Skip to main content
Compliance

EU AI Act Fines for Non-Compliance 2025: Actual Penalties and Risk Tiers

Moses Dor — BizLegal AI · July 1, 2026 · 5 min read


What are the actual EU AI Act fines for non-compliance in 2025?

The EU AI Act (Regulation 2024/1689) became enforceable on August 1, 2024 in phases, with full enforcement of high-risk system obligations by August 2, 2026. Penalties reach €35,000,000 or 7% of global annual turnover (whichever is higher) for prohibited AI practices under Article 5, €15,000,000 or 3% for high-risk system violations under Article 99, and €7,500,000 or 1% for supplying incorrect information to regulators. General-purpose AI (GPAI) providers face €15,000,000 or 3% of turnover under Article 101. The European AI Office, established February 2024, leads enforcement. BizLegal AI's EU AI Act Risk Classifier generates Article 6 risk-tier classification with citation map in 60 seconds — free preview, $19 full report.

What does the EU AI Act classify as "prohibited" AI under Article 5?

Which AI systems are banned outright?

The EU AI Act bans four categories of AI practices entirely under Article 5(a)–(d). First, subliminal manipulation techniques designed to operate beyond human consciousness, distorting behavior and undermining autonomy. Second, exploitation of vulnerabilities targeting children, elderly persons, disabled individuals, or those in precarious socioeconomic situations to materially distort their behavior in harmful ways. Third, social credit scoring by public authorities that rates individuals or groups based on social conduct, restricting access to essential services or opportunities without legitimate safeguards. Fourth, real-time remote biometric identification in public spaces for law enforcement, with narrow exceptions for serious crime prevention and identified missing persons.

The real-world impact is immediate: Clearview AI's facial recognition database was banned across the EU in 2024 for mass surveillance violations. Member states' data protection authorities treat Article 5 violations as the most serious tier, requiring mandatory investigation within 60 days of complaint filing. Companies caught deploying prohibited systems face immediate injunctions and asset freezes pending fines.

What are the penalties for Article 5 violations?

Violations of Article 5 carry the EU AI Act's maximum penalty: €35,000,000 or 7% of global annual turnover, whichever is higher. For multinational AI companies, the 7% calculation is particularly punitive—applied to worldwide revenue, not EU-only revenue. A company with €10 billion global turnover faces a potential €700 million fine for a single prohibited practice.

Member states retain discretion to set their own penalty frameworks, but Article 99 requires all penalties be "effective, proportionate and dissuasive." France's CNIL (Commission Nationale de l'Informatique et des Libertés) has already signaled €10–50 million penalty ranges for Article 5 cases. Italy's Garante per la Protezione dei Dati and Spain's AESIA (Autoridad de Supervisión de Inteligencia Artificial) publish penalty matrices publicly. Enforcement is not uniform—smaller member states may impose minimum fines while larger markets like Germany escalate rapidly.

How do prohibited AI cases get reported and investigated?

The European AI Office in Brussels coordinates enforcement across all 27 member states. Each nation designates market surveillance authorities (NCAs: National Competent Authorities) to receive complaints, conduct investigations, and recommend enforcement actions. The AI Office consolidates findings and can initiate own-motion investigations for systemic violations.

Article 87 establishes whistleblower protections—employees and external parties can report violations confidentially to NCAs or the AI Office without fear of retaliation. Typical investigation timelines run 3–9 months from complaint to formal notice, with an additional 30-day cure period before fines are issued. Companies have 14 days to appeal to national administrative courts. The European AI Office publishes anonymized investigation summaries quarterly, creating compliance precedent.

Which AI systems are classified as "high-risk" under Article 6 and Annex III?

What are the 8 high-risk categories in Annex III?

Article 6 and Annex III identify eight high-risk AI categories requiring mandatory compliance with extensive obligations (testing, documentation, human oversight, transparency).

(1) Biometric identification and categorization: Real-time facial recognition, gait analysis, iris scanning—used for identity verification or demographic profiling.

(2) Critical infrastructure management: AI controlling power grids, water systems, transportation networks where failure causes cascading harm.

(3) Education and vocational training: AI systems determining course placement, admissions decisions, or skill assessments affecting educational trajectories.

