EU AI Act Fines for Companies: Up to €35 Million or 7% of Global Turnover
The EU AI Act (Regulation 2024/1689) is the world's first comprehensive AI law, and it reaches far beyond European companies. It applies to providers placing AI systems on the EU market and to deployers using AI within the EU — including a US or UK company whose AI system's output is used in the Union. Obligations scale by risk class: certain practices are banned outright, high-risk systems carry extensive documentation, oversight and quality requirements, and further systems face transparency duties.
The sanctions regime is deliberately GDPR-like, keyed to worldwide group turnover so that global companies cannot treat EU exposure as a rounding error. Enforcement is shared between national market-surveillance authorities in each member state — Germany is establishing its national supervisory structure — and the European Commission's AI Office for general-purpose AI models. Non-compliant systems can also simply be barred from the EU market, which for many businesses bites harder than any fine.
International companies get caught through their EU footprint: customers demanding conformity evidence in procurement, market-surveillance sweeps of high-risk use cases like HR screening or credit scoring, complaints from affected individuals, and incident reports. Because obligations phase in on a fixed calendar — bans already apply, high-risk duties follow — the exposure grows with time, not with discovery.
The sanctions you are facing
Using prohibited AI practices carries fines of up to €35 million or 7% of global annual turnover.
High-risk AI is subject to extensive requirements on data, transparency, and human oversight under Annex III of the EU AI Act.
Non-compliant systems may not be placed on the market or operated.
Frequently asked questions
Does the EU AI Act apply to companies headquartered outside the EU?
Yes. The AI Act applies to providers placing AI systems on the EU market regardless of establishment, and to non-EU providers and deployers where the system's output is used in the EU. Non-EU providers of covered systems must generally appoint an EU authorised representative, mirroring the GDPR's extraterritorial approach.
How are AI Act fines calculated?
Fines are tiered by violation type and expressed as a maximum of a fixed amount or a percentage of total worldwide annual turnover, whichever is higher. The top tier — for engaging in prohibited AI practices — reaches €35 million or 7% of global turnover; lower tiers apply to breaches of other obligations and to supplying incorrect information to authorities.
Who enforces the AI Act in Germany?
Market surveillance is organized nationally: each member state designates supervisory authorities, and Germany is setting up its national enforcement structure for this purpose, while the European Commission's AI Office supervises general-purpose AI models. Companies should expect enforcement through documentation requests, audits and market-surveillance measures, alongside pressure from EU customers demanding conformity in contracts.
We only use third-party AI tools — can we still be fined?
Yes. The AI Act imposes duties on deployers, not just developers. Using a high-risk AI system requires, among other things, operating it per the provider's instructions, ensuring human oversight and appropriate input data, and monitoring operation. Deployers can also slide into provider obligations if they substantially modify a system or market it under their own name.