Book my free AI audit
    We use cookies to analyse site usage and improve your experience. No tracking occurs until you accept.

    EU AI Act Fines 2026: What a Luxembourg SME Risks

    (Updated )
    AI Compliance
    EU AI Act Fines 2026: What a Luxembourg SME Risks

    Quick answer: The EU AI Act sets three fine tiers under Article 99: up to €35 million or 7% of global turnover for Article 5 prohibited practices, €15 million or 3% for most other obligations — including the Article 50 transparency duties that took effect on 2 August 2026 — and €7.5 million or 1% for supplying incorrect information. Article 99(6) gives SMEs and start-ups the lower of the two figures, so a Luxembourg SME with €30 million turnover faces up to €2.1 million on tier 1, not €35 million; Regulation (EU) 2026/1744 extended a comparable lower cap to small mid-caps on the second and third tiers. The penalty regime has applied since 2 August 2025 — it did not start this month, and it was not deferred.

    Last verified 7 August 2026.

    Two things people get wrong about AI Act fines

    First: the penalty framework did not "switch on" in August 2026. Chapter XII of the AI Act, including Article 99, has applied since 2 August 2025. Regulation (EU) 2026/1744 amended Article 99 in July 2026 but did not defer it. If you were told the fines only become real once the high-risk regime lands, that was never true.

    Second: the €35 million headline is the wrong number for almost every reader of this page. For SMEs and start-ups, Article 99(6) inverts the ordinary rule. More on that below, because it changes the board conversation completely.

    We have written about what actually applies now after the Digital Omnibus moved the high-risk deadline to 2 December 2027, about whether you are a provider or a deployer, about high-risk systems, Article 4 literacy, GPAI obligations and Article 5 prohibitions. One question remains: what is the actual exposure if a Luxembourg SME does nothing?

    No jargon, no scare tactics, real numbers, three tiers, the Luxembourg enforcement context, and the three pragmatic moves that get you to "defensible".

    The three fine tiers, in plain numbers

    TierWhat triggers itMaximum
    1Article 5 prohibited practices — social scoring, manipulative AI, exploitation of vulnerability, untargeted facial-image scraping, emotion recognition in workplaces and education, and the rest of the Article 5 list€35 million or 7% of global annual turnover, whichever is higher
    2Most other obligations — high-risk system requirements, GPAI obligations, Article 50 transparency, and (added by the omnibus) certain Article 25 value-chain cooperation and information duties€15 million or 3%, whichever is higher
    3Incorrect, incomplete or misleading information to a notified body or competent authority€7.5 million or 1%, whichever is higher

    Note where Article 50 sits. Failing to disclose that your chatbot is a chatbot is a tier 2 matter — the same band as a high-risk documentation failure. That is the live exposure for an ordinary Luxembourg SME today, because Article 50 has applied since 2 August 2026 while the high-risk regime does not bite until 2 December 2027.

    The SME reversal — the number that actually applies to you

    Article 99(6) states that for SMEs, including start-ups, each fine is capped at the lower of the percentage and the fixed amount, not the higher.

    Worked through on a Luxembourg SME with €30 million turnover:

    TierFixed amountPercentage of €30mApplicable cap for an SME
    1 (Article 5)€35,000,0007% = €2,100,000€2,100,000
    2 (incl. Article 50)€15,000,0003% = €900,000€900,000
    3 (information)€7,500,0001% = €300,000€300,000

    Still company-ending numbers for most Luxembourg SMEs. But not the €35 million the trade press fixated on — and the difference matters when you are arguing for a compliance budget, because a proportionate ask lands better than an apocalyptic one.

    Regulation (EU) 2026/1744 went further. It wrote the definitions of SME and small mid-cap enterprise into the AI Act itself and attached concrete accommodations: a simplified technical documentation form for high-risk systems, proportionate quality-management requirements extended across the SME category, priority access to AI regulatory sandboxes, and a lower fine cap for small mid-caps on the tier 2 and tier 3 bands. If your company sits just above the SME threshold, check whether the small mid-cap definition now catches you — it is a materially better position than it was in 2025.

    Article 99(7) additionally requires authorities to have regard to the size and the interests of an SME when setting the amount. "Up to" means up to.

