# EU AI Act penalties are not a €35 million coin toss

> EU AI Act penalties can reach 7% of global turnover, but SME caps, role, timing, harm and cooperation determine realistic exposure.

The maximum fine in the EU AI Act is frightening by design, but it is a poor estimate of what a small or medium business will actually pay. A founder who treats €35 million as the expected loss will overspend on paperwork. A founder who dismisses the number as Brussels theatre may miss a prohibited use, ignore an authority, or discover too late that the company is legally a provider rather than a customer.

Exposure comes from a chain of facts: which AI system you operate, your role under the Act, which obligation applies on the relevant date, what harm occurred, and how you respond when an authority asks questions. Turnover changes the ceiling. Conduct and evidence shape the case below it.

This is a management view of enforcement, not a substitute for advice on a specific deployment. The useful work for an SMB is still operational: inventory systems, classify roles and uses, assign owners, preserve evidence, and stop the few practices the law flatly prohibits.

## The fine table is a ceiling, not a forecast

Article 99 creates three main bands for operators of AI systems. A breach of an Article 5 prohibition can draw up to €35 million or 7% of total worldwide annual turnover from the preceding financial year, whichever is higher for an undertaking. Breaches of listed duties for providers, deployers, importers, distributors, authorised representatives, and notified bodies, plus Article 50 transparency duties, can reach €15 million or 3%. Incorrect, incomplete, or misleading information supplied in reply to an authority or notified body can reach €7.5 million or 1%.

The phrase that founders often miss comes immediately after those numbers. For SMEs, including startups, each ceiling is the lower of the percentage and the fixed amount. A qualifying company with €4 million in worldwide turnover therefore has theoretical Article 99 ceilings of €280,000 for a prohibited practice, €120,000 for the 3% band, and €40,000 for the information band. Those are still ceilings, not quotes from a regulator.

Do not apply that arithmetic casually to a group of companies. The Act uses the competition law concept of an undertaking, which can reach beyond one legal entity when businesses form one economic unit. It also uses worldwide turnover, not EU revenue and not the revenue of the product under review. Corporate structure deserves legal analysis before anyone types a number into a board slide.

A board estimate needs three numbers, not one. Show the statutory ceiling, a scenario range based on current facts, and the cost of correction such as withdrawing a feature, notifying customers, or rebuilding records. Keep legal uncertainty visible. Treating the ceiling as a booked loss is as misleading as assigning a zero because no authority has contacted the company.

General-purpose AI model providers sit under a separate Commission fine in Article 101. That ceiling is 3% of annual total worldwide turnover or €15 million, whichever is higher, for intentional or negligent failures such as breaching model duties, withholding requested documents, ignoring a required measure, or denying model access for evaluation. Most SMBs that call a model through an API do not become the provider of that underlying model. They can, however, be providers or deployers of an AI system built on top of it.

A maximum answers how far the authority may go. It does not answer whether a violation occurred, which authority acts, whether corrective measures come first, or where the final amount lands.

## Your legal role matters more than your vendor invoice

Buying AI does not make a company a mere customer under the Act. The legal roles follow what the company does with the system, whose name appears on it, and where it enters the market.

A provider develops an AI system or has one developed and places it on the market or puts it into service under its own name or trademark. A deployer uses an AI system under its authority, outside personal activity. Importers and distributors have their own duties. A product manufacturer can inherit provider duties when it puts an AI system on the market with its product under its own name.

Consider a recruiting startup that licenses a ranking engine, changes the user flow, brands the result as its own candidate score, and sells it to employers. Its contract may call it a reseller. The Act may treat it as a provider, especially if its changes amount to a substantial modification or it puts the system on the market under its name. The employers using the score can be deployers. One technical service now creates different duties on both sides of the invoice.

Territory is broad as well. The Act covers providers placing systems or general purpose models on the EU market even if the provider sits outside the Union. It also reaches providers and deployers outside the EU when the system's output is used in the Union. A US company cannot settle scope by blocking EU signups while its enterprise customer sends outputs into an EU hiring or lending process.

Make four fields mandatory in the AI inventory: business use, system owner, legal role, and EU connection. Add the vendor and model as supporting facts. An inventory that begins and ends with a list of subscriptions cannot support a defensible classification.

Contracts allocate work and financial risk between parties, but they do not rewrite the statutory role. A clause saying the vendor handles compliance does not remove a deployer's duties. Ask instead whether the contract gives your team the information, logs, change notices, audit cooperation, and exit rights needed to perform those duties. An indemnity helps only after the loss and only if the vendor can pay it.

