Sovergate
← Back to Blog
Compliance8 min read · 5 October 2026

EU AI Act Article 12 Penalties: Fines for Non-Compliance Explained

Which penalty tier Article 12 falls into, how the €15M / 3% figure is actually calculated, who enforces it, and what regulators weigh when they set a fine.

The headline number attached to the EU AI Act is large: up to €35 million or 7% of global annual turnover. But that ceiling does not apply to every breach. Article 12 — the automatic logging obligation for high-risk AI systems — sits in a specific penalty tier, and understanding which one changes how you should think about your exposure.

This guide breaks down the fine structure, explains which tier Article 12 falls into, shows how the figure is actually calculated, and describes what regulators weigh when they assess whether your logging obligation has been met.

The three penalty tiers

The EU AI Act sets administrative fines in Article 99, structured into tiers according to the severity of the breach.

TierType of breachMaximum fine
Tier 1 — highest (Art. 99(3))Violations of the prohibited practices in Article 5Up to €35M or 7% of total worldwide annual turnover
Tier 2 — middle (Art. 99(4))Breaches of operator obligations, including those for high-risk systems — and therefore Article 12Up to €15M or 3% of total worldwide annual turnover
Tier 3 — lowest (Art. 99(5))Supplying incorrect, incomplete or misleading information to authoritiesUp to €7.5M or 1% of total worldwide annual turnover

In each case the cap is whichever amount is higher — except for SMEs, including start-ups, where Article 99(6) applies the lower of the two figures to keep penalties proportionate to size. Member States can also use warnings and non-monetary measures (Article 99(1)).

Which tier does Article 12 fall into?

The middle tier: up to €15 million or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher.

Strictly, Article 99(4) does not list Article 12 itself. It lists the obligations of each operator, and a logging failure reaches you through whichever applies to you:

  • —Providersbreach Article 16, which requires them to ensure their high-risk system meets the requirements of Chapter III, Section 2 — including Article 12's automatic logging capability.
  • —Deployers breach Article 26, which requires them to keep the logs generated by the system for at least six months (Article 26(6)).

The same tier covers most of the operational requirements for high-risk AI — risk management, data governance, technical documentation, human oversight and logging. It is not the top tier reserved for prohibited practices, but it is the tier most high-risk operators are realistically exposed to, because logging is a continuous, every-transaction obligation that is easy to get wrong at scale.

How the figure is actually calculated

The “€15M or 3%” formula produces very different caps depending on company size — and on whether you qualify as an SME (broadly, fewer than 250 employees and turnover up to €50M or a balance sheet up to €43M).

An SME with €20M turnover. The lower of €15M and 3% applies: the maximum is €600,000.

A company with €50M turnover and 400 employees. Too many employees to qualify as an SME, so the higher figure applies. 3% is €1.5M, below €15M, so the maximum is €15M.

A group with €2bn turnover. 3% is €60M, far above €15M, so the percentage governs. Above €500M turnover, exposure rises with every euro of revenue.

These are maximums. The actual fine is set case by case using the factors below, and Article 99(1) requires it to be effective, proportionate and dissuasive.

Group turnover, not subsidiary turnover.The AI Act caps fines by the turnover of the “undertaking”. For GDPR fines, the EU Court of Justice held in ILVA(C-383/23, February 2025) that an undertaking is the whole economic unit, so the parent group's turnover counts. The AI Act uses the same concept, and the same reading is widely expected.

What regulators actually assess

Article 99(7) lists the circumstances authorities must weigh when deciding whether to fine and how much. For a logging breach, the factors that tend to matter most are:

  • —Nature, gravity and duration — whether logging was absent entirely, incomplete or merely imperfect, how long the gap lasted and how many people were affected.
  • —Intentional or negligent character. A documented, good-faith logging programme with a minor gap is treated very differently from no logging at all.
  • —Degree of responsibility, taking into account the technical and organisational measures you had in place.
  • —Cooperation and mitigation — how you worked with the authority and what you did to limit harm.
  • —How the breach became known — and in particular whether you notified it yourself.
  • —Fines already imposed by other authorities for the same conduct.

This is why the quality of your audit trail matters as much as its existence. When something goes wrong, the question regulators ask is rarely only what the model did — it is whether you can produce a credible, tamper-evident record of what the system did and when. An audit trail that cannot answer that question is itself evidence of inadequate technical and organisational measures.

Who enforces it

Enforcement is handled by national market surveillance authorities designated by each EU Member State, coordinated at EU level through the AI Office and the European Artificial Intelligence Board. The body knocking on your door is a national regulator, applying the AI Act's harmonised penalty framework within its own procedural rules.

For companies operating across multiple Member States this matters: a high-risk system deployed EU-wide can attract attention from any national authority where it affects individuals.

The cost of getting logging wrong

For a high-risk AI operator, an Article 12 failure is not a paperwork fine. It is a middle-tier breach with a cap of at least €15 million for any company that is not an SME, rising to 3% of group turnover for large groups.

And unlike a one-off documentation error, a logging failure compounds. Article 12 covers the lifetime of the system, so a gap is not a single missed record — it is every decision the system made during the unlogged period, none of which you can later reconstruct or defend.

How to reduce your exposure

The mitigations map directly to the factors regulators weigh:

  • —Log automatically and completely, so there is no gap to find.
  • —Make logs tamper-evident, so the record is credible without your assurance.
  • —Start early. A logging programme running well before the deadline demonstrates good faith and produces the clean historical trail that defends individual decisions.
  • —Keep documentation consistent with the logging you actually run, so your Article 11 technical documentation and your Article 12 logs tell the same story.

For the full mechanics of compliant logging — what to capture, retention, tamper-evidence and the GDPR intersection — see our complete Article 12 compliance guide, or work through the Article 12 checklist.

Sovergate exists to remove this exposure: automatic capture, local PII scrubbing, cryptographic tamper-evidence, EU data residency and regulator-ready audit packs — installed in two lines of code.

Frequently asked questions

Is the Article 12 fine €35M or €15M?

For Article 12, the relevant ceiling is €15M or 3% of total worldwide annual turnover, whichever is higher. The €35M / 7% tier applies only to prohibited practices under Article 5.

Is the fine based on revenue or profit?

Turnover — total worldwide annual turnover for the preceding financial year — not profit. For GDPR fines, the EU Court of Justice has held that this means the turnover of the whole corporate group, and the AI Act uses the same concept of an undertaking.

Do smaller companies face the same fines?

No. For SMEs, including start-ups, the cap is the lower of the fixed amount and the percentage. For an SME with €20M turnover, the maximum for an Article 12 breach is therefore €600,000, not €15M.

When can fines start being imposed for Article 12 breaches?

High-risk obligations, including Article 12, take effect on 2 December 2027 for stand-alone Annex III systems following the Digital Omnibus amendment.

Does having logs guarantee no fine?

No — but a complete, tamper-evident, well-documented logging programme directly addresses several of the factors regulators must weigh when setting penalties, and is the best evidence that you took adequate technical and organisational measures.

This guide is maintained by Sovergate, a European AI compliance platform providing Article 12 logging for companies using LLMs in high-risk contexts. It is for informational purposes only and does not constitute legal advice. Regulation referenced: EU Regulation 2024/1689 (EU AI Act), Articles 5, 12, 16, 26, 99. Deadline: 2 December 2027.

Last updated October 2026.

Ready to close your Article 12 exposure?

Two lines of code. PII scrubbed locally. Data stored in Germany. Monthly compliance reports ready for your legal team.