Insights

    AI Regulation

    Turnover-based fines change who has to care

    Devence Lab

    · 2 min read

    Share
    Turnover-based fines change who has to care
    Photograph · Unsplash

    Up to €35M or 7% of global turnover for prohibited practices, €15M or 3% for high-risk and GPAI failures. Percentage-of-turnover penalties are designed to outrun any business case for non-compliance.

    The AI Act's penalties are tiered: up to €35 million or 7% of global annual turnover for prohibited practices, and up to €15 million or 3% for high-risk and general-purpose AI non-compliance. The percentage figures are the operative ones for any organisation of scale.

    Why percentage penalties work differently

    A fixed fine is a cost that can be modelled. For a large enough business, a €35 million exposure against a profitable non-compliant product is arithmetic, and the arithmetic sometimes favours paying.

    A percentage of global turnover removes that option by construction. It scales with the organisation rather than the infringement, and it is drawn from revenue rather than profit — so it lands regardless of whether the offending activity made money. GDPR established the pattern and the AI Act has adopted it deliberately.

    Percentage-of-turnover penalties exist to make the compliance calculation come out one way.

    The organisational consequence

    It moves AI governance out of the technology function. A 3% of turnover exposure is a board-level number, which means it acquires the attention, the budget and the reporting line that board-level numbers get.

    In our experience that is mostly good and partly hazardous. Good, because AI governance chronically lacks authority and this supplies it. Hazardous, because board attention on a penalty tends to produce documentation designed to demonstrate compliance rather than controls designed to prevent harm, and the two diverge quickly under deadline pressure.

    Spending the attention well

    If executive interest has arrived because of the fine, the useful move is to convert it into the controls that also reduce operational risk rather than into a paper exercise. Inventory, classification, evaluation records and incident response serve both purposes; a policy document signed by everyone serves only one.

    The organisations that come out of this well will be the ones that used a regulatory forcing function to build things they needed anyway. The others will have excellent binders.

    Sources

    1. EU AI Act 2026 Updates: Compliance Requirements and Business RisksLegal Nodes
    2. EU Artificial Intelligence Act — developments and analysesartificialintelligenceact.eu
    3. The right balance: how to fix European Union artificial intelligence regulationBruegel

    Written by the Devence Lab research team.

    Share

    Collaborate

    We share findings with partners operating in the same constraint space.

    Get in touch