Five EU regimes, five penalty ceilings, and one event can trigger several. What the numbers are, how they stack, and why the fine is rarely the largest cost.
---
The short answer
Five regimes, five ceilings, and one event can engage more than one of them.
AI Act €35 000 000 or 7% prohibited practices (Art. 5)
GDPR €20 000 000 or 4% most serious infringements
CRA €15 000 000 or 2.5% essential requirements, manufacturer duties
NIS2 €10 000 000 or 2% essential entities
NIS2 € 7 000 000 or 1.4% important entities
DORA set by Member States, plus direct EU oversight of critical
ICT third-party providersAll the percentage figures are of total worldwide annual turnover for the preceding financial year, and all read "whichever is higher".
That phrase is the whole story for large organisations. Above roughly €500 million in turnover, the fixed sums stop being relevant — the percentage governs, and the fixed number in the headline is simply the wrong figure to plan against.
---
Why the AI Act tops the table
€35 million or 7% is the highest cyber-adjacent penalty in EU law, higher than GDPR.
It applies to Article 5 prohibited practices — social scoring, certain emotion inference in workplaces and education, untargeted facial image scraping, some biometric categorisation.
These prohibitions have been in force since February 2025. Not upcoming. And unlike every other obligation discussed here, there is no conformity route: you cannot document, assess or certify your way into a prohibited practice. The only compliant state is not doing it.
Which makes this the cheapest audit on this page and the one least often run. It is a short list, checked against a system inventory, in an afternoon.
Lower tiers under the AI Act reach €15 million or 3% for other obligations, and €7.5 million or 1% for supplying incorrect information.
---
The tier everyone ignores, in three separate regimes
The CRA, the AI Act and NIS2 all penalise incorrect, incomplete or misleading information supplied to authorities or notified bodies — separately from the underlying defect.
CRA €5 000 000 or 1%
AI Act €7 500 000 or 1%This is an exposure created entirely by how you answer, not by what you built. A confident response that turns out to be wrong is its own infringement.
The practical consequence is a habit, not a control: "we do not know yet, and here is when we will" is a complete and safe answer. A guess presented as a fact is not.
---
How the regimes stack on one event
They do not merge, and they do not automatically double.
A single incident can engage several regimes because they regulate different things about it:
a vulnerability actively exploited in your product
CRA did you report it within 24 hours, and was the product compliant
NIS2 did your organisation's measures and reporting meet Article 21 and 23
GDPR was personal data breached, and was Article 32 security adequate
DORA if you are a financial entity, ICT incident classification and reportingFour assessments, four authorities, four sets of evidence. The ne bis in idem principle constrains punishing the same conduct twice, but these are not the same conduct — a product defect, an organisational failure, a data breach and a financial-sector incident are distinct findings.
The planning consequence is not about the arithmetic of fines. It is that one event generates several notifications on several clocks to several recipients, and that is a runbook problem to solve before the event, not during it.
---
Why the fine is rarely the largest cost
Market surveillance authorities under the CRA can restrict, prohibit, withdraw or recall a non-compliant product from the EU market.
For most manufacturers a withdrawal is a far larger event than a percentage of turnover. A fine taxes revenue; a withdrawal stops it. It is public, it reaches customers directly, and it lands on a timescale set by someone else.
NIS2 adds a different instrument entirely: Article 20 makes management bodies responsible for approving and overseeing the measures, and Member States must provide for their liability. Some transpositions allow temporary prohibition of individuals from management functions in essential entities.
That is a personal consequence, and it changes who in the organisation is actually interested in this conversation.
---
Where the numbers stop being EU-level
NIS2 is a Directive. The ceilings are set at EU level; the regime inside them is national, and transpositions differ in scope, thresholds and enforcement posture.
DORA does not set EU-wide administrative fine ceilings for financial entities in the way the other regulations do — Member States determine penalties, and DORA layers on direct EU oversight of designated critical ICT third-party providers, including periodic penalty payments.
So a group operating in several Member States faces one ceiling and several regimes. A single group-level compliance number is a simplification that will not survive an actual proceeding.
---
What actually determines the figure
Across all five, the factors are recognisably the same family:
- Nature, gravity and duration of the infringement
- Intentional or negligent character
- Mitigation taken
- Previous infringements
- Cooperation with the authority
- Self-reporting
All but the first are behaviour, and most are documented behaviour.
Duration is the one to think hardest about, because it is measured from when the situation began, not from when you noticed. A product shipping without a compliant vulnerability handling process for eighteen months carries an eighteen-month infringement regardless of awareness.
Which produces the least intuitive conclusion on this page: a dated determination made today is a penalty control. It does not fix the defect — it bounds the duration, and duration is the only factor that gets strictly worse with time and can never be repaired retroactively.
---
What to do with all of this
1. Stop planning against the fixed sums if your turnover exceeds roughly €500 million. They are not your number.
2. Run the Article 5 audit. It is short, the prohibitions are already in force, and it carries the highest ceiling in EU law with no conformity route available.
3. Date your classifications, across every instrument that reaches you. It is the cheapest thing on this list and it bounds the factor that only worsens.
4. Build the multi-clock runbook. One event, several notifications, several authorities. Design it while nothing is happening.
5. Brief the management body properly. Under NIS2 their approval is an obligation and their liability is personal. A board that has not been told this has not really been briefed.
6. Never guess to an authority. Three regimes penalise the answer independently of the fact.
---
Calculate your own exposure — free, no account
- [Penalty calculator](/resources/penalty-calculator) — on your own turnover, across the regimes that reach you
- [Free readiness assessment](/assess) — which obligations apply, and which artefacts are missing
- [Compliance responsibility mapper](/resources/responsibility-mapper) — a RACI by role
---
Further reading
→ CRA penalties → Essential versus important under NIS2 → What is the EU AI Act → What is DORA → GDPR security baseline → One evidence set across five EU regulations
---
*This is regulatory information, not legal advice, and nothing here constitutes a compliance guarantee. Penalty regimes for NIS2 and DORA are set at Member State level within EU parameters and differ between jurisdictions. Verify against the current texts and applicable national law, and consult your competent authority or a qualified adviser.*
