Who checks this in Germany?
Every EU member state must designate at least one national market surveillance authority for AI. In Germany, the Bundesnetzagentur takes on this role centrally, supported by a new coordination and competence centre that bundles cooperation with existing specialist authorities – in areas with already-established oversight (such as financial supervision), the respective specialist authorities remain responsible. For GPAI models with systemic risk, enforcement instead sits with the European Commission via the European AI Office, not the national authority.
The three fine tiers in detail (Art. 99)
- Highest tier: up to €35 million or 7% of global annual turnover – exclusively for violations of the prohibited practices (Art. 5).
- Middle tier: up to €15 million or 3% of global annual turnover – for violations of most other obligations (e.g. high-risk requirements, transparency duties).
- Lowest tier: up to €7.5 million or 1% of global annual turnover – for false, incomplete, or misleading information given to authorities.
SME proportionality
Art. 99(6) explicitly provides that for small and medium-sized enterprises and start-ups, the LOWER of the two values (fixed amount or percentage) applies each time – an economically meaningful difference compared to large corporations. Additionally, Art. 99(7) lists seven criteria to be considered when setting the actual fine: the nature and severity of the violation, the number of affected people and the extent of harm, intent versus negligence, mitigation measures taken, cooperation with the authority, prior violations, and the company's financial situation. A fine is therefore not an automatic formula, but the result of a case-by-case assessment.
Practice section: what actually gets checked in an audit
An audit goes considerably more smoothly if the homework from this course is already done: the documented inventory from “The Risk Pyramid in Detail”, the role classification from “Provider or Deployer?”, the training records from “The AI Literacy Duty”, a fundamental rights impact assessment from “Human Oversight and the Fundamental Rights Impact Assessment” (where applicable), and the labelling evidence from “Transparency Obligations for Chatbots, Deepfakes & AI Content”. On top of that: automatically generated logs must be kept for at least six months – a simple but frequently overlooked technical duty. This classification doesn't replace case-by-case legal advice.