AI Act penalties. The figures you see quoted are maximums, and for an SME the rule is reversed.
Thirty-five million euros is the figure you see in every article and every course advert. It's a theoretical maximum tied to prohibited practices, and the regulation has one line that turns the calculation round for small businesses.
There are three bands, in Article 99: up to €35 million or 7% for prohibited practices, up to €15 million or 3% for a list of obligations, up to €7.5 million or 1% for misleading information given to the authorities.
For SMEs the lower amount applies, whichever is lower of the fixed figure and the percentage, not the higher. That's paragraph 6, and it covers all three bands.
The amount is set on ten criteria, including cooperation, self-reporting and measures already taken. The statutory maximum isn't where the calculation starts.
In Italy the framework isn't complete. Supervision sits with ACN, but the decrees giving it enforcement powers are due by 10 October 2026.
This piece belongs to the guide on AI Act obligations for businesses and SMEs and looks more closely at the penalty regime. It's written for people running a business, and it stops where a lawyer's work begins.
The three bands in Article 99
The regulation grades by seriousness, and the top band is almost five times the bottom one. Each band sets a ceiling, not an amount owed.
| Band | What it punishes | Ceiling |
|---|---|---|
| Prohibited practicesArticle 99(3) | Failing to comply with the ban on the practices in Article 5: conduct that no organisational measure can make acceptable. |
€35 million or 7% of total worldwide annual turnover, whichever is higher |
| Operator obligationsArticle 99(4) | A closed list: obligations of providers (Article 16), authorised representatives (22), importers (23), distributors (24), deployers (26), notified bodies (31, 33 and 34), and transparency (50). |
€15 million or 3%, whichever is higher |
| Misleading informationArticle 99(5) | Supplying incorrect, incomplete or misleading information to notified bodies or national competent authorities in reply to a request. |
€7.5 million or 1%, whichever is higher |
The middle band is the one that reaches an ordinary business, because it holds the deployer obligations and transparency. The first covers conduct an SME wouldn't normally engage in, and the third only comes into play once an authority has already knocked on the door.
The line that turns the calculation round for small businesses
It's paragraph 6, and it's very rarely quoted. For SMEs, including start-ups, each fine is capped at the percentages or amount set in paragraphs 3, 4 and 5, whichever is lower.
“In the case of SMEs, including start-ups, each fine referred to in this Article shall be up to the percentages or amount referred to in paragraphs 3, 4 and 5, whichever thereof is lower.”
Regulation (EU) 2024/1689, Article 99(6)
For every other operator the rule is the opposite: the higher of the fixed figure and the percentage applies. For a business turning over €10 million, the gap between the two rules in the middle band is the gap between €300,000 and €15 million.
There's a second safeguard too, in paragraph 1: when Member States set their own penalty rules, they must take into account the interests of SMEs, including start-ups, and their economic viability. It's an instruction to the national legislator, and in Italy that legislator hasn't written the rule yet.
The ten criteria that lead to a figure
Paragraph 7 lists the circumstances to consider when deciding whether to impose a fine and how much it should be. The mere existence of that list tells you the statutory maximum is a ceiling, and that the road to it is long.
The criteria include: the nature, gravity and duration of the infringement, with the number of people affected and the level of damage; fines already imposed by other authorities for the same conduct; the operator's size, turnover and market share; financial benefits gained or losses avoided.
Four criteria reward the business's own behaviour, and those are the ones you can work on before anything happens: the degree of cooperation with the authorities, the degree of responsibility, taking into account the technical and organisational measures in place, how the authority became aware of the infringement and whether the operator reported it itself, and whether it was intentional or negligent.
In plain terms: a list of the systems in use, a record of training initiatives and a documented human approval step aren't box-ticking. They are exactly what paragraph 7 asks the authority to look at.
The fines the Commission imposes
Alongside the national authorities there's a direct European channel, aimed at model providers. Article 101 allows the Commission to fine providers of general-purpose AI models up to 3% of worldwide annual turnover or €15 million, whichever is higher.
There are four grounds: infringing the relevant provisions of the regulation, failing to comply with a request for documents or information, failing to comply with a requested measure, or failing to give access to the model for an evaluation. Intent or negligence is required.
For an Italian business that channel isn't a risk, it's market intelligence: the providers of the models you use answer directly to the Commission, and Article 100 sets up a similar mechanism for EU institutions, run by the European Data Protection Supervisor.
What isn't on the list
The list in paragraph 4 is closed and names specific articles. Some important obligations aren't on it, and the most relevant for a small business is Article 4 on staff AI literacy, which stays outside that band.
That doesn't mean the obligation has no consequences. Paragraph 1 of the same Article 99 leaves it to Member States to set the rules on penalties and other enforcement measures, which can include warnings and non-monetary measures, and requires them to be effective, proportionate and dissuasive.
The practical point is that for those obligations the answer comes from national law, not from a European figure already on the books. Anyone quoting you a precise amount for missing training is citing a rule that, in that form, doesn't exist.
Two frameworks that can add up
The AI Act doesn't replace the data protection penalty regime. The GDPR, in Article 83, goes up to €10 million or 2% of worldwide annual turnover for some infringements, and up to €20 million or 4% for the most serious, including those on the basic principles of processing and the conditions for consent.
The authorities are different and so are the grounds, as the page on the AI Act and the GDPR explains: in Italy the Garante acts on data processing, ACN on the AI Act. The same case can touch both, for example an undisclosed assistant processing customer data without a legal basis.
