Back to The LoopOperating Thesis

The Fine Is Priced At Your Turnover

EX Venture·2026-09-17
The Fine Is Priced At Your Turnover

The EU AI Act deadlines are binding until the amending text is adopted, not until it is proposed. And the penalty is a percentage of group turnover, with a lower SME figure that is still measured against the small company own revenue.

The obligations follow the output, not the address

The EU AI Act is Regulation (EU) 2024/1689. It entered into force on 1 August 2024 and it is the first comprehensive legal framework for artificial intelligence written anywhere. The scope clause is where most founders stop reading, and it is the clause that decides whether the rest of the document concerns them. The regulation applies to any company that places an AI system on the EU market, puts one into service inside the EU, or whose AI output is used in the EU. Headquarters is not part of the test. A company built in Delaware, Singapore or Tel Aviv is in scope the moment its model answers a question asked from Frankfurt.

That single sentence rules out the most common assumption in early stage technology, which is that European regulation is a problem for European companies.

Two dates have already passed

The regulation did not arrive in one piece. It arrived in a sequence, and two steps of that sequence are behind anyone reading this in 2026.

Prohibited practices were banned from 2 February 2025, with no grandfathering. The list is short and specific: social scoring by public authorities, manipulative techniques that distort behaviour, emotion recognition in workplaces and schools, real time remote biometric identification in publicly accessible spaces except under narrow exceptions, and systems that exploit the vulnerabilities of specific groups. Alongside that ban, obligations on AI literacy took effect for every provider and deployer.

From 2 August 2025 the obligations on general purpose AI models applied, the national competent authorities had to be operational, and the penalty regime became active.

The next date is binding, and the delay is not law

The date that matters most to the operators I speak to is 2 August 2026, when the high risk obligations for standalone systems listed in Annex III apply in full. That list is wider than most people expect: biometrics, critical infrastructure, education, employment, credit scoring, law enforcement, migration, justice and democratic processes.

The European Commission proposed pushing that date to December 2027 through the Digital Omnibus in November 2025. A proposal is not a delay. It requires approval by both Parliament and Council, and the trilogue process was still working towards a political agreement with a target of 28 April 2026. Until the amending text is formally adopted, 2 August 2026 remains the operative date, and the firms that advise on this are telling clients to plan against the original text rather than the press coverage of the amendment.

Annex I covers AI used as a safety component in products already governed by EU product safety law, where third party conformity assessment is required: medical devices, vehicles, machinery, toys. That date is 2 August 2027, with the same caveat about the proposed shift, in that case to 2028. Legacy public sector high risk systems placed on the market before 2026 run to 2 August 2030.

The fine is a percentage, and the percentage is the point

Article 99 sets three tiers, and the structure is more interesting than the headline number.

The first tier covers the prohibited practices: up to EUR 35,000,000 or 7 per cent of total worldwide annual turnover, whichever is higher. The second covers the high risk obligations and systemic risk violations on general purpose models: EUR 15,000,000 or 3 per cent, whichever is higher. The third covers incorrect, incomplete or misleading information given to notified bodies or national authorities: EUR 7,500,000 or 1 per cent, whichever is higher.

For small and medium sized enterprises, Article 99(6) reverses the comparison. The fine is capped at whichever of the two figures is lower. On a company with EUR 2 million of revenue, the first tier ceiling is therefore not EUR 35 million. It is EUR 140,000, which is 7 per cent of revenue.

That is the sentence worth carrying into a board meeting. A seed stage company is not immune from the regulation, and it is not protected from it either. In a business with two million euros of turnover and no margin, a EUR 140,000 penalty is the same existential event as a nine figure fine is to a listed group.

Turnover is measured across the group

The second trap is the unit of measurement. Turnover is calculated at group level, not at the level of the entity that deployed the system. A small operating subsidiary inside a larger corporate family does not get the smaller balance sheet for the purposes of the ceiling. The subsidiary inherits the group figure.

The actual fine within those ceilings is set by national market surveillance authorities, which weigh the nature of the infringement, its gravity and duration, the degree of cooperation, prior violations, and the size of the company. Cooperation is therefore priced, and so is a documented attempt to comply that failed rather than an absence of any attempt.

What the high risk route asks for in practice

High risk classification is not a label. It is a specification. A compliant system needs risk management running as a continuous process, data governance covering the training and validation sets, technical documentation of the design and the intended purpose, logs that allow events to be reconstructed, human oversight designed into the loop rather than bolted on, a conformity assessment, registration in the EU database, and post market monitoring after release.

Read as a list, this is a description of engineering discipline that most teams already believe they have. The difference is that the regulation requires it to be written down, versioned and producible on request, which converts an implicit practice into an auditable artefact and a line item in the budget.

What the dates mean for a small builder

Two facts decide the planning, and both are dates rather than opinions. Annex III high risk obligations are operative from 2 August 2026 unless the amending text is adopted, and no adopted text existed as of the April 2026 brief this analysis draws on. The penalty for non compliance is a percentage of group turnover, with a lower figure for smaller companies that is still measured against the small company own revenue.

The probability that the amending text clears Parliament and Council and takes effect before 2 August 2026 is not zero, and it is close to the number most teams are pricing at zero. The practical consequence is that a system in one of the Annex III categories placed on the market today is being placed against the original calendar. Building the documentation alongside the product costs a fraction of retrofitting it onto a system that has been running for a year. The difference between the two routes is not the quality of the engineering. It is the date on which the engineering was written down.

For more information, reach out to media@exventure.co. Julien Uhlig is available for advisory work, board seats and media appearances.

EX-AI Summit 2026

18-20 November. Online, Las Palmas, Bali.

Three days on what happens to work, capital and institutions when the map stops matching the ground. The academy that trains the operators across every company in the group is EX Epic Academy - 25,000 applications, 25 seats per cohort, 210 alumni across 19 countries.

ex-aisummit.com →EX Epic Academy →media@exventure.co