(4) Employment and worker management: Resume screening, performance monitoring, shift allocation, predictive attrition systems.

(5) Access to essential private and public services: Credit scoring, loan approval, insurance underwriting, housing allocation, public benefits eligibility.

(6) Law enforcement: Predictive policing, suspect profiling, evidence analysis, crime risk assessment.

(7) Migration, asylum, and border control: Visa decisions, deportation risk ranking, entry screening.

(8) Administration of justice and democratic processes: Judicial sentencing recommendations, regulatory compliance monitoring, election risk systems.

Each category triggers Article 8–15 compliance obligations: algorithmic risk assessment, training data quality logs, human oversight protocols, and documentation trails. Non-compliance fines reach €15,000,000 or 3% of turnover.

What is "limited risk" vs "high risk" vs "prohibited"?

The EU AI Act establishes a three-tier risk framework.

Limited Risk (transparency-only tier) includes chatbots, deepfake detection tools, AI-generated content labeling systems, and general-purpose language models. Article 50 requires only disclosure that AI generated the content—no training audits, no human override systems. Compliance cost: near-zero.

High Risk (Article 6 + Annex III) demands full compliance: risk assessments, training data documentation, performance testing across demographic groups, human override mechanisms, and audit trails. Compliance cost: €50,000–€500,000+ per system depending on complexity.

Prohibited (Article 5) bans outright—no compliance pathway exists. Deploying a prohibited system incurs immediate injunctions and fines regardless of size.

Examples: A chatbot answering customer service queries = limited risk. A chatbot determining loan eligibility = high risk. A chatbot scraping biometric data without consent = prohibited.

How does my company know if our AI is "high-risk"?

Follow this decision tree:

(1) Does your AI system appear on the Annex III list? Review the eight categories above. If your system manages employee hiring, controls grid power, or makes deportation decisions, it is high-risk. Answer "yes" → stop, implement Article 8–15 controls immediately.

(2) Is it a safety component of a product covered by EU harmonization legislation? If your AI is embedded in a medical device, motor vehicle, or toy and affects safety-critical outcomes, it is high-risk even if not explicitly listed. Answer "yes" → high-risk classification.

(3) Use BizLegal AI's classifier. Visit BizLegal AI's EU AI Act Risk Classifier for 60-second automated assessment. Input your system description, data inputs, and decision scope. Receive Article 6 risk-tier classification with full citation map to Annex III and Article 8–15 requirements. Free preview; $19 full compliance report with remediation checklist.

Risk Management System (Article 9)

High-risk AI systems require a documented risk management system throughout their entire lifecycle—from design through deployment and beyond. Providers must identify potential risks, evaluate their severity and likelihood, and implement mitigation measures proportionate to identified hazards. This process must be iterative, revisited whenever significant updates or incidents occur. The EU AI Act alignment with ISO/IEC 42001 (AI Management System standard) provides a practical framework: establish risk ownership, maintain a risk register documenting each identified hazard, assign risk scores, and document mitigation actions with responsible parties and timelines. A practical checklist includes: (1) documenting foreseeable misuse scenarios, (2) assessing impacts on vulnerable populations, (3) identifying technical failure modes, (4) defining residual risk acceptance thresholds, (5) implementing controls (technical safeguards, operational procedures, human oversight), (6) testing mitigation effectiveness, and (7) maintaining audit trails. Member state authorities will expect providers to demonstrate this systematic approach during conformity assessments and post-market surveillance.

Data Governance and Training Data (Article 10)

Training, validation, and test datasets must be relevant, representative, free of errors, and complete—a baseline requirement for high-risk AI system transparency and performance. Providers must establish governance processes ensuring data quality throughout the system lifecycle. This includes bias detection mechanisms (statistical testing for fairness across protected characteristics) and documented mitigation strategies when bias is identified. Data lineage documentation—tracking the origin, preprocessing steps, and composition of datasets—is essential for regulatory accountability and post-incident investigation. The GDPR intersection matters critically: Article 22 (automated individual decision-making) overlaps with high-risk AI classification, meaning many systems must comply with both regimes. If training data includes personal data from EU residents, GDPR's lawful basis requirements apply; if systems make consequential decisions about individuals, Article 22 consent/safeguards are mandatory. Practical implementation requires data governance policies defining roles, approval workflows, and incident procedures; regular bias audits with documented results; and traceability mechanisms showing what data trained which model versions.

