AI + Penalties

What AI non-compliance costs: EU, UK, United States, Australia

Huceptron InsightsBy the Huceptron senior partners·5 min read

The headline number is EUR 35 million or 7% of worldwide annual turnover, whichever is higher. It gets quoted a great deal and it is correct, but it applies to a narrow band of conduct that almost no legitimate business engages in.

The tiers that matter for an ordinary company are considerably lower, and the structure is worth understanding properly rather than through the headline.

The three tiers

Up to EUR 35 million or 7% of worldwide annual turnover - for engaging in a prohibited practice under Article 5. Social scoring, exploiting vulnerabilities, untargeted facial scraping, emotion inference at work or in education outside the narrow exceptions.

This is the deliberate-wrongdoing tier. If you are anywhere near it, the fine is not your first problem.

Up to EUR 15 million or 3% of worldwide annual turnover - for most other breaches by providers, deployers, importers, distributors and notified bodies. Failures of the high-risk obligations, transparency duties, and the general operator requirements live here.

This is the tier an otherwise well-run company could realistically reach, through omission rather than intent.

Up to EUR 7.5 million or 1% of worldwide annual turnover - for supplying incorrect, incomplete or misleading information to authorities or notified bodies.

Worth noting: this one can be triggered by a bad answer to a regulator's question, which is a different kind of risk from a bad system.

The SME provision

For SMEs and start-ups the ceiling is the lower of the two figures rather than the higher. That inversion is deliberate and it materially changes the exposure for a small Irish company - the percentage figure caps the euro figure rather than the other way round.

It does not, however, change the obligations. Smaller firms owe the same duties; they simply face a proportionate ceiling if they fail them.

Public bodies

Irish public-sector bodies face a separate and considerably lower ceiling, set in the national implementing legislation.

Who actually issues the fine

In Ireland, your sectoral market surveillance authority - not a central AI regulator. If the Central Bank supervises you, the Central Bank is who administers this. Authorised officers can inspect, and authorities can issue contravention and prohibition notices, which in practice arrive long before any fine does.

A prohibition notice stopping a system you depend on is, for most businesses, the more serious commercial event.

What regulators weigh

Penalties must be effective, proportionate and dissuasive, and authorities take into account the nature and gravity of the breach, whether it was intentional or negligent, what the operator did to mitigate, previous history, the size of the operator, and whether they cooperated.

That last cluster is the practical point. The difference between a company that can show its AI inventory, its risk assessments and its oversight arrangements, and one that cannot, is not a technicality at the enforcement stage. It is most of the outcome.

What non-compliance costs outside the EU

No other major jurisdiction has copied the EU’s turnover-linked AI penalties. That does not make the exposure small; it makes it come from somewhere else.

United Kingdom. There is no AI-specific penalty at all. The exposure runs through the regimes that already applied. UK GDPR maxima are the higher of GBP 17.5 million or 4% of worldwide turnover, and automated decision-making is squarely within them since Articles 22A to 22D commenced on 5 February 2026. Discrimination awards under the Equality Act 2010 are uncapped. Online Safety Act penalties, where the service is in scope, reach the higher of GBP 18 million or 10% of qualifying worldwide revenue. FCA action against a regulated firm is not measured in fines alone.

United States. Statute by statute, and mostly per violation rather than by turnover. Texas TRAIGA: USD 10,000 to 200,000 per violation, USD 2,000 to 40,000 a day for a continuing violation, a 60-day cure period, enforcement by the attorney general only, no private right of action. California SB 53: up to USD 1 million per violation. California SB 942: USD 5,000 a day. New York’s RAISE Act from 1 January 2027: USD 1 million and USD 3 million tiers. New York City Local Law 144, the bias audit rule: up to USD 500 for a first violation and USD 500 to 1,500 for each subsequent one - trivial on its face, except that each day a tool is used without a current audit and each candidate who was not given notice counts separately. FTC and SEC matters settle on their own terms and bring consent orders that outlast the cheque.

Australia. Again no AI-specific penalty, and again a serious backstop. A serious or repeated interference with privacy carries a maximum of the greatest of AUD 50 million, three times the benefit obtained, or 30% of adjusted turnover in the relevant period. Australian Consumer Law penalties run on the same formula. Directors’ duties under the Corporations Act are personal, and ASIC has said plainly that AI does not substitute for independent judgment.

Two things follow. First, in three of these four jurisdictions the largest number on the page is a data protection or consumer law number, not an AI number - so an AI programme that has not been through privacy and consumer law is not de-risked. Second, the cheapest form of all of this is the evidence you did not keep. We size that exposure for clients in Ireland, the United Kingdom, the United States and Australia, where we have representation.

The sober view

Nobody is being fined 7% of turnover for a support chatbot that forgot to say it was a bot. But the cost of being unable to answer basic questions when asked - what AI do you run, who owns it, what does it decide, who checks it - is real, and it arrives long before any penalty does.

One week. Then you know.
The AI audit week - what applies to you, where the gaps are, and what to do first
See what the week covers →