Administrative Fines on Union Institutions, Bodies, Offices and Agencies
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.This specific provision addresses a distinct category of administrative fines applicable exclusively to Union institutions, bodies, offices and agencies, which differs from fines applicable to private actors and requires separate treatment to capture the unique institutional context and procedures.
Overview
8 sources · Sep 8, 2026Legal Framework
Article 100 of the AI Act establishes a dedicated administrative-fines regime for Union institutions, bodies, offices and agencies. Unlike the general enforcement provisions applicable to private actors, this article vests fining authority exclusively in the European Data Protection Supervisor (EDPS). The provision is structurally separate from the AI Act's standard penalty framework, reflecting the principle that EU institutions operate under a distinct supervisory architecture.
"The European Data Protection Supervisor may impose administrative fines on Union institutions, bodies, offices and agencies falling within the scope of this Regulation."
— AI Act Art. 100(1)
When determining whether to impose a fine and setting its amount, the EDPS must weigh all relevant circumstances, with due regard to six enumerated factors. These include:
"the nature, gravity and duration of the infringement and of its consequences, taking into account the purpose of the AI system concerned"
— AI Act Art. 100(1)(a)
Further factors cover the institution's degree of responsibility — including technical and organisational measures implemented — mitigation efforts, cooperation with the EDPS, prior similar infringements, and how the infringement came to light. The framework mirrors the GDPR's fining methodology in structure but is calibrated to the institutional context, where the supervised entity is itself a public body bound by EU administrative law principles.
Key Developments
The CJEU has actively shaped the broader administrative-fines landscape through cases such as Deutsche Wohnen SE v Staatsanwaltschaft Berlin, Österreichische Datenschutzbehörde v CRIF, and UI v Österreichische Post AG. These rulings address fining principles under the GDPR — including the requirement that fines be effective, proportionate and dissuasive — and the procedural safeguards attaching to administrative penalties. While none directly interprets AI Act Article 100, they establish the doctrinal baseline against which the EDPS's fining decisions will be assessed.
The EDPB's Guidelines 04/2022 on the calculation of administrative fines under the GDPR provide a harmonised methodology that supervisory authorities — including the EDPS in its parallel capacity — are expected to follow. The Danish DPA's enforcement action against Taxa 4x35 (a €160,000 fine recommendation for data-minimisation failures) illustrates how DPAs operationalise the gravity-and-duration criterion, though that case involved a private actor rather than a Union institution.
Status of the Debate
This topic is contested and actively litigated. The CJEU's case law on administrative fines — particularly Deutsche Wohnen and CRIF — reveals divergent judicial approaches to the proportionality and procedural requirements of administrative penalties. Article 100 AI Act has not yet been tested in court, and its interaction with the EDPS's existing powers under Regulation (EU) 2018/1725 raises unresolved questions about parallel proceedings and double jeopardy. What would resolve the open question is a preliminary reference specifically addressing whether the Article 100 criteria require the EDPS to apply the EDPB's fining methodology or whether the institutional context justifies a distinct calculation approach.
Practical Guidance
- Map your AI systems to Article 100 scope now. Union institutions deploying high-risk or prohibited AI systems should conduct a full inventory, as the EDPS's fining power attaches directly to any system falling within the Regulation's scope.
- Document technical and organisational measures. Article 100(1)(b) explicitly weighs implemented measures as a factor in determining the institution's degree of responsibility — robust documentation directly reduces fine exposure.
- Prioritise cooperation and mitigation. The framework rewards proactive engagement with the EDPS and damage mitigation; institutions that remedy infringements before or during investigation benefit under Article 100(1)(c) and (d).
- Track prior infringements. Article 100(1)(e) treats similar previous infringements as an aggravating factor — maintain an internal register of EDPS interactions to anticipate cumulative exposure.
- Align with EDPB fining methodology. Although Article 100 is institution-specific, the EDPB Guidelines 04/2022 provide the prevailing calculation framework; institutions should model potential fine exposure using that methodology as a planning baseline.
Nothing of this type on this topic.