What are the penalties for noncompliance with the AI Act?

Why work with us:

– We improve your accessibility
– We enhance your customer experience
– We increase your efficiency

Want to know how we’ve been using AI to enhance the customer experience for years?

“With Pegamento, we found not just a supplier, but a true partner in change. Thanks to their expertise and our joint DevOps approach, we have made great strides in a short time. The technology supports our people so they can focus on where they make a difference: personal contact with entrepreneurs.”

Fines under the AI Act can amount to 35 million euros or 7% of global annual revenue, whichever is higher. The amount depends on the severity of the violation: the most severe penalties apply to prohibited AI practices, while less serious violations have lower maximum fines. In this article, we answer the most frequently asked questions about enforcement, fines, and what your organization can do to remain compliant. Want to know what AI-driven intelligence looks like within a responsible framework? Then read on.

How high can fines under the AI Act go?

The AI Act has three categories of fines with increasing maximum amounts. The highest fine is 35 million euros or 7% of global annual revenue. The middle category ranges up to 15 million euros or 3%, and the lowest category up to 7.5 million euros or 1%. In each case, the higher of the two amounts applies, except for small and medium-sized enterprises.

A more favorable rule applies to SMEs and startups: they pay the lower of the fixed amount or the percentage. This offers some protection for smaller players, but does not eliminate the obligation to comply.

The provisions on fines are set forth in Article 99 of the regulation and have been in effect since August 2, 2025. Providers of General Purpose AI (GPAI) models are subject to a separate regime and may be fined by the European Commission up to a maximum of 15 million euros or 3% of annual turnover under Article 101.

Which violations result in the most severe penalties?

The heaviest fines—up to 35 million euros or 7% of global annual revenue—are imposed for violations of the prohibited practices listed in Article 5. These are AI applications that are considered to pose an unacceptable risk and will be completely banned as of February 2, 2025.

Examples of prohibited practices that may result in the maximum fine:

  • Subliminal or manipulative techniques that influence behavior without a person’s awareness and cause significant harm
  • Exploiting vulnerabilities based on age, disability, or socioeconomic status
  • Social scoring by government agencies
  • Predictive policing based solely on profiling
  • Building facial recognition databases through undirected scraping
  • Emotion recognition in the workplace or in educational institutions (excluding medical or safety exceptions)
  • Real-time remote biometric identification in public spaces for law enforcement, except in strictly defined cases

Non-compliance with other obligations—such as the absence of technical documentation or an incomplete risk management system for high-risk AI—results in fines in the middle category: up to 15 million euros or 3%. Providing incorrect or misleading information to supervisory authorities falls into the lightest category: a maximum of 7.5 million euros or 1%.

Who enforces the AI Act and imposes fines?

Enforcement of the AI Act is divided into two levels. The European AI Office, established within the European Commission’s Directorate-General for CNECT, is responsible for overseeing GPAI models in all 27 member states. National market surveillance authorities are responsible for high-risk AI in general.

In practice, this decentralized model means that enforcement priorities and interpretations may vary by Member State. In January 2026, Finland became the first Member State to grant formal enforcement powers to its national authority under Article 99.

In addition to the national authorities, the AI Board—with one representative per member state—plays a coordinating role. An independent scientific panel advises on implementation and may issue a qualified warning when it identifies risks. The Commission itself may directly fine GPAI providers under Article 101.

Does the AI Act also apply to non-European companies?

Yes, the AI Act has extraterritorial effect. The regulation applies to anyone who develops, markets, imports, or uses AI systems within the EU, regardless of the organization’s country of establishment. The law also applies when the output of a system created outside the EU is used within the EU.

This mechanism is also known as the “Brussels effect, comparable to the global impact that the GDPR had after 2018 on how companies around the world handle personal data. Companies outside the EU that offer AI systems to European users are required to appoint an authorized representative in the EU.

Importers and distributors also have their own obligations: they must verify that conformity assessments have been conducted, that the CE marking and declaration of conformity are present, and retain the documentation for ten years. A distributor or importer who adds their name to a system or makes a substantial modification becomes the supplier themselves, with all the associated responsibilities.

When will enforcement of the AI Act take effect?

