EU AI Act enforcement fines 2026: what is confirmed?

Which companies are actually getting fined, and which headlines are recycling penalty ceilings? EU AI Act enforcement fines 2026 require a decision ledger, not a list of familiar AI vendors. The primary sources reviewed for this article on 5 October establish enforcement powers, applicable obligations and maximum penalties. They do not establish a named-company register of 2026 AI Act fines. That is a limit of this review, not proof that no authority has imposed a penalty.

The distinction matters because the timetable changed. The Commission says enforcement began on 2 August 2026, but the July AI Omnibus amendment moved Annex III high-risk rules to December 2027 and product-embedded high-risk rules to August 2028. A fine story resting solely on the old high-risk deadline needs checking. This analysis separates actual decisions from statutory exposure, maps the responsible authorities, and proposes an evidence packet for engineering teams. For the broader jurisdictional picture, start with our AI regulation overview. Here the narrower question is what the fetched enforcement record actually supports.

EU AI Act compliance timeline: 2026 enforcement, 2027 legacy GPAI and Annex III, 2028 product rules
Original AI-generated AI Made diagram based on the cited Commission guidance. Selected application dates; exceptions and grace periods are discussed in the article.

EU AI Act enforcement fines 2026: what can be verified

Our admission rule for a confirmed fine is straightforward: identify the sanctioned legal entity, the deciding authority, the decision date, the legal basis, the amount, and the procedural status. A regulator’s decision or an official notice tied to that decision qualifies. An anonymous industry recap without a docket does not. This is an editorial evidence threshold, not a claim that every authority publishes decisions in an identical format.

The Commission’s enforcement framework explains when it may adopt a penalty decision. The July announcement explains when enforcement begins. Neither document is itself a penalty against a company. A maximum expressed as “up to” is exposure, not an invoice; an information request is an investigative step, not a finding of infringement. Those distinctions follow the investigative and sanctioning stages described in the official enforcement framework.

Accordingly, this article does not attach an AI Act fine to OpenAI, Anthropic, Google or any other model provider without an identified primary decision. It also does not promote circulating anonymous hiring, lending or retail cases into confirmed sanctions. Their absence from this article means the verification threshold was not met; it says nothing definitive about confidential investigations or unpublished national activity. The review covers the ten primary documents cited here, not an exhaustive multilingual search of every Member State’s decisions.

There is a useful historical control. CNIL’s October 2022 newsletter records a €20 million sanction against Clearview AI and an instruction to stop collecting and using data about people in France without a legal basis. That dated record cannot become a 2026 AI Act penalty merely because the conduct involves AI. The Commission dates the AI Act’s entry into force to August 2024 in its overview. Match the decision date and legal instrument before putting a historic privacy sanction into a new-law total.

A maintenance ledger should therefore have separate fields for alleged conduct, applicable provision, investigation, preliminary findings, final decision and appeal. Never encode all six as one “enforcement” Boolean. Our AI safety decisions analysis uses the same underlying discipline: the document’s legal effect matters more than the headline’s urgency.

The dates changed; the old August checklist is stale

The Commission’s AI Omnibus announcement says the amendment entered into force on 27 July 2026. It lists two extended application dates: 2 December 2027 for high-risk systems in Annex III, and 2 August 2028 for high-risk AI embedded in regulated physical products in Annex I. Its enforcement page repeats those dates. This is no longer just a proposal to delay obligations; the fetched official announcement describes an amendment in force. Use the current amendment announcement, not a pre-amendment slide deck.

That does not postpone everything. The Commission’s overview says the original eight categories of prohibited practices became effective in February 2025. Its GPAI guidelines distinguish application of provider obligations from 2 August 2025, Commission enforcement from 2 August 2026, and the compliance date of 2 August 2027 for GPAI models placed on the market before 2 August 2025. Different product histories can therefore produce different obligations within one corporate group. The GPAI provider guidance makes this split explicit.

Article 50 transparency obligations apply from 2 August 2026. The Commission FAQ describes a limited marking-and-detection grace period to 2 December 2026 for systems placed on the market before the August date. It does not describe a general holiday for all transparency obligations. It also says content generated before 2 August need not be labelled retroactively. A deployment register needs the system’s market-placement date and the content’s generation date, not simply a release year.

The resulting engineering task is a versioned obligation map. Record the system, the intended purpose, your role, the market-placement date, the applicable provision and its application date. Then review those fields when the system changes. A recruiting product can be in a future high-risk compliance workstream while a public chatbot already faces current transparency obligations. The Commission’s risk-based overview separates those categories; do not flatten them into one August deadline. This is technical planning guidance, not a substitute for a legal assessment of a specific deployment.

