TL;DR: EU AI Act fines are not one number. They are three tiers. The scary headline — up to €35M (7% of global turnover) — covers only banned AI practices, like social scoring. A normal SaaS with a chatbot sits under Article 50. That tier runs up to €15M or 3% of turnover. The duties apply from August 2, 2026. They follow your users, not your office. Here is the full map, and how to check your product before a regulator does.

Most fear content online quotes the biggest number and applies it to everything. That is not how the law reads. It is not how the fines will work either. Know which tier fits your product. It is the difference between a fix you ship this week and a risk that keeps you up at night for no reason.

QuestionAnswer
What is the biggest fine?
€35M / 7% of turnover — but only for banned AI practices.
What does a normal SaaS face?
The Article 50 tier: up to €15M / 3% of turnover.
When does it start?
August 2, 2026. The date does not move for small teams.
Does it apply outside the EU?
Yes, if you have EU users. The law follows users, not offices.
Is this the same as GDPR?
No. Separate law, separate duties. You need both.
How do I check my exposure?
A 60-check Compliance Score, plus a free URL scan.

The three fine tiers, in plain terms

The Act ties each penalty to a specific failure. There is no single flat number. Which ceiling applies depends on what went wrong.

What went wrongMaximum fineWho this hits
Banned AI practices€35M or 7% of global turnoverSocial scoring, AI that tricks or exploits people
Article 50 and high-risk failures€15M or 3% of global turnoverMissing AI disclosure — most SaaS AI features live here
Misleading regulators€7.5M or 1% of global turnoverWrong or partial info given during a review

In each case, “whichever is higher” applies. For scale: GDPR’s own ceiling is €20M or 4% of turnover. The AI Act’s top tier goes past it on purpose. That tells you how the EU ranks banned practices. It also tells you something useful. If your product does not score or trick people, the €35M number is not your number.

Article 50 is the section that governs your chatbot

Run a chatbot? A feature that writes text or makes images? Anything a user might take as human? Then Article 50 is your section. One caution when you search. Many older guides cite Art. 52 — the draft numbering. The final law moved these duties to Article 50. Cite the wrong article in your own docs and it shows you never read the law.

What Article 50 asks of you is short:

None of this is hard to build. A notice, a label, a line of copy. Most products skip it anyway. The AI tool that built the feature never treated disclosure as part of the build.

Why August 2, 2026 is the date that matters

August 2, 2026 is when the Article 50 duties apply, along with key powers to fine. It is a future date, and it is close. If your product touches EU users, the date applies to you. It does not matter where your company is based.

A two-person SaaS team in Austin with 400 users in Germany is in scope. Company size does not exempt you. Neither does “it is just a small feature.” If the feature talks to users or makes content they see, it counts.

How vibe-coded apps walk into this

We scan AI-built products all week, and the pattern repeats. The feature works. The disclosure is missing. Lovable, Bolt, Cursor, and v0 can ship a working chatbot in an afternoon. None of them ask whether that chatbot needs an Article 50 notice. None of them wire one in by default.

If you shipped with one of these tools, assume the disclosure layer was never built. Not because you cut corners. The AI treated it as someone else’s problem, and that someone is now you. Across 100 AI-built apps we scanned, the average Launch Readiness Score was 42/100. The same builds that skip security defaults skip the legal layer too. Both gaps live in the same corners: skipped defaults, missing headers, features shipped without the layer underneath. See the security half of that pattern in our vibe coding security guide. Or test two common gaps right now with the free security headers checker and Supabase RLS checker.

AI Act vs GDPR: you need both, not either

Founders often treat these as one audit with two names. They are not.

GDPR governs how you collect, store, and use personal data. Consent records, retention rules, lawful basis, breach notices — all GDPR. The AI Act governs how your AI behaves and what you tell users about it. Disclosure text, risk class, human oversight docs — all AI Act.

A product can pass a GDPR review and still fail an AI Act check. The reverse is also true. If you are early on the data side, start with our GDPR guide for vibe-coded apps. Then come back to the disclosure layer.

How to check your exposure this week

Three steps, in order of effort:

  1. Open your product as a user. Talk to your own chatbot. Is there a clear notice that it is an AI? Is generated content labeled? If not, you have an Article 50 gap.
  2. Run the free scan on your live URL. It scores the security side out of 100 in about a minute. No code access.
  3. Run the Compliance Score — 52 automatic checks across GDPR, the EU AI Act, SOC 2 foundations, and ISO 27001 foundations. It costs $799 one time and returns a ranked fix plan, not a wall of legal text. The fee is credited if you later want the fixes done for you.

Want the full legal walkthrough — risk classes, who counts as a provider, the paper trail? Read our EU AI Act compliance guide for SaaS founders. Pricing for every option is on the pricing page.

The trust case, separate from the fines

There is a plain business reason to do this early. Users have started to expect AI disclosure. A clear “you are talking to an AI” notice reads as honest. Leaving it out reads as hiding something. The law is about to require the exact behavior that already builds trust. Ship it early and it costs you a line of copy. Ship it late and it costs you the benefit of the doubt.

FAQ

What is the maximum EU AI Act fine a SaaS company can face?

The top ceiling is 35 million euros or 7% of global turnover. It applies only to banned AI practices, such as social scoring. A typical SaaS with a chatbot faces the lower tier: up to 15 million euros or 3% of turnover.

Which article covers chatbot transparency in the EU AI Act?

Article 50 of the final law. Older guides cite a number from the draft text. The real duties live in Article 50: tell users they are talking to an AI, and label AI-made content.

When do EU AI Act fines start applying?

The Article 50 duties apply from August 2, 2026. The date does not move for small teams. It applies based on where your users are, not where your company is based.

Does a small SaaS startup really need to worry about EU AI Act fines?

Yes, if any EU users use your AI feature. The law follows your users, not your office. There is no small-team carve-out. A two-person team with a few hundred EU users is in scope.

Is EU AI Act compliance different from GDPR compliance?

Yes. GDPR governs how you handle personal data. The AI Act governs how your AI behaves and what you tell users about it. An app can pass one review and still fail the other, so you need both.

How do I check if my AI app is exposed to EU AI Act fines?

Run a check against your live product. Launch Ready Code’s Compliance Score runs 52 automatic checks across GDPR, the EU AI Act, SOC 2, and ISO 27001 foundations, with a fix roadmap. There is also a free URL scan for the security side.

The fines are real. You can close them out with a week of honest work. Know your tier. Fix the disclosure. Check the security defaults the same tools skipped. Start with the scan — it is the cheapest look a regulator will never have to take.

Run the free scan — $0, about 30 seconds