EU AI Act Penalties: Fine Calculations and Real Enforcement Scenarios
The EU AI Act's penalty framework looks terrifying on paper – up to €35 million or 7% of global turnover for the worst violations. But the actual enforcement math tells a different story, one where SME protections, mitigating factors, and GDPR precedent suggest most Bulgarian tech companies face far lower exposure than the headline numbers imply.

The EU AI Act’s penalty framework looks terrifying on paper – up to €35 million or 7% of global turnover for the worst violations. But the actual enforcement math tells a different story, one where SME protections, mitigating factors, and GDPR precedent suggest most Bulgarian tech companies face far lower exposure than the headline numbers imply. The question is whether teams understand the calculation mechanics well enough to budget for compliance correctly.
In Brief
The EU AI Act (Regulation EU 2024/1689) establishes a three-tier penalty structure with maximum fines reaching €35 million or 7% of global annual turnover for prohibited AI practices, €15 million or 3% for high-risk system violations, and €7.5 million or 1.5% for transparency failures. Article 99(6) provides critical SME protection: smaller companies pay the lower of the two amounts, not the higher.
For Bulgarian software companies serving EU markets, the transparency tier (Article 50 violations like unlabeled chatbots or AI-generated content) represents the most likely enforcement exposure, with realistic first-offense penalties in the low thousands of euros rather than millions.
The companies shaping these regulatory frameworks – Experian, Accenture, Infragistics, Merkle – are the same ones presenting at ISTA 2026, where compliance strategy meets implementation reality.
The Three-Tier Penalty Structure
Article 99 of the AI Act defines penalties that scale with violation severity. Understanding which tier applies to specific AI deployments determines whether compliance budgets need six figures or four.
Tier 1: Prohibited AI Practices – up to €35 million or 7% of turnover
This ceiling applies exclusively to Article 5 violations: social scoring systems, real-time biometric surveillance in public spaces, AI exploiting vulnerabilities of specific groups, and manipulative or deceptive AI systems. These prohibitions became effective in February 2025.
Most Bulgarian software companies will never trigger this tier unless they’re building surveillance infrastructure or deliberately manipulative systems.
Tier 2: High-Risk AI System Violations – up to €15 million or 3% of turnover
This tier covers non-compliance with requirements for high-risk AI systems listed in Annex III. The categories that matter for Bulgarian tech include: AI used in credit scoring and creditworthiness evaluation, employment and worker management systems, and AI safety components in critical infrastructure.
If a company deploys AI-based fraud detection that declines transactions without human oversight, or uses AI for CV screening without proper documentation, Tier 2 applies. The requirements span Articles 9-15: risk management systems, data governance, technical documentation, transparency, human oversight, and cybersecurity.
Tier 3: Transparency and Other Violations – up to €7.5 million or 1.5% of turnover
This is where most enforcement will land. Article 50 transparency obligations require disclosure when users interact with AI systems (chatbots), when content is AI-generated, and when deep fakes or synthetic media are involved.
Failing to label AI-generated product descriptions, not disclosing that a customer service bot is AI-powered, or publishing AI-generated images without marking them – all Tier 3 violations. The transparency rules become effective in August 2026.
The SME Calculation That Changes Everything
Here’s where the math diverges dramatically from the headlines. For large corporations, the AI Act uses a “whichever is higher” model. A company with €100 million in global turnover faces:
- Tier 1: €35 million vs. €7 million (7%) = €35 million maximum
- Tier 2: €15 million vs. €3 million (3%) = €15 million maximum
- Tier 3: €7.5 million vs. €1.5 million (1.5%) = €7.5 million maximum
But Article 99(6) flips this for SMEs and startups: the lower of the two amounts applies. A Bulgarian startup with €500,000 annual turnover faces:
- Tier 1: €35 million vs. €35,000 (7%) = €35,000 maximum
- Tier 2: €15 million vs. €15,000 (3%) = €15,000 maximum
- Tier 3: €7.5 million vs. €7,500 (1.5%) = €7,500 maximum
For a micro-enterprise with €200,000 turnover, Tier 3 maximum drops to €3,000. This SME provision is arguably the most important protection in the entire regulation for Bulgarian tech companies, most of which fall well below the large enterprise threshold.
Enforcement Architecture: Who Actually Issues Fines
Enforcement is decentralized across EU member states. Each country must designate at least one national competent authority. As of April 2026, most designations are complete:
- Germany: Federal Network Agency (Bundesnetzagentur)
- France: CNIL (Commission nationale de l’informatique et des libertés)
- Ireland: Expected to handle many cases given tech company EU operations there
- European AI Office: Coordinates cross-border cases and enforces rules for general-purpose AI models directly
Bulgaria has not yet publicly announced its designated authority, though the Commission for Personal Data Protection (CPDP) – which handles GDPR enforcement – is the likely candidate given institutional overlap.
