
Image AI-generated. All text human-written.
For years, AI governance sat comfortably inside IT and data science teams, treated as a technical checklist rather than a strategic risk. The EU AI Act has changed that equation permanently. With fines that can exceed even GDPR’s ceiling, non-compliance is no longer a line item buried in a compliance report — it’s a liability that boards, investors, and executive teams now have to actively manage.
The Fine Structure: Three Tiers, One Simple Rule
The EU AI Act enforces penalties under Article 99, using a three-tier structure. Each tier sets both a fixed euro cap and a percentage of global annual turnover — and regulators apply whichever figure is higher (with one key exception for smaller companies, covered below).
Tier 1 — Prohibited AI Practices: up to €35 million or 7% of global turnover This is the most severe tier, reserved for AI systems banned outright under Article 5. It covers things like social scoring, manipulative AI systems that exploit vulnerabilities, and unauthorized real-time biometric identification in public spaces. Notably, this 7% ceiling exceeds GDPR’s maximum of 4%, making it one of the strictest data-and-technology penalty regimes in the world.
Tier 2 — High-Risk AI Violations: up to €15 million or 3% of global turnover This tier applies to breaches involving high-risk AI systems — those used in areas like credit scoring, employment decisions, critical infrastructure, or essential public services. Violations here typically involve missing conformity assessments, inadequate human oversight, or gaps in required technical documentation.
Tier 3 — Misleading Information: up to €7.5 million or 1% of global turnover The lightest tier still carries real weight. It applies when a company provides incorrect, incomplete, or misleading information to regulators or notified bodies during an assessment or investigation.
In every tier, the percentage is calculated on worldwide turnover — not just EU revenue — meaning companies headquartered outside the EU are not shielded simply because most of their business happens elsewhere. There’s also a notable twist for smaller companies: under Article 99(6), SMEs and startups get the lower of the two figures (fixed cap or percentage) rather than the higher one that applies to larger firms.
Why Fines Are Rarely the First Consequence
The headline numbers are attention-grabbing, but in practice, financial penalties tend to be the last domino to fall, not the first. Before a fine ever lands, companies are far more likely to face:
- Product withdrawal — Regulators can order non-compliant AI systems pulled from the market before any monetary penalty is assessed.
- Procurement exclusion — Public sector clients and larger enterprise buyers increasingly require AI Act compliance as a condition of doing business, meaning non-compliance can quietly cost contracts long before it costs a fine.
- Regulatory investigations — An open investigation alone can consume months of legal and operational resources, regardless of its outcome.
- Investor scrutiny — As AI governance becomes a standard part of due diligence, unresolved compliance gaps are increasingly treated as material risk in funding and M&A conversations.
These consequences compound. A procurement exclusion can trigger investor questions, which can trigger a broader governance review, which can surface the very gaps that invite regulatory attention in the first place.
From Technical Checklist to Board-Level Risk
The scale of these penalties — and the operational disruption that precedes them — is why AI governance has moved up the org chart. It’s no longer sufficient for a data science or engineering team to own compliance quietly in the background. Boards are increasingly expected to understand:
- Which AI systems the company builds, deploys, or procures fall under “high-risk” or “prohibited” classifications
- What documentation, risk management, and human oversight structures are already in place
- How exposure scales with the company’s global turnover, not just its EU footprint
Enforcement of prohibited-practice rules has already been active since February 2025, and general-purpose AI model obligations followed in August 2025, meaning the compliance clock isn’t a future concern — it’s already running.
The Takeaway
The EU AI Act didn’t just introduce fines; it introduced a new category of enterprise risk that sits alongside financial, cybersecurity, and regulatory risk on the board’s agenda. Companies that treat AI governance as a one-time technical audit are missing the point. The real cost of non-compliance shows up long before a fine does — in lost contracts, stalled products, and investor doubt.
EU AI Act Compliance Disclaimer
This article is provided for general informational and educational purposes only and should not be considered legal, regulatory, or compliance advice. The EU AI Act is evolving, and its requirements can vary depending on the organisation, AI system, role, and specific use case. For professional advice and guidance on EU AI Act compliance, visit www.exclevelai.eu.