EU AI Act Fines: What Small Businesses and SMEs Actually Risk

The headline figures from the EU AI Act are striking: fines of up to 7% of global annual turnover, or up to €35 million for the most serious violations. But those numbers apply to a narrow category of prohibited AI practices — the kind that affect fundamental rights, social scoring, and manipulation of human behavior. For the vast majority of small businesses and sole traders, the relevant fine tier is considerably lower. Here is a realistic picture of what enforcement looks like for SMEs.

The Three-Tier Fine Structure Under Article 99

Article 99 of the EU AI Act establishes three distinct levels of administrative fines, calibrated to the severity of the violation:

Where most website owners sit: If your AI Act exposure is a chatbot without a disclosure notice or unlabeled AI-generated content on your site, you are in the Tier 2 category — up to 3% of global annual turnover or €15 million, whichever is higher. This is the tier that applies to Article 50 transparency violations. It sits below the prohibited-practices tier, but it is still a serious obligation, not the lowest band.

What 3% of Turnover Actually Means for an SME

The Article 50 tier is well below the €35 million ceiling, but the calculation is still material for small businesses:

These are maximum figures — regulators are not required to impose the maximum, and in practice initial enforcement actions for minor violations by small operators are far more likely to result in a warning and corrective order than an immediate fine. But failing to comply with a corrective order escalates the situation considerably.

Proportionality: What the Regulation Actually Says

Article 99(6) explicitly states that when determining the fine amount, national supervisory authorities must take into account the size and market share of the operator, the nature, gravity and duration of the infringement, and whether the infringement was intentional or negligent. For SMEs and microenterprises, this proportionality principle is a meaningful protection.

A microenterprise that had no awareness of the regulation and promptly remediated when notified is in a very different position from a mid-sized company that was repeatedly warned and continued non-compliant practices. Regulators across the EU have generally followed a similar approach under GDPR — early enforcement concentrated on larger organisations, with smaller businesses receiving guidance and correction notices first.

That said, the GDPR precedent cuts both ways. Supervisory authorities demonstrated that they are willing to fine SMEs when violations are clear, repeated, or involve significant harm to consumers. Transparency violations under Article 50 — particularly deceptive chatbots that users believe are human — could attract more serious regulatory attention than, say, a missing cookie disclosure.

Which Authorities Are Likely to Enforce First

Each EU member state designates one or more national competent authorities (NCAs) responsible for supervising AI Act compliance. These are typically the existing data protection or consumer protection bodies. The countries most likely to begin enforcement activity earliest, based on their GDPR enforcement track record and stated AI Act priorities, are:

The European AI Office, established within the European Commission, has an oversight role for general-purpose AI models but will not directly handle most SME-level transparency violations — those stay with national authorities.

Timeline: August 2026 and Beyond

The transparency obligations of Article 50 apply from 2 August 2026. National supervisory authorities need to be formally designated before they can begin issuing fines, and some member states are still working through the designation process. This means formal enforcement with financial penalties may not arrive on day one — but regulatory attention, spot checks, and corrective orders can start immediately after the deadline.

The practical enforcement window for SMEs is likely to be the second half of 2026 and into 2027. By that point, regulators will have had months to develop templates and processes, and consumer complaints about undisclosed AI chatbots or AI-generated content will provide easy investigation starting points.

The Real Risk Is Not the Fine Itself

For most small businesses, the direct financial exposure from an Article 50 fine is manageable — especially at the lower end of the scale. The more significant risks are:

The simplest risk mitigation for most SMEs is to address the Article 50 transparency requirements now — they are not technically complex, and the compliance cost is low compared to any of the above scenarios. Use legibright.eu to check your current exposure in seconds. The checker identifies chatbot disclosure gaps and AI content labeling issues, so you know exactly what needs attention before the August deadline.

This article is for general information only and does not constitute legal advice. For your specific situation, consult a qualified legal professional.