The enforcement model mirrors GDPR: complaints can originate from consumers, competitors, or regulatory initiative. Cross-border cases are coordinated through the European AI Office, similar to the EDPB’s role under GDPR. For Bulgarian companies serving customers across the EU, the “one-stop-shop” principle means the authority in the company’s main establishment handles the case, but affected member states can raise objections.
Mitigating Factors That Reduce Actual Penalties
Article 99(7) lists specific factors authorities must consider when setting fine amounts:
- Nature and gravity: How serious is the violation and how many people were affected?
- Intent vs. negligence: Did the company knowingly violate rules, or was it an oversight?
- Mitigation steps: Did the company fix the issue once notified?
- Cooperation: Did the company cooperate with the investigation?
- Previous violations: Is this a first offense?
- Financial benefit: Did the company gain advantage from the violation?
- Company size: SME and startup status is a formal mitigating factor
GDPR enforcement history confirms that demonstrable good faith reduces penalties significantly. A company that receives a warning, immediately remediates, and cooperates fully rarely sees maximum fines. The pattern suggests AI Act enforcement will follow similar proportionality principles.
What GDPR Enforcement Predicts About AI Act Penalties
GDPR has been enforced since May 2018, providing eight years of data on how EU regulators approach technology enforcement. Key patterns that likely carry over:
Slow start: GDPR fines were modest in 2018-2019. Regulators issued warnings and guidance before imposing major penalties. Expect the same for the AI Act through 2026-2027.

Big targets first: The largest GDPR fines went to Meta (€1.2 billion), Amazon (€746 million), and Google (several fines totaling over €200 million). Small businesses were rarely targeted in the first two years.
Complaint-driven: Most GDPR enforcement actions started with consumer complaints, not proactive audits. Competitors also file complaints strategically – a dynamic Bulgarian companies should anticipate.
Proportionality in practice: Despite maximum fines of 4% of turnover, actual GDPR fines for SMEs averaged in the low thousands of euros. The AI Act’s explicit SME provisions suggest similar proportionality.
What This Means for Bulgaria
Bulgarian software companies face a specific compliance landscape shaped by several factors:
No local cloud region: Major hyperscalers don’t operate Bulgarian data centers, meaning AI workloads typically run in Frankfurt, Amsterdam, or Warsaw. This doesn’t change AI Act applicability – the regulation follows the AI system’s deployment and affected users, not server location – but it does complicate documentation requirements for high-risk systems that must demonstrate data governance compliance.
NIS2 and DORA overlap: Bulgarian companies in financial services or critical infrastructure face dual compliance burdens. AI systems used in network security monitoring, fraud prevention, or financial transactions must comply with both AI Act requirements and sector-specific resilience regulations. The CPDP (or whichever authority Bulgaria designates) will need to coordinate with financial regulators on overlapping enforcement.
Outsourcing exposure: Many Bulgarian tech companies provide development services to Western European clients. When those clients deploy AI systems, the Bulgarian provider may be classified as a “provider” under Article 3 if they developed the system, even if the client is the “deployer.” This creates liability exposure that service contracts should explicitly address.
August 2026 deadline: High-risk AI system requirements and transparency obligations become enforceable in August 2026. Bulgarian companies have roughly four months to audit existing AI deployments, implement required disclosures, and document compliance measures.
Do This Next Sprint
- Inventory AI systems by tier: Map every AI deployment to the three penalty tiers. Chatbots, content generation, and recommendation systems likely fall under Tier 3 transparency requirements. Fraud detection, credit scoring, and HR screening tools may trigger Tier 2 high-risk obligations.
- Calculate actual exposure: Apply the SME formula to your company’s turnover. Most Bulgarian tech companies will find their maximum Tier 3 exposure is under €10,000, not €7.5 million.
- Implement Article 50 disclosures: Add clear AI disclosure language to chatbot interfaces, mark AI-generated content, and update privacy policies to describe AI system usage. This is the lowest-effort, highest-impact compliance step.
- Document good faith: Create an evidence trail showing compliance efforts before enforcement begins. Audit reports, disclosure implementation dates, and internal training records all serve as mitigating evidence if a complaint arises.
- Review service contracts: If providing AI development services to EU clients, clarify liability allocation for AI Act compliance in contracts. Determine whether the Bulgarian provider or the client bears “provider” obligations under the regulation.
Dig Deeper
- EU AI Act Article 99 Full Text – The complete penalty provisions with all mitigating factors
- European Commission AI Act Implementation Timeline – Official dates for when each provision becomes enforceable
- DLA Piper AI Laws of the World – Comparative enforcement analysis across jurisdictions
- EU AI Act Compliance Checker – Interactive tool to determine which obligations apply to specific AI systems


