The real maximum EU AI Act fine for an SME is not 35 million euro
For a 50-person SaaS at 10M euro turnover, the real maximum EU AI Act fine is about 700,000 euro, not the 35 million you keep seeing quoted. Article 99(6) is why.
Download the PDF guide700,000 euro. That is the real maximum EU AI Act fine for a 50-person SaaS doing 10M euro in global turnover. Not the 35 million euro you keep seeing quoted.
The part most coverage skips
Article 99 sets two numbers for every violation: a fixed euro cap and a percentage of global turnover. For most companies the fine is the higher of the two. But Article 99(6) carves out SMEs and start-ups, and for them it flips to the lower of the two.
What that means in numbers
- A 50-person firm at 10M euro turnover is an SME.
- For the worst category, prohibited AI practices, the cap is the lower of 35M euro and 7% of turnover. 7% of 10M is 700,000 euro, so the 35M figure never touches you.
- For the tier most SaaS actually worry about, high-risk non-compliance at 3%, it drops to 300,000 euro.
Still real money, but a very different planning conversation than 35M euro.
The third, lowest tier: getting the paperwork wrong
The 7 percent and 3 percent legs are the two everyone quotes, but Article 99 has a third ceiling, and it is the one an SME is most likely to actually meet. Article 99(5) covers supplying incorrect, incomplete or misleading information to a notified body or a national competent authority when they ask for it, and it is capped below both of the others: up to 7.5 million euro or 1 percent of worldwide turnover. The same Article 99(6) rule applies, so for an SME it is the lower of the two, which for the 50-person firm at 10M euro turnover is about 100,000 euro, not 7.5 million.
That leaves an SME exposure ladder of three rungs, each of them the turnover percentage rather than the fixed cap: about 700,000 euro for a prohibited practice, about 300,000 euro for missing a high-risk or transparency duty, and about 100,000 euro for a bad or incomplete answer to a regulator. The bottom rung is worth planning around precisely because it is the least dramatic: it is triggered by a documentation gap, an out-of-date technical file or a conformity record that does not match what you actually shipped, rather than by any deliberate misuse. Keeping those records straight and current is the cheapest insurance against the one tier a compliant-but-disorganised company is most likely to trip.
The fine tracks the rule you break, not a single headline number
The ceiling depends on which obligation you fall short of, so the first honest step is to know which tier your system is in. Running a prohibited practice sits in the 7% leg, the worst one. Missing the obligations that come with a high-risk system, or the transparency duties on a limited-risk one, sits in the lower 3% leg. Minimal-risk uses, which is most everyday AI, carry no dedicated obligations of this kind at all. So the exposure and the work both follow from the classification: figure out the tier first, and the fine calculator turns your own turnover into the real number rather than the 35M headline.
When these fines can actually be levied
The amount is only half the planning question. The other half is from when a regulator can impose it, because the tiers switch on at different times. The 7 percent leg is already live: prohibited AI practices have been banned since 2 February 2025 and the penalty provisions of the Act have applied since 2 August 2025, so that ceiling is not hypothetical. The 3 percent leg attaches to obligations that start later. The Article 50 transparency duties apply from 2 August 2026, while the high-risk obligations were pushed back by the 2026 digital omnibus to 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for AI built into regulated products. A fine for missing a high-risk obligation cannot land before that obligation itself applies, so for most SMEs the nearer date to plan around is the 2 August 2026 transparency one, not the high-risk deadline the headlines fixate on. General-purpose AI model makers sit on a separate Article 101 track that the AI Office can enforce from 2 August 2026, but that is aimed at foundation-model providers, not most businesses that use AI inside a product.
Frequently asked questions
What is the real maximum EU AI Act fine for an SME?
For a 50-person SaaS at 10M euro turnover it is about 700,000 euro, not the 35 million you see quoted. Article 99(6) caps SME and start-up fines at the lower of the fixed amount and the percentage, so for a prohibited practice it is 7% of 10M (700,000 euro), and the 35M figure never applies.
Does the 35 million euro AI Act fine apply to small companies?
No. The 35M euro figure is the higher leg aimed at large companies. Under Article 99(6) SMEs and start-ups are capped at the lower of the fixed amount and the turnover percentage, so a small firm real maximum is the percentage of its own turnover.
What is the AI Act fine for high-risk non-compliance for an SME?
For an SME the high-risk tier (3%) is the lower of the fixed cap and 3% of turnover. At 10M euro turnover that is about 300,000 euro, well below the headline figures aimed at large firms.
Is there a lower AI Act fine tier than the 3 percent one?
Yes, and it is the one an SME is most likely to meet. Article 99(5) sets a third ceiling for supplying incorrect, incomplete or misleading information to a notified body or a national competent authority when they ask: up to 7.5 million euro or 1 percent of worldwide turnover. For an SME the Article 99(6) rule again takes the lower of the two, so for a 10M euro-turnover firm it is about 100,000 euro. It bites on a documentation gap, an out-of-date technical file or an incomplete answer to a regulator, rather than any deliberate misuse.
When do EU AI Act fines start applying?
The tiers switch on at different dates. The 7 percent leg for prohibited AI practices is already enforceable: those practices have been banned since 2 February 2025 and the penalty provisions of the Act have applied since 2 August 2025. The 3 percent leg attaches to duties that phase in later, the Article 50 transparency rules from 2 August 2026 and the high-risk obligations, postponed by the 2026 digital omnibus, from 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for AI inside regulated products. A fine cannot precede the obligation it enforces, so the date that binds you depends on which tier your system is in.
Run the numbers for your own case
Every figure above comes from a free tool you can use in your browser, with no signup.
Size your own AI Act exposureLatest news on this
A dated, sourced update to a price or rule covered above.
What to actually do about it
For most SMEs the honest answer is limited-risk or minimal-risk, where the fix is a transparency notice and an AI inventory rather than any spend, and our free generators cover both. The cost only turns real in the high-risk tier, where the conformity regime means keeping risk-management, data-governance, and oversight records audit-ready by hand. If that is where you landed:
- Track governance evidence with Vanta (coming soon)Collects and monitors compliance evidence on a schedule and maps it to frameworks, which helps once a high-risk system means standing risk-management, data-governance, and oversight records you have to keep current. Worth it only if you actually landed in the high-risk tier or are already running a SOC 2 or ISO 27001 program; if you are limited-risk or minimal-risk, the free transparency notice and a simple register are all you need, and paying for evidence tooling would be money the fine math above says you do not have to spend.
If you buy through a link above we may earn a commission, at no extra cost to you. It never changes which option we call the cheaper or better fit; the math on this page is the same either way.
Get the next cost breakdown by email
We publish a new honest, tool-backed breakdown like this every few days. Leave your email and we will let you know when the next one goes up. One confirmation link, nothing else until you click it.
More data-stories
What SOC 2 really costs a startup in 2026
For a 25-person B2B SaaS on AWS, SOC 2 Type II in year one runs about 63,000 to 98,000 dollars. The auditor invoice is the small part.
SOC 2 vs ISO 27001: which does a European startup actually need
Most guides answer this from a North American desk, where SOC 2 is the default. If you sell from Europe, the honest answer is usually the other one. Here is how to decide, what each costs, and why the choice is the buyer’s, not yours.
Vanta vs Drata vs Secureframe: how to actually choose a SOC 2 platform
The three compliance-automation platforms overlap so heavily on features that price is the wrong first question, especially since none of them publish list prices. Here is what actually separates them, and the two cost lines the platform quote never includes.