AI Act sanctions can reach 35 million euros or 7 % of worldwide annual turnover for the most serious breaches. But for a small business the rule flips: the fine is capped at the lower of the fixed amount and the percentage, not the higher one. In practice, a compliant small organisation risks almost nothing, and a negligent one is mostly exposed to the middle tier of 15 million euros or 3 %.
Read the full guide
EU AI Act 2026: The Complete Compliance Guide for SMEs and Nonprofits
Answer a few questions and get a personalized assessment with recommendations tailored to your industry.
Assess my AI maturityRelated articles
Dive deeper with these complementary articles.
The EU AI Act (Regulation 2024/1689) applies to your SME or nonprofit as soon as you use an AI tool, even a simple ChatGPT subscription. Since February 2025 you must train your teams; on 2 August 2026 the transparency obligations and the penalty regime take effect.
AI Act sanctions can reach 35 million euros or 7 % of worldwide annual turnover for the most serious breaches. But for a small business the rule flips: the fine is capped at the lower of the fixed amount and the percentage, not the higher one. In practice, a compliant small organisation risks almost nothing, and a negligent one is mostly exposed to the middle tier of 15 million euros or 3 %.
This article breaks down the three penalty tiers set by EU Regulation 2024/1689 (Article 99), when each sanction takes effect, which authorities enforce them, and above all what actually triggers a fine when you are an SME or a nonprofit that uses AI without building it. For the full picture of obligations, start from the AI Act compliance guide for SMEs.
The regulation sets three levels of sanction, from heaviest to lightest, and always keeps the higher of the fixed amount and the turnover percentage (except for SMEs, see below).
Here is the exact structure laid out in Article 99 of EU Regulation 2024/1689:
| Type of breach | Maximum fine | Legal basis |
|---|---|---|
| Use of a prohibited AI practice (Article 5) | 35 M€ or 7 % of worldwide annual turnover | Art. 99(3) |
| Failure to meet obligations (provider, deployer, transparency, notified body) | 15 M€ or 3 % of worldwide annual turnover | Art. 99(4) |
| Incorrect, incomplete or misleading information given to an authority | 7.5 M€ or 1 % of worldwide annual turnover | Art. 99(5) |
The top tier targets the prohibited practices of Article 5: social scoring, harmful manipulation, emotion recognition in the workplace, biometric categorisation, among others. These are uses a typical SME almost never deploys.
The middle tier, at 15 million euros or 3 %, is the one that concerns the most organisations. It covers breaches of the transparency obligations in Article 50, such as failing to flag a chatbot or AI-generated content. This tier also applies to breaches by deployers, meaning organisations that use an AI system in a professional setting.
Article 99(6) reverses the usual logic: for an SME or start-up, the fine applied is the lower of the two ceilings, the fixed amount or the percentage, not the higher one.
In concrete terms, a company with 2 million euros in turnover that commits a middle-tier breach will not face 15 million euros, but 3 % of its turnover, meaning 60,000 euros at most, since that figure is below the fixed amount. The regulation also explicitly requires that the economic viability of the organisation be taken into account.
This provision changes how the risk should be read. The alarmist headlines about 35 million euros really target large model providers, not a micro-business or a nonprofit using ChatGPT day to day. The French public administration confirmed this in its 7 August 2026 communication: authorities apply the principle of proportionality for SMEs. That does not mean zero risk, but a risk calibrated to the real size of the organisation.
For an SME or nonprofit that uses AI without building it, three situations concentrate most of the risk: a prohibited practice, a transparency failure, or misleading information given to an inspector.
The concrete cases that expose a small organisation to a fine are rarer than assumed:
By contrast, simply using a generative AI tool to write, summarise or code is not sanctionable in itself. GDPR compliance remains a separate obligation that stacks with the AI Act rather than replacing it. To know exactly which category your organisation falls into, the article on who is affected by the AI Act details the provider, deployer and user statuses.
The general penalty regime took effect on 2 August 2025, but the various obligations, and therefore the associated fines, activate on staggered dates through December 2027.
The milestones to remember:
The full AI Act timeline lays out each of these dates in detail. The delayed entry of the high-risk track means that, today, an SME's real exposure is mostly about transparency and prohibited practices, not yet the heavy documentation obligations of high-risk systems.
Fines are issued by national market surveillance authorities, with a specific role for the European AI Office and the Commission over general-purpose models.
In France, the authorities designated under the regulation lead the supervision. The European AI Office and the European Data Protection Supervisor act on transparency obligations. For providers of general-purpose AI models, such as large language models, the European Commission supervises and sanctions directly since 2 August 2026, under Article 101.
The final amount is never automatic. Article 99(7) requires taking into account the severity of the breach, its duration, the organisation's degree of cooperation, whether the breach was intentional, and the technical and organisational measures already in place. An organisation that has documented its uses and trained its teams starts with a real advantage in an inspection.
The best protection against a sanction is not legal, it is operational: map your AI uses, flag generated content, and train your teams.
Three workstreams cut most of the risk for an SME or nonprofit:
These actions are proportionate to the size of an SME and can be carried out in a few weeks, not several months.
Can an SME really receive a 35 million euro fine? No, except in extreme cases. This ceiling targets the prohibited practices of Article 5, very rare in an SME, and it is in any case reduced to the turnover percentage for a small organisation, under Article 99(6).
Is using ChatGPT or another AI tool sanctionable? No, using a generative AI tool to work is not a breach. The risk comes from a prohibited use, a transparency failure on generated content, or misleading information given to an authority.
Since when do the sanctions apply? The penalty regime has applied since 2 August 2025. Transparency obligations have been sanctionable since 2 August 2026, and high-risk system obligations from 2 December 2027.
Who decides the fine amount? National surveillance authorities, taking into account severity, duration, cooperation and measures already in place, following the criteria of Article 99(7). The European Commission acts directly for general-purpose models.
Does the AI Act replace GDPR? No. The two texts stack. A single situation can trigger both an AI Act sanction and a GDPR sanction, with different authorities and different logics.
What does a nonprofit risk when using AI? The same rules apply, with the principle of proportionality. A nonprofit that uses AI for routine tasks and flags its generated content stays at very low risk.
GrowthPerf is a Qualiopi-certified training organisation specialising in AI and no-code for SMEs and nonprofits. We help organisations map their AI uses, bring their transparency into compliance and train their teams to the level the regulation expects, without needless jargon or costly over-compliance.
Our AI training for business covers concrete uses and the compliance basics that matter day to day. To review your situation and priorities, book a free 30-minute audit: together we identify your real exposure level and the first actions to take.