Fines of Up to 35 Million Euro or 7 Percent of Global Turnover

Lesson concept diagram

The penalties for violating Article 5 prohibited practices are severe and are among the highest in EU data and AI regulation. Understanding the scale of these penalties is important for business decision-making and risk management.

The maximum financial penalty is 35 million EUR or 7 percent of global annual turnover, whichever is higher. For large multinational technology companies, 7 percent of global turnover can exceed 5 billion EUR. For large financial services, insurance or telecommunications companies, 7 percent can exceed 1-3 billion EUR. Even for mid-size companies with 500 million EUR annual turnover, 7 percent (35 million EUR) approaches the ceiling of standard large fines. This means the practical penalty ceiling for most significant organisations is not the 35 million EUR floor but 7 percent of their total global turnover.

The regulators imposing these fines are national competent authorities in each EU member state. These are typically data protection authorities (like the UK’s Information Commissioner’s Office), competition authorities (like the German Bundeskartellamt or French CNIL), or dedicated AI enforcement authorities. The fines are enforced through legal proceedings and administrative law, and organisations have the right to appeal through national courts. However, the threat of enforcement is real and credible. Companies have faced billions of euros in fines under other EU regulations. The EU Commission has explicitly stated it will aggressively enforce Article 5 violations.

In addition to financial penalties, regulators can issue additional enforcement actions. They can issue prohibition notices requiring the system to be shut down immediately with no compliance period. They can issue corrective orders requiring the organisation to take specific remedial steps. They can publish a statement publicly naming the organisation, the violation and the fine. For consumer-facing organisations, public reputation damage can be as costly or more costly than the financial penalty itself.

Regulators can also suspend or exclude organisations from public procurement. If you have violated Article 5 and been fined, you may be ineligible to bid for government procurement contracts for a specified period of time. Some national regulators impose mandatory exclusion for three to five years. This can eliminate significant revenue streams for companies that depend on government contracts.

The financial impact extends significantly beyond the regulatory fine itself. If you have violated Article 5, individuals affected by the violation may have legal rights to sue you for compensation. Some EU member states have made it easier for individuals to claim damages in administrative courts or have streamlined class action procedures. This creates material class action risk. If you deployed a prohibited emotion inference system to 1000 employees without their knowledge, and each can claim damages, the cumulative liability could reach tens of millions of euros above and beyond the regulatory fine.

Insurance implications also matter significantly. If you have professional indemnity insurance or cyber liability insurance, you may find that the insurer excludes coverage for violations of regulation or for intentional or reckless breaches. An investigation might reveal that your prohibited practice was deployed despite internal warnings about Article 5 compliance. The insurer may decline to cover your losses.

The way to manage these financial risks effectively is straightforward: screen AI systems systematically against Article 5, do not deploy prohibited practices, and document your screening process thoroughly. The cost of thorough screening is a fraction of the cost of violation and enforcement.

Consider that a fine of 700 million EUR (7 percent of a 10 billion EUR company) does not come from a budget line or insurance. It comes from shareholder capital, which means your investors lose value. It comes from operational cash, which means your business cannot invest in growth or innovation. For smaller companies, a multi-million euro fine can be existential. Beyond shareholder impact, the regulatory enforcement attracts media attention, damages reputation, causes customer churn and makes recruitment harder. The hidden costs often exceed the fines themselves. Employees do not want to work for a company known for violating human rights protections. Customers do not want to do business with organisations that have been fined for misusing people’s faces or emotions. Partners are reluctant to work with non-compliant organisations.

The business case for Article 5 compliance is straightforward: screening AI systems against the prohibition costs virtually nothing; deploying them and being caught costs millions or billions. For a CFO or board, the risk-return calculation is obvious. For a technology leader, the calculation is equally clear: compliance is cheaper than enforcement.