EU AI Act fines for SMEs: the 2026 rules Spanish companies should use
EU AI Act fine ceilings for SMEs after the 2026 Omnibus, with current dates, proportionality rules, and a practical evidence checklist.
Javier Chulvi BernadLLM EngineerMadridSearch demand for “AI Act fines for SMEs” often starts with the largest numbers in the regulation: EUR 35 million and 7% of worldwide annual turnover. Those figures are real, but they are ceilings for the most serious category of infringement, not an automatic fine for an ordinary company using an AI assistant. A useful assessment starts with the company’s role, the system’s purpose, the applicable obligation, and the facts of the case.
This article reflects the EU AI Act as amended by Regulation (EU) 2026/1744, the Digital Omnibus on AI, which entered into force on 27 July 2026. It is practical information, not legal advice.
The three main fine ceilings
Article 99 establishes different maximum levels for different infringements:
| Category | Maximum stated in Article 99 |
|---|---|
| Non-compliance with prohibited AI practices under Article 5 | EUR 35 million or 7% of total worldwide annual turnover |
| Non-compliance with the operator obligations listed in Article 99(4), including specified transparency duties | EUR 15 million or 3% |
| Supplying incorrect, incomplete, or misleading information to notified bodies or competent authorities | EUR 7.5 million or 1% |
The category matters. A customer-support chatbot, a hiring system, a medical device, and a general internal writing assistant do not automatically have the same classification or obligations. Nor does every breach lead to the maximum. Article 99 requires penalties to be effective, proportionate, and dissuasive, and it lists case-specific factors such as the nature, gravity, duration, consequences, cooperation, previous infringements, and the organisation’s size.
The SME rule is important, but it is not immunity
For undertakings generally, the applicable maximum can be the higher of the fixed amount or turnover percentage. For SMEs, including start-ups, Article 99 applies the lower of those two maxima. That proportionality rule can substantially reduce the ceiling for a smaller company.
It does not make compliance optional. The authority still evaluates the relevant infringement and circumstances. A simple turnover example can illustrate a ceiling, but it cannot predict the fine a real company would receive. Legal form, group turnover, role in the AI value chain, national enforcement rules, and the particular conduct can all matter.
The 2026 Omnibus also extended a lower-of-the-two rule to small mid-cap companies for the fine categories addressed by the amendment. Companies should confirm whether they meet the applicable SME or small mid-cap definition instead of relying on employee count alone.
What changed in July 2026
The Digital Omnibus on AI entered into force on 27 July 2026. Among other changes, the European Commission reports that it extended application dates for high-risk systems: 2 December 2027 for the Annex III categories and 2 August 2028 for high-risk systems embedded in products covered by Annex I.
It also changed Article 4. Providers and deployers must take measures to support the development of AI literacy among staff and other people who operate AI systems on their behalf. That is more precise than saying every company must guarantee a fixed competence level for every worker. Sensible measures can include role-based training, approved-tool guidance, escalation routes, and records showing what the organisation has done.
The Omnibus did not remove the need to classify systems, respect prohibited-practice rules, or comply with obligations that are already applicable. A changed deadline for one high-risk requirement is not a general postponement of the entire AI Act.
A five-question SME triage
Before estimating fine exposure, document answers to five questions:
- What is the company’s role? Is it a provider, deployer, importer, distributor, product manufacturer, or another operator?
- What is the intended use? Recruitment, credit, healthcare, safety, biometric use, customer interaction, and internal knowledge work can lead to very different analyses.
- Is the system prohibited, high-risk, transparency-regulated, or outside those categories? Classification should follow the regulation and current official guidance.
- Which rules apply now? Record the relevant article and application date instead of relying on an old compliance calendar.
- What evidence exists? Keep the system inventory, owner, purpose, approved data, provider information, training measures, human oversight, incidents, and decisions.
AESIA’s practical guides can help Spanish organisations structure this work, especially for high-risk systems. AESIA expressly describes those guides as non-binding and subject to revision; they support implementation but do not replace the regulation or case-specific advice.
Controls that are useful even before a legal classification is complete
A small company can reduce avoidable risk with a compact operating record:
- Maintain an inventory of AI systems and named owners.
- Record intended purpose, users, data categories, and external providers.
- Prohibit uses that have not been reviewed where the impact is sensitive.
- Give staff clear acceptable-use and escalation instructions.
- Keep meaningful human review for consequential decisions.
- Preserve vendor documentation and changes to system configuration.
- Log incidents, complaints, corrective actions, and review dates.
- Revisit the inventory when a tool, purpose, model, or integration changes.
The AI governance toolkit for SMEs provides a starting structure, and the broader AI Act guide for Spanish SMEs explains the risk-based framework. These resources are operational aids, not a substitute for legal analysis.
Where Polp fits—and where it does not
Polp’s public product page describes answers grounded in connected company documents with traceable sources. That can help a team retrieve its approved policies and evidence, but using Polp does not by itself classify an AI system, satisfy every AI Act duty, or guarantee compliance. The organisation remains responsible for its use case, governance, data, and decisions.
A sensible next step is to assemble the inventory and evidence first. If the use case affects employment, credit, healthcare, safety, biometrics, or fundamental rights, obtain qualified legal and technical review. For a walkthrough of how Polp can support governed internal knowledge, request a demo.