Three penalty ceilings, two important size exceptions

Article 99 sets national-enforcement ceilings, not a fixed tariff for every AI incident. Paragraph 3 provides up to €35 million or 7% of the undertaking’s worldwide annual turnover in the preceding financial year, whichever is higher, for prohibited practices under Article 5. Paragraph 4 provides up to €15 million or 3% for its listed obligations, including Article 50 transparency. Paragraph 5 provides up to €7.5 million or 1% for incorrect, incomplete or misleading information supplied in reply to specified requests. The updated Article 99 text is the relevant source for these bands.

The size exceptions need their own line. For SMEs, including start-ups, paragraph 6 uses the lower percentage-or-amount limb for the fines under that article. The new paragraph 6a extends the lower-limb treatment to small mid-cap companies for paragraphs 4 and 5. It does not say the same thing for paragraph 3’s prohibited-practice band. “Every smaller company always gets the lower figure” is therefore too broad even before assessing whether an enterprise qualifies for the category.

GPAI provider penalties have a separate route. Article 101 allows the Commission to impose fines not exceeding 3% of worldwide annual turnover in the preceding financial year or €15 million, whichever is higher, for the specified intentional or negligent infringements. It includes failures to comply with document, information, measures or model-access requests. Do not transplant Article 99’s SME wording into Article 101 without checking the governing provision. The Article 101 text also requires preliminary findings and an opportunity for the provider to be heard.

Actual amounts depend on the case. Article 99 lists circumstances including the infringement’s nature, gravity and duration, affected people, cooperation and mitigation. Article 101 likewise invokes proportionality and appropriateness. A financial exposure model should retain those uncertainties rather than treat the maximum as an expected loss. For a board presentation, put “statutory ceiling” above the number and “confirmed decision amount” in a different column. If the second column is unsupported, leave it blank.

Which authority can investigate your system

The current enforcement framework allocates GPAI models to the AI Office. It also gives the Office specified AI-system responsibilities: systems developed by the underlying GPAI model provider or a provider within the same business group, and systems integrated into designated very large online platforms or search engines. Other AI systems fall to national competent authorities. The European Data Protection Supervisor handles AI systems used by EU institutions. This is an authority map, not evidence that any named company has already been sanctioned.

For investigations, the framework distinguishes a simple request for information from one issued by Commission decision. Incorrect or misleading replies to simple requests can attract fines; for decision-based requests, failure to reply or incomplete replies can also do so. The Office can require model access for evaluations and request measures, including restrictions on model availability. Those powers make a searchable documentation trail an operational concern even before a penalty decision exists.

Our recommendation is to route regulatory requests through a named owner who can preserve the original request, identify its legal basis, and coordinate a checked response. Keep the production version and the response version connected. Do not let one team export current evaluation scores while another supplies documentation for a retired checkpoint. That proposed control is an engineering response to the documented information and evaluation powers, not a universal regulator-prescribed implementation.

Our AI readiness assessment is useful for assigning ownership and escalation paths. For this narrower exercise, the acceptance test is whether a team can retrieve evidence about the relevant version without inventing a narrative after the request arrives. A neatly branded governance page is not evidence that the underlying files are complete.

GPAI obligations are not a blanket rule for every wrapper

The GPAI scope guidance says significant modifications can bring modified-model providers within the obligations, while minor changes do not automatically do so. It also describes conditional open-source exemptions from certain obligations. Neither statement supports treating every prompt wrapper as a foundation-model provider, nor assuming that an open-weight licence removes every responsibility. Establish whether you provide a model, provide a system, deploy a system, or combine roles.

The GPAI Code of Practice has three chapters: Transparency, Copyright, and Safety and Security. The first two provide a route for demonstrating Article 53 compliance. Safety and Security addresses the most advanced models with systemic risk under Article 55. The Commission says the code is voluntary; providers can demonstrate compliance through other adequate means. A code signature is not itself a penalty decision or an immunity certificate.

The official code page lists providers including Anthropic, Google, Microsoft, Mistral AI and OpenAI as signatories. It separately says xAI signed the Safety and Security chapter and must demonstrate transparency and copyright compliance through alternative adequate means. That difference can inform a supplier-documentation request. It cannot be converted into a finding that xAI violated the Act or paid a fine. Check the code’s actual chapters and signatory statement.

For a downstream team, request documentation that matches the model you actually consume and record its limitations. Keep your system-level assessment separate from the upstream provider’s model-level obligations. Our AI and copyright analysis supplies adjacent context, but training-data copyright policy and output labelling are different compliance questions. One vendor PDF should not be used to answer both by default.

