Search "EU AI Act fines" and you'll find articles describing specific companies fined tens of millions of euros in 2026. At least one widely-circulated report claims a US tech platform was fined €45 million in March 2026. Here's the problem: that claim doesn't hold up against the Act's own statutory text, and it isn't corroborated by a single major news outlet, law firm tracker, or the European Commission's own AI Office communications. Before you build a compliance strategy around "real enforcement cases," it's worth knowing what's actually verifiable.
No confirmed, verifiable fines under EU AI Act Article 99 have been publicly documented as of mid-2026. Article 5 prohibited-practice violations have technically been enforceable since February 2025 and the Commission has reportedly opened initial investigations, but the fine provisions themselves — and the Commission's enforcement powers over GPAI providers — only take full legal effect on August 2, 2026. Reports describing specific multi-million-euro fines already issued are not corroborated by primary sources.
What the Act Itself Actually Says About Timing
Article 99 establishes the EU AI Act's three-tier fine structure — up to €35 million or 7% of global turnover for Article 5 prohibited-practice violations, up to €15 million or 3% for high-risk system non-compliance, and up to €7.5 million or 1% for supplying misleading information to authorities. But multiple independent, technically detailed compliance trackers consistently agree on one point: while Article 5's prohibitions and Article 4's AI literacy requirement have applied since February 2, 2025, the fine provisions under Article 99 that would actually let a regulator impose those penalties attach once Article 99 itself becomes applicable — which, for most obligations, is August 2, 2026. The Commission's own supervision and enforcement powers over general-purpose AI model providers specifically don't activate until that same date, a full year after GPAI obligations themselves became legally binding in August 2025.
This gap — obligations in force since 2025, but the enforcement machinery only fully activating in August 2026 — is exactly why claims of already-issued multi-million-euro fines deserve scrutiny. If a €45 million fine had genuinely been issued against a major US tech platform months before the Commission's own enforcement powers took effect, it would be front-page news across every major outlet covering EU tech policy, not a claim traceable to a single lesser-known source with no corroboration from the AI Office, national competent authorities, or established legal trackers.
What Is Actually Happening Right Now
The honest picture, cross-checked against the Act's own text and independent legal analysis, looks like this:
- Article 5 prohibited practices are live and actionable. Since February 2, 2025, systems using subliminal manipulation, exploiting vulnerabilities, or conducting real-time biometric identification in public spaces (subject to narrow exceptions) have been legally prohibited — this is the one area where enforcement action is genuinely possible today, and at least one tracker indicates the Commission has opened preliminary investigations into potential violations.
- Fine provisions aren't fully operative yet. Article 99's actual penalty mechanism, and the procedural rights that go with it (a hearing before a fine is issued, judicial review of the decision), attach to obligations as those obligations themselves become applicable — which for the bulk of the Act's substantive requirements is August 2, 2026, though the Digital Omnibus agreement has since pushed the Annex III high-risk deadline specifically to December 2, 2027.
- Enforcement will be split across multiple bodies, not centralized. National competent authorities designated by each Member State supervise most AI Act compliance; the Commission's AI Office handles GPAI provider enforcement directly and coordinates cross-border cases. There's no single "EU AI Act regulator" the way GDPR has data protection authorities — expect enforcement patterns to be uneven across member states initially, similar to how GDPR enforcement took years to become consistent.
- Complaint-driven enforcement is the expected starting mechanism. Once Article 99 activates, the most likely trigger for an early investigation is a complaint from an affected individual — a rejected job candidate, a denied loan applicant — rather than proactive regulatory sweeps, again mirroring how GDPR enforcement actually ramped up.
Why This Matters for Your Compliance Planning
Treating unverified fine reports as established fact leads to two bad outcomes in opposite directions. Overreacting to a fabricated €45 million headline can push resources toward performative, deadline-panicked compliance theater rather than substantive risk work. Underreacting because "nothing's really being enforced yet" ignores that Article 5 prohibited practices are genuinely live today, and that the August 2026 GPAI enforcement date and December 2027 high-risk deadline are both real, dated, and approaching regardless of what's already happened.
The GDPR precedent is instructive and worth taking seriously: enforcement started slowly and unevenly, then accelerated sharply once national authorities built institutional capacity — cumulative GDPR fines had exceeded €4 billion by 2024, years after the regulation took effect. The AI Act's enforcement infrastructure is explicitly being built on that same foundation, and legal trackers broadly expect a shorter learning curve this time. The absence of confirmed fines today is not evidence the Act lacks teeth — it's evidence the teeth haven't finished coming in yet.
How to Verify Any EU AI Act Enforcement Claim Yourself
- Check the date against Article 99's applicability schedule — a claimed fine dated before August 2, 2026 for anything other than an Article 5 prohibited-practice violation should be treated with real skepticism.
- Look for corroboration from the AI Office directly, a national competent authority, or a major established outlet — not a single blog post or content-mill article with no named regulatory source.
- Cross-reference against established legal trackers (major law firms' AI Act practice pages, the official artificialintelligenceact.eu explainer) — these sources are conservative and consistent with each other on enforcement timing in a way that single-source claims about specific fines are not.
Frequently Asked Questions
Has anyone actually been fined under the EU AI Act?
As of mid-2026, no confirmed, corroborated fines under Article 99's penalty provisions have been publicly documented. Article 5 prohibited-practice enforcement is technically possible since February 2025, with reports of preliminary Commission investigations, but no confirmed fine has been substantiated by primary regulatory sources.
When do EU AI Act fines actually become enforceable?
Article 99's fine mechanism attaches to obligations as those obligations become applicable — August 2, 2026 for most provisions and the Commission's GPAI enforcement powers, and December 2, 2027 for Annex III high-risk systems under the Digital Omnibus agreement.
Are EU AI Act prohibited practices already enforceable?
Yes. Article 5's prohibited practices and Article 4's AI literacy requirement have applied since February 2, 2025, making this the one area where genuine enforcement action is possible today, ahead of the broader Article 99 fine machinery.
Who enforces the EU AI Act?
National competent authorities designated by each Member State supervise most compliance; the European Commission's AI Office handles general-purpose AI model provider enforcement directly and coordinates cross-border cases.
Related reading: the EU AI Act's revised 2026-2028 timeline, EU AI Act risk classifications explained, and why reading the Act's text alone isn't enough to pass the AIGP exam.