Skip to main content

Tag: AI fines

Article 50 of the EU AI Act: transparency is no longer optional

Artificial intelligence is already part of everyday business life. Companies use chatbots on their websites, AI-generated text in marketing, AI images in social media, virtual assistants in customer service, and avatars or synthetic video content in branding and communication.

The problem is that many businesses have focused only on whether the technology works. Far fewer have asked the legal question: does it comply?

That is where Article 50 of the EU AI Act becomes highly relevant. Article 50 sets out transparency obligations for providers and deployers of certain AI systems. In practice, this means that, in some situations, a business must inform people that they are interacting with AI or disclose that content has been artificially generated or manipulated.

What does Article 50 actually require?

Article 50 is not a general rule for every internal use of AI. It is more targeted. It applies to certain AI systems and certain outputs.

Under the official text, Article 50 covers, among other things:

  • AI systems intended to interact directly with natural persons, unless it is obvious that the person is interacting with AI.
  • AI systems generating synthetic audio, image, video or text content, whose outputs must be marked in a machine-readable and detectable way as artificially generated or manipulated, subject to the limits set out in the Regulation.
  • Deployers of emotion recognition systems or biometric categorisation systems, who must inform exposed individuals of the operation of the system.
  • Deployers of AI systems generating or manipulating deepfake image, audio or video

    In short: if your company uses AI in a way that affects how users perceive content or interaction, transparency may no longer be optional.

    Why should businesses care?

    Many companies assume that if an agency built the chatbot, a SaaS tool generated the content, or a tech provider installed the system, the legal side must already be covered.

    That assumption is risky.

    The AI provider may be focused on functionality. Your marketing agency may be focused on conversion. Your general accountant may not be advising on the EU AI Act at all. Yet your company may still be the one exposed if the use of AI is not transparent enough. content, who must disclose that the content has been artificially generated or manipulated, with a softer rule for clearly artistic, creative, satirical or fictional works.

    The legal risk is not only theoretical. It is operational and reputational. A competitor, customer, employee or authority may eventually ask a very simple question:

    How are you using AI, and have you informed users properly?

    If the answer is vague, improvised or undocumented, the business is exposed.

    What kind of businesses may be affected?

    Article 50 may be relevant if your business:

    • uses a chatbot or AI assistant on its website;
    • uses AI-generated content in customer-facing communications;
    • publishes AI-created or AI-manipulated images or videos;
    • uses avatars or synthetic spokesperson videos;
    • relies on AI-generated text in public-facing information;
    • deploys deepfake-style content;
    • uses emotion recognition or biometric categorisation systems.

    Not every business will be affected in the same way. But many businesses already use AI in customer-facing environments without having reviewed the legal transparency angle.

    What are the fines for non-compliance?

    This is the part that gets attention — and understandably so.

    Under Article 99 of the EU AI Act, non-compliance with Article 50 transparency obligations may be subject to administrative fines of up to EUR 15,000,000 or, if the offender is an undertaking, up to 3% of its total worldwide annual turnover for the preceding financial year, whichever is higher.

    The Regulation also makes clear that, in the case of SMEs, including start-ups, the fine is capped at the lower of the relevant percentage or amount. It further states that penalties must be effective, proportionate and dissuasive, while taking into account the interests of SMEs and their economic viability.

So the correct message is not “every SME will be fined millions”. That would be legally sloppy and commercially unhelpful.

The correct message is this:

Non-compliance can be costly, and businesses should not wait for a complaint, inspection or challenge before checking whether their AI use is transparent enough.

When does this matter?

The AI Act provides that the Regulation applies from 2 August 2026, subject to certain exceptions for different parts of the Regulation.

That means businesses already using AI should not leave this until the last minute. Transparency issues are often not difficult to identify, but they do require a proper legal review.

The real issue: evidence of diligence

In practice, one of the most important questions is not simply whether a company made a mistake.

It is whether the company can show that it acted seriously and diligently.

A business that has reviewed its systems, identified where Article 50 may apply,

documented its use of AI and adopted a reasonable action plan is in a very different position from a business that has done nothing at all.

That is why legal review matters.

AI compliance is not about panic

The goal is not to scare businesses away from AI.

The goal is to use AI properly, transparently and with legal awareness.

Most companies do not need panic. They need clarity.

They need to know what applies, what does not, and what practical steps they should take now.

