Back to blog

Blog / High-risk

EU AI Act Fines and Penalties: What AI SaaS Founders Risk in 2026–2027

Published 9 July 2026·Last updated 21 July 2026·6 min read
Author: ActBrief Editorial·Reviewer: External legal review pending

Not legal advice. This article is a preliminary technical guide for AI SaaS teams. Always confirm classification and obligations with qualified counsel. Effective dates reflect the Digital Omnibus updates as of July 2026.

Changelog
Updated 21 July 2026: Annex III standalone high-risk obligations deferred to 2 December 2027; Annex I embedded high-risk to 2 August 2028 (Council approval 29 June 2026). Art. 50 transparency remains 2 August 2026.

The fines that get everyone's attention

The headline numbers are scary: €35 million or 7% of global annual turnover. But the reality is more nuanced — and in some ways more concerning for SaaS founders.

Fine tiers explained

ViolationMax fineCompared to GDPR
Prohibited AI practices (Art. 5)€35M or 7% turnoverSame as GDPR top tier
Non-compliance with high-risk obligations€15M or 3% turnoverGDPR mid tier
Providing incorrect info to authorities€7.5M or 1% turnoverGDPR low tier

Enforcement timeline (updated July 2026 — Digital Omnibus)

DateMilestone
Feb 2025AI Act entered into force
Feb 2025Prohibited practices (Art. 5) apply
Aug 2025GPAI provider obligations apply
2 Aug 2026Transparency / disclosure (Art. 50) applies
2 Dec 2027Standalone high-risk systems (Annex III) — deferred by Digital Omnibus
2 Aug 2028High-risk AI embedded in Annex I regulated products

Key: Do not treat August 2026 as a blanket “high-risk enforcement” date. The Council gave final approval to the Digital Omnibus on AI on 29 June 2026, deferring standalone Annex III high-risk duties to 2 December 2027 and embedded Annex I high-risk duties to 2 August 2028. Article 50 transparency still matters in 2026.

Key for SaaS founders: Transparency and prohibited-practices risk are near-term. Full Annex III conformity / registration pressure is a 2027 planning problem — still start the evidence pack early, but don’t invent false urgency.

Who gets fined first

National regulators (each EU member state designates one) will prioritize:

  1. Prohibited AI — social scoring, manipulative AI, real-time biometric surveillance
  2. High-risk systems with clear harm — HR tools that discriminate, credit scoring errors
  3. Non-compliant transparency — SaaS products with no AI disclosure

If you're a B2B AI SaaS without AI disclosure on your website, you're in category 3 — and that's the easiest fix.

The real risk for SaaS founders

The fine itself is usually not the biggest risk. What hurts more:

What enforcement looks like in practice

The EU AI Act is enforced by each member state's market surveillance authority. In practice:

Your risk calculation

Your situationEstimated riskWhat to do
No AI disclosure (user-facing / Art. 50)Rising into Aug 2026Draft disclosure this month
Potential Annex III, no evidence packHigh for diligence; duties largely from Dec 2027Scan + confirm Art. 6(3) + legal review
Limited risk, basic docsLower regulatory near-termMaintain Art. 50 + inventory
Minimal risk, some docsLowRe-check when use case changes

The bottom line

Parts of the AI Act are already enforceable (notably prohibited practices and, from 2 August 2026, Article 50 transparency). Standalone Annex III high-risk duties were deferred to 2 December 2027. Fines are real for what is in force — but most SaaS teams should prioritize an evidence pack and Art. 50 work now, not invent a false 2026 high-risk registration deadline.

The worst position is not knowing which obligations apply when.

Official sources

Ready for legal review?

Get a free readiness brief for your product — not a commodity risk label.

Get a free readiness brief for your product