EU AI Act: How expensive can it be for your company?
Which fine frameworks apply, why SMEs are also affected and how AI inventory, role clarification and evidence reduce risks.

TL;DR
- Up to 35 million euros or 7% turnover in prohibited practices.
- Role and risk class determine the specific obligations.
- Evidence capability is just as important as good intentions.
- An AI inventory is the pragmatic first step.
The EU AI Act not only brings new obligations for companies, but also noticeable financial risks. Many discussions quickly revolve around the large maximum amounts: 35 million euros, 15 million euros or certain percentages of global annual sales. At first glance, these numbers seem like an issue for corporations. However, this would be a dangerous mistake for small and SMEs.
Because the real question is not just: “What is the maximum amount a fine can be?” The more important question is: “Which AI systems do we use, what role do we have in them, what obligations do we have and what evidence can we provide in an emergency?”
This is precisely where the greatest risks arise in practice.
The fines at a glance
The EU AI Act works with graduated sanctions. The highest scope concerns prohibited AI practices. Violations of such bans can be sanctioned with up to 35 million euros or up to 7 percent of global annual turnover. The deciding factor is generally the higher amount. For SMEs and start-ups, special rules apply under Article 99, where the lower value may apply.
A second important level concerns violations of other obligations, such as obligations of providers, operators or transparency obligations. Here the framework can be up to 15 million euros or up to 3 percent of global annual sales.
A third level concerns false, incomplete or misleading information provided to competent authorities or notified bodies. Here the framework can be up to 7.5 million euros or up to 1 percent of global annual sales.
In addition, there are separate regulations for providers of general-purpose AI models. Significant sanctions can also be relevant here if obligations are not met, information is not provided or orders are not followed.
It is important to note that these amounts are maximum limits. The actual sanction depends on the individual case. Authorities take into account, among other things, the type, severity and duration of the violation, the people affected, possible damage, company size, cooperation, intent or negligence as well as existing technical and organizational measures.
Why global annual sales are relevant
Many companies underestimate the relationship to sales. For larger companies, the percentage share can quickly exceed the fixed euro amounts. For smaller companies, even lower percentages can be economically sensitive.
A simple example: With a worldwide annual turnover of 10 million euros, 3 percent already corresponds to 300,000 euros. With a turnover of 100 million euros, 3 percent would be 3 million euros. With 1 billion euros in sales, 7 percent would already be 70 million euros.
These calculations do not yet say what fine would actually be imposed. However, they show why AI compliance does not only become relevant when a company is very large or develops highly complex AI. The use of external AI tools can also trigger obligations if they are used in sensitive processes, with personal data or in areas with increased risk.
The biggest risk is often not “banned AI”
When it comes to the EU AI Act, many companies first think of extreme scenarios: social scoring, unauthorized manipulation or problematic biometric applications. These issues are important, but they are not the only area of risk.
For many organizations, the realistic risks lie elsewhere. For example, if a high-risk system is not recognized as such. Or when a company misjudges its own role. Anyone who believes they are just a user of a system can trigger additional obligations under certain circumstances, for example if the purpose, method of use or integration are significantly changed.
A lack of evidence can also be problematic. A company can have good intentions and still be underprepared if documentation, logs, training, vendor documents, or internal approvals cannot be found. Especially when it comes to authorities, it's not just what is claimed internally that counts, but what can be comprehensibly proven.
Another cost lever is poor communication with authorities. False, incomplete or contradictory information carries its own fines. It should therefore be clear who prepares information, who checks it and on what documentation it is based.
What companies should specifically check now
The first step is an AI inventory. Many companies do not fully understand where AI is already being used. Departments use chatbots, marketing tools, analysis functions, automation or AI functions in existing software. Without an overview, no reliable risk assessment is possible.
A good AI inventory answers at least these questions: Which system is used? In which department? For what purpose? With what data? From which provider? In what process? And who is responsible internally?
In the second step, the role should be clarified for each relevant system. Are you a provider, operator, dealer, importer or downstream provider? This classification is crucial because duties depend heavily on the role.
This is followed by the risk classification. Does a system affect prohibited practices? Could it fall into a high-risk area, such as human resources, education, critical infrastructure or sensitive decision-making processes? Are there transparency obligations towards users, customers, applicants or employees?
Only on this basis can it be meaningfully decided which measures need to be prioritized.
Evidence is your protective shield
A central point in the EU AI Act context is verifiability. Companies should not only implement measures, but also document them. This includes vendor documents, technical documentation, compliance information, logging concepts, training records, data protection audits, role descriptions, release processes and risk assessments.
Human supervision is particularly important. AI spending should not be adopted blindly when it can have relevant impact. Clear responsibilities, options for intervention and escalation channels are needed.
Training is also becoming more important. People who work with AI systems must adequately understand their capabilities and limitations. This not only affects IT teams, but also departments, managers and employees who evaluate or further process AI results.
How to pragmatically reduce risk
AI compliance doesn’t have to start with a huge bureaucratic project. A pragmatic 30-day approach makes more sense.
In the first phase, an AI inventory is created. Roles and risk classes are then provisionally determined. Evidence should then be requested for critical systems and gaps documented. Then it's about operationalization: human supervision, training, logs, information requirements and reporting channels. Finally, management should receive a prioritized risk list with those responsible, deadlines and specific measures.
It is important not to wait for everything to be perfect. An incomplete but actively maintained AI inventory is better than no overview at all. A documented acceptance is better than an oral decision without evidence. A clear owner is better than diffuse responsibility.
Conclusion: The EU AI Act is a management issue
The fines of the EU AI Act are high enough to attract attention. But the real value of good preparation lies not only in avoiding sanctions. It is also about using AI in a safer, more transparent and controllable way.
Companies should therefore not view the issue of fines in isolation. More relevant is the combination of AI inventory, role clarification, risk assessment, documentation, training, supervision and clear decision-making paths.
Anyone who knows today which AI systems are used in the company, which obligations may be relevant and which evidence is missing can reduce risks in a targeted manner. If you only start searching in an emergency, you lose time, control and trust.
The EU AI Act does not make AI compliance a side issue for lawyers, but rather a management task. Companies that take a structured approach early on not only create legal certainty, but also a better basis for effective AI projects.
Sources
- 1.Regulation (EU) 2024/1689 – in particular Article 99 — European Union, 2024
- 2.AI Act – regulatory overview — European Commission
