valuable.
05What is the realistic exposure for most organisations?
Remediation under deadline rather than maximum fines. Being told to fix a live system on a schedule you did not choose is expensive in itself, and it is the outcome most organisations should be planning against.
Continue exploring
Related capabilities
Start with the hard problem
Need the outcome owned, not merely analyzed?
Tell us where delivery is constrained. We’ll map the fastest credible path from intent to verified production.