AI Regulation
Turnover-based fines change who has to care
Up to €35M or 7% of global turnover for prohibited practices, €15M or 3% for high-risk and GPAI failures. Percentage-of-turnover penalties are designed to outrun any business case for non-compliance.
The AI Act's penalties are tiered: up to €35 million or 7% of global annual turnover for prohibited practices, and up to €15 million or 3% for high-risk and general-purpose AI non-compliance. The percentage figures are the operative ones for any organisation of scale.
Why percentage penalties work differently
A fixed fine is a cost that can be modelled. For a large enough business, a €35 million exposure against a profitable non-compliant product is arithmetic, and the arithmetic sometimes favours paying.
A percentage of global turnover removes that option by construction. It scales with the organisation rather than the infringement, and it is drawn from revenue rather than profit — so it lands regardless of whether the offending activity made money. GDPR established the pattern and the AI Act has adopted it deliberately.
Percentage-of-turnover penalties exist to make the compliance calculation come out one way.
The organisational consequence
It moves AI governance out of the technology function. A 3% of turnover exposure is a board-level number, which means it acquires the attention, the budget and the reporting line that board-level numbers get.
In our experience that is mostly good and partly hazardous. Good, because AI governance chronically lacks authority and this supplies it. Hazardous, because board attention on a penalty tends to produce documentation designed to demonstrate compliance rather than controls designed to prevent harm, and the two diverge quickly under deadline pressure.
Spending the attention well
If executive interest has arrived because of the fine, the useful move is to convert it into the controls that also reduce operational risk rather than into a paper exercise. Inventory, classification, evaluation records and incident response serve both purposes; a policy document signed by everyone serves only one.
The organisations that come out of this well will be the ones that used a regulatory forcing function to build things they needed anyway. The others will have excellent binders.
Sources
- EU AI Act 2026 Updates: Compliance Requirements and Business Risks — Legal Nodes
- EU Artificial Intelligence Act — developments and analyses — artificialintelligenceact.eu
- The right balance: how to fix European Union artificial intelligence regulation — Bruegel
Written by the Devence Lab research team.