Few provisions are misquoted as often as the penalty article of the AI Act. The figures are usually right; the attribution almost never is. This page sets out the catalogue in full — including the obligations for which there is expressly no fine at all.
By Patrick de Kathen, Founder of KlarComply · Reviewed on
Article 99 grades administrative fines by the seriousness of the infringement. Anyone quoting a single number has not read the article.
| Provision | Concerns | Range |
|---|---|---|
| Art. 99(3) | Non-compliance with the prohibition of the AI practices in Article 5 | up to 35 million euros or 7 per cent of total worldwide annual turnover for the preceding financial year |
| Art. 99(4) | Non-compliance with the obligations exhaustively listed there | up to 15 million euros or 3 per cent of total worldwide annual turnover |
| Art. 99(5) | Supplying incorrect, incomplete or misleading information to authorities | up to 7.5 million euros or 1 per cent of total worldwide annual turnover |
In each case the higher of the two figures applies — with one important exception, which follows immediately.
Article 99(6) is explicit: in the case of small and medium-sized enterprises, including start-ups, each fine shall be up to the percentages or amount referred to in paragraphs 3 to 5, whichever thereof is lower.
In practice: a company with five million euros of turnover facing an Article 50 infringement is not looking at a ceiling of 15 million euros. It is looking at 3 per cent — that is, 150,000 euros. That is still a great deal of money. It is a different sentence from the one used in the marketing.
This is the core of the article and the point at which most accounts become imprecise. Paragraph 4 lists exhaustively which obligations carry the range of up to 15 million euros or 3 per cent:
| Point | Provision | Subject matter | Who it binds |
|---|---|---|---|
| a | Art. 16 | Obligations of providers of high-risk systems | providers |
| b | Art. 22 | Obligations of authorised representatives | authorised representatives |
| c | Art. 23 | Obligations of importers | importers |
| d | Art. 24 | Obligations of distributors | distributors |
| e | Art. 26 | Obligations of deployers of high-risk systems | deployers |
| f | Art. 31, 33(1), (3) and (4), Art. 34 | Requirements for notified bodies | notified bodies |
| g | Art. 50 | Transparency obligations for providers and deployers | including ordinary deploying companies |
For a company that uses AI rather than develops it, exactly two points are relevant: e, once a high-risk system is in use, and g for the transparency obligations. Everything else addresses roles along the supply chain that rarely arise in a mid-sized business.
The AI literacy obligation in Article 4 — the one usually described as a training duty — is not named in Article 99(4). The list is exhaustive. For a breach of Article 4 standing alone, the regulation therefore provides no separate administrative fine.
This is not a question of interpretation. It is a matter of reading: the catalogue names Articles 16, 22, 23, 24, 26, 31, 33, 34 and 50. Article 4 is not among them. You can check that in the official text linked at the foot of this page, and we would rather you did.
Anyone advertising “up to 15 million euros for missing AI training” is quoting a range that belongs to other obligations. Why training is nonetheless sensible and legally relevant — through Article 32 GDPR and the directors' duty of care — is set out on the AI literacy obligation.
Two facts are worth stating precisely, because they get merged. Article 4 has applied since 2 February 2025. The Digital Omnibus, in force since July 2026, softened its wording from an obligation to ensure a sufficient level of AI literacy to an obligation to support the development of AI literacy — a duty of effort rather than a duty of result.
Neither change affects the penalty position, because there was never a penalty attached. The softening does not create one and does not remove one. What it does change is the standard against which your effort is measured, and doing nothing at all still does not satisfy a duty of effort.
Article 99(7) names the criteria the authority must take into account. They are the real lever, because they sit between the statutory range and the actual figure:
Two of these are within any company's control: cooperation and the degree of fault. Producing a documented classification, a policy and a training record argues against intent and in favour of cooperation, and both reduce the assessment substantially. That is the practical value of documentation, independent of the statutory ceiling.
The addressee is the company as a legal entity, not the individual. The regulation provides no personal fine against a named AI lead.
Here the picture shifts. Directors owe the company a duty of care — that is the position under the company law of every EU and EEA state, and under the general duty of care recognised for directors in the UK and officers in the US. Allowing AI into the business without setting rules, allocating responsibility and supervising compliance is a failure of organisation. The exposure that follows is internal liability towards the company, and in several jurisdictions it is not covered by the entity's own insurance as a matter of course.
This is worth stating carefully, because it is the point at which marketing material tends to invent things. There is no European statute imposing a personal fine on a director for an AI Act breach. What exists is the ordinary duty of care, applied to a new subject matter — and that is sufficient reason to write things down.
Three errors repeat:
Enforcement sits with the national market surveillance authorities designated by each member state, coordinated at Union level by the European AI Office and the AI Board. Which authority that is varies by country — some have handed it to their telecoms or data protection regulator, others created something new. If you sell into several member states you may deal with more than one. The Commission also runs an AI Act Service Desk as a single entry point for questions, aimed particularly at smaller companies.
