The AI Act penalties. The numbers that circulate are the maximums, and for an SME the rule is reversed.
Thirty-five million euros is the figure seen in every article and every course advert. It is a theoretical maximum tied to prohibited practices, and the regulation contains a line that, for small businesses, reverses the calculation criterion.
There are three bands, in Article 99: up to 35 million or 7% for prohibited practices, up to 15 million or 3% for a list of obligations, up to 7.5 million or 1% for misleading information to authorities.
For SMEs the lower amount applies between the fixed figure and the percentage, not the higher. It is paragraph 6, and it applies to all three bands.
The amount is set on ten criteria, including cooperation, self-reporting and measures already adopted. The statutory maximum isn't the starting point of the calculation.
In Italy the picture isn't complete. Supervision lies with ACN, but the decrees giving it penalty powers are expected by 10 October 2026.
This piece sits within the guide to the AI Act obligations for companies and SMEs and looks more closely at its penalty regime. It is written for whoever runs a business, and it ends where a lawyer's work begins.
The three bands of Article 99
The regulation distinguishes by gravity, and the gap between the highest and the lowest band is almost fivefold. Each band indicates a ceiling, not an amount due.
| Band | What it punishes | Ceiling |
|---|---|---|
| Prohibited practicesArticle 99(3) | Non-compliance with the prohibition of the practices in Article 5, that is, conduct no organisational measure makes admissible. |
€35 million or 7% of total worldwide annual turnover, whichever is higher |
| Operators' obligationsArticle 99(4) | A closed list: obligations of providers (Article 16), authorised representatives (22), importers (23), distributors (24), deployers (26), notified bodies (31, 33 and 34) and transparency (50). |
€15 million or 3%, whichever is higher |
| Misleading informationArticle 99(5) | Supplying incorrect, incomplete or misleading information to notified bodies or national competent authorities in reply to a request. |
€7.5 million or 1%, whichever is higher |
The middle band is the one that affects an ordinary business, because it contains the deployer's obligations and transparency. The first concerns conduct an SME normally doesn't engage in, and the third is triggered only after an authority has already come knocking.
The line that reverses the calculation for small businesses
It is paragraph 6, and it is very rarely cited. In the case of SMEs, including start-ups, each fine is up to the percentages or amount indicated in paragraphs 3, 4 and 5, whichever is lower.
«In the case of SMEs, including start-ups, each fine referred to in this Article shall be up to the percentages or amount referred to in paragraphs 3, 4 and 5, whichever thereof is lower.»
Regulation (EU) 2024/1689, Article 99(6)
For all other operators the criterion is the opposite: the higher of the fixed figure and the percentage applies. For a company with a turnover of ten million, the difference between the two criteria, in the middle band, lies between three hundred thousand euros and fifteen million.
There is also a second protection, in paragraph 1: when laying down their own penalty rules, Member States must take into account the interests of SMEs, including start-ups, and their economic viability. It is a directive addressed to the national legislator, and in Italy that legislator hasn't written the rule yet.
The ten criteria used to reach a figure
Paragraph 7 lists the circumstances to consider when deciding whether to impose a fine and when setting its amount. The mere existence of that list says the statutory maximum is a ceiling, and that the path to reach it is long.
Among the criteria: the nature, gravity and duration of the infringement, with the number of people affected and the level of damage; fines already imposed by other authorities for the same infringement; the size, turnover and market share of the operator; the financial benefits gained or losses avoided.
Four criteria reward the company's behaviour, and those are the ones you can work on before anything happens: the degree of cooperation with the authorities, the degree of responsibility taking into account the technical and organisational measures implemented, the manner in which the authority became aware of the infringement and whether the operator notified it, and the intentional or negligent character.
In other words: a list of the systems in use, a record of training initiatives and a documented human approval step aren't formalities. They are exactly what paragraph 7 asks to be looked at.
The penalties the Commission imposes
Alongside the national authorities there is a direct European channel, which concerns model providers. Article 101 allows the Commission to impose on providers of general-purpose AI models fines of up to 3% of worldwide annual turnover or €15 million, whichever is higher.
The conditions are four: having infringed the relevant provisions of the regulation, having failed to comply with a request for documents or information, having failed to comply with a requested measure, or having failed to give access to the model for an evaluation. Intent or negligence is required.
For an Italian business that channel isn't a risk, it is information about the market: the providers of the models you use answer directly to the Commission, and Article 100 provides a similar mechanism, entrusted to the European Data Protection Supervisor, for Union institutions.
What isn't on the list
The list in paragraph 4 is closed and names specific articles. Some important obligations aren't there, and the most relevant case for a small business is Article 4 on staff literacy, which stays outside that band.
That doesn't mean the obligation has no consequences. Paragraph 1 of the same Article 99 leaves Member States to lay down the rules on penalties and other enforcement measures, which may also include warnings and non-monetary measures, and requires them to be effective, proportionate and dissuasive.
The practical point is that for those obligations the answer comes from national law, not from a European figure already written. Anyone giving you a precise amount for missed training is citing a rule that, in that form, doesn't exist.
Two frameworks that can add up
The AI Act doesn't replace the data protection penalty regime. The GDPR, in Article 83, goes up to €10 million or 2% of worldwide annual turnover for some infringements, and up to €20 million or 4% for the most serious, including those on the basic principles of processing and the conditions for consent.
The authorities are different and so are the conditions, as the page on AI Act and GDPR explains: in Italy the Data Protection Authority acts on data processing, ACN on the AI Act. The same matter can touch both levels, for example an undisclosed assistant processing customer data without a legal basis.
