Chapter 12: Enforcement, Penalties, and the Authorities — Who Enforces What, and How Much Can It Cost?
What you will learn: By the end of this chapter, you will understand which authorities enforce the EU AI Act, how enforcement is structured at EU and national levels, what the penalty framework looks like in detail, how fines are calculated, what non-financial consequences exist, and what practical steps you can take to prepare for enforcement actions.
Why Enforcement Matters Now
A regulation without enforcement is a suggestion. The EU AI Act is not a suggestion.
The EU has a track record of enforcing technology regulation with significant financial impact. GDPR fines have exceeded €4 billion cumulatively since 2018, with individual penalties reaching hundreds of millions of euros against major technology companies. The EU AI Act builds on this enforcement infrastructure and in several areas goes further — the maximum fine percentages under the AI Act (7% of global annual turnover) exceed those under GDPR (4%).
Enforcement is not a future concern. Article 5 (prohibited practices) and Article 4 (AI literacy) have been in force since 2 February 2025. Authorities can already investigate and penalise violations of these provisions. The full high-risk enforcement regime activates on 2 December 2027, with possible extension to 2 August 2028 for systems that are safety components of products under existing EU harmonised legislation.
The Two-Level Enforcement Structure
The EU AI Act creates a dual enforcement architecture: an EU-level body for GPAI models and national authorities for everything else.
EU Level: The AI Office
The European AI Office, established within the European Commission, is the sole competent authority for enforcing GPAI model obligations (Articles 51–56, covered in Chapter 11). This centralised approach avoids the problem GDPR encountered, where a GPAI provider could be subject to 27 different national interpretations of the same obligations.
The AI Office has the power to request information from GPAI providers, conduct evaluations of GPAI models, require corrective measures, restrict or withdraw models from the market, and impose fines. For systemic-risk models, the AI Office can require providers to conduct additional adversarial testing, implement specific mitigation measures, or — in extreme cases — suspend the model’s availability in the EU.
The AI Office also plays a coordination role: it issues guidelines, facilitates codes of practice, maintains the EU database of high-risk AI systems, and supports national authorities with technical expertise.
National Level: Market Surveillance Authorities and Notifying Authorities
Each EU Member State must designate one or more national competent authorities to supervise the application and implementation of the AI Act within its territory. These authorities handle enforcement of all AI system obligations — prohibited practices, high-risk system requirements, limited-risk transparency, and AI literacy.
In practice, many Member States are expected to assign these responsibilities to existing regulatory bodies. Data protection authorities (which already enforce GDPR) are natural candidates for AI systems that process personal data. Sector-specific regulators — financial services authorities, healthcare regulators, employment agencies — may handle AI systems within their domain. Some Member States are establishing dedicated AI offices or divisions.
Each Member State must also designate at least one notifying authority responsible for setting up and carrying out the procedures for the assessment, designation, and notification of conformity-assessment bodies (notified bodies) for high-risk AI systems that require third-party conformity assessment.
The Practical Implication: If you are a deployer operating in multiple EU countries, you may face enforcement actions from multiple national authorities, each interpreting the regulation in their national context. If you are a GPAI provider, you deal primarily with the AI Office. If you are both — for example, a company that develops a GPAI model and also deploys high-risk systems built on it — you face both layers.
The Penalty Framework
The AI Act establishes three tiers of maximum fines, calibrated to the severity of the violation:
Tier 1 — Prohibited Practices (Art 99(3))
Violations of Article 5 (prohibited AI practices) carry the highest penalties: up to €35 million or 7% of the total worldwide annual turnover of the preceding financial year, whichever is higher. This tier reflects the EU’s position that prohibited practices represent the most serious violations — systems that should never have been deployed.
For the avoidance of doubt: if your organisation has global annual revenue of €500 million and deploys a prohibited AI system, the maximum fine is €35 million (7% of €500 million = €35 million, so the fixed cap equals the percentage in this case). For an organisation with €1 billion in revenue, the maximum rises to €70 million.
Tier 2 — Non-compliance with AI System Obligations (Art 99(4))
Article 99(4) sets this tier by a closed list of provisions: the obligations of providers (Article 16), authorised representatives (Article 22), importers (Article 23), distributors (Article 24) and deployers (Article 26); the requirements for notified bodies (Article 31, Article 33(1), (3) and (4), and Article 34); and the transparency obligations for providers and deployers under Article 50. Non-compliance with any of these carries fines up to €15 million or 3% of global annual turnover, whichever is higher.
This tier covers the bulk of practical compliance failures: failing to conduct a conformity assessment, not providing Instructions for Use, inadequate human oversight, missing FRIA documentation, insufficient log retention, failure to notify workers, and so on.
