Enforcement, Penalties, and the Authorities — What Non-Compliance Actually Costs

Published 4 May 2026 · 1 min read

A regulation without enforcement is a suggestion. The EU AI Act is not a suggestion. GDPR fines have exceeded €4 billion since 2018. The AI Act goes further — maximum fines reach 7% of global turnover, exceeding GDPR’s 4% ceiling. And enforcement is already live: Article 5 and Article 4 have been enforceable since 2 February 2025.

The enforcement structure operates on two levels. The European AI Office — established within the Commission — is the sole authority for GPAI model obligations, avoiding 27 different national interpretations of the same rules. For everything else — prohibited practices, high-risk systems, limited-risk transparency, AI literacy — each Member State designates national market-surveillance authorities. If you operate across multiple EU countries, you may face enforcement actions from multiple authorities simultaneously.

Penalties follow three tiers calibrated to severity. Prohibited practices carry fines up to €35 million or 7% of global annual turnover. Non-compliance with high-risk, limited-risk, or deployer obligations carries up to €15 million or 3%. Supplying incorrect information to authorities carries up to €7.5 million or 1%. For SMEs, fines are capped at the lower of the fixed amount and the percentage — reducing the existential threat, but not eliminating it. A €350,000 fine can still devastate a startup.

But fines are not the only consequence. Authorities can order system withdrawal from the market, require specific corrective actions with deadlines, restrict a system’s availability in a Member State, and publish enforcement decisions — creating permanent reputational damage that can exceed any financial penalty. Cross-border cooperation means an enforcement action in one country can trigger investigations in others.

The actual fine depends on factors including severity, intent, cooperation with authorities, and existing compliance measures. The single most important differentiator between a warning and a maximum fine is the quality of your compliance documentation. Organisations that can demonstrate documented, good-faith efforts — training records, risk assessments, monitoring logs, corrective actions — are in a fundamentally different position from those that cannot.

What’s in the full chapter

The full chapter covers the two-level enforcement structure in detail, all three penalty tiers with calculation examples, SME adjustments, non-financial enforcement powers, which organisations are likely to be investigated first, six concrete steps to prepare for enforcement, the complete enforcement timeline, and a 10-item self-check.

Read the Full Chapter

Get the complete Chapter 12 with penalty tables, the SME proportionality rule, market-surveillance powers, and the 8-item enforcement-readiness checklist.

Read the Full Chapter Check Your AI Risk Level — Free