Enforcement of the AI Act will be phased in and will not take full effect on a single date. The first requirements, including the prohibited practices and the AI literacy requirement, have been in effect since February 2, 2025. The penalty provisions themselves have been in effect since August 2, 2025.

The complete timeline is as follows:

  1. February 2, 2025: Prohibited Practices (Article 5) and the AI Literacy Requirement (Article 4) take effect
  2. August 2, 2025: Penalty provisions (Article 99), GPAI obligations, governance structure, and designation of national authorities
  3. August 2, 2026: Most requirements for high-risk Annex III systems will become enforceable
  4. August 2, 2027: Requirements for high-risk AI as a safety component of regulated products (Annex I); GPAI models that were on the market before August 2025 must be compliant by that date at the latest

In 2026, the enforcement of high-risk systems will therefore be the next major milestone. Organizations that have not yet begun their compliance process have little leeway left.

How can organizations avoid fines?

Organizations can avoid fines by creating a structured AI registry now that lists all the AI systems they develop or use, and by determining their role for each system: Are they a provider, deployer, importer, or distributor? Determining this role is crucial because the obligations vary significantly depending on the role.

Practical steps to remain compliant:

  • Create a comprehensive registry of all AI systems and classify them by risk level
  • Check whether any of your systems fall under the prohibited practices listed in Article 5, which are already in effect
  • Ensure that employees who work with AI systems have demonstrable AI literacy
  • Prepare technical documentation for high-risk systems and implement a risk management system
  • For high-risk AI, designate individuals responsible for human oversight
  • Retain logs from high-risk systems for at least six months
  • Inform employees before high-risk AI systems are put into use (Article 26(7))
  • Be aware of circumstances that could inadvertently make you a provider, such as modifying an existing system or putting your name on it

Also note the distinction between the deployer and the provider: anyone who makes a substantial change to an AI system or alters its intended use in such a way that the system becomes high-risk automatically assumes full provider liability.

How Pegamento Helps with AI Act Compliance

At Pegamento, we understand that the AI Act is a complex issue for many organizations, especially if you’re already using multiple AI applications in your customer engagement processes. We help you use AI responsibly and in compliance with regulations, without falling into any regulatory pitfalls.

What we can do for you:

  • Provide insight into which of your AI applications fall under the AI Act and what risk level applies
  • Delivering AI solutions designed with human oversight as a fundamental principle, in accordance with the requirements for high-risk systems
  • Implement our Agentic AI for customer service in a way that is transparent, verifiable, and documented
  • Offering everything under one roof: from consulting and implementation to management and support, without silos or complex supplier structures
  • We operate according to our ISO 27001-certified procedures, supplemented by ISO 9001 and ISO 26000, to ensure information security and quality

Our approach combines proven standard building blocks into a solution that fits your organization perfectly, without the need for costly customization. This allows you to reap the benefits of AI while keeping the risks of non-compliance under control. Would you like to know how we can implement this for your organization? Contact us, and we’d be happy to work with you to find a solution.

Frequently Asked Questions

Wat is het verschil tussen een aanbieder en een deployer onder de AI Act, en waarom maakt dat uit voor mijn boeterisico?

Een aanbieder (provider) is de partij die een AI-systeem ontwikkelt en op de markt brengt, terwijl een deployer het systeem van een ander inzet in zijn eigen bedrijfsprocessen. Dit onderscheid is cruciaal omdat aanbieders veel zwaardere verplichtingen hebben, zoals het opstellen van technische documentatie, het uitvoeren van conformiteitsbeoordelingen en het aanbrengen van een CE-markering. Let op: als deployer kun je ongemerkt aanbieder worden — bijvoorbeeld wanneer je een ingekocht AI-systeem substantieel aanpast of het voor een ander doel inzet dan waarvoor het was bedoeld.

Hoe weet ik of mijn AI-systeem als 'hoog-risico' wordt geclassificeerd?

