Fines under EU AI Act Article 50: what operators really face
EUR 35 million and 7% of turnover concern prohibited AI practices, not the labeling obligation. Article 50 has a lower range – and the practical risk for ordinary websites is low.
The deterrent figures from the headlines – EUR 35 million, 7 percent of worldwide turnover – belong to the prohibited AI practices, not to the labeling obligation. For breaches of the transparency obligations in Article 50, the EU AI Act provides a lower range: up to EUR 15 million or 3 percent of worldwide annual turnover. For an ordinary business website without deepfakes the practical risk is low – what matters is not losing the existing machine-readable mark.
Which fine range applies to what
| Category | Range | Concerns website operators? |
|---|---|---|
| Prohibited AI practices (Art. 5) | up to EUR 35m / 7% | normally no |
| Transparency obligations (Art. 50) | up to EUR 15m / 3% | yes, for AI images and deepfakes |
| False information to authorities | up to EUR 7.5m / 1% | only during an ongoing procedure |
For small and medium-sized enterprises, the lower of the two values applies (fixed amount or percentage).
Who enforces this in Germany
With the AI Market Surveillance and Innovation Promotion Act (KI-MIG), in force since 29 July 2026, the Federal Network Agency (Bundesnetzagentur) is the central market surveillance authority for the AI Act. It can investigate breaches and impose fines. The KI-MIG additionally adds national fines of up to EUR 50,000 for breaches of cooperation and information duties.
What keeps the risk small
- Label deepfakes visibly – that is the only direct obligation to act for operators.
- Preserve the machine-readable mark: AI images from DALL·E, Firefly or Google carry it; it must not be lost when the WordPress image sizes are generated.
- Images from before 2 August 2026 are exempt.
- Clearly recognisable illustrations and icons are not covered by the visible labeling obligation.
Where IMG Performer fits in
IMG Performer detects AI images on upload automatically, lets you categorise borderline cases manually, and writes the machine-readable mark back into every image size generated by WordPress – with a visible label on request. That covers the part that can be solved technically. Details: Labeling AI images for the EU AI Act and the checklist for WordPress operators.
Disclaimer
Legal note: general context, not legal advice. The binding sources are the original text of the EU AI Act (Regulation (EU) 2024/1689, eur-lex.europa.eu/eli/reg/2024/1689/oj), the KI-MIG, and the guidance of the responsible authorities. As of September 2026.
Frequently asked questions
Can a small company really be hit with fines in the millions?
The legal framework states upper limits. For SMEs the lower of the two values applies, and fines must be proportionate. Realistically, an ordinary business website is more likely to face a complaint and a request to remedy than a maximum penalty – the risk rises with intent and with intent to deceive in the case of deepfakes.
Do I have to actively report anything?
No. There is no notification or registration obligation for using AI images on your own website.
Does this also apply to AI-generated text?
Text that is editorially reviewed and taken responsibility for is exempt from the labeling obligation. The obligation targets synthetic media such as image, audio and video.