Blog - Norva Solutions

EU AI Act: Penalties and Enforcement

Written by Kevin M. Hyams | Aug 23, 2026, 11:19:09 AM

By Kevin M. Hyams 

Why I wrote this article

The headline fines in the EU AI Act naturally attract attention. They are substantial, and compliance practitioners need to understand them. However, I wrote this article because the fine is only one part of the enforcement picture.

In practice, an organisation may be more immediately concerned about being required to correct a system, restrict its use, withdraw it from the market, recall it, suspend testing, or explain its decisions to customers, management, affected people, and regulators.

My purpose is not to suggest that every mistake will lead to the maximum penalty, or to use the size of the fines to scare organisations into action. It is to help compliance practitioners understand the range of possible consequences and use that understanding to support proportionate, evidence-based compliance work.

The EU AI Act is intended to protect health, safety and fundamental rights while supporting trustworthy AI and innovation. Its enforcement provisions should therefore be understood as part of a wider framework for correcting problems, reducing risk and encouraging organisations to meet the requirements that apply to them.

The question behind effective EU AI Act compliance

NORVA helps compliance teams answer one simple question:

“Are we meeting the requirements that apply to us?”

For the EU AI Act, that question requires more than knowing the maximum fines. It requires the organisation to determine its role, identify the provisions that apply, assess how those requirements are being met, document the evidence, and act promptly where a gap is found.

A structured assessment can help an organisation identify an issue while it is still manageable. That is much more constructive than discovering it only after a complaint, incident, customer challenge, or regulatory enquiry.

The maximum fines are serious, but they are not automatic

The EU AI Act establishes maximum administrative fine levels. These are ceilings, not fixed amounts imposed for every infringement. Penalties must be effective, proportionate, and dissuasive, and the circumstances of the individual case are relevant.

Factors such as the nature, gravity, and duration of the infringement, its consequences, the degree of responsibility, mitigation, cooperation, and previous infringements can affect the enforcement outcome. The Act also requires that account be taken of the interests and economic viability of small and medium-sized enterprises, including start-ups.

The practical lesson is not that every organisation will receive the maximum fine. It is that compliance decisions should be capable of being explained, evidenced, and corrected when necessary.

The three principal administrative fine levels

1. Prohibited AI practices: up to €35 million or 7% of worldwide annual turnover

Non-compliance with the prohibited AI practices in Article 5 can attract an administrative fine of up to €35 million. For an undertaking, the maximum may instead be up to 7% of its total worldwide annual turnover for the preceding financial year, whichever is higher.

This is the highest general fine tier in the Act. Article 5 addresses practices regarded as unacceptable. Examples include specified manipulative or exploitative practices, certain social-scoring uses and other prohibited biometric, law-enforcement or decision-related uses, subject to the precise wording, conditions and exceptions in the Act.

The important compliance task is to screen the intended purpose, technical capability, and actual or proposed use of the system before it is placed on the market, put into service or used. Where classification remains uncertain, the sensible response may be to pause the activity and obtain specialist advice rather than proceed on an unsupported assumption.

2. Specified operator and transparency obligations: up to €15 million or 3%

Non-compliance with specified obligations applying to operators and notified bodies can attract a fine of up to €15 million. For an undertaking, the maximum may instead be up to 3% of total worldwide annual turnover for the preceding financial year, whichever is higher.

This tier includes specified obligations relating to providers, authorised representatives, importers, distributors, deployers, notified bodies, and Article 50 transparency requirements.

For compliance teams, this reinforces the importance of correctly identifying the organisation’s role. A business that considers itself merely a customer, reseller, integrator or technology user may perform a regulated role carrying distinct obligations under the Act.

3. Incorrect, incomplete or misleading information: up to €7.5 million or 1%

Supplying incorrect, incomplete or misleading information to a notified body or national competent authority in response to a request can attract a fine of up to €7.5 million. For an undertaking, the maximum may instead be up to 1% of total worldwide annual turnover for the preceding financial year, whichever is higher.

This is an important reminder that the regulatory response is itself a controlled compliance activity. Information supplied to an authority should be accurate, complete, reviewed, and supported by records. Where facts are uncertain, it is better to identify uncertainty clearly than to present an assumption as an established fact.

How the fine ceiling applies to SMEs and start-ups

For small and medium-sized enterprises, including start-ups, the applicable ceiling under Article 99 is the lower of the relevant fixed amount and percentage of turnover. For larger undertakings, the general rule uses the higher amount.

This does not remove the obligation to comply. It reflects the Act’s requirement for proportionate enforcement and recognition of the economic viability of smaller organisations.

