Published on This Week in AI

EU AI Act Fines and Enforcement: How Penalties Work in 2026

The EU AI Act's enforcement regime took shape through 2025 and 2026 as national market surveillance authorities and the European AI Office assumed their oversight roles. For businesses operating AI systems in the EU, understanding how fines are calculated, who enforces the rules, and what procedural safeguards exist is essential compliance knowledge.

The Three-Tier Penalty Structure

The AI Act establishes three maximum fine levels, each tied to the severity of the violation:

For SMEs and startups, national authorities apply proportionate caps — typically the lower of the percentage or the euro amount — and guidance from the AI Office emphasizes proportionality for smaller operators. The regulation explicitly requires authorities to consider the size and economic resources of the infringing party when setting fines.

Who Enforces the AI Act?

National Market Surveillance Authorities

Member states designate one or more national market surveillance authorities to enforce the AI Act within their territory for most AI systems. These are typically existing product safety regulators — in Germany this is the Bundesnetzagentur and sector-specific bodies; in France, the CNIL has jurisdiction for AI systems processing personal data alongside a designated AI authority. National authorities have investigative powers including inspecting AI systems, requesting documentation, and ordering corrective measures or market withdrawals.

The European AI Office

The AI Office, established within the European Commission, has exclusive jurisdiction over general-purpose AI (GPAI) model providers — particularly those with systemic risk. It coordinates enforcement across member states, develops technical standards, and can itself impose fines on GPAI providers for violations of the GPAI-specific obligations. The AI Office is also the body that maintains and publishes the list of GPAI models with systemic risk designation.

The Enforcement Process

Complaint and Investigation

Enforcement can begin through market surveillance authority investigation, a complaint from a natural or legal person with a legitimate interest, or a referral from another EU body. Once a suspected violation is identified, authorities must notify the operator and give it the opportunity to remedy the non-compliance before imposing penalties, except in cases of serious risk requiring urgent intervention.

Corrective Measures First

The Act establishes a graduated enforcement approach. Authorities typically first require corrective measures — updating documentation, implementing human oversight, withdrawing a non-compliant system from specific use cases — before imposing financial penalties. Fines are available when corrective measures are ignored or the violation is willful or negligent.

Appeals

Enforcement decisions are subject to judicial review under national administrative law. The AI Office's decisions regarding GPAI model providers can be challenged before the Court of Justice of the EU. Appeals do not automatically suspend enforcement decisions, though courts can grant interim relief.

High-Risk AI: What Triggers Enforcement?

In 2026, the highest-priority enforcement targets are high-risk AI systems deployed without completing the required conformity assessment, registration in the EU AI database, or CE marking process. Authorities have indicated that systems used in employment decisions (hiring, performance management, dismissal), credit scoring, access to essential services, and law enforcement analytics are enforcement priorities because these systems directly affect fundamental rights.

Frequently Asked Questions

When did AI Act enforcement begin?

Enforcement of prohibited AI practices began on February 2, 2025 — six months after the Act entered into force. Enforcement of GPAI model obligations began in August 2025. High-risk AI system requirements began applying in August 2026. Some sector-specific AI obligations linked to existing harmonized standards apply from 2027.

Can a company be fined for using a third-party AI that turns out to be non-compliant?

Deployers of high-risk AI systems have their own obligations under the Act and can face enforcement if they fail to meet them — even if the underlying AI system was provided by a third-party developer. The Act attempts to allocate responsibility proportionally between providers and deployers, but the chain of obligation means that due diligence on AI vendors is now a compliance requirement, not merely a risk management preference.

Is the AI Act's enforcement coordinated across all member states?

The AI Office coordinates cross-border enforcement through the European Artificial Intelligence Board, which includes representatives from national authorities. Where an AI system is deployed in multiple member states and creates a risk, national authorities are required to coordinate their response. Lead authority rules — similar to GDPR's one-stop-shop mechanism — apply in some circumstances for GPAI model providers.

Related reading: EU AI Act: What Businesses Need to Know · EU AI Act Prohibited Practices (August 2026)