EU AI Act Fines: What Small Businesses and SMEs Actually Risk
The headline figures from the EU AI Act are striking: fines of up to 7% of global annual turnover, or up to €35 million for the most serious violations. But those numbers apply to a narrow category of prohibited AI practices — the kind that affect fundamental rights, social scoring, and manipulation of human behavior. For the vast majority of small businesses and sole traders, the relevant fine tier is considerably lower. Here is a realistic picture of what enforcement looks like for SMEs.
The Three-Tier Fine Structure Under Article 99
Article 99 of the EU AI Act establishes three distinct levels of administrative fines, calibrated to the severity of the violation:
- Tier 1 — up to €35 million or 7% of global turnover: Reserved for prohibited AI practices under Article 5. These are systems that manipulate human behavior through subliminal techniques, exploit vulnerabilities, enable mass surveillance, or conduct social scoring by public authorities. Most ordinary businesses will never come near this tier.
- Tier 2 — up to €15 million or 3% of global turnover: Applies to non-compliance with operator obligations, including the transparency obligations under Article 50 (chatbot disclosure and AI content labeling) as well as requirements affecting high-risk AI systems (Annex III) in sensitive sectors like healthcare, employment, and credit. This is the tier that covers most website owners.
- Tier 3 — up to €7.5 million or 1% of global turnover: Applies only to supplying incorrect, incomplete, or misleading information to authorities — not to Article 50 transparency obligations.
Where most website owners sit: If your AI Act exposure is a chatbot without a disclosure notice or unlabeled AI-generated content on your site, you are in the Tier 2 category — up to 3% of global annual turnover or €15 million, whichever is higher. This is the tier that applies to Article 50 transparency violations. It sits below the prohibited-practices tier, but it is still a serious obligation, not the lowest band.
What 3% of Turnover Actually Means for an SME
The Article 50 tier is well below the €35 million ceiling, but the calculation is still material for small businesses:
- A freelancer or sole trader with €80,000 in annual revenue: 3% = €2,400
- A small e-commerce store with €300,000 in annual revenue: 3% = €9,000
- A growing SaaS with €1.5 million in annual revenue: 3% = €45,000
- A mid-sized digital agency with €5 million in annual revenue: 3% = €150,000
These are maximum figures — regulators are not required to impose the maximum, and in practice initial enforcement actions for minor violations by small operators are far more likely to result in a warning and corrective order than an immediate fine. But failing to comply with a corrective order escalates the situation considerably.
Proportionality: What the Regulation Actually Says
Article 99(6) explicitly states that when determining the fine amount, national supervisory authorities must take into account the size and market share of the operator, the nature, gravity and duration of the infringement, and whether the infringement was intentional or negligent. For SMEs and microenterprises, this proportionality principle is a meaningful protection.
A microenterprise that had no awareness of the regulation and promptly remediated when notified is in a very different position from a mid-sized company that was repeatedly warned and continued non-compliant practices. Regulators across the EU have generally followed a similar approach under GDPR — early enforcement concentrated on larger organisations, with smaller businesses receiving guidance and correction notices first.
That said, the GDPR precedent cuts both ways. Supervisory authorities demonstrated that they are willing to fine SMEs when violations are clear, repeated, or involve significant harm to consumers. Transparency violations under Article 50 — particularly deceptive chatbots that users believe are human — could attract more serious regulatory attention than, say, a missing cookie disclosure.
Which Authorities Are Likely to Enforce First
Each EU member state designates one or more national competent authorities (NCAs) responsible for supervising AI Act compliance. These are typically the existing data protection or consumer protection bodies. The countries most likely to begin enforcement activity earliest, based on their GDPR enforcement track record and stated AI Act priorities, are:
- France (CNIL) — among the most active EU data protection authorities, with a strong track record of enforcement and well-resourced AI expertise
- Netherlands (Autoriteit Persoonsgegevens) — proactive on digital rights and technology regulation, early statements on AI Act enforcement priorities
- Germany (BfDI and state-level DPAs) — complex federal structure but well-resourced authorities with significant technical capacity
- Ireland (DPC) — responsible for many large tech companies' EU operations, though enforcement timelines have historically been longer
The European AI Office, established within the European Commission, has an oversight role for general-purpose AI models but will not directly handle most SME-level transparency violations — those stay with national authorities.
Timeline: August 2026 and Beyond
The transparency obligations of Article 50 apply from 2 August 2026. National supervisory authorities need to be formally designated before they can begin issuing fines, and some member states are still working through the designation process. This means formal enforcement with financial penalties may not arrive on day one — but regulatory attention, spot checks, and corrective orders can start immediately after the deadline.
The practical enforcement window for SMEs is likely to be the second half of 2026 and into 2027. By that point, regulators will have had months to develop templates and processes, and consumer complaints about undisclosed AI chatbots or AI-generated content will provide easy investigation starting points.
The Real Risk Is Not the Fine Itself
For most small businesses, the direct financial exposure from an Article 50 fine is manageable — especially at the lower end of the scale. The more significant risks are:
- Corrective orders: A supervisory authority can require you to make specific changes to your site within a tight timeframe. Failure to comply triggers higher penalties and, potentially, orders to suspend AI functionality entirely.
- Reputational damage: Enforcement decisions are public. A finding that your chatbot deceived users into thinking they were speaking with a human is not good press for a customer-facing business.
- Operational disruption: Being under investigation, responding to regulatory enquiries, and engaging legal counsel costs time and money that may exceed the fine itself.
The simplest risk mitigation for most SMEs is to address the Article 50 transparency requirements now — they are not technically complex, and the compliance cost is low compared to any of the above scenarios. Use legibright.eu to check your current exposure in seconds. The checker identifies chatbot disclosure gaps and AI content labeling issues, so you know exactly what needs attention before the August deadline.
This article is for general information only and does not constitute legal advice. For your specific situation, consult a qualified legal professional.