    Who actually issues the fines in Luxembourg?

    The AI Act delegates national enforcement to competent authorities designated by each Member State. Luxembourg has not finished that process.

    Bill of law n°8476, deposited with the Chamber of Deputies on 23 December 2024, is the instrument. It designates the national authorities and sets the national administrative penalty rules. Its architecture:

    • CNPD (Commission nationale pour la protection des données) — national competent authority, single point of contact, and market surveillance authority by default for AI systems not covered by an existing sectoral regulator. The CNPD would also operate Luxembourg's Article 57 regulatory sandbox.
    • CSSF — AI systems in the financial sector, within its existing supervisory remit.
    • CAA (Commissariat aux Assurances) — AI systems in insurance.
    • ILR (Institut Luxembourgeois de Régulation) — high-risk AI deployed by entities that are essential or important under Luxembourg's NIS2 transposition.
    • ILNAS — notifying authority for conformity assessment bodies, not the general market surveillance authority.

    Earlier commentary — including an earlier version of this article — put ILNAS or the ILR in the lead role. The bill as deposited puts the CNPD at the centre. The CNPD has been preparing accordingly, convening the "AI Act in Action" conference in Luxembourg in January 2026.

    The bill was still in the parliamentary process at the time of writing, and the date of adoption cannot be predicted. That does not suspend your obligations: the AI Act is a regulation with direct effect, and the Commission enforces the GPAI layer directly through the AI Office regardless of national designation.

    Practically: a single AI system in a Luxembourg financial-services firm could face questions from the CSSF and the CNPD on different aspects, with cross-referrals. The administrative cost of multiple supervisors is real and sits on top of any fine.

    What "doing nothing" exposes you to, ranked by what is actually live

    Live today — highest realistic enforcement probability

    1. Article 50 transparency. Applicable since 2 August 2026 and enforced by national market surveillance authorities. Providers must design systems that interact with people so the person knows it is an AI, and must mark generative outputs machine-readably (with a grace period to 2 December 2026 for systems already on the market). Deployers must disclose deepfakes, disclose AI-generated public-interest text absent human editorial responsibility, and inform people exposed to emotion recognition or biometric categorisation. Tier 2. This is the single most likely first contact for an ordinary Luxembourg SME, because the breach is visible from the outside — a regulator, a competitor or a customer can see an undisclosed chatbot without opening your files.

    2. Article 5 prohibited practices. Applicable since 2 February 2025. Highest severity, tier 1. Most Luxembourg SMEs are not in Article 5 territory, but two patterns catch ordinary businesses: emotion-recognition or "engagement scoring" tools pointed at employees, and manipulative optimisation in onboarding flows. Two further prohibitions — non-consensual intimate imagery and CSAM generation — join the list on 2 December 2026.

    3. Article 4 AI literacy. Applicable since 2 February 2025, and softened by the omnibus: the duty is now to take measures to support the development of AI literacy rather than to ensure a sufficient level of it. Lower standard, same obligation. No certification scheme; a documentation expectation. Cheapest thing on this list to fix. See our Article 4 piece.

    4. GPAI obligations. Applicable to model providers since 2 August 2025, and the Commission's power to fine them started 2 August 2026 (up to 3% or €15 million). This is your model vendor's exposure, not yours — unless you fine-tune or substantially modify a model and put it out under your own name, in which case see the classification question. Legacy models placed on the market before 2 August 2025 have until 2 August 2027.

    Not yet live — but the work has to start now

    5. Provider vs deployer classification. No standalone fine attaches to failing to classify. It is the prerequisite to knowing which of everything above you owe, and its absence is what turns a routine information request into a bad week. Five-minute test here.

    6. High-risk systems (Annex III). Deferred to 2 December 2027 by Regulation (EU) 2026/1744; product-embedded AI to 2 August 2028. Tier 2 when it applies. Highest single compliance bill for a Luxembourg SME, and a twelve-to-eighteen-month build. See the high-risk roadmap.

    7. Documentation and record-keeping. Providers of high-risk systems keep technical documentation; deployers keep logs for at least six months. This is the category that stacks a tier 3 information-supply failure on top of a tier 2 substantive one.

