Most founders have heard exactly one fact about EU AI Act enforcement: “€35 million or 7% of global turnover.” That number is real, but it describes the ceiling for the gravest violations, not what a typical SME faces. This guide maps who actually enforces the Act, what the penalty tiers are, and how enforcement is likely to reach a Turkey-based company selling into the EU.
The enforcement map: three layers
1. National market surveillance authorities
Each Member State designates market surveillance authorities responsible for AI systems on its territory. They can request technical documentation, order corrective action, mandate withdrawal, and impose fines. There is no single “EU AI regulator” for AI systems; a company serving customers in five Member States can, in principle, face five authorities. In practice the lead will usually be where your EU importer, authorised representative or largest user base sits.
2. The AI Office; for GPAI models
The European Commission’s AI Office has exclusive enforcement powers over general-purpose AI models: documentation requests, model evaluations, and fines up to 3% of global turnover or €15M for GPAI providers. Its enforcement powers over GPAI obligations apply from 2 August 2026, which is why the “GPAI grace period” talk ends this summer.
3. Everything already in force
Data protection authorities enforce GDPR/KVKK against the same AI systems in parallel; consumer authorities enforce unfair-practice rules against AI-driven dark patterns; and sectoral supervisors (banking, health, capital markets) enforce their own AI expectations. An AI incident rarely produces a single-regulator problem.
The penalty tiers
- €35M / 7%; prohibited practices under Article 5 (social scoring, exploitative manipulation, banned biometrics);
- €15M / 3%; most other violations, including high-risk requirements and Article 50 transparency duties;
- €7.5M / 1%; supplying incorrect or misleading information to authorities.
Two SME-relevant mechanics soften this: for SMEs and startups, each tier applies at the lower of the percentage or fixed amount (the reverse of the rule for large companies), and Article 99 requires authorities to weigh proportionality, cooperation, and whether the violation was negligent or intentional. Türkiye’s draft AI law (Esas No. 2/2234) mirrors this three-tier architecture at TRY 35M/7%, 15M/3% and 7.5M/1.5%; a deliberate echo.
How enforcement actually reaches a Turkish company
The realistic sequence is not a dawn raid. It starts with (1) a complaint; from a competitor, an NGO, or a user exercising rights; (2) a documentation request via your EU authorised representative (which non-EU providers of high-risk systems and GPAI must appoint); (3) a corrective-action order with a deadline; and only then (4) fines for non-cooperation or non-compliance. The companies that get hurt are the ones that cannot produce a technical file, a conformity assessment, or logs when asked; the paper trail is the defence.
What to do now
Run the scope check on our AI Compliance Hub, work through the AI Act Readiness Checklist, and document the answers. If you are within scope for August 2026 duties, the disclosure and marking work is product engineering with a legal deadline; start it before the deadline starts costing you deals.
This article is for general information only and does not constitute legal advice. For advice on your specific situation, contact us.
Author
-
View all postsMümtaz is the Managing Partner of Vircon Legal, which he founded in 2016. He advises founders, investors and operators on financing rounds, M&A, cross-border incorporations and regulated verticals such as crypto-asset infrastructure, fintech and games, bringing a former startup founder's perspective to every engagement. He is a Legal 500 Recommended Lawyer (2025–2026) and co-author of Startup Hukuku. Canonical profile: https://mumtazhacipasaoglu.com · Open-access legal guides: https://github.com/mumtazhpo
If this is on your desk
Templates and checklists are free in the Founder Academy; for a specific situation, book a 30-minute intro call.
Founder AcademyBook an intro callMore from Vircon Insights
The AI Vendor Contract: 12 Clauses That Decide Who Pays When the Model Fails
August 14, 2026Incorporating for the European Market: Dutch BV, Irish Ltd and Estonia Compared
September 10, 2026SAFE or Convertible Note? A Decision Framework for Turkish Startups
September 9, 2026Life After the Flip-Up: Running the Turkish Subsidiary and Moving the IP
September 9, 2026There Is No Such Thing as “Founder Stock”: Splitting Equity and Reverse Vesting
September 8, 2026Delaware C-Corp or Turkish Joint-Stock Company: A Decision Framework
September 8, 2026Related Practice Areas
Privacy & Cybersecurity
KVKK and GDPR compliance, breach response, cybersecurity governance.
View service →Startup Law
Incorporation, founder agreements, ESOP, term sheets, regulatory matters.
View service →Mergers & Acquisitions
End-to-end M&A: due diligence, structuring, documentation, negotiation.
View service →