How Bennet & Rey can help

At Bennet & Rey, we help businesses, entrepreneurs and SMEs review their use of AI from a legal perspective.

Final thought

Article 50 of the EU AI Act sends a clear message: if your business uses certain AI systems, transparency is not optional.

If you use chatbots, avatars, AI-generated content or other customer-facing AI tools, now is the time to ask the legal question — not later.

Because the real risk is not just the fine.

The real risk is discovering too late that your AI was visible to everyone except your legal review.

If you have any quesions, please let us know. At Bennet & Rey we are here to help you.

Fines for the Misuse of AI: What Self-Employed Professionals and SMEs Need to Know

Artificial intelligence is already part of the day-to-day operations of many businesses.

Self-employed professionals, retailers, professional firms and small and medium-sized enterprises use tools such as ChatGPT, Microsoft Copilot and other AI systems to draft documents, respond to enquiries, prepare marketing campaigns, analyse information and improve internal processes.

Using these tools is not, in itself, unlawful.

However, the professional use of artificial intelligence is not free from legal obligations. The European Union Artificial Intelligence Act establishes a system of responsibilities and penalties that may also apply to self-employed professionals and SMEs.

The key question is not simply whether a business uses artificial intelligence. It is how the technology is used, for what purpose and what consequences it may have for clients, employees, job applicants or consumers.

Can an SME be fined for using artificial intelligence?

Yes.

A self-employed professional or an SME may fall within the scope of the EU AI Act when using an AI system as part of its professional or commercial activity.

The Regulation uses the term “deployer” to describe a natural or legal person who uses an AI system under their authority, except where the system is used in the course of a personal, non-professional activity.

This means that a business does not need to have developed its own artificial intelligence system in order to assume legal responsibilities.

It may be sufficient for the business to use an AI tool to make decisions, screen job applicants, assess employees, classify customers, generate content or provide services.

Not all uses of artificial intelligence, however, carry the same level of risk.

The EU AI Act follows a risk-based approach. The most demanding obligations apply to prohibited AI practices and systems classified as high-risk.

When does the EU AI Act apply?

The Regulation is being introduced progressively.

The general provisions and prohibitions relating to certain AI practices began to apply on 2 February 2025.

The rules concerning penalties began to apply on 2 August 2025.

Most of the Regulation will become fully applicable from 2 August 2026, although some specific provisions are subject to different implementation dates.

Businesses should therefore not wait until the last moment to review how artificial intelligence is being used within their organisations.

What fines does the EU AI Act establish?

The Regulation provides for three principal levels of administrative fines.

1. Prohibited AI practices

Breaching the prohibition on certain artificial intelligence practices may lead to fines of up to:

€35 million or 7% of the company’s total worldwide annual turnover.

Prohibited practices include, in certain circumstances, AI systems that manipulate human behaviour, exploit people’s vulnerabilities, carry out certain forms of social scoring or use prohibited biometric technologies.

2. Breaches of other obligations under the Regulation

Failure to comply with other obligations applicable to providers, deployers, importers, distributors or notified bodies may lead to fines of up to:

€15 million or 3% of total worldwide annual turnover.

This category may include breaches connected with high-risk AI systems, transparency, documentation, human oversight or cooperation with the competent authorities.

3. Providing incorrect, incomplete or misleading information

Providing incorrect, incomplete or misleading information to the relevant authorities or notified bodies may lead to fines of up to:

€7.5 million or 1.5% of total worldwide annual turnover.

Do the same maximum amounts apply to SMEs?

The Regulation expressly takes account of the position of small and medium-sized enterprises, including start-ups.

Where the infringing business is an SME, the maximum fine in each category is the lower of:

  • the fixed monetary amount established in the Regulation; or
  • the relevant percentage of the business’s annual turnover.

For example, if a small business has an annual turnover of €500,000, the percentage-based maximums would be:

  • up to €35,000 for a prohibited AI practice: 7%;
  • up to €15,000 for other infringements: 3%;
  • up to €7,500 for providing incorrect, incomplete or misleading information: 1.5%.

This does not mean that these amounts will automatically be imposed.

The competent authority must consider the circumstances of the individual case and ensure that any penalty is effective, proportionate and dissuasive.

