Article 99 of the European AI Act sets three fine tiers: up to 35 million euros or 7% of global turnover for prohibited practices, up to 15 million or 3% for non compliance with other obligations (including Article 4 training), and up to 7.5 million or 1% for providing inaccurate information to authorities. For SMEs, the lower of the two figures always applies. In Spain, there's a crucial nuance almost no one discusses: the national law designating who imposes these fines is still in Congress, so the real risk today doesn't come from where most people expect. When asked about AI Act fines, I notice people anticipate hearing that these penalties only concern big tech companies. That fifteen million euros is a figure exclusively for multinationals. This is a misconception, but so is the opposite error: fear mongering as if the AESIA will be knocking on your door tomorrow. Let's clarify the situation. What Are the Potential Fines Under the European AI Act? Article 99 of outlines three tiers of penalties. Supervision and enforcement of already applicable rules (prohibitions, AI literacy, transparency, and general purpose AI models) will begin at national and EU levels starting August 2, 2026: | Infraction | Maximum Fine | Who is typically affected | | | | | | Prohibited practices (Art. 5): social scoring, subliminal manipulation, biometric identification in public spaces without authorization | €35M or 7% of global annual turnover (whichever is higher) | Extreme, infrequent cases | | Non compliance with other obligations, including Article 4 training , Article 50 transparency, and high risk obligations | €15M or 3% (whichever is higher) | Most businesses | | Providing inaccurate, incomplete, or misleading information to authorities | €7.5M or 1% (whichever is higher) | Those already undergoing a procedure | For SMEs and startups, the rule is reversed: the lower of the two amounts applies , not the higher. A company with two million euros in annual revenue, for non compliance with Article 4, faces an effective maximum fine of sixty thousand euros (3% of its turnover, not 15 million). One with five hundred thousand faces fifteen thousand. These figures alone won't bankrupt anyone. However, they're also not a risk worth ignoring when the cost of compliance is much lower, and in many cases, . Who Can Impose These Fines in Spain Today? This is the nuance that distinguishes this article from most circulating information, and it's important to state it precisely because both exaggerations—panic and complacency—lead to poor decisions. Fines under the regulation are imposed by national market surveillance authorities, and each Member State was required to designate them and establish their sanctioning procedure. Spain has not yet completed this step: the Organic Law Project for the Good Use and Governance of AI , which designates AESIA as the primary authority and sets the procedure, was approved by the Council of Ministers on May 26, 2026, and is currently undergoing parliamentary processing, with an amendment period open this summer. Until it is published in the BOE (Official State Gazette), AESIA lacks the channel to impose AI Act fines. Does this mean there's no risk? No, and here lies the trap of complacency: Obligations are still enforceable. The European regulation is directly applicable; it doesn't require Spanish law to bind you. What's missing is the national sanctioning channel, not the obligation itself. The risk today comes through other avenues. The AEPD (Spanish Data Protection Agency) can already impose penalties (under GDPR) for AI use that mishandles personal data. An employee can file a claim. A major client can audit you as a supplier. Due diligence in a corporate transaction can uncover issues. None of these triggers await Spanish law. And Spanish law comes with its own regime. The pending bill adds a category of minor infractions with fines up to 500,000 euros to the European tiers and designates a division of authorities: AESIA as the primary, AEPD for biometrics, and the Bank of Spain and CNMV (National Securities Market Commission) in the financial sector. Final amounts may change with amendments, but the direction is clear: the channel is being built, not discarded. AI Act and GDPR Fines Are Cumulative This is the least discussed point, yet it matters most to SMEs. If your company uses AI tools that process personal data—and most do, as nearly all enterprise AI works with customer, employee, or supplier data—a single infraction can simultaneously trigger two sanctioning frameworks: the AI Act and the GDPR. These are distinct authorities that can act independently on the same event. The real cost of non compliance isn't one fine. It could be two. And the GDPR fine isn't waiting for any law: the AEPD imposes it today. What Would an Inspection Look for Regarding Training? Once the sanctioning channel is operational, what the authority will evaluate regarding Article 4 is not whether all your emplo