Transparency is a product requirement, not a footer

The Commission’s Article 50 FAQ distinguishes several responsibilities: informing people about direct AI interaction, machine-readable marking of generated outputs, notification around emotion recognition or biometric categorisation, and disclosure of deepfakes or specified public-interest text. The same page says direct-interaction notices should be clear, distinguishable and available from the start of the first interaction, subject to the stated exception when the AI nature is obvious. A notice hidden behind several navigation steps is not a sound default design.

For deepfakes, the FAQ says deployers cannot rely solely on the provider’s machine-readable marks to satisfy human-facing disclosure. That is an important integration boundary. Our suggested test is to follow an asset through generation, storage, transformation and publication, checking both the machine-readable provenance mechanism and the visible or audible disclosure. A screenshot of a watermark setting does not show whether the delivered asset retains it.

For AI-generated public-interest text, the FAQ describes an exception where substantive human review or editorial control and editorial responsibility apply. It explicitly excludes superficial spelling or grammar checks from the meaning of human review or editorial control. An automated QA pass is not a natural person exercising professional judgement. A publication using automated drafting should either provide the appropriate disclosure or establish the actual review and responsibility arrangement; it should not silently claim human review because software checked the copy.

The implementation recommendation here is a release checklist with a captured first-interaction notice, a provenance test and a publication disclosure decision. Record exceptions with reasoning rather than embedding them as undocumented defaults. The legal scope, exceptions and grace-period limits remain those in the Commission’s Article 50 FAQ. This article and its diagrams are AI-generated editorial material, not representations of human legal review.

Build an evidence packet before a regulator asks

The practical deliverable is a packet that explains what you ship, what obligations you believe apply, and what evidence supports that assessment. We propose six components: a system-and-role inventory; a dated obligation map; supplier documentation for the exact model version; transparency test results; a limitations and incident record; and a decision log naming the accountable owner. These are our engineering recommendations. They are not a claim that those six filenames constitute a legally sufficient compliance package.

Version the packet with the release. Record what changed in prompts, tools, retrieval, models and intended purpose, then decide which tests or assessments require repeating. Avoid retaining unnecessary personal data merely to make the packet look comprehensive. A hash of an evaluation artifact plus its controlled storage location can help with traceability, but a hash alone does not prove that a claim in the artifact is true.

Use a tabletop exercise rather than a marketing score. Ask a colleague to request the intended purpose of the deployed system, the basis for its role classification, the current disclosure path, and the documentation underlying one performance claim. Track missing files and inconsistent versions as remediation items. Do not report the exercise as a regulator audit or a conformity assessment. Our agent safety evaluation framework offers a related way to organise behavioural evidence.

The point is not to replace legal analysis with YAML. It is to make legal analysis and technical implementation inspectable together. A counsel-approved interpretation without an implemented disclosure is incomplete engineering work; a deployed control without a documented reason can be hard to explain. Keep the fine ledger separate from this packet so an unverified news item never becomes the assumed legal basis for a product change.

What to do next: update the ledger, not the panic

Which companies have confirmed EU AI Act fines in 2026?

The primary documents reviewed here do not establish a named-company list. That is a bounded verification result, not proof that no fines exist. Require an identified authority decision before adding a company or amount to a confirmed-fines ledger.

What is the maximum fine under the EU AI Act?

Article 99 provides a prohibited-practice ceiling of €35 million or 7% of worldwide annual turnover, generally using the higher limb. Other bands, SME and SMC rules, and the separate Article 101 GPAI route differ. A maximum is not the amount of a confirmed sanction.

Did all high-risk AI rules start in August 2026?

No. The Commission’s July amendment announcement sets 2 December 2027 for Annex III high-risk systems and 2 August 2028 for high-risk AI embedded in Annex I regulated products. Current transparency and GPAI enforcement dates are separate.

Does signing a code of practice remove liability?

No. The GPAI code is a voluntary route for demonstrating compliance. A signature is neither proof of every implementation detail nor a finding of infringement. Providers using other adequate means still need to demonstrate compliance.

The next step is concrete: refresh the obligation map from the current official timeline, test the disclosure path of one deployed system, and assemble its version-matched evidence packet. In parallel, keep a fine ledger with explicit gaps rather than filling them with anonymous cases. Consult the official enforcement framework for the authority and powers, then use the readiness assessment to assign owners. The expensive mistake is not merely underestimating a ceiling. It is acting on the wrong provision, the wrong date or a decision that nobody can produce.