Tier 3 — Incorrect Information (Art 99(5))
Supplying incorrect, incomplete, or misleading information to notified bodies or national competent authorities in reply to a request carries fines up to €7.5 million or 1% of global annual turnover, whichever is higher (Article 99(5)). Fines on providers of general-purpose AI models — including for incorrect information supplied to the AI Office — are imposed separately by the Commission under Article 101, at up to €15 million or 3% of turnover.
This tier targets obstruction of the regulatory process — lying to regulators, falsifying documentation, or withholding material information during investigations or conformity-assessment procedures.
SME and Startup Adjustments
The AI Act includes a proportionality principle for small and medium-sized enterprises (SMEs), including startups. For SMEs, the fines are capped at the lower of the percentage-based amount and the fixed euro amount. In practice, this means an SME with €5 million in annual revenue faces a maximum Tier 1 fine of €350,000 (7% of €5M), not €35 million. This proportionality is significant — it reduces the existential threat that maximum fines would otherwise pose to smaller organisations — but it does not eliminate the risk. A €350,000 fine can still be devastating for a startup.
How Fines Are Calculated
The maximum amounts above are ceilings, not automatic penalties. The actual fine in any given case is determined by national authorities (or the AI Office for GPAI) taking into account a range of factors specified in Article 99(7):
Nature, gravity, and duration of the infringement. A one-time oversight corrected promptly is treated differently from a sustained, deliberate violation. Deploying a prohibited system knowingly for two years is far more serious than a brief period of non-compliance with a transparency obligation.
Intentional or negligent character. Deliberate violations attract higher penalties than negligent ones. An organisation that knowingly deploys workplace emotion recognition — aware it is prohibited — faces a different calculus than one that genuinely misclassified the system.
Actions taken to mitigate harm. If you discovered the violation, ceased the practice, notified affected persons, and took corrective action before the authority intervened, this works in your favour. Self-reporting and voluntary remediation are explicitly recognised as mitigating factors.
Degree of responsibility. What technical and organisational measures were in place? An organisation with a documented compliance programme, training records, risk assessments, and monitoring procedures demonstrates higher responsibility than one with no compliance infrastructure at all.
Previous infringements. Repeat violations escalate penalties. A first-time violation with good-faith corrective action is treated more leniently than a pattern of non-compliance.
Degree of cooperation with authorities. Cooperation during investigations, timely responses to information requests, and transparency with regulators reduce penalties. Obstruction, delay, and evasion increase them.
The way the infringement became known. Self-reporting is viewed more favourably than discovery through a complaint or investigation.
Size and market share of the infringer. Larger organisations with more resources are expected to maintain higher compliance standards and face proportionally higher penalties.
Beyond Financial Penalties
Fines are the most visible enforcement tool, but they are not the only one. The AI Act grants authorities several additional powers that can be equally or more impactful:
Order to withdraw or recall a system (Art 79). If a high-risk AI system does not comply with the requirements, or if a prohibited system is identified, the authority can order the system to be withdrawn from the market or recalled from deployers. This means not just stopping new deployments but actively removing the system from existing operational use.
Corrective measures (Art 79(3)). Authorities can order specific corrective actions — updating documentation, implementing additional safeguards, conducting assessments, modifying the system — with defined deadlines. Failure to comply with a corrective order can trigger additional penalties.
Restriction of availability (Art 79(5)). Authorities can restrict the making available of an AI system on the market, effectively banning it from being sold or deployed in that Member State, pending compliance.
Public disclosure. Enforcement decisions are typically made public. This creates reputational risk that can exceed the financial penalty. A published finding that an organisation deployed prohibited AI or failed to comply with high-risk requirements becomes permanent public information — affecting customer trust, partner relationships, investor confidence, and employee recruitment.
Cross-border cooperation (Art 74). National authorities can cooperate and share information across borders. An enforcement action in one Member State can trigger investigations in others. The AI Office serves as a coordination point for cross-border cases involving GPAI models.
Who Gets Investigated First
Authorities have limited resources and will prioritise investigations. Based on the GDPR enforcement pattern and the AI Act’s structure, the highest-priority targets are likely to be:
Prohibited practices. These carry the highest fines and the strongest political imperative. Authorities will actively look for social scoring, workplace emotion recognition, and other Article 5 violations, particularly in high-visibility sectors.
High-risk systems in sensitive domains. Law enforcement, immigration, employment, and credit scoring attract scrutiny because they affect fundamental rights most directly. These are the domains where complaints from affected individuals are most likely.
Complaints-driven investigations. Under GDPR, a significant portion of enforcement actions originated from complaints — by individuals, employees, competitors, or civil-society organisations. The same pattern will likely emerge under the AI Act. An employee who discovers their employer uses an AI system for performance monitoring without notification has a basis for complaint.