Technical Documentation and Logging (Articles 11-12)

Annex IV specifies nine mandatory documentation sections: (1) intended purpose and reasonably foreseeable misuse, (2) performance characteristics across relevant scenarios, (3) input/output data specifications, (4) human oversight measures, (5) quality and governance of training/validation/test data, (6) model architecture and decision logic, (7) risk management outcomes, (8) performance testing results, and (9) compliance with other EU laws. This documentation must be maintained and updated throughout the system's operational life. Automatic logging is equally critical: high-risk systems must record logs of inputs, outputs, and key decisions (logging granularity depends on use case and risk). Logs must be retained for sufficient periods to enable incident investigation and conformity verification—typically 6 months to 3+ years depending on impact severity. These documentation and logging obligations support both conformity assessment (Article 43 initial evaluation) and post-market surveillance, enabling regulators to reconstruct system behavior and investigate complaints or adverse incidents.

Human Oversight (Article 14)

Effective human oversight requires designing high-risk AI systems to enable qualified supervisors to: (a) understand system capabilities and limitations, (b) detect anomalies or deteriorating performance, (c) choose not to deploy or to disable the system, and (d) intervene during operation if needed. This is operationalized through explainable AI requirements—systems must communicate their reasoning in ways meaningful to non-technical supervisors—and through interface design that surfaces confidence scores, decision drivers, and uncertainty. For example, a loan-approval system must show not just "approved" but why (credit score, income stability, collateral) and how confident the model is (e.g., 92% confidence). Oversight also requires training procedures: organizations must ensure supervisors understand the system's typical behavior and know when outputs warrant skepticism. Real-world implementation includes: (1) designing dashboards showing key metrics and anomaly flags, (2) establishing escalation protocols when confidence drops or unusual patterns emerge, (3) conducting regular human-in-the-loop audits, and (4) maintaining audit logs of human override decisions for performance monitoring and model retraining.

Accuracy, Robustness, Cybersecurity (Article 15)

High-risk AI systems must meet declared accuracy levels across relevant use cases and populations—providers cannot claim high accuracy in lab conditions and deploy lower accuracy in practice. This requires testing across diverse demographic groups and operational scenarios, with documented performance metrics (precision, recall, F1-score, etc.). Robustness demands resilience to errors, faults, and distribution shifts: if a facial recognition system trained on summer photos fails on winter images, that's a robustness gap. Testing must include adversarial attack scenarios (e.g., deliberately crafted inputs designed to fool the system) and stress-testing under degraded conditions (missing data, corrupted inputs, out-of-distribution scenarios). Cybersecurity requirements scale with risk: a high-risk employment screening system requires stronger defenses than a low-risk chatbot. Practical measures include: (1) threat modeling to identify attack vectors, (2) encryption of training data and model parameters, (3) access controls and audit logging, (4) regular penetration testing, and (5) incident response procedures. Organizations should document their cybersecurity baseline and justify why it's proportionate to identified threats.

When Does the GPAI Tier Kick In?

General-Purpose AI (GPAI) models possess "significant generality"—meaning they perform a broad range of distinct tasks without task-specific retraining. The EU AI Act defines a computational threshold: models trained with 10^25 floating-point operations (FLOPs) or more trigger GPAI obligations. This threshold, formalized in the 2025 EU AI Act Code of Practice, was chosen to capture frontier models (GPT-4, Claude, Gemini, Llama 2) while excluding smaller specialized systems. Above this threshold, models are designated "GPAI with systemic risk" by Commission decision, triggering Articles 51-55 obligations. The practical implication: OpenAI's GPT-4 (trained with far more than 10^25 FLOPs) is designated; a 7-billion-parameter domain-specific model is not. GPAI obligations are lighter than high-risk AI system requirements—there's no conformity assessment, no AI database registration—but they include transparency (technical documentation, training data summaries), risk evaluation, adversarial testing, and serious incident reporting to the EU AI Office. Non-designated GPAI models must still provide transparency per Article 50 (disclosing AI nature of content, copyrighted material used, etc.).