Smaller organisations may have fewer specialised resources, making a clear and manageable assessment method especially important. A proportionate process should make it easier to identify what applies, record the conclusion and organise the supporting evidence without requiring a heavy compliance technology implementation.

General-purpose AI model providers have a separate fine framework

The Commission can impose fines on providers of general-purpose AI models of up to €15 million or 3% of total worldwide annual turnover in the preceding financial year, whichever is higher.

The grounds include intentional or negligent infringement of relevant provisions, failure to comply with document or information requests, providing incorrect, incomplete or misleading information, failure to comply with requested measures and failure to provide access to a model for evaluation.

The general-purpose AI model framework matters because an organisation should distinguish between using a system that incorporates a model and providing, modifying, fine-tuning, or making the model available. Those activities can lead to different roles and responsibilities.

Separate fines apply to EU institutions and bodies

The European Data Protection Supervisor may impose administrative fines on EU institutions, bodies, offices, and agencies. The maximum is €1.5 million for non-compliance with Article 5 prohibitions and €750,000 for other requirements or obligations under the Act.

Although these amounts differ from the private sector’s fine tiers, the underlying lesson is similar: the enforcement response should reflect the circumstances, responsibility, mitigation, cooperation, and impact of the infringement.

Enforcement is not limited to financial penalties

A large fine may be the most visible consequence, but it may not be the consequence that most directly affects operations. The Act gives authorities powers intended to bring systems into compliance and protect people and the market.

Corrective action

An authority can require an operator to bring an AI system into compliance and take corrective action within a prescribed period. This can involve technical, organisational, contractual, documentary, or operational changes, depending on the requirement and the system.

Responding early and constructively may help reduce the duration and consequences of a compliance gap. It also demonstrates that the organisation has governance capable of identifying, owning, and remediating the issue.

Restriction, prohibition, withdrawal and recall

Where adequate corrective action is not taken, an authority may restrict or prohibit an AI system from being made available or put into service, require its withdrawal from the market or require a recall.

For an organisation, these measures can affect customers, contracts, product plans, revenue, service delivery, and reputation. This is why the ability to link each requirement to an assessed response, responsible owner and supporting evidence is valuable well before formal enforcement begins.

Misclassification of a high-risk AI system

Where a provider has classified an Annex III AI system as non-high risk under Article 6(3), a market surveillance authority can evaluate that classification. If the system is found to be high-risk, the provider can be required to bring it into compliance and take corrective action.

Failure to correct the position can lead to fines. Deliberate misclassification intended to circumvent the high-risk requirements can also lead to fines. The practical safeguard is a documented classification assessment that records the legal test, facts, reasoning, evidence, reviewer decision and reassessment trigger.

Formal non-compliance

Persistent deficiencies involving CE marking, the EU declaration of conformity, registration in the EU database, appointment of an authorised representative or availability of technical documentation can lead to a high-risk AI system being restricted, prohibited, withdrawn or recalled.

Some of these matters may appear administrative, but they are part of the evidence chain showing that the system passed through the required compliance process.

Suspension or termination of real-world testing

If testing in real-world conditions does not meet the applicable conditions, an authority may suspend or terminate the testing or require changes.

This can affect research programmes, pilot projects, contracts, and deployment schedules. A well-documented approval process can help establish whether the test qualifies, what conditions apply, and who is responsible for monitoring them.

Investigations, inspections and information requests

The enforcement framework enables authorities and the AI Office, within their respective responsibilities, to request information, investigate compliance, and carry out inspections. An organisation may also be asked to provide access to a general-purpose AI model for evaluation.

This places practical importance on record quality. Technical documentation, assessment reasoning, evidence references, approvals, incidents, remediation and change history should be capable of being located and explained without reconstructing the entire assessment after the request arrives.

Periodic penalty payments

Under the amended enforcement framework, the AI Office can use periodic penalty payments to compel compliance with specified investigations, information requests, inspections, corrective actions, binding commitments, or decisions. Where applicable, the ceiling may reach 5% of average daily income or worldwide annual turnover in the preceding financial year per day, calculated from the date set in the decision.

The purpose is to secure compliance with the decision. The practical response is to assign ownership quickly, understand exactly what the authority requires, and maintain a controlled record of the organisation’s response.

Publication of enforcement decisions

Certain AI Office enforcement decisions may be published with the names of the parties, the main content of the decision and any penalties imposed, while taking account of legitimate interests in protecting confidential information.

Publication can increase scrutiny from customers, employees, investors, suppliers, and the wider market. This is another reason to approach enforcement cooperatively and to be able to demonstrate the steps taken to prevent, identify, and correct the issue.

Complaints, explanations and reporting can bring issues to light

The Act provides routes through which concerns may reach an authority or require an organisational response.