Hoog-risico AI-systemen zijn opgesomd in Bijlage I en Bijlage III van de AI Act en omvatten toepassingen in sectoren zoals onderwijs, personeelsbeheer, kredietverlening, rechtshandhaving en kritieke infrastructuur. Een praktische eerste stap is om per AI-systeem te beoordelen in welke context het wordt ingezet en welke beslissingen het (mede) beïnvloedt. Systemen die significante impact hebben op de toegang van mensen tot diensten, kansen of rechten, vallen al snel in de hoog-risico categorie en vereisen een volledig risicomanagementsysteem, technische documentatie en menselijk toezicht.

Wat houdt de AI-geletterdheidsplicht precies in, en hoe toon ik aan dat mijn organisatie hieraan voldoet?

De AI-geletterdheidsplicht (Artikel 4) verplicht aanbieders én deployers om ervoor te zorgen dat medewerkers die met AI-systemen werken voldoende kennis en vaardigheden hebben om die systemen verantwoord te gebruiken. In de praktijk betekent dit dat je trainingen of bewustwordingsprogramma’s moet opzetten, afgestemd op de rol van de medewerker en het risiconiveau van het systeem. Aantoonbaarheid is hierbij essentieel: leg trainingen, deelnemerslijsten en leerinhoud vast zodat je bij een audit kunt bewijzen dat je aan deze verplichting voldoet.

Kunnen boetes onder de AI Act worden gecombineerd met GDPR-boetes voor hetzelfde incident?

Ja, dat is in principe mogelijk. Veel AI-systemen verwerken persoonsgegevens, waardoor een overtreding tegelijkertijd zowel de AI Act als de AVG/GDPR kan schenden — denk aan een gezichtsherkenningssysteem dat zonder rechtsgrondslag biometrische data verwerkt. De toezichthoudende autoriteiten zijn in dat geval verplicht tot samenwerking en afstemming, maar dubbele sancties zijn niet uitgesloten. Dit maakt het des te belangrijker om AI-compliance en privacycompliance als één geïntegreerd traject aan te pakken in plaats van als aparte silo’s.

Wat moet ik doen als ik AI-systemen van externe leveranciers gebruik — ben ik dan zelf ook aansprakelijk?

Als deployer ben je verantwoordelijk voor het correcte gebruik van het AI-systeem binnen jouw organisatie, ook als het systeem is ontwikkeld door een externe partij. Je bent onder meer verplicht om te controleren of de aanbieder een conformiteitsbeoordeling heeft uitgevoerd, of de CE-markering aanwezig is en of de technische documentatie beschikbaar is. Leg contractueel vast welke verplichtingen bij de aanbieder liggen en welke bij jou, en zorg dat je toegang hebt tot de informatie die je nodig hebt voor menselijk toezicht en incidentrapportage.

Is er een overgangsregeling voor AI-systemen die al vóór de AI Act in gebruik waren?

Ja, er gelden overgangsbepalingen voor bestaande systemen. AI-systemen die al vóór 2 augustus 2026 op de markt waren en als hoog-risico worden geclassificeerd onder Bijlage III, hoeven pas per die datum volledig compliant te zijn. Voor systemen die vallen onder Bijlage I (veiligheidscomponenten van gereguleerde producten) geldt een deadline van 2 augustus 2027. GPAI-modellen die vóór augustus 2025 al beschikbaar waren, moeten uiterlijk 2 augustus 2027 aan de verplichtingen voldoen. Deze overgangsperiodes bieden ruimte, maar zijn geen excuus om compliance-trajecten uit te stellen — de voorbereidingstijd is aanzienlijk.

Wat zijn de meest voorkomende fouten die organisaties maken bij het voorbereiden op de AI Act?

Een veelgemaakte fout is het onderschatten van de scope: veel organisaties realiseren zich niet hoeveel AI-systemen ze al in gebruik hebben, inclusief ingebedde AI in SaaS-tools of HR-software van derden. Een tweede veelvoorkomende fout is het te laat starten met het opstellen van technische documentatie en risicobeoordelingen, waardoor er onvoldoende tijd is voor een gedegen implementatie. Tot slot vergeten organisaties regelmatig hun rol kritisch te beoordelen: wie een bestaand systeem aanpast of hergebruikt buiten het oorspronkelijke toepassingsgebied, neemt automatisch aanbiedersverplichting op zich — met alle bijbehorende compliance-eisen.

More blogs

Download the white paper here

Deepen your knowledge with Pegamento’s white papers.