Skip to content

Build1 publisher3 min readPublished

The AI Act's top fine stays at 35 million euros until turnover passes 500 million

The European AI Office starts enforcing on 2 August 2026, and every Article 99 tier is written as the higher of a fixed sum or a share of global turnover. The crossover point decides which number a company is actually exposed to.

The Engineer · Build desk

Illustration accompanying The AI Act's top fine stays at 35 million euros until turnover passes 500 million

What happened

  • Article 99 of the EU AI Act sets three operator tiers: 35 million euros or 7 percent for prohibited practices, 15 million or 3 percent for high-risk and transparency duties, and 7.5 million or 1 percent for misleading regulators.
  • Both the high-risk tier and the Article 50 transparency tier are set at 15 million euros or 3 percent and apply to providers and deployers alike.
  • The mitigating factors include voluntary disclosure before enforcement action begins and prompt corrective action within 30 days of notification.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • constraint A 30-day corrective-action window sets the pace for compliance fixes. Relabeling a UI, republishing a model card and changing a logging path have to be shippable inside a month, not queued for the next quarter's roadmap.
  • exposure Integration teams are now reachable at the same 3 percent of group turnover as the model provider they buy from, which means the labeling duty cannot be pushed upstream in a contract and forgotten.
  • cost For a group under 500 million euros of turnover the percentages never bind, so the fixed sums are the whole exposure and a small deployer carries the same ceiling as a large one.
  • precedent Not answering an information request is itself an enforcement priority, so the first compliance artifact tested in practice will be whatever documentation a provider can produce on request.

The tiers are written as the higher of a fixed amount or a percentage of global annual turnover, and for companies the higher figure applies [2]. So the number worth computing is the one where the two meet. At 7 percent, the 35 million euro ceiling is matched by turnover of 500 million euros [1]. At 3 percent, the 15 million euro tier crosses at the same 500 million [2]. The 1 percent tier for supplying incorrect or misleading information to authorities crosses at 750 million [3]. Below those lines, the fixed sum is the exposure ceiling and the percentage never binds.

GDPR's 20 million or 4 percent crosses at 500 million too [4]. Above that line, the AI Act's top tier takes 1.75 times the share of turnover that GDPR does [5].

For most engineering teams the scoping is the harder fact. Prohibited practices under Article 5 carry the 35 million or 7 percent tier and apply to any organization [5]. The high-risk tier and the Article 50 transparency tier both sit at 15 million or 3 percent, and both apply to providers and deployers [6]. A team that trains nothing and hosts nothing, and only wires a vendor model into a product, is in the same tier as the vendor for a labeling failure.

Two entries on the mitigating list have delivery dates attached. Voluntary disclosure counts only before enforcement action begins [9]. That requires finding your own non-compliance before a regulator does. Prompt corrective action counts within 30 days of notification [9]. Thirty days is short for a change that touches a model card, a UI string, a logging path and a published document, and shorter still if nobody owns all four.

The tier amounts and categories come from Article 99. The calculation methodology, the aggravating and mitigating lists, and the quarterly enforcement calendar come from a dev.to breakdown that attributes them to the European Commission, 2024 [16]. That same post states it was drafted with AI assistance and reviewed for factual accuracy, and that AI-origin labeling applies under Article 50 [15]. A breakdown of the labeling duty that carries its own origin label is at least internally consistent. Its text says enforcement begins on 2 August 2026, while its comparison table lists the Act as effective since August 2026, so treat the calendar as that publisher's reading rather than published AI Office guidance [3][17].

Nothing in the penalty structure names an artifact. It names duties, ceilings and the parties they reach [1][5][6]. The deliverable comes from the enforcement sequence the post describes: information requests and corrective action orders first, financial penalties after, with direct penalty proceedings available for intentional non-compliance or failure to cooperate [4]. An information request is answered with documents that already exist. Failure to engage with those requests is listed as Priority 2 for Q3-Q4 2026, behind GPAI models with systemic risk above 10^25 FLOPs [13]. High-risk obligations become enforceable in Q3-Q4 2027, about 16 months after enforcement opens [14][6].

What to watch

  • Whether the AI Office publishes its own calculation methodology and 30-day corrective-action window, or whether those remain one publisher's reading.
  • The first information requests to GPAI providers above 10^25 FLOPs, and whether any escalate to corrective action orders.
  • High-risk classification guidance in Q1-Q2 2027: it decides who is inside the 15 million euro tier before the December 2027 deadline.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories