"€35 million." It sells the story, and it's technically true — the AI Act's maximum penalty for prohibited AI practices is €35M or 7% of global annual turnover, whichever is higher. Meaningless to a 60-person B2B firm in Leeds or Cork — and the wrong number to plan around.
Here's the one that matters: €15 million or 3% of global turnover, the tier for breaching the Act's obligations. Documentation you never wrote. Logging you never configured. AI literacy training you never ran. Those live here, and here is where SMEs get caught. For the full picture, see our guide to the EU AI Act for UK and Irish businesses — this is the numbers-first companion to it.
The three penalty tiers, in plain English
Article 99 of the AI Act sets three penalty tiers. They scale with the seriousness of the breach, not with how scary the technology sounds.
Tier 1 · Prohibited practices (Art. 99(3))
Up to €35M or 7% of global annual turnover — whichever is higher
This covers practices the EU has banned outright: social scoring, manipulative systems, untargeted facial-image scraping, emotion recognition in workplaces and schools. Most SMEs will never be in this tier — they don't build these systems.
Tier 2 · Obligations for providers and deployers (Art. 99(4))
Up to €15M or 3% of global annual turnover — whichever is higher
The SME tier. It covers failure to meet the Act's requirements: risk management, technical documentation, log-keeping, human oversight, transparency duties, and Article 4 AI literacy — ensuring staff are competent to use the AI tools they're given. It's also the tier where gaps are cheapest to close.
Tier 3 · Incorrect or misleading information (Art. 99(5))
Up to €7.5M or 1% of global annual turnover — whichever is higher
Supplying incorrect, incomplete or misleading information to authorities investigating your AI use. This tier punishes the cover-up, not the gap.
One piece of arithmetic SMEs miss: for most small firms, the percentage is higher than the euro cap. 3% of turnover bites long before €15M does. A £5M-turnover firm isn't risking €15M — it's risking 3%, roughly £150K. Plan against the percentage, not the headline.
How enforcement actually starts
Enforcement doesn't start with a fine. The Act is policed by national market-surveillance authorities, and their standard opening move is an information request: tell us what AI you use and how you manage it. Fines sit at the end of a ladder — information requests, then corrective action orders, then penalties.
Three consequences follow:
- Your inventory is your defence. Answering an information request with a documented AI register, literacy records and a risk classification is a correspondence. Answering "we'd have to check with everyone" is an investigation.
- Cooperation is priced in. Authorities weigh the severity and duration of the breach, company size, and how cooperative you are. Fines scale with risk class and cooperation — stonewalling moves you up the ladder.
- In Ireland, the DPC is in the room. Ireland has assigned market-surveillance duties alongside the Data Protection Commission — a regulator with a track record of policing extraterritorial EU law. Assume competent, GDPR-style enforcement.
What UK SMEs specifically risk
First, jurisdiction. The Act applies extraterritorially — EU customers, EU-used output, or EU-based users put you in scope wherever you're registered. The three tests are unpacked in does the EU AI Act apply to UK businesses? — worth two minutes, because the penalties below only matter if the Act reaches you.
Then, the money. A plausible mid-range case: a £5M-turnover UK B2B services firm running standard AI tools, caught by an EU customer's regulator. A Tier 2 exposure at 3% is about £150K — plus the cost of complying on a deadline instead of on your schedule. Real, survivable, avoidable.
But the fine is rarely the expensive part:
- Procurement gatekeeping. AI-compliance questionnaires are now standard vendor due diligence. "Describe your AI governance framework" is a standard RFP line. A blank answer doesn't trigger a fine — it removes you from the shortlist.
- Contract friction. Customers who discover unmanaged AI exposure in their supply chain respond with audit clauses, remediation deadlines — or quiet non-renewal. Churn costs more than fines.
For most UK and Irish SMEs, the realistic worst case isn't a regulator — it's a customer asking an AI-governance question you can't answer by Friday.
What actually reduces your exposure
The moves that matter are cheap, fast, and useful regardless of enforcement — a working weekend and some honesty, no legal department required:
- Build an AI inventory. Every tool, plugin and "AI-powered" feature your staff use — including the ones nobody approved. You can't document, classify or defend what you haven't listed.
- Close the Article 4 literacy gap. Obligations have applied since February 2025, and training records are the cheapest evidence of good faith you can produce. A documented baseline turns a Tier 2 gap into a closed item.
- Write the basic documentation. For each significant tool: what it does, what data it touches, who oversees it, what it must never be used for. Two pages per tool is plenty — and it doubles as the answer bank for customer questionnaires.
The pattern: the artefacts that satisfy a regulator also win procurement checks. Compliance work compounds.
What to do next
Work the ladder:
- Step 1 — Take the AI Act quiz (2 minutes). Six questions, instant read on where your AI use actually lands.
- Step 2 — Exposure Assessment. A structured pass over customers, users and AI output to confirm which of the Act's triggers you meet, and how hard.
- Step 3 — AI Readiness Diagnostic. The full map — every tool, data flow and obligation, prioritised. Our AI Act Readiness service works alongside your legal counsel: they interpret the regulation, we make your systems legible against it.
The numbers here are ceilings, not fate. The SMEs that get hurt by the AI Act won't be the ones fined €35M — they'll be the ones who met a questionnaire they couldn't answer. Find out where you stand: take the AI Act quiz.