The maximum amount of the penalties set out in the European AI Act (€35 million or 7% of worldwide turnover) circulates widely, often without explanation. For an SME, this figure tends to trigger two excessive reactions: panic, or indifference because it seems unrealistic. Neither is the right one.
A Ceiling, Not an Automatic Amount
This amount is a maximum ceiling, intended for the most serious breaches: typically uses classified as unacceptable risk. It does not apply automatically or uniformly to every minor irregularity. The regulation provides for a graduated scale of penalties depending on the severity of the breach.
What Really Matters for an SME
The real risk for most SMEs is not incurring the maximum penalty, but not knowing where they stand: which tools are being used, with what data, and at what level of risk. It is this lack of visibility that exposes a company, far more than the use of AI itself.
The Timeline to Know
- Since February 2025: staff training on AI and a ban on certain unacceptable-risk practices.
- Since 2 August 2026: a new set of obligations, notably on the transparency of AI systems and their classification by risk level.
What an SME Can Do, Concretely
Three actions address most of the risk: identifying the actual AI uses within the company, classifying each one by risk level, and keeping an up-to-date register. This is not a complex process in itself: it is mainly a process that few companies have carried out yet.
This regulatory timeline may change. This guide does not replace personalized legal advice for your situation.