The regulation takes the risk of duplication into account. Point (b) of paragraph 7 asks to consider whether other market surveillance authorities have already applied fines to the same operator for the same infringement, and point (c) extends the reasoning to infringements of other rules arising from the same conduct.
Who can impose penalties in Italy, today
Article 20 of Law 132/2025 designates AgID and ACN as the National Authorities for artificial intelligence, and gives ACN supervision, including inspection and penalty activities. The powers of the Bank of Italy, CONSOB and IVASS as market surveillance authorities in their respective sectors remain unaffected.
The picture isn't complete, though. Article 24 delegates to the Government the adoption of the legislative decrees giving those authorities all the supervisory, inspection and penalty powers provided for by the regulation, within twelve months of the law's entry into force, that is, by 10 October 2026.
The honest reading is that the European obligations are in full force while the Italian penalty framework is under construction, and that this window is closing. The full calendar of deadlines keeps the two sequences, European and Italian, together.
The realistic risk, and what reduces it
For an ordinary business the concrete danger is very far from the statutory maximum, and it takes one form only: a complaint from a customer, a candidate or an employee that opens an investigation. From that moment only two things count, and both are about documents.
The first is what you can show: which systems run, who uses them, what has been explained to people, which disclosures are on the page, who approves before a message goes out. The second is when you wrote it, because a document dated before the incident weighs differently from one produced afterwards.
In the systems we build that record is born together with the system: every message that commits the company, that is, offers, quotes, prices and confirmations, goes out only after a person has read and approved it. Replies on information already approved by the owner can go out on their own, the owner switches the function on and off channel by channel, and the reply states that it is a system as Article 50 requires, applicable from 2 August 2026.
The extended scope, with what we never do, is in the AI principles, and the list of systems we actually use is on the AI transparency page.
Questions and answers
What are the AI Act penalties?
Article 99 provides three bands. Up to €35 million or 7% of total worldwide annual turnover for breach of the prohibitions of Article 5. Up to €15 million or 3% for a closed list of obligations, including those of providers (Article 16), deployers (Article 26) and transparency (Article 50).
Up to €7.5 million or 1% for supplying incorrect, incomplete or misleading information to the authorities. They are ceilings, not automatic amounts.
Do SMEs pay as much as large companies?
No. Paragraph 6 establishes that for SMEs, including start-ups, each fine is up to the percentages or amount of paragraphs 3, 4 and 5, whichever is lower. For everyone else the opposite criterion applies, that is, the higher of the fixed figure and the percentage.
Paragraph 1 adds that Member States, when writing the national rules, must take into account the interests of SMEs and their economic viability.
Who can apply them in Italy?
Article 20 of Law 132/2025 designates AgID and ACN, and gives ACN supervision, including inspection and penalty activities. The powers of the Bank of Italy, CONSOB and IVASS in their respective sectors remain unaffected.
The picture isn't complete: Article 24 delegates to the Government the assignment of those powers by legislative decree by 10 October 2026. Until then the Italian penalty framework remains under construction, while the European obligations are in full force.
How is the amount decided?
Paragraph 7 lists ten circumstances: nature, gravity and duration of the infringement with the number of people affected; fines already imposed by other authorities; size, turnover and market share; benefits gained or losses avoided; degree of cooperation; technical and organisational measures implemented; how the authority learned of the infringement and whether the operator notified it; intentional or negligent character; actions to mitigate the harm.
Four of these reward what a company does before anything happens.
Can the AI Act and the GDPR penalise the same fact?
They are separate frameworks punishing different things, and both can be triggered. The GDPR (Article 83) goes up to 10 million or 2% and, for the most serious infringements, to 20 million or 4%. The AI Act goes up to 35 million or 7% for prohibited practices.
The authorities are different: in Italy the Data Protection Authority on data processing, ACN on the AI Act. Paragraph 7, point (b), however, asks for fines already imposed by other authorities for the same infringement to be considered.
Notes on sources
- Regulation (EU) 2024/1689 (AI Act), EUR-Lex: Article 99 for the three bands, the closed list in paragraph 4, the SME rule in paragraph 6 and the ten criteria in paragraph 7; Article 100 for Union institutions; Article 101 for providers of general-purpose models.
- Regulation (EU) 2016/679 (GDPR), EUR-Lex: Article 83(4) and (5), for the two bands of 10 million or 2% and 20 million or 4%.
- Law No 132 of 23 September 2025, Italian Official Gazette No 223 of 25 September 2025: Article 20 on the national authorities and the powers of the Bank of Italy, CONSOB and IVASS; Article 24 on the delegation and penalty powers.
- This page doesn't give an amount for breach of Article 4, because that article doesn't appear in the closed list of paragraph 4 and the consequence depends on national rules Italy has yet to adopt. When a figure doesn't exist, it isn't estimated.
- The calculation examples in the text are built to explain the difference between the two criteria, and don't describe a real case or a penalty actually imposed.
This article is an operational overview, not a legal opinion. On a concrete dispute, or on how to reply to a request from an authority, the answer comes from a professional who looks at your company.
Four criteria out of ten reward what you did beforehand.
The list of systems, the training record and the human approval step are half a day's documents, and they are exactly what Article 99 asks to be looked at when setting an amount. Those documents only count, however, if they carry a date before the problem, and a date can't be added after the fact. It is fifteen minutes on a call, with the Cruscotto open.