4Geeks chosen to deliver AI education in the Bahamas alongside Harvard, Oxford, and Columbia.See more
8 min read

AI Act Fines: How Much They Can Cost and Who Can Penalize You in Spain Today

Article 99 of the European AI Act sets three fine tiers: up to 35 million euros or 7% of global turnover for prohibited practices, up to 15 million or 3…

Article 99 of the European AI Act sets three fine tiers: up to 35 million euros or 7% of global turnover for prohibited practices, up to 15 million or 3% for breaching the obligations listed in its paragraph 4 (including deployer obligations under Article 26 and Article 50 transparency), and up to 7.5 million or 1% for providing inaccurate information to authorities. For SMEs, the lower of the two figures always applies. Article 4 training is not in any of the three tiers. In Spain, there's a crucial nuance almost no one discusses: the national law designating who imposes these fines is still in Congress, so the real risk today doesn't come from where most people expect.

When asked about AI Act fines, I notice people anticipate hearing that these penalties only concern big tech companies. That fifteen million euros is a figure exclusively for multinationals. This is a misconception, but so is the opposite error: fear-mongering as if the AESIA will be knocking on your door tomorrow. Let's clarify the situation.


What Are the Potential Fines Under the European AI Act?

Article 99 of Regulation (EU) 2024/1689 outlines three tiers of penalties. Supervision and enforcement of already-applicable rules (prohibitions, AI literacy, transparency, and general-purpose AI models) will begin at national and EU levels starting August 2, 2026:

InfractionMaximum FineWho is typically affected
Prohibited practices (Art. 5): social scoring, subliminal manipulation, biometric identification in public spaces without authorization€35M or 7% of global annual turnover (whichever is higher)Extreme, infrequent cases
Breaching the obligations listed in Art. 99(4): operators of high-risk systems (providers, authorised representatives, importers, distributors and deployers under Art. 26), notified bodies, and Art. 50 transparency€15M or 3% (whichever is higher)Companies that use or sell high-risk AI or AI subject to transparency duties
Providing inaccurate, incomplete, or misleading information to authorities€7.5M or 1% (whichever is higher)Those already undergoing a procedure

For SMEs and startups, the rule is reversed: the lower of the two amounts applies, not the higher. A company with two million euros in annual revenue that breaches one of the Article 99(4) obligations (for example, Article 50 transparency) faces a maximum fine of sixty thousand euros (3% of its turnover, not 15 million). One with five hundred thousand faces fifteen thousand.

What about Article 4 training? It is not on that list. Article 99(4) lists one by one the obligations punishable with up to 15 million or 3%, and Article 4 is not among them; the Digital Omnibus (Regulation (EU) 2026/1744) did not add it either. The regulation sets no specific fine for Article 4: penalties for breaching it are left to each Member State (Article 99(1)), and in Spain they depend on the national law still going through Congress.

These figures alone won't bankrupt anyone. However, they're also not a risk worth ignoring when the cost of compliance is much lower, and in many cases, zero thanks to FUNDAE credit.


Who Can Impose These Fines in Spain Today?

This is the nuance that distinguishes this article from most circulating information, and it's important to state it precisely because both exaggerations—panic and complacency—lead to poor decisions.

Fines under the regulation are imposed by national market surveillance authorities, and each Member State was required to designate them and establish their sanctioning procedure. Spain has not yet completed this step: the Organic Law Project for the Good Use and Governance of AI, which designates AESIA as the primary authority and sets the procedure, was approved by the Council of Ministers on May 26, 2026, and is currently undergoing parliamentary processing, with an amendment period open this summer. Until it is published in the BOE (Official State Gazette), AESIA lacks the channel to impose AI Act fines.

Does this mean there's no risk? No, and here lies the trap of complacency:

Obligations are still enforceable. The European regulation is directly applicable; it doesn't require Spanish law to bind you. What's missing is the national sanctioning channel, not the obligation itself.

The risk today comes through other avenues. The AEPD (Spanish Data Protection Agency) can already impose penalties (under GDPR) for AI use that mishandles personal data. An employee can file a claim. A major client can audit you as a supplier. Due diligence in a corporate transaction can uncover issues. None of these triggers await Spanish law.

And Spanish law comes with its own regime. The pending bill adds a category of minor infractions with fines up to 500,000 euros to the European tiers and designates a division of authorities: AESIA as the primary, AEPD for biometrics, and the Bank of Spain and CNMV (National Securities Market Commission) in the financial sector. Final amounts may change with amendments, but the direction is clear: the channel is being built, not discarded.


AI Act and GDPR Fines Are Cumulative

This is the least discussed point, yet it matters most to SMEs.

If your company uses AI tools that process personal data—and most do, as nearly all enterprise AI works with customer, employee, or supplier data—a single infraction can simultaneously trigger two sanctioning frameworks: the AI Act and the GDPR. These are distinct authorities that can act independently on the same event.

The real cost of non-compliance isn't one fine. It could be two. And the GDPR fine isn't waiting for any law: the AEPD imposes it today.


What Would an Inspection Look for Regarding Training?

Once the sanctioning channel is operational, what the authority will evaluate regarding Article 4 is not whether all your employees are AI experts. It's whether the company took active and proportional measures. Specifically, three things:

  1. An inventory of the AI systems the company uses, who uses them, and for what purpose.
  2. Records of training provided: dates, content, participants.
  3. A justification of proportionality: why that training is appropriate for each person's use.

If your company lacks any of these three, exposure is total. If it has them, exposure drops drastically, because an obligation of means is satisfied by demonstrating means, and that's exactly what these three elements demonstrate. What Article 4 specifically requires is detailed here.


The Cost-Risk Comparison That Drives Action

For non-compliance with Article 4, the EU regulation sets no amount: the penalty will depend on Spanish law, plus any penalties under GDPR if personal data is involved. In contrast, a comprehensive AI training program for a team of twenty people, properly documented and subsidized through FUNDAE credits, can cost zero additional euros. At 4Geeks, we designed the AI Fluency program precisely for this purpose: documented role-specific training for non-technical teams.

I draw this explicit contrast because it's the most compelling argument for action. It's not about compliance for compliance's sake. It's about a very basic cost-risk comparison with an obvious conclusion.

What is truly priceless, or prohibitively expensive, is waiting for a trigger event with empty records. Not because an agency will go company by company, but because an investigation can arise from an employee complaint, a client audit, or a corporate transaction. These triggers don't give advance warning.


The Regulation (EU) 2024/1689 (known as the AI Act) was published in the Official Journal of the European Union on July 12, 2024, entering into force 20 days later, on August 1, 2024. The first obligations (the Article 5 prohibitions and the Article 4 AI literacy duty) have applied since February 2, 2025, according to the implementation schedule set out in Article 113. The European Commission has published a detailed guide to facilitate understanding and compliance with these regulations, especially for SMEs, emphasizing the importance of early preparation to avoid future penalties.

A Necessary Clarification

This article does not constitute legal advice. I am not a lawyer and do not claim to be one. If your company uses AI in higher-impact contexts (e.g., HR selection, financial decisions, healthcare, infrastructure), the risk analysis is more complex and requires a specialist.

What I can state clearly is this: the training obligation under Article 4 applies to all companies using AI, regardless of the risk level of their systems. It's the foundational requirement, the part any company can address without legal consulting, and the cheapest protection available. The rest of the regulation has more layers; this one does not.


Víctor Gómez is the CEO and co-founder of 4Geeks Academy Spain.

Take your next step in tech

Compare our career programs and pick your path.

Frequently Asked Questions