The vendor questionnaire should match the use. Ask which entity provides the system, the intended purpose stated in instructions, whether the vendor claims a risk classification, what material changes trigger notice, and how you can export evidence. If the answers conflict with the product's actual behavior, record the conflict and resolve it before launch. Vendor paperwork is an input to classification, not the classification itself.

The costly classification error is usually role drift. A team starts as a deployer, adapts or wraps a tool, exposes it to customers, and keeps the old label. Review the role again when the company changes the model, intended purpose, brand, customer access, or decision authority.

## Enforcement is split across several doors

There is no single EU AI police force handling every company and every system. National market surveillance authorities supervise AI systems, including prohibited practices, transparency duties, and high risk systems. The European Commission's AI Office supervises providers of general purpose AI models and a defined subset of systems connected to those models. The European Data Protection Supervisor handles AI used by EU institutions, bodies, and agencies.

That split changes how a case can begin. A national authority can receive a complaint, learn of an incident, run sector surveillance, or receive information from another authority. Fundamental rights bodies can request information and cooperation from market surveillance authorities when an AI incident touches discrimination, privacy, or another protected right. Existing sector regulators do not disappear because the product now contains AI.

Customers and workers will often see the failure before management does. A chatbot disclosure disappears, an applicant cannot understand a rejection, or a worker notices that a score drives shifts. Support, human resources, privacy, and whistleblowing channels therefore form part of the detection system. If those teams tag AI complaints consistently, the company can investigate one event before it becomes a pattern across products or countries.

Market surveillance authorities can demand documentation and data, conduct remote monitoring, and gain access to source code under the conditions in the Act and EU market surveillance rules. They can require corrective action within a prescribed period. If a system presents a risk, the process can lead to restriction, withdrawal, recall, or other measures. A fine is one tool in that sequence, not the whole enforcement model.

Cross-border cases require coordination. If an authority finds that a problem extends beyond its territory, it informs the Commission and other Member States. The European Artificial Intelligence Board gives national representatives a place to coordinate. The Scientific Panel and Advisory Forum add technical and stakeholder input, but they do not replace the authorities that investigate or decide cases.

For an SMB, the practical contact may come from a familiar national regulator rather than the AI Office. Route every regulatory request to one accountable owner, record the deadline, preserve the original request, and answer only after technical and legal owners reconcile the facts. The 1% information band makes improvised certainty expensive. An accurate statement of what the company has not established is safer than a confident invention.

## Early signals point to evidence before spectacle

The first enforcement signal is institutional, not a wall of fine decisions. The Commission spent the opening phases publishing guidance, building the AI Office, convening the AI Board, appointing scientific and advisory bodies, and setting up ways for model providers to submit material. National authorities received investigation and market surveillance responsibilities. That is the machinery required for enforcement built on documents.

The second signal is the Commission's stated approach to providers of general purpose models. During the first year after those duties began on 2 August 2025, the AI Office offered close informal collaboration, especially to providers following the voluntary Code of Practice. The Commission also said that full enforcement, including fines, would begin from 2 August 2026. Cooperation was an implementation posture, not an amnesty written into the Act.

The third signal comes from the guidelines on prohibited practices. They give explanations and examples, but the Commission says they are not binding and that authoritative interpretation belongs to the Court of Justice of the European Union. A company should use the guidelines to understand the regulator's view while keeping its own reasoned scope analysis. Copying a paragraph from guidance without mapping it to product facts produces weak evidence.

This points to a likely early pattern: authorities can test clear obligations and poor responses before litigating the hardest boundaries. A business using an obviously prohibited practice, ignoring a transparency duty, or sending misleading information gives an authority a cleaner file than a novel system with a careful classification and documented controls.

Do not confuse a cooperative opening with a promise of warnings first. Article 99 allows warnings and measures without fines in national penalty systems, but it does not guarantee every company a warning. Authorities must consider proportionality and the economic viability of SMEs. They must also make enforcement effective and dissuasive.

There is still little mature decisional history under the Act's newly active enforcement regime. Anyone presenting a precise average AI Act fine for startups is selling false confidence. Use the statutory factors and your actual deployments, not a borrowed enforcement statistic.

Run one response drill before a real request. Pick the AI system with the greatest effect on people and ask the owner to produce its classification, current instructions, test evidence, change history, notices, complaints, and vendor records within five business days. Then ask engineering to confirm every factual claim. The gaps reveal whether the problem is missing evidence, unclear ownership, or a control that never operated.

