There are three AI Act fine tiers. Most people only know one of them.
Everyone knows the headline number. Almost nobody plans for the other two. That gap tells you exactly how most organisations are preparing, and why so many will still be caught. The three tiers Prohibited practices cost up to 35 million euros or 7% of worldwide annual turnover, whichever is higher. Breaching operator or general-purpose model duties runs to 15 million euros or 3%. Giving an authority incorrect, incomplete or misleading information costs up to 7.5 million euros or 1%. Small and medium companies are capped at the lower of the two figures rather than the higher. Read the third tier twice. It does not punish reckless AI. It punishes an inaccurate answer. You can act in good faith, answer a regulator from a spreadsheet nobody updated, and land inside it. Which is the cheapest tier to avoid, and the only one that is purely an admin problem. Why that tier is a governance failure, not a legal one AI compliance means proving your AI meets rules somebody els...