Article 99 of the European AI Act sets three fine tiers: up to 35 million euros or 7% of global turnover for prohibited practices, up to 15 million or 3% for non-compliance with other obligations (including Article 4 training), and up to 7.5 million or 1% for providing inaccurate information to authorities. For SMEs, the lower of the two figures always applies. In Spain, there's a crucial nuance almost no one discusses: the national law designating who imposes these fines is still in Congress, so the real risk today doesn't come from where most people expect.
When asked about AI Act fines, I notice people anticipate hearing that these penalties only concern big tech companies. That fifteen million euros is a figure exclusively for multinationals. This is a misconception, but so is the opposite error: fear-mongering as if the AESIA will be knocking on your door tomorrow. Let's clarify the situation.
What Are the Potential Fines Under the European AI Act?
Article 99 of Regulation (EU) 2024/1689 outlines three tiers of penalties. Supervision and enforcement of already-applicable rules (prohibitions, AI literacy, transparency, and general-purpose AI models) will begin at national and EU levels starting August 2, 2026:
| Infraction | Maximum Fine | Who is typically affected |
|---|---|---|
| Prohibited practices (Art. 5): social scoring, subliminal manipulation, biometric identification in public spaces without authorization | €35M or 7% of global annual turnover (whichever is higher) | Extreme, infrequent cases |
| Non-compliance with other obligations, including Article 4 training, Article 50 transparency, and high-risk obligations | €15M or 3% (whichever is higher) | Most businesses |
| Providing inaccurate, incomplete, or misleading information to authorities | €7.5M or 1% (whichever is higher) | Those already undergoing a procedure |
For SMEs and startups, the rule is reversed: the lower of the two amounts applies, not the higher. A company with two million euros in annual revenue, for non-compliance with Article 4, faces an effective maximum fine of sixty thousand euros (3% of its turnover, not 15 million). One with five hundred thousand faces fifteen thousand.
These figures alone won't bankrupt anyone. However, they're also not a risk worth ignoring when the cost of compliance is much lower, and in many cases, zero thanks to FUNDAE credit.
Who Can Impose These Fines in Spain Today?
This is the nuance that distinguishes this article from most circulating information, and it's important to state it precisely because both exaggerations—panic and complacency—lead to poor decisions.
Fines under the regulation are imposed by national market surveillance authorities, and each Member State was required to designate them and establish their sanctioning procedure. Spain has not yet completed this step: the Organic Law Project for the Good Use and Governance of AI, which designates AESIA as the primary authority and sets the procedure, was approved by the Council of Ministers on May 26, 2026, and is currently undergoing parliamentary processing, with an amendment period open this summer. Until it is published in the BOE (Official State Gazette), AESIA lacks the channel to impose AI Act fines.
Does this mean there's no risk? No, and here lies the trap of complacency:
Obligations are still enforceable. The European regulation is directly applicable; it doesn't require Spanish law to bind you. What's missing is the national sanctioning channel, not the obligation itself.
The risk today comes through other avenues. The AEPD (Spanish Data Protection Agency) can already impose penalties (under GDPR) for AI use that mishandles personal data. An employee can file a claim. A major client can audit you as a supplier. Due diligence in a corporate transaction can uncover issues. None of these triggers await Spanish law.
And Spanish law comes with its own regime. The pending bill adds a category of minor infractions with fines up to 500,000 euros to the European tiers and designates a division of authorities: AESIA as the primary, AEPD for biometrics, and the Bank of Spain and CNMV (National Securities Market Commission) in the financial sector. Final amounts may change with amendments, but the direction is clear: the channel is being built, not discarded.
AI Act and GDPR Fines Are Cumulative
This is the least discussed point, yet it matters most to SMEs.
If your company uses AI tools that process personal data—and most do, as nearly all enterprise AI works with customer, employee, or supplier data—a single infraction can simultaneously trigger two sanctioning frameworks: the AI Act and the GDPR. These are distinct authorities that can act independently on the same event.
The real cost of non-compliance isn't one fine. It could be two. And the GDPR fine isn't waiting for any law: the AEPD imposes it today.
What Would an Inspection Look for Regarding Training?
Once the sanctioning channel is operational, what the authority will evaluate regarding Article 4 is not whether all your employees are AI experts. It's whether the company took active and proportional measures. Specifically, three things:
- An inventory of the AI systems the company uses, who uses them, and for what purpose.
- Records of training provided: dates, content, participants.
- A justification of proportionality: why that training is appropriate for each person's use.
If your company lacks any of these three, exposure is total. If it has them, exposure drops drastically, because an obligation of means is satisfied by demonstrating means, and that's exactly what these three elements demonstrate. What Article 4 specifically requires is detailed here.
The Cost-Risk Comparison That Drives Action
The maximum fine for non-compliance with Article 4 for a medium-sized SME can reach sixty thousand euros, plus any penalties under GDPR if personal data is involved. In contrast, a comprehensive AI training program for a team of twenty people, properly documented and subsidized through FUNDAE credits, can cost zero additional euros. At 4Geeks, we designed the AI Fluency program precisely for this purpose: documented role-specific training for non-technical teams.
I draw this explicit contrast because it's the most compelling argument for action. It's not about compliance for compliance's sake. It's about a very basic cost-risk comparison with an obvious conclusion.
What is truly priceless, or prohibitively expensive, is waiting for a trigger event with empty records. Not because an agency will go company by company, but because an investigation can arise from an employee complaint, a client audit, or a corporate transaction. These triggers don't give advance warning.
The Regulation (EU) 2024/1689 (known as the AI Act) was published in the Official Journal of the European Union on July 12, 2024, entering into force 20 days later, on August 1, 2024. The first obligations, related to prohibitions on AI systems, will apply starting August 2, 2026, according to the implementation schedule set out in Article 113. The European Commission has published a detailed guide to facilitate understanding and compliance with these regulations, especially for SMEs, emphasizing the importance of early preparation to avoid future penalties.
A Necessary Clarification
This article does not constitute legal advice. I am not a lawyer and do not claim to be one. If your company uses AI in higher-impact contexts (e.g., HR selection, financial decisions, healthcare, infrastructure), the risk analysis is more complex and requires a specialist.
What I can state clearly is this: the training obligation under Article 4 applies to all companies using AI, regardless of the risk level of their systems. It's the foundational requirement, the part any company can address without legal consulting, and the cheapest protection available. The rest of the regulation has more layers; this one does not.
Víctor Gómez is the CEO and co-founder of 4Geeks Academy Spain.