Transparency Requirements for GPAI Providers

GPAI providers must publish technical documentation summarizing the model's characteristics, capabilities, limitations, and intended use. This includes model architecture details, training compute (FLOPs), dataset composition summaries (without exposing proprietary data), and known risks or failure modes. Copyright compliance documentation is mandatory: providers must disclose which copyrighted materials were used in training and provide mechanisms (where feasible) for rights holders to opt out of future training. Training data summaries—aggregated descriptions of data sources, languages, and domains—must be publicly available or shared with downstream users. Downstream providers (companies building applications on top of GPAI, like a startup using GPT-4 to power employment screening) must receive comprehensive technical documentation from upstream GPAI providers to enable them to assess risks and implement appropriate safeguards. This layered transparency ensures information flows through the supply chain: OpenAI documents GPT-4 for downstream users, those users document their applications for their end customers, and regulators can trace the entire pipeline.

Systemic Risk GPAI Obligations

GPAI models designated as having systemic risk (Commission decision, typically large frontier models) must comply with Article 55 obligations: (1) model evaluation across diverse scenarios, including adversarial testing to probe failure modes and security vulnerabilities; (2) serious incident reporting to the EU AI Office (within 72 hours of discovery) when incidents cause significant harm—e.g., widespread misinformation, security breaches, discrimination affecting thousands; (3) cybersecurity protections proportionate to systemic risk (stronger encryption, access controls, intrusion detection); and (4) cooperation with AI Office investigations. Real examples: OpenAI's GPT-4, Anthropic's Claude 3, Google's Gemini, and Meta's Llama models are all designated. These providers must evaluate their models' susceptibility to jailbreaking, generation of illegal content, and multilingual hate speech; conduct red-teaming (internal adversarial testing); document incidents; and report serious harms to regulators. The EU AI Office maintains a confidential registry of such reports, coordinating across member states and enabling rapid response to emerging systemic risks.

How Much Does EU AI Act Compliance Software Cost?

For most Series A-C SaaS companies shipping AI features into the EU market, the compliance cost-benefit analysis is clear. Manual legal review ($50K–200K, 6–12 months) creates audit-trail gaps and delays market entry. Big-4 consulting ($150K–500K, 3–6 months) is expensive and creates vendor lock-in—proprietary frameworks mean you're dependent on those consultants for updates. Self-building on HuggingFace or open-source tools requires 6–12 months of engineering time and yields no governance structure or regulatory defensibility. The BizLegal AI Risk Classifier ($19 per report / $49/month) delivers audit-defensible risk classification (Article 6 + Annex III mapping, citation traceback, compliance roadmap) in 1–2 weeks, with continuous regulatory monitoring at scale. For companies with multiple AI features or portfolio management needs, LexAudit ($99/month) tracks 50+ global AI regulations simultaneously, and DocAI ($97/scan) risk-scores commercial AI addendums and licensing terms in 60 seconds. The strategic advantage: get to compliance-ready status fast, redeploy engineers to product work, and build in regulatory monitoring from day one rather than discovering violations post-launch.

Q: Is My OpenAI Wrapper Considered "High-Risk" Under the EU AI Act?

The answer depends entirely on use case. If you're building an OpenAI-powered chatbot for a critical service—loan approval, employment screening, medical triage, child custody recommendations—then yes, your wrapper inherits high-risk classification because the downstream application is high-risk (Article 6, Annex III). Conversely, if you're using OpenAI for content generation, code review, or marketing copy, your system faces limited risk (Article 50 transparency obligations only: disclose AI involvement, copyright compliance). The rule: the risk tier of the underlying GPAI model (GPT-4) matters less than the risk tier of your application. A loan-approval system using a low-accuracy GPAI is still high-risk; a marketing chatbot using high-accuracy GPT-4 is low-risk. Use the BizLegal AI Risk Classifier to map your specific use case against Annex III criteria: if your system makes a consequential decision about a vulnerable group or processes special category data, it's high-risk and requires full compliance (Article 9–15 obligations).