The regulation allows for the risk of double punishment. Point (b) of paragraph 7 asks whether other market surveillance authorities have already imposed fines on the same operator for the same infringement, and point (c) extends that reasoning to infringements of other laws arising from the same conduct.
Who can impose penalties in Italy today
Article 20 of Law 132/2025 designates AgID and ACN as the national authorities for artificial intelligence, and gives ACN the supervisory role, including inspections and penalties. The Bank of Italy, CONSOB and IVASS keep their powers as market surveillance authorities in their own sectors.
But the framework isn't complete. Article 24 empowers the Government to adopt the legislative decrees giving those authorities all the supervisory, inspection and enforcement powers the regulation provides for, within twelve months of the law coming into force: by 10 October 2026.
The honest reading is that the European obligations apply in full while Italy's penalty framework is still being built, and that window is closing. The full timeline of deadlines puts the two sequences, European and Italian, side by side.
The realistic risk, and what reduces it
For an ordinary business the real danger is a long way from the statutory maximum, and it takes one form: a complaint from a customer, a job applicant or an employee that opens an investigation. From that point on only two things count, and both are on paper.
The first is what you can show: which systems run, who uses them, what people have been told, which disclosures are on the page, who approves a message before it goes out. The second is when you wrote it down, because a document dated before the incident carries a different weight from one produced afterwards.
In the systems we build, that record is created along with the system: any message that commits the business, such as offers, quotes, prices and confirmations, goes out only after a person has read and approved it. Replies drawing on information the owner has already approved can go out on their own, the owner switches that on and off channel by channel, and the reply says it comes from a system, as Article 50 requires from 2 August 2026.
The full scope, including what we never do, is in our AI principles, and the list of systems we actually use is on the AI transparency page.
Questions and answers
What are the AI Act penalties?
Article 99 sets three bands. Up to €35 million or 7% of total worldwide annual turnover for breaching the prohibitions in Article 5. Up to €15 million or 3% for a closed list of obligations, including those of providers (Article 16), deployers (Article 26) and transparency (Article 50).
Up to €7.5 million or 1% for supplying incorrect, incomplete or misleading information to the authorities. These are ceilings, not automatic amounts.
Do SMEs pay as much as large companies?
No. Paragraph 6 says that for SMEs, including start-ups, each fine is capped at the percentages or amount in paragraphs 3, 4 and 5, whichever is lower. For everyone else the opposite rule applies: the higher of the fixed figure and the percentage.
Paragraph 1 adds that Member States, when writing national rules, must take into account the interests of SMEs and their economic viability.
Who can impose them in Italy?
Article 20 of Law 132/2025 designates AgID and ACN, and gives ACN the supervisory role, including inspections and penalties. The Bank of Italy, CONSOB and IVASS keep their powers in their own sectors.
The framework isn't complete: Article 24 empowers the Government to assign those powers through legislative decrees by 10 October 2026. Until then Italy's penalty framework is still being built, while the European obligations apply in full.
How is the amount decided?
Paragraph 7 lists ten circumstances: the nature, gravity and duration of the infringement, with the number of people affected; fines already imposed by other authorities; size, turnover and market share; benefits gained or losses avoided; the degree of cooperation; the technical and organisational measures in place; how the authority found out about the infringement and whether the operator reported it; whether it was intentional or negligent; action taken to mitigate the damage.
Four of these reward what a business does before anything happens.
Can the AI Act and the GDPR penalise the same thing?
They are separate frameworks punishing different things, and both can apply. The GDPR (Article 83) goes up to €10 million or 2% and, for the most serious infringements, €20 million or 4%. The AI Act goes up to €35 million or 7% for prohibited practices.
The authorities are different: in Italy, the Garante on data processing and ACN on the AI Act. Paragraph 7(b), however, asks for fines already imposed by other authorities for the same infringement to be taken into account.
Notes on sources
- Regulation (EU) 2024/1689 (AI Act), EUR-Lex: Article 99 for the three bands, the closed list in paragraph 4, the SME rule in paragraph 6 and the ten criteria in paragraph 7; Article 100 for EU institutions; Article 101 for providers of general-purpose models.
- Regulation (EU) 2016/679 (GDPR), EUR-Lex: Article 83(4) and (5), for the two bands of €10 million or 2% and €20 million or 4%.
- Law no. 132 of 23 September 2025, Gazzetta Ufficiale no. 223 of 25 September 2025 (in Italian): Article 20 on the national authorities and the powers of the Bank of Italy, CONSOB and IVASS; Article 24 on the delegated power and enforcement powers.
- This page gives no amount for breaching Article 4, because that article isn't on the closed list in paragraph 4, and the consequence depends on national rules Italy has yet to adopt. When a figure doesn't exist, we don't estimate one.
- The worked examples in the text are there to explain the difference between the two rules, and don't describe a real case or a fine actually imposed.
This article is a practical overview, not legal advice. On an actual investigation, or how to respond to a request from an authority, the answer has to come from a professional who looks at your business.
Four criteria out of ten reward what you did beforehand.
The list of systems, the training record and the human approval step take half a day to document, and they are exactly what Article 99 asks the authority to look at when it sets an amount. But those documents only count if they're dated before the problem, and a date can't be added after the fact. It's fifteen minutes on a call, with the Cruscotto open.