Three fine tiers in the AI Act
| For what | Maximum fine | Who it really hits |
|---|---|---|
| Prohibited practices (Art. 5) — e.g. subliminal manipulation, social scoring, scraping likenesses | EUR 35m or 7% of worldwide turnover — whichever is higher | A narrow group. If you do not build systems on the ban list, this tier is a headline, not your risk. |
| Breach of other duties — incl. transparency (Art. 50), provider/deployer duties, high-risk systems | EUR 15m or 3% of turnover | This is your tier. Unlabelled chatbot, missing disclosures, neglected deployer duties — all land here. |
| False or incomplete information to authorities | EUR 7.5m or 1% of turnover | Anyone who “colours” their compliance status in a response to a request. Do not do that. |
Two softening clauses clickbait ignores: for SMEs and startups the lower of the two values (amount vs percentage) applies to verify, and the authority sets the fine proportionately — weighing severity, cooperation and intent. The maximum is a ceiling, not a price list.
Who pays: provider, deployer — and the moment you switch roles
The AI Act splits duties along the chain. A provider (system creator) is accountable for design, technical documentation and marking. A deployer (the firm applying the system) — for how it is used, human oversight and disclosures to its audience. “We bought it from a vendor” therefore does not shift liability: for an unlabelled chatbot on your site, you answer, not the vendor.
There is also a trap that catches surprisingly many firms: a deployer becomes a provider — with the full duty pack — when it materially modifies the system, changes its intended purpose, or brands it as its own. If you sell clients “your” AI assistant built on someone else’s model, read that sentence again.
A 120-person firm, a chatbot and AI in recruiting — a realistic sequence
- August 2026. The customer-service chatbot runs without disclosing it is AI. Formally: Art. 50 breach → up to EUR 15m / 3%. In reality: authorities start with requests and remediation deadlines, not maximum fines. Sounds harmless — keep reading.
- September 2026. Your largest corporate client sends an updated vendor questionnaire: “Do you use AI systems? Please evidence Art. 4 and Art. 50 compliance.” You have neither a training register nor a labelling deployment note. A contract worth 40× the cost of compliance hangs on an email you cannot answer.
- December 2026. PLD enters: software — including AI systems — is a “product” under civil liability. A rejected candidate alleges discrimination by an AI recruiting tool. In a civil dispute, missing documentation acts as a presumption favouring the claimant — and missing Art. 4 training becomes the simplest negligence evidence.
- Balance sheet. Administrative fine: maybe zero. Real costs: frozen contract, civil dispute, emergency client audit — i.e. the most expensive way possible.
Why an administrative fine is not your biggest problem
1. PLD: from December 2026 an AI error is a product defect
The new Product Liability Directive covers software and AI systems (application from 9 Dec 2026 to verify). The key mechanism is not award size but burden of proof: documentation gaps can trigger a presumption of defectiveness. An authority fine needs an inspection; a civil claim needs only an unhappy customer and a lawyer.
2. B2B contracts: the questionnaire arrives before the inspector
Corporates push their duties down the supply chain — exactly as with GDPR and as with NIS2. For an SME supplier that means the first “supervisory authority” is the client’s procurement team — with no appeal process and a simple sanction: no compliance, no contract.
3. Tenders and grants: compliance as an entry condition
Public procurement and grant programmes increasingly write AI compliance into the conditions. Non-compliance then does not cost a fine — it costs revenue you never see.
Cost of compliance vs cost of inaction
A defensive minimum — AI policy, documented Art. 4 training, Art. 50 labelling, inventory and evidence memo — for a 50–500 person firm is usually tens of thousands of PLN, mostly one-off. On the other side: fine tiers in millions of euro, frozen contracts and civil disputes with a reversed burden of proof. You do not need a precise ROI model to see the asymmetry — we will publish a full calculation soon in an article on the cost of inaction.
Common questions
Do SMEs pay lower fines?
When setting the fine the authority considers the entity’s size and situation, and for SMEs the lower of the two values (amount vs turnover %) applies. Proportionality softens the amount — it does not erase the duties.
From when are fines enforceable in Poland?
The fine framework applies from 2 August 2026 with national supervision. For GPAI model providers the Commission may act from August 2025. Details of the Polish implementing act — including the authority — to verify.
Who imposes fines?
National market surveillance authorities (in Poland designated by the implementing act); for GPAI models — the European Commission.
Will liability insurance cover a fine?
Administrative fines are typically excluded from policies, and PLD liability is often only partly covered. Compliance and documentation are the only full protection — insurance will not replace them.
Let’s walk your exposure point by point
Half an hour: what you have, what applies, where the gaps are, and which to close before 2 August versus which can wait. You leave with a priority list — whether you do it with us or alone.
Book a callThis article is informational and is not legal advice. Fine tiers come from Regulation 2024/1689; PLD mechanisms from Directive 2024/2853. The fine in any concrete case always depends on the circumstances.