  • A natural or legal person who considers that the Act has been infringed may submit a complaint to the relevant market surveillance authority.
  • Certain affected persons may request a clear and meaningful explanation of the role of a specified high-risk AI system in a decision that produces legal or similarly significant adverse effects.
  • EU whistleblower-protection rules apply to the reporting of infringements of the Act.
  • identify which requirements apply to the organisation, system, model and operator role;
  • work through regulation-specific assessment questions in a logical sequence;
  • understand why each question matters and what can go wrong if the issue is overlooked;
  • record assessed responses, rationale, ratings and validation methods;
  • connect conclusions to illustrative evidence and legal source materials;
  • identify gaps, actions, and reassessment triggers; and
  • produce practical dashboards, status reports and risk outputs without a heavy GRC implementation.

These rights do not mean that every complaint or concern establishes non-compliance. They do mean that organisations should be ready to examine the issue fairly, preserve relevant records, and explain how the system and decision process operate.

One AI issue may engage more than one legal framework

The EU AI Act operates alongside other applicable laws, including those relating to data protection, privacy, consumer protection, product safety, employment and workers’ rights.

A single event may therefore require more than one assessment. For example, a problem involving personal data may need to be considered separately under applicable data protection law. Product, contractual, employment, discrimination, or consumer issues may also need their own review.

This is not a reason to make every AI assessment unnecessarily complex. It is a reason to identify dependencies and route the issue to the appropriate specialist when the facts require it.

A constructive compliance response

The scale of the maximum penalties can make the EU AI Act feel daunting. In my view, the more useful response is to turn that concern into a practical, proportionate programme of work.

1. Confirm scope and roles

Identify the systems, models, legal entities, operator roles, uses, and locations that determine which provisions apply.

2. Prioritise the highest-consequence requirements

Screen prohibited practices, high-risk classifications, general-purpose AI model responsibilities, and transparency requirements early. Do not leave a material classification unresolved while the system proceeds towards release or use.

3. Assess each applicable requirement

Record the assessed response, rationale, evidence, responsible owner, reviewer decision, and any gap requiring remediation.

4. Correct issues promptly

A well-managed gap is different from an ignored one. Assign actions, due dates, and owners, and retain evidence of the corrective work.

5. Prepare for questions

Keep the assessment and evidence sufficiently clear that management, customers, auditors, and regulators can understand how the conclusion was reached.

6. Reassess when circumstances change

Changes to intended purpose, model, data, integration, deployment, branding, market activity or operator role may alter the compliance position.

How NORVA supports this work

NORVA’s Excel-native compliance assessment tools are designed to help compliance teams move from regulatory text to a structured, evidence-supported assessment.

For EU AI Act work, NORVA helps teams:

The objective is not to promise that a template prevents every problem or guarantees compliance. It is to make serious compliance assessment easier to start, easier to complete, more affordable, and easier to explain.

“Are we meeting the requirements that apply to us, and can we show how we reached that conclusion?”

NORVA supports that work in a familiar Excel environment, while preserving the need for professional judgement and legal, technical, or other specialist advice where appropriate.

Conclusion

The EU AI Act’s penalties are substantial, but the most useful compliance message is not that organisations should be frightened by the highest possible fine.

It is that the Act expects organisations to understand their role, identify the requirements that apply, assess how those requirements are being met, and correct problems when they arise.

Financial penalties form part of that framework. So do corrective measures, restrictions, withdrawal, recall, investigations, explanations, and published decisions.

The proportionate response is therefore to build a clear assessment trail before an enforcement question arises. That enables the organisation to identify gaps earlier, prioritise the highest-risk issues, assign remediation, and demonstrate the reasoning and evidence supporting its position.

Compliance assessment is serious work, but it should still be practical, manageable, and capable of being completed with confidence.

Source and Legal Review Note

This article is based principally on Regulation (EU) 2024/1689, including Articles 75c, 76, 79–87 and 99–101, as amended by Regulation (EU) 2026/1744 and reflected in the EUR-Lex consolidated text dated 27 July 2026.

The consolidated text is a documentation tool and has no legal effect of its own. The authentic original and amending Regulations published in the Official Journal of the European Union remain the authoritative legal sources.

The maximum figures described in this article are regulatory ceilings. The applicable authority, legal basis, national penalty rules, facts, date of application, organisational status and circumstances of the individual case should be reviewed before relying on any penalty analysis.

This article provides general information for practical compliance assessment purposes. It does not constitute legal advice. Organisations should obtain qualified legal advice where an infringement, enforcement action, prohibited practice, high-risk classification, general-purpose AI model obligation or material regulatory response is involved.