EU AI Act penalties: what actually gets fined, and how the exposure reaches data suppliers

The fine architecture is tiered by conduct rather than by company size. The failures that produce penalties in practice are documentary, and they travel down the supply chain as contract terms.

The tiers are ordered by conduct

The penalties sit in Article 99 of the regulation, and they are organised as tiers. Each tier is expressed as the higher of two figures: a fixed ceiling, or a percentage of total worldwide annual turnover. The percentage is what gives the regime its teeth against large companies and what makes the fixed ceiling meaningful for everyone else.

The top tier is reserved for the prohibited practices — the uses that are banned outright rather than regulated. The middle tier covers most operational obligations, including the transparency duties and the provider and deployer duties that ordinary companies actually live under. The lowest tier covers procedural failures, among them supplying incorrect, incomplete or misleading information to the authorities and notified bodies.

Two design details matter more than the ordering. For smaller companies the regulation applies the lower of the two figures, so the percentage does not operate as an open-ended exposure. And the middle tier is where a data-heavy company is most likely to land, because it covers the obligations that depend on documentation rather than on intent.

There is a separate route for general-purpose models: the Commission itself can fine a provider for infringing the general-purpose obligations, which means enforcement does not depend on a national authority choosing to act.

The failure that produces a penalty is usually documentary

In regimes shaped like this one, penalties are rarely triggered by a dramatic act. They are triggered by an assertion that cannot be supported when someone asks.

Three patterns to expect:

  • A claim of compliance with no underlying record — a published summary that describes a corpus the company cannot evidence, or a policy that exists as a paragraph on a website.
  • Information given to an authority that turns out to be incomplete. That moves a company from the operational tier into the procedural one and converts an inquiry into an enforcement matter.
  • Continuing an activity after an obligation has attached. A one-off breach is a moment; a continuing one is a multiplier, and it is usually the result of nobody owning the question.

Timing is phased, and the data obligations are not in the first wave

The regulation applies in stages rather than on a single date: the prohibitions and the lightest duties first, then the general-purpose model obligations, then the bulk of the high-risk system requirements. The application dates have also been the subject of proposed amendments, so a plan that pins everything to one date is a plan built on a moving part.

The sequencing creates a specific trap for data teams. The earliest obligations were the narrowest ones, and they rewarded companies that bought compliance tooling early and could show activity. The obligations that depend on collection-time records arrive later — and by the time they bite, the collection that should have been documented is already in the past.

The safe planning assumption is therefore not a date but an ordering: anything that has to be captured while people are being recorded is urgent regardless of the calendar, and anything that can be written from records that exist can wait.

Where a data supplier sits in the chain

A data supplier is not the addressee of these provisions. The duties run to providers and deployers, and a company that only records and sells material has no direct obligation under the penalty article.

The exposure is contractual instead, and it arrives through three channels:

  • Indemnities. A buyer facing a penalty traceable to undocumented data will look for the clause that shifts the cost, and will find it if it was negotiated.
  • Audit and access rights. A buyer under examination needs to produce corpus records. If the supplier holds them, the contract has to compel production within a timeframe that fits the inquiry.
  • Warranty breaches. A statement that consent was obtained is a representation. If it is false, that is a claim whether or not any regulator ever looks at the project.

What to do before a fine exists

The work that reduces penalty exposure is unglamorous and mostly consists of records. The items that pay off:

  • Keep the consent version and the annotation guideline version tied to each delivered batch, so any batch can be traced to the terms in force when it was made.
  • Answer due diligence questionnaires with artifacts, and correct earlier answers in writing when they turn out to have been optimistic.
  • Put retention, deletion and notification obligations in the contract rather than in an email thread that will not survive a change of staff.
  • Rehearse the disclosure: if a buyer asked today for the rights basis of a corpus delivered last year, who would answer, and from which file?
  • Give one person ownership of the answer. Most penalty exposure in this area is a question nobody owned until it was asked.

The first consequence is commercial, not financial

Long before any authority acts, the disclosure obligations change what buyers demand. A provider that cannot produce the inputs for a training content summary has a blocked sale rather than a pending penalty, and a supplier that cannot support a buyer's disclosure has a deal that stalls at the procurement stage.

That is the practical reason to treat the penalty architecture as a commercial document rather than a legal one. It tells you which questions will arrive in a purchase process, and it tells you which records are worth keeping when keeping them is inconvenient.

This is a commercial and operational summary rather than legal advice. Exposure depends on the specific conduct, on the role the company occupies, and on counsel's reading of the current text.

More insights

Submit a sourcing request

Tell us the language, the hours, and what the data needs to look like. You will get a real number and a real timeline — not a range. If we cannot source it well, we will tell you that instead.

  • Pilot batch before the full run, so problems surface early.
  • Consent documentation delivered with the data.
  • No medical or clinical data. No recorded telephone calls.

We reply within two business days. Your details are used only to answer this request. See our privacy policy.

Contact

Talk to a human

Send a specification and we will come back with a real number and timeline.

Submit a sourcing request

Or email hello@linguacorpus.com