    Quick checkpoint. If you have not done the provider-vs-deployer classification across your AI systems, stop reading and do that first. It takes about 30 minutes per system and it is the prerequisite to everything else — the structured version is our AI Act readiness service.

    Running a Luxembourg SME?

    Book a free 30-minute AI audit — we’ll tell you honestly where AI pays off for your business, and where it doesn’t.

    Book a free AI audit

    What enforcement actually looks like in practice

    Regulation does not land in a vacuum; it lands on a national regulatory culture. Luxembourg's is, by EU standards, risk-based, dialogue-first, and proportionate to the size of the regulated entity — the consistent pattern across the CSSF, the CNPD and the ILR over the last decade. That is an observation, not legal advice and not a guarantee.

    What that means for a Luxembourg SME:

    • First contact is likely a question, not a fine. Competent authorities tend to open with a request for information.
    • A defensible documentation file changes everything. A register of AI systems, a documented provider/deployer classification, an Article 50 disclosure inventory, a literacy training log and a written human-oversight design produce a very different conversation from one where none of those exist.
    • The fine, if it comes, is calibrated. Article 99(7) plus the SME and small mid-cap caps mean the realistic exposure is a fraction of the headline.
    • Enforcement capacity is uneven right now. Several Member States, Luxembourg among them, have not completed their market surveillance designations. That is a reason to build the file calmly, not a reason to skip it — the obligations are already binding and the designation gap will close.

    The three pragmatic moves that get you to "defensible"

    None of these are expensive. Together they are about two days of work for a typical Luxembourg SME.

    1. Build the AI systems register. One spreadsheet, one row per system. Columns: name, owner, provider-or-deployer, Article 50 duties attaching and whether they are live on the product, Annex III high-risk yes/no/filtered, human-oversight design, current literacy training. Half a day. This single document changes 80% of what an enforcement conversation looks like.
    2. Fix the Article 50 disclosures. Walk every customer-facing AI surface — website chatbot, voice agent, in-app assistant, AI-generated published content — and confirm the disclosure exists, in FR, DE and EN, at first interaction. Half a day for most SMEs, and it closes the only exposure on this page that is live today.
    3. Document the literacy programme and the classification. Even if the "programme" is a 20-minute internal video and a one-pager attached to the employment contract, write it down. Then run the 5-minute test across every system. One day for around ten systems.

    Two days of work. For most Luxembourg SMEs the exposure from not doing it runs to six or seven figures; the cost of doing it is four figures. That ratio is almost embarrassing to have to argue.


    Make the exposure a number you can put in a board pack

    "Up to €35 million" is not a number a board can act on. "€900,000 tier 2 cap, three live Article 50 gaps, two systems that become high-risk on 2 December 2027" is.

    The 20 More AI Act Readiness Assessment produces exactly that, in ten working days:

    1. The AI system register — every system and AI feature, with the provider-or-deployer determination made and evidenced per system.
    2. The Article 50 gap report — the disclosures you owe today, mapped to the specific chatbots, voice agents, screens and published content missing them, with the 2 December 2026 machine-readable-marking items scheduled as engineering work. This is the live tier-2 exposure, closed.
    3. The Annex III exposure list — which systems are high-risk on 2 December 2027, which fall under the Article 6(3) filter and why, whether an Article 27 FRIA is yours, and a costed work programme.
    4. A one-page board memo — with your actual capped exposure per tier, calculated on your turnover, signed and dated.

    See the AI Act readiness service, or book the 30-minute scoping call. We will send the register template the same day — pre-filled with the columns a Luxembourg supervisor asks for. No pitch deck.

    Is your AI project eligible for up to 70% Luxembourg funding?

    Max €17,500 per project. Instant estimate — 4 quick questions, no email required.

    Check my eligibility (2 min)

    Ready to put this into practice?

    Two ways to start — pick whichever fits your timing.

    Tags:
    Luxembourg
    EU AI Act
    Compliance
    Fines
    Penalties

    Related Resources

    AI Implementation in Luxembourg

    Explore our comprehensive guide to AI adoption, implementation, and governance in Luxembourg.

    Read the Guide

    Work with an AI consultant in Luxembourg

    See what we build, what it costs, and how projects qualify for up to 70% SME co-funding.

    AI Consultant in Luxembourg