CEO · AI Act · Article 99(6)

The EUR 140,000 AI Act Fine That Ends the Startup

Article 99(6) applies "whichever thereof is lower" to SMEs and start-ups. For a Fortune 500, 7 percent of turnover is a disclosable but absorbable line item. For a seed-stage founder whose cap table and career ride on the next eighteen months of runway, the same seven percent against a small revenue base consumes the company.

In brief: EU AI Act Article 99(6) caps SME fines at the lower of the absolute euro ceiling or the turnover percentage. A EUR 2 million-revenue AI startup faces a EUR 140,000 Tier 1 maximum (7 percent of turnover) for prohibited-practice exposure. Prohibitions have applied since 2 February 2025; Article 50 and GPAI enforcement remain key 2026 checkpoints; high-risk dates now need the 2027/2028 AI Omnibus caveat. The pre-loaded Article 3 glossary pack is a governance artifact, not a legal shield.

The EUR 140,000 that ends the company

Article 99 of the EU AI Act sets three fine tiers. For undertakings the higher of an absolute euro cap or a percentage of worldwide turnover applies. Paragraph 6 inverts that calculus for startups and SMEs.

"In the case of SMEs, including start-ups, each fine referred to in this Article shall be up to the percentages or amount referred to in paragraphs 3, 4 and 5, whichever thereof is lower." — AI Act Article 99(6) (artificialintelligenceact.eu)

At first glance the rule reads as startup-friendly. It is not. Article 99(1) anchors the principle: penalties shall be "effective, proportionate and dissuasive" while considering "the interests of SMEs, including start-ups, and their economic viability." Proportionate, in the regulator's view, means enough to change behaviour. For a Fortune 500, that is a press-release expense. For a seed-stage AI company, a single Tier 1 penalty can land in the same zone as multiple months of payroll against the runway the company has left.

#TierTriggerAbsolute capTurnover capSME max (EUR 2M revenue)
1Tier 1Prohibited AI practices (Article 5)EUR 35,000,0007%EUR 140,000
2Tier 2High-risk AI obligations, most other breachesEUR 15,000,0003%EUR 60,000
3Tier 3Incorrect or misleading information to authoritiesEUR 7,500,0001%EUR 20,000

The EUR 140,000 example is direct arithmetic under Article 99(6): 7 percent of EUR 2 million, which is lower than the EUR 35 million absolute cap. A EUR 10 million-revenue startup sits at a EUR 700,000 Tier 1 ceiling on the same rule. A pre-revenue seed-stage company sits at a zero-percent-of-turnover cap on the literal reading of Article 99(6); in practice, regulators retain discretion under Article 99(7) to weigh facts and the entity's economic viability, and operational disruption, legal fees, and reputational fallout from an enforcement action can still be terminal regardless of whether a monetary fine is imposed.

What this costs the CEO personally

At a seed or Series A stage, the CEO typically holds a non-trivial minority stake on a fully diluted basis. A going-concern event triggered by regulatory fine, legal fees, and a lost round follows a predictable path: liquidation preferences clear, common stock extinguishes, the founder's equity position goes to zero. The career chapter closes with a regulator-named enforcement file on the public record.

That is not a recoverable event. Unlike a layoff or a missed quarter, an AI Act enforcement action against a startup becomes part of the founder's diligence history. The next fundraise mentions it. The next board seat requires explaining it. The personal stakes are total.

This article covers the statutory AI Act tier only. Parallel SEC + DOJ individual charges — the Saniger and Raz cases — sit on top for founders with US capital in the cap table; see the AI washing disclosure article.

The investor diligence question

A founder who can produce a time-stamped, four-eyes-approved record of which Article 3 terms the company has classified, by whom, and against which statutory definition has an artifact investors, underwriters, and acquirers can inspect. The survey evidence on CEO confidence is blunt: KPMG's 2025 CEO Outlook (n=1,350) found 69 percent of CEOs cite the pace of AI regulation as a barrier to success. EY's Responsible AI Pulse (August 2025) found only 14 percent of CEOs strongly agree their organization has appropriate AI controls in place, versus 29 percent of the broader C-suite. (Controls are not the same as regulatory compliance — but the gap is what investors probe.)