One structural point is worth holding on to. The AI Act is a regulation. It applies directly and identically in every member state; there is no national transposition that could diverge from it. Only the designation of the authority and the national procedural rules are a domestic matter. So if somebody tells you the substance differs in their country, ask which provision they mean.
The realistic sequence: an authority does not open with a fine. It opens with a request for information, followed where necessary by an order to remedy with a deadline, and only then by sanctions. Anyone who can deliver at the request-for-information stage is generally through.
Note Article 99(5) while you are there: incorrect, incomplete or misleading information is itself subject to a fine. An unanswered question is better than an invented answer.
Anyone asking about real financial exposure will usually find it somewhere other than Article 99.
| Risk | Basis | Practical frequency |
|---|---|---|
| Lost contracts | a supplier questionnaire you cannot evidence | high — see the AI supplier questionnaire |
| Data protection fine | Art. 83 GDPR, including via Articles 28 and 32 | medium — real enforcement has existed for years |
| Loss of trade secret protection | Directive (EU) 2016/943 | medium — detail here |
| Unfair competition and advertising claims | misleading statements, missing disclosures | rising since August 2026 |
| Product liability | Directive (EU) 2024/2853, transposition due 9 December 2026 | ahead — software and AI count as products |
| Contractual penalties | assurances given in framework agreements | medium — frequently overlooked |
The product liability date deserves a sentence of its own. Directive (EU) 2024/2853 brings software and AI systems within the definition of a product, extends the notion of damage to include destruction or corruption of data, and eases the burden of proof for claimants in technically complex cases. It is a civil liability regime: it does not depend on an authority taking an interest, only on someone suffering damage and bringing a claim.
When somebody quotes you a figure — in a marketing email, a webinar or a proposal — ask these four. They settle the matter in two minutes:
You can put this check to an AI as well. Ask verbatim: “Does Article 99(4) of Regulation (EU) 2024/1689 list Article 4 of that regulation?” The answer is no, and you need neither us nor a consultant to establish it. That we hand you the question is deliberate.
Which of these are still open takes two minutes to establish with the free quick check — no sign-up, and an honest result.
The penalty regime follows the scope regime. Article 2 brings providers and deployers in a third country within the AI Act where the output produced by the AI system is used in the Union, and Article 99 then applies to that activity. Being incorporated in London, Zurich or New York is not a defence, and no EU registration is needed for the duty to apply.
One asymmetry is worth knowing: providers outside the EU that place systems on the EU market must appoint an authorised representative in the Union under Article 22 — and Article 22 is in the catalogue, at point b. Deployers do not carry that duty. If you are unsure which side of the provider/deployer line you sit on, resolve that before anything else, because it changes which points in the catalogue can ever apply to you.
There are three ranges. Prohibited practices under Article 5: up to 35 million euros or 7 per cent of total worldwide annual turnover. The obligations listed exhaustively in Article 99(4), including Article 50: up to 15 million euros or 3 per cent. Incorrect information to authorities: up to 7.5 million euros or 1 per cent.
No. Article 99(4) lists the penalised obligations exhaustively and names Articles 16, 22, 23, 24, 26, 31, 33, 34 and 50. Article 4 is not among them. For a breach of the AI literacy obligation standing alone the regulation provides no separate administrative fine.
Yes. Under Article 99(6), for small and medium-sized enterprises including start-ups, the lower of the two figures applies — the percentage where it comes to less than the absolute amount. At five million euros of turnover that means a ceiling of 150,000 euros for an Article 50 breach rather than 15 million.
Not under the AI Act, which addresses the company. Internally, directors owe the company a duty of care under the company law of every EU and EEA state, and under the equivalent duties recognised in the UK and the US. Allowing AI into the business with no rules, no allocated responsibility and no supervision is a failure of organisation, and the exposure that follows is internal liability towards the company.
Not for Article 4, because there was never a penalty attached to it. The Omnibus softened the wording from ensuring AI literacy to supporting its development, which changes the standard of effort rather than the sanction. It postponed the high-risk obligations to December 2027 and August 2028, and expressly left the 2 August 2026 date for Article 50 untouched.
Realistically it starts with a request for information, followed if needed by an order to remedy with a deadline, and only then are sanctions considered. Anyone who can deliver at the request stage is generally through. Note that incorrect or incomplete information is itself subject to a fine under Article 99(5).
Two: Article 50 on transparency, through point g, and Article 26 on deployer obligations for high-risk systems, through point e. Article 5 sits alongside them with the highest range — in ordinary businesses that mainly means the prohibition on inferring emotions in the workplace.
Not the substance. The AI Act is a regulation and applies directly and identically in every member state; there is no national transposition that could diverge from it. What is national is the designation of the market surveillance authority and the procedural rules it works under.
The free quick check walks through ten points — AI inventory, training status, transparency duties, responsibilities. Two minutes, no sign-up, an honest result and your concrete gaps.
Start the quick check — free