Relevant factors may include:

  • the nature and seriousness of the infringement;
  • its duration;
  • the number of people affected;
  • the damage caused;
  • whether the conduct was intentional or negligent;
  • the measures taken to correct the infringement;
  • the level of cooperation with the authorities;
  • any previous infringements;
  • and the financial capacity of the business.

Can the use of ChatGPT lead to a fine?

Using ChatGPT, Copilot or another generative AI tool does not, by itself, constitute an infringement.

The legal risk arises when a business uses artificial intelligence without appropriate safeguards or for purposes that may affect the rights of other people.

Examples may include:

  • entering clients’ personal data or confidential information into an AI system without first assessing the risks;
  • using AI to select or reject job applicants without sufficient human oversight;
  • assessing employee performance or behaviour through automated systems;
  • publishing AI-generated or manipulated images, videos or audio without complying with applicable transparency obligations;
  • making significant decisions solely on the basis of AI-generated output;
  • using tools that produce discriminatory or biased results;
  • or allowing staff to use AI systems without training or internal guidance.

Other legislation may also apply alongside the EU AI Act, including the General Data Protection Regulation, employment law, consumer protection law, intellectual property law and professional duties of confidentiality.

AI literacy is also a legal obligation

The EU AI Act requires providers and deployers of AI systems to take measures to ensure that the people using those systems on their behalf have a sufficient level of AI literacy.

This does not necessarily mean turning every member of staff into a technical expert.

It means ensuring that employees understand, according to their roles:

  • which AI tools they are permitted to use;
  • what information they must not enter;
  • the limitations of the system;
  • when AI-generated output must be reviewed;
  • what risks may arise;
  • and when human intervention is required.

Allowing employees to use AI without any training, policy or supervision may expose a business to unnecessary legal and operational risks.

What should an SME do now?

The first step is not to prohibit artificial intelligence.

It is to understand how AI is actually being used within the organisation.

Many businesses believe that they do not use AI in any significant way, while their employees may already be using it to summarise documents, draft emails, review CVs, prepare quotations, generate images or respond to client enquiries.

An initial review should include the following measures.

1. Identify the AI tools being used

The business should know which artificial intelligence systems are used by its employees, collaborators and external service providers.

2. Determine how they are being used

Using AI to improve the wording of a document does not create the same level of risk as using it to select employees or decide whether a customer should receive a service.

3. Assess the level of risk

The business should determine whether the system falls within a prohibited practice, a high-risk system, a system subject to transparency duties or a lower-risk use.

4. Review the information entered into the system

It is important to determine whether employees are entering personal data, confidential information, trade secrets or client documents into AI tools.

5. Establish human oversight

AI-generated outputs should not be accepted automatically, particularly where they may have legal, financial or personal consequences.

6. Train employees

Staff should receive clear and proportionate guidance on the authorised use of artificial intelligence.

7. Adopt an internal AI policy

An internal policy can establish which tools are authorised, for which purposes they may be used and which safeguards must be followed.

Compliance without preventing innovation

The EU Artificial Intelligence Act is not intended to prevent businesses from using this technology.

Its purpose is to promote artificial intelligence that is safe, transparent and respectful of fundamental rights.

For self-employed professionals and SMEs, compliance does not have to become a disproportionate burden. The measures adopted should reflect the size of the business, the nature of its activity and the actual risks created by the AI systems it uses.

However, ignoring the legislation or assuming that a practice must be acceptable because “everyone is using AI” may lead to legal, reputational and financial consequences.

The best form of prevention is to review current AI use, identify the risks and establish clear internal rules before a problem arises.

How can Bennet & Rey help?

Bennet & Rey offers a legal AI compliance assessment and internal policy service for SMEs and professional firms.

The service may include:

  • identifying the AI tools currently used within the business;
  • analysing their purposes and legal risks;
  • reviewing the use of personal data and confidential information;
  • classifying AI systems according to their level of risk;
  • preparing an internal AI use policy;
  • establishing human oversight procedures;
  • drafting clauses for employees, collaborators and suppliers;
  • and recommending appropriate AI literacy and training measures.

The objective is not to prevent a business from using artificial intelligence, but to help it use AI safely, proportionately and in a way that reflects its actual activities.

Every organisation uses artificial intelligence differently. The first step should therefore be an individual assessment to determine which measures are genuinely necessary.

Does your business use artificial intelligence, and are you unsure whether it complies with the new rules?

Contact Bennet & Rey to request an AI compliance assessment.