An investor reading those surveys expects evidence that the founder is in the 14 percent who can point to appropriate AI controls — and can show the documentation behind that.

The calendar changed for high-risk systems

Article 113 set the original transitional provisions. The 7 May 2026 AI Omnibus political agreement changed the planning dates for high-risk systems, pending final Official Journal text.

Prohibitions are already enforceable. A startup currently deploying an AI system that could be classified as prohibited under Article 5 is already in a Tier 1 exposure window. Correct Article 3 classification is the first-order control; legal review, conformity assessment, and technical documentation come downstream but depend on the definitions being right.

How terminology governance helps

Compliance Glossary for Confluence is not a legal shield. It does not prevent an enforcement action, replace qualified counsel, or substitute for conformity assessment under Articles 9, 11, or 17. It is a concrete governance artifact: a time-stamped, four-eyes-approved, version-controlled record of how a startup classifies the terms that determine which tier applies.

The outcome: the 68 Article 3 definitions come pre-loaded. The startup approves them inside Confluence, with two-person sign-off and a permanent change history. For current pricing, see the Atlassian Marketplace.

The Compliance Glossary Forge app is Forge-native. The app does not operate external servers and issues no external API calls (its manifest carries no external:fetch:backend permission), and adds no third-party processor for EU data-protection review of app data. For customers who are themselves regulated financial entities subject to DORA, Forge-native architecture keeps app data within the customer's Atlassian region and avoids adding a separately-registrable ICT third-party service provider.

Frequently asked questions

What is the AI Act fine for an SME or startup?

Article 99(6) applies the lower of the two caps. For a EUR 2 million-revenue AI startup, Tier 1 (prohibited practices) = EUR 140,000 (7 percent of turnover, lower than the EUR 35 million absolute cap). Tier 2 (high-risk breaches) = EUR 60,000. Tier 3 (misleading information to authorities) = EUR 20,000. For a pre-revenue startup the turnover cap is zero, but operational disruption, legal fees, and reputational fallout from an enforcement action remain terminal regardless of whether a monetary fine is imposed.

Why is a EUR 140,000 fine existential for a startup?

A fine of that size, plus legal fees of the underlying action, plus reputational impact on the next round, often exceeds remaining runway for a seed- or Series-A AI company. The founder's equity extinguishes in a down-round or wind-down. The same percentage at Fortune 500 scale is an expense line; at startup scale it is the business.

When do AI Act penalties apply?

Prohibited-practice and GPAI checkpoints are already live. After the 7 May 2026 AI Omnibus political agreement, stand-alone high-risk AI rules move to 2 December 2027 and product-embedded high-risk rules move to 2 August 2028 as planning dates pending final legal text. Article 99 fines still matter for prohibited practices, transparency obligations, and misleading information to authorities.

Which sources should startups re-check?

Re-check Regulation (EU) 2024/1689, the European Commission AI Act page, the Council AI Omnibus political agreement, and AI Act Service Desk Article 50 before using deadline language in investor or board materials.

How does a terminology glossary help?

Article 3 contains 68 definitions that determine which tier applies. "High-risk AI system", "prohibited practice", "substantial modification", "GPAI model", "deployer", and "provider" each have precise statutory meanings. A four-eyes-approved, audit-trailed glossary records who approved which definition, when, and against which regulatory text. That is evidence of reasonable care — not a legal shield, but a concrete record an enforcement authority, investor, or D&O underwriter can inspect.

This article is informational and is not legal advice. Consult qualified counsel for AI Act compliance decisions specific to your facts.

Get the 68 Article 3 definitions governed before the next AI Act checkpoint

For current pricing, see the Atlassian Marketplace.

Evaluate in Confluence Read the Security Whitepaper

Related reading