High-profile incidents. If an AI system causes a publicised harm — a wrongful denial of benefits, a discriminatory hiring decision, a safety failure — regulatory attention follows rapidly.
Systemic-risk GPAI models. The AI Office is specifically mandated to monitor systemic-risk models. The largest model providers will be under continuous scrutiny.
Preparing for Enforcement
You cannot eliminate enforcement risk, but you can substantially reduce both the likelihood and severity of action against your organisation. The following measures directly address the factors authorities consider when calculating penalties:
Document everything. Classification assessments, risk analyses, FRIA and DPIA reports, IFU receipt records, training records, monitoring logs, notification copies, corrective actions — all should be documented, dated, and stored. The single most important difference between an organisation that receives a warning and one that receives a maximum fine is the quality of its compliance documentation.
Build a compliance timeline. Map every obligation against its enforcement date. Do not wait until 2 December 2027 to begin high-risk compliance. Authorities will expect that organisations have been preparing during the transition period, not scrambling at the deadline.
Establish an internal reporting channel. Create a process for employees, contractors, and partners to flag potential AI Act violations internally before they become external complaints. Early internal detection enables corrective action before regulatory involvement.
Train your team. Article 4 AI literacy is already in force. Documented training records demonstrate good faith and reduce the “negligent” characterisation that increases penalties.
Monitor regulatory guidance. The AI Office, national authorities, and sector regulators will issue guidance documents, FAQs, and codes of practice throughout 2025 and 2026. These non-binding documents indicate how authorities intend to interpret and enforce the regulation. Tracking and implementing this guidance demonstrates active compliance effort.
Prepare an incident-response plan. If a violation is discovered — internally or by an authority — have a pre-defined plan for assessment, cessation of the violating practice, notification of affected persons, corrective action, and communication with authorities. Speed and transparency in response are among the strongest mitigating factors.
Enforcement Timeline Summary
| Date | What Becomes Enforceable |
|---|---|
| 2 February 2025 | Article 4 (AI literacy), Article 5 (prohibited practices) |
| 2 August 2025 | GPAI model obligations (Art 51–56) |
| 2 August 2026 | Limited-risk transparency obligations (Article 50) |
| 2 December 2027 | Full high-risk AI system obligations, deployer obligations, conformity assessment, CE marking, EU database registration |
| 2 August 2028 | Extended deadline for high-risk systems that are safety components of products under existing EU harmonised legislation (e.g., medical devices, machinery) |
| Ongoing | Post-market monitoring, serious-incident reporting, periodic review of risk management, updated training |
Self-Check
| # | Question | Your Answer |
|---|---|---|
| 1 | Do you know which national authority is competent for AI Act enforcement in each country where you operate? | ✔ / ✘ |
| 2 | Have you mapped your AI systems against the enforcement timeline above? | ✔ / ✘ |
| 3 | Is Article 4 AI-literacy training already delivered and documented (in force since Feb 2025)? | ✔ / ✘ |
| 4 | Have you confirmed no Article 5 prohibited practices are in operation (enforceable since Feb 2025)? | ✔ / ✘ |
| 5 | Is compliance documentation stored centrally and accessible for regulatory requests? | ✔ / ✘ |
| 6 | Do you have an internal reporting channel for potential AI Act violations? | ✔ / ✘ |
| 7 | Is there an incident-response plan for AI-related compliance failures? | ✔ / ✘ |
| 8 | Are you monitoring AI Office and national authority guidance publications? | ✔ / ✘ |
| 9 | If you are a GPAI provider: have you prepared for AI Office oversight (effective Aug 2025)? | ✔ / ✘ / N/A |
| 10 | Do you have legal counsel identified for AI Act matters? | ✔ / ✘ |
Summary
The EU AI Act is enforced through a two-level structure: the AI Office handles GPAI model obligations centrally, while national market-surveillance authorities enforce all AI system obligations in each Member State. Penalties are structured in three tiers — up to €35 million or 7% of turnover for prohibited practices, up to €15 million or 3% for other AI system violations, and up to €7.5 million or 1% for supplying incorrect information to authorities. Fines are calibrated by severity, intent, duration, cooperation, and prior violations, with proportionality adjustments for SMEs. Beyond financial penalties, authorities can order system withdrawal, require corrective measures, restrict market availability, and publish enforcement decisions. Enforcement is not hypothetical — Article 5 and Article 4 are already enforceable, GPAI obligations follow in August 2025, and the full regime activates in August 2026. The most effective preparation is systematic documentation, proactive training, internal reporting mechanisms, and continuous monitoring of regulatory guidance. Organisations that can demonstrate documented, good-faith compliance efforts before enforcement actions occur are in a fundamentally different position from those that cannot.
← Back to Blog Summary Chapter 13 →