AI Act fines: the 2026 sanctions table — and who really pays

The headline AI Act fine targets prohibited practices that a typical Polish firm does not run. Real exposure looks different: lower tiers, deployer liability, and a chain where missing documentation becomes evidence against you — in a civil dispute, a corporate client questionnaire, a tender. Let’s price it honestly.

Sanctions table

Three fine tiers in the AI Act

For whatMaximum fineWho it really hits
Prohibited practices (Art. 5) — e.g. subliminal manipulation, social scoring, scraping likenessesEUR 35m or 7% of worldwide turnover — whichever is higherA narrow group. If you do not build systems on the ban list, this tier is a headline, not your risk.
Breach of other duties — incl. transparency (Art. 50), provider/deployer duties, high-risk systemsEUR 15m or 3% of turnoverThis is your tier. Unlabelled chatbot, missing disclosures, neglected deployer duties — all land here.
False or incomplete information to authoritiesEUR 7.5m or 1% of turnoverAnyone who “colours” their compliance status in a response to a request. Do not do that.

Two softening clauses clickbait ignores: for SMEs and startups the lower of the two values (amount vs percentage) applies to verify, and the authority sets the fine proportionately — weighing severity, cooperation and intent. The maximum is a ceiling, not a price list.

Liability chain

Who pays: provider, deployer — and the moment you switch roles

The AI Act splits duties along the chain. A provider (system creator) is accountable for design, technical documentation and marking. A deployer (the firm applying the system) — for how it is used, human oversight and disclosures to its audience. “We bought it from a vendor” therefore does not shift liability: for an unlabelled chatbot on your site, you answer, not the vendor.

There is also a trap that catches surprisingly many firms: a deployer becomes a provider — with the full duty pack — when it materially modifies the system, changes its intended purpose, or brands it as its own. If you sell clients “your” AI assistant built on someone else’s model, read that sentence again.

Scenario

A 120-person firm, a chatbot and AI in recruiting — a realistic sequence

Not a fine simulation · a sequence simulation
  1. August 2026. The customer-service chatbot runs without disclosing it is AI. Formally: Art. 50 breach → up to EUR 15m / 3%. In reality: authorities start with requests and remediation deadlines, not maximum fines. Sounds harmless — keep reading.
  2. September 2026. Your largest corporate client sends an updated vendor questionnaire: “Do you use AI systems? Please evidence Art. 4 and Art. 50 compliance.” You have neither a training register nor a labelling deployment note. A contract worth 40× the cost of compliance hangs on an email you cannot answer.
  3. December 2026. PLD enters: software — including AI systems — is a “product” under civil liability. A rejected candidate alleges discrimination by an AI recruiting tool. In a civil dispute, missing documentation acts as a presumption favouring the claimant — and missing Art. 4 training becomes the simplest negligence evidence.
  4. Balance sheet. Administrative fine: maybe zero. Real costs: frozen contract, civil dispute, emergency client audit — i.e. the most expensive way possible.
Three more realistic risks

Why an administrative fine is not your biggest problem

1. PLD: from December 2026 an AI error is a product defect

The new Product Liability Directive covers software and AI systems (application from 9 Dec 2026 to verify). The key mechanism is not award size but burden of proof: documentation gaps can trigger a presumption of defectiveness. An authority fine needs an inspection; a civil claim needs only an unhappy customer and a lawyer.

2. B2B contracts: the questionnaire arrives before the inspector

Corporates push their duties down the supply chain — exactly as with GDPR and as with NIS2. For an SME supplier that means the first “supervisory authority” is the client’s procurement team — with no appeal process and a simple sanction: no compliance, no contract.

3. Tenders and grants: compliance as an entry condition

Public procurement and grant programmes increasingly write AI compliance into the conditions. Non-compliance then does not cost a fine — it costs revenue you never see.

The maths

Cost of compliance vs cost of inaction

A defensive minimum — AI policy, documented Art. 4 training, Art. 50 labelling, inventory and evidence memo — for a 50–500 person firm is usually tens of thousands of PLN, mostly one-off. On the other side: fine tiers in millions of euro, frozen contracts and civil disputes with a reversed burden of proof. You do not need a precise ROI model to see the asymmetry — we will publish a full calculation soon in an article on the cost of inaction.

14 days
until supervision starts
2 wks
for a defensive minimum
FAQ

Common questions

Do SMEs pay lower fines?

When setting the fine the authority considers the entity’s size and situation, and for SMEs the lower of the two values (amount vs turnover %) applies. Proportionality softens the amount — it does not erase the duties.

From when are fines enforceable in Poland?

The fine framework applies from 2 August 2026 with national supervision. For GPAI model providers the Commission may act from August 2025. Details of the Polish implementing act — including the authority — to verify.

Who imposes fines?

National market surveillance authorities (in Poland designated by the implementing act); for GPAI models — the European Commission.

Will liability insurance cover a fine?

Administrative fines are typically excluded from policies, and PLD liability is often only partly covered. Compliance and documentation are the only full protection — insurance will not replace them.

30 minutes · no obligation

Let’s walk your exposure point by point

Half an hour: what you have, what applies, where the gaps are, and which to close before 2 August versus which can wait. You leave with a priority list — whether you do it with us or alone.

Book a call

This article is informational and is not legal advice. Fine tiers come from Regulation 2024/1689; PLD mechanisms from Directive 2024/2853. The fine in any concrete case always depends on the circumstances.

RW

Rafał Wiatrowski — for 25 years has built and deployed technology: from code, through CTO roles, to GenAI strategy for large organisations. Designs production AI systems (agents, RAG, MCP) and helps companies move from pilots to accountable deployments. Executive MBA (Carlson School of Management).

Jeden artykuł tygodniowo. Zero lania wody.

Subskrybuj →