Q: When Does the EU AI Act Start Applying to My Company?

The EU AI Act phases in across four key dates, and all apply to non-EU companies shipping AI into the EU market. February 2, 2025: Prohibitions on AI systems identified in Article 5 (social credit scoring, real-time biometric mass surveillance in public, etc.) are enforceable; AI literacy and governance structures must be established. August 2, 2025: General-Purpose AI obligations (Articles 51–55) take effect—GPAI providers must publish technical documentation, copyright disclosures, and incident reporting procedures. August 2, 2026: High-risk AI system obligations (Articles 9–15) become enforceable for new systems—risk management, human oversight, documentation, logging must be in place. August 2, 2027: Existing high-risk systems deployed before August 2, 2026 must achieve compliance. If you ship AI features into the EU market today, you're already subject to February 2025 prohibitions and August 2025 GPAI obligations; high-risk systems deployed after August 2026 require immediate compliance.

Q: What Happens If I Get an EU AI Act Violation?

Member state market surveillance authorities investigate violations and can impose corrective measures (orders to modify or withdraw systems). The EU AI Office coordinates cross-border enforcement and can escalate cases. Penalties under Article 99 are severe: up to €35 million or 7% of global annual turnover (whichever is higher) for prohibited AI violations; up to €15 million or 3% for high-risk system non-compliance; up to €10 million or 2% for governance/documentation failures. Real-world enforcement precedent exists: Italy's Garante temporarily banned Replika in 2023 (predating the AI Act, under GDPR); France's CNIL fined Clearview AI €20 million for GDPR violations in 2024 (biometric data scraping). Expect EU enforcement to follow similar patterns: 3–9 month investigation timelines, public settlement announcements, reputational damage. The strategic lesson: fix violations before regulators discover them. Maintain audit logs proving your compliance efforts; when violations are found, remediate rapidly and document remediation. Cooperation and transparency reduce penalties.

Q: Do I Need to Register My AI System With the EU Database?

High-risk AI systems: yes, providers must register in the EU AI Database (Article 49, Annex VIII). Registration requires providing system name, intended purpose, provider details, and compliance certification. The database is semi-public: member state authorities can access it for market surveillance; high-risk system details (minus proprietary information) may be public-facing. Limited-risk systems (Article 50 transparency obligations only): no registration required. Prohibited systems: cannot be placed on the market, so registration is moot. Standalone GPAI: not registered by default, unless the Commission designates it as having systemic risk, in which case providers must report serious incidents to the AI Office (not the public database). In practice, registering high-risk systems early (even before August 2026 enforcement) creates a compliance signal and may reduce investigation timelines if issues arise post-deployment.

Q: Can US Companies Ignore the EU AI Act if They Don't Have an EU Office?

Absolutely not. Article 2 extraterritorial reach is explicit: the EU AI Act applies to (a) providers placing AI on the EU market (selling, licensing, distributing), (b) deployers in the EU, and (c) providers/deployers outside the EU if the output is used in/affects EU residents. Real example: a US company selling an AI-powered hiring tool to EU customers, or a US GPAI provider whose model is accessed via API by EU users, is fully subject to the Act. Enforcement may require appointing an EU representative (per GDPR precedent) and establishing compliance procedures even without physical presence. Non-compliance exposes the company to: (1) member state market surveillance actions (orders to cease distribution), (2) financial penalties (

Related reads

Compliance

BOI Filing: Who Bears Liability When the Certifying Officer Gets It Wrong?

Compliance

Compliance Ops Retainer vs. In-House CCO: What Early-Stage Fintechs Actually Need

Compliance

MiCA Article 68: What EU Crypto-Asset Service Providers Must Do Before the Transitional Period Ends

Compliance

MiCA CASP Authorization: Which EU Member State Should You File In?

Need compliance support beyond what a post can provide?

DocAI scans your SaaS agreements, DPAs, and vendor contracts for the clauses that destroy startups — clause location, severity, and suggested negotiation position — in under 10 minutes.

Scan a Contract — $97

This article is for informational purposes only and does not constitute legal advice. Regulations vary by jurisdiction and change frequently. Consult a licensed attorney for advice specific to your situation.

Contact