The drill should end with corrections, not a presentation. Assign a due date to each missing record, decide whether the system can continue while the gap remains, and preserve the drill result. Repeating it after a material release tests whether governance follows the product or merely describes the old version.

## The calendar decides which duty can be fined

The Act arrived in stages, and the AI Omnibus that entered into force on 27 July 2026 changed important dates. A compliance plan built from an old timeline can be both expensive and wrong.

Article 5 prohibitions and AI literacy duties started applying on 2 February 2025. Governance rules and duties for providers of general purpose AI models started on 2 August 2025. The Commission's enforcement powers for those model duties apply from 2 August 2026, while providers of models placed on the market before 2 August 2025 have until 2 August 2027 to comply.

Article 50 transparency rules generally apply from 2 August 2026. These include informing people when they interact with certain AI systems and disclosures for specified synthetic or manipulated content. A limited transition for some marking and detection duties can apply to generative systems placed on the market before that date until 2 December 2026. It is not a general transparency holiday.

Under the amended timetable, rules for high risk systems in listed sensitive uses apply from 2 December 2027. Rules for high risk AI embedded in products covered by specified EU product safety laws apply from 2 August 2028. Those extensions give teams time to prepare evidence and standards. They do not postpone prohibitions, current transparency duties, duties for general purpose models, or other laws such as the GDPR, consumer law, employment law, and product safety rules.

Maintain dates per obligation, not one date called AI Act compliance. For each system, record the provision, role, trigger, application date, transition condition, and evidence owner. Put a source date beside every legal conclusion. When EU legislation changes, the owner can identify which decisions need review without reopening the entire program.

The calendar also prevents premature spending. A deployer of an ordinary internal assistant should not buy a high risk conformity assessment because a vendor deck uses the phrase enterprise AI. The same company should not wait until 2027 to stop prohibited emotion inference in the workplace or to train staff who operate AI on its behalf.

Review the timeline quarterly and after each legal amendment. Track the Official Journal text separately from Commission guidelines and voluntary codes because they do different jobs. The regulation creates the duty, an amendment can move or change it, guidelines state the Commission's interpretation, and a code can offer one compliance route. Mixing those sources produces deadlines that nobody can defend.

## Most SMB exposure starts with four use cases

An SMB's realistic exposure usually comes from the purpose and impact of a system, not from how sophisticated its model sounds. Four common patterns deserve an early review.

| Use case | First classification question | Immediate concern |
| --- | --- | --- |
| CV ranking or worker scoring | Does it make or support employment decisions? | Prohibited features, high risk timing, data protection, and human oversight |
| Customer chatbot | Does a person know they are interacting with AI? | Article 50 notice, escalation, records, and misleading claims |
| Generated content on matters of public interest | Does a human exercise editorial review and responsibility? | Disclosure rules and proof of the review process |
| AI feature sold under your brand | Are you placing a system on the market as provider? | Provider duties, technical documentation, monitoring, and role drift |

A fifth pattern, employee use of general chat tools, often produces more governance noise than direct AI Act fine exposure. It still matters because staff can leak data, rely on fabricated output, or quietly move AI into hiring and customer decisions. Address it with access rules, training tied to the actual jobs, and an approval route for new uses. Do not label every prompt high risk.

Walk through the recruiting case. A 70-person company enables a tool that ranks applicants, then lets managers treat the top score as the interview list. The company is probably a deployer, not the underlying model provider. Employment use may fall into the high risk regime when the relevant provisions apply. If the tool also infers emotions during video interviews, the separate workplace prohibition may already control the analysis, subject to the narrow medical or safety exception. Waiting for the later high risk date would miss the live prohibition.

Now take a support chatbot. It answers shipping questions and hands difficult cases to staff. It is not high risk merely because it uses a large model. The immediate AI Act issue may be the transparency notice, while consumer protection and privacy rules govern its claims and data. The sensible control set is smaller: a clear notice, tested escalation, limits on consequential actions, incident ownership, and records of material changes.

Spend in proportion to the use. The regulation does not reward a 100-page policy that nobody connects to a system.

## A short register beats a shelf of policies

The most useful compliance artifact is a living exposure register that connects a deployment to a decision. One row should be enough for an executive, engineer, and lawyer to see why the company acted.

Use these fields for every AI system:

1. Name the business purpose, affected people, owner, vendor, model, and countries of use.
2. Record the company's role and the facts supporting it, including branding, modifications, and who sets the intended purpose.
3. Classify prohibited, high risk, transparency, general purpose model, or outside those categories, with the applicable date.
4. Link each required control to evidence, a named owner, and a review date.
5. Record incidents, complaints, vendor changes, model changes, and the decision to continue, restrict, or stop use.

The failure this prevents is common. Procurement approves an AI vendor on security terms. A product manager later exposes the tool to customers. Marketing calls the output proprietary. Engineering switches the underlying model. Human resources then reuses the feature to rank applications. Each team sees a local change, while the legal role and risk category move underneath the company.

Set change triggers in the delivery process. A release cannot quietly change intended purpose, affected group, decision authority, model, data source, customer visibility, or geography without reopening classification. The reviewer does not need to be a committee. The company needs one owner with authority to stop the release and a route to obtain specialist advice.

Preserve versions. A current policy cannot prove what control existed when an incident happened. Keep the classification memo, approved use, test result, notice text, training record, vendor terms, and release version together. If a regulator asks why the company believed a rule did not apply, a dated analysis is evidence. A memory reconstructed after the request is a story.

This register also makes budgeting sane. Counsel reviews the genuinely uncertain rows. Engineers test systems that can affect people. Low impact tools receive lighter controls. The company can explain why it spent differently across uses.

## Conduct determines where a case lands below the cap

Article 99 tells authorities to consider the nature, gravity, and duration of the infringement, its consequences, the system's purpose, the number of affected people, and the harm they suffered. The authority also looks at company size, turnover, market share, responsibility, technical and organisational measures, financial benefit, previous penalties, and cooperation.

Intent and negligence matter. So does persistence. A company that finds a weak notice, fixes it, preserves the record, and checks related systems presents different facts from one that suppresses a complaint and leaves the same design running. Corrective action does not erase a violation, but the Act expressly makes mitigation and cooperation relevant.

Multiple rules can meet in one event. A hiring system may raise AI Act, GDPR, discrimination, and employment law issues. Article 99 asks whether other authorities have already imposed fines for infringements arising from the same activity or omission. That guards against blind duplication in the amount assessment, but it does not merge the laws or prevent every parallel proceeding.

Financial exposure also includes measures that never appear in the fine table. A forced withdrawal can interrupt revenue. Reworking a product under deadline consumes engineering capacity. Contract claims, employee disputes, customer notices, and reputational damage can exceed the administrative penalty for a small company. The exposure register should name these consequences beside the statutory band so management does not optimise for the fine while ignoring the business interruption.

Authorities can also treat several provisions or systems in one proceeding. The Act limits the total fine for related infringements so that it does not exceed the maximum for the most serious infringement, but companies should not read that as a volume discount. Separate conduct, jurisdictions, people, and legal regimes can still create separate consequences.

When a request arrives, freeze deletion for relevant records, identify the exact legal entity and system version, and build a factual chronology. Separate verified facts from assumptions. Correct inaccurate earlier statements promptly and explain the correction. Do not let ten employees send partial answers through different channels.

The worst error a company creates for itself is misleading the authority while trying to look prepared. Article 99 gives that conduct its own fine band. A narrow, supported answer with a promised date for more information is better than a polished answer that engineering cannot prove.

## Evidence should follow the system into production

Compliance fails when it stays in a legal folder while the system changes weekly. Put evidence tasks into product and operations work: classification at approval, notice checks in release testing, model and prompt version records where they affect behavior, complaint routing in support, and periodic review owned by the business team.

Use a short evidence chain for each material control. State the requirement, the control, how the team tests it, where the result lives, who reviews failure, and what stops deployment. This is specific enough to audit and small enough to maintain. A policy that says humans oversee AI does not show which human can reverse a decision, what information they receive, or whether anyone measured automation bias.

Founders should ask for exceptions, not assurances. Which AI use has no owner? Which classification rests only on vendor marketing? Which check for a prohibited practice lacks a product test? Which customer notice is absent from the released interface? Which regulatory answer could the company not support within a week? Those questions expose operating risk faster than asking whether the company is compliant.

A Team & AI Audit can connect this inventory work to engineering cost and ownership decisions, but the company still needs legal counsel for conclusions tied to its facts and Member State. The useful handoff is a register counsel can review, not a blank request to interpret every AI tool the business has bought.

Set a board tolerance for unresolved high impact uses. If the team cannot establish the role, applicable date, and control owner, restrict the deployment until it can. The €35 million headline may never describe your company. An undocumented system affecting employees or customers can describe it tomorrow.
