Skip to main content

€15M EU fine risk for ChatGPT, Claude and Gemini: what actually changed

Ilustrační obrázek
A nurse in Lyon uses ChatGPT to rewrite a patient letter. A bakery in Kraków lets Claude answer weekend messages. A teacher in Leipzig asks Gemini to turn a textbook chapter into a quiz. None of them will be fined. But the companies providing those chatbots now face EU rules with enforceable obligations — including penalties that can reach €15 million or a percentage of worldwide annual turnover, depending on the infringement and the party responsible.

EU enforcement is moving from deadlines to supervision

For years, the EU AI Act lived as a future deadline. The first major GPAI obligations began applying on 2 August 2025, while the Act's transparency rules in Article 50 apply from 2 August 2026. The European Commission's AI Office has responsibility for supervising providers of general-purpose AI models and can investigate whether those providers comply with the Act.

The Commission's powers are not a general licence to inspect any model or demand any material at any moment. Under the AI Act, it can request information and documentation from GPAI providers, carry out evaluations, and investigate possible breaches within its remit, particularly where a model may present systemic risks. National authorities remain responsible for many obligations concerning AI systems and their deployers. The AI Act text and the European Commission's AI regulatory framework set out those roles.

The rules can apply to providers outside the EU when their AI models or systems are placed on the EU market, put into service in the EU, or their output is used in the Union, depending on the relevant provision. OpenAI, Anthropic and Google are therefore not outside the Act simply because they are US companies. The same analysis can apply to Meta's Llama, DeepSeek's models, xAI's Grok and Europe's own Mistral, although the duties depend on the provider's role, the model's classification and how it is placed on the market.

The implementation calendar is not one single switch. GPAI provider duties and the Commission's related supervisory role are distinct from the later transparency obligations in Article 50 and from the obligations applying to high-risk AI systems. Treating every deadline as an August 2026 “activation” obscures which organisation must do what.

The €15 million question: how the fine ladder works

The headline number is €15 million — but it is not an absolute ceiling in every case. For the relevant categories, the AI Act allows a fine of up to €15 million or 3% of the undertaking's total worldwide annual turnover for the preceding financial year, whichever is higher. That “whichever is higher” rule applies to undertakings generally; under Article 99, for SMEs and start-ups the applicable maximum for those administrative fines is the lower of the fixed amount and the relevant percentage. The applicable percentage is based on global turnover, not merely revenue generated in the EU. The ceiling and the responsible authority depend on the infringement and on whether the case concerns a provider, deployer or another undertaking.

ViolationMaximum fine…or share of global turnover
Prohibited AI practices€35 million7%
Other breaches of the AI Act, including applicable high-risk obligations€15 million3%
GPAI provider obligations under the Commission's enforcement regime (Article 101)€15 million3%
Supplying incorrect, incomplete or misleading information to the Commission or national authorities€7.5 million1%

SME and start-up exception: For the Article 99 administrative-fine bands, an SME or start-up faces the lower of the fixed amount and the percentage-based turnover amount. This means the “whichever is higher” rule is not applied to such businesses automatically. The separate Article 101 GPAI fine regime remains in place.

These are statutory maximums, not automatic tariffs. The Act requires the competent authority to consider factors such as the nature, gravity, duration and consequences of the infringement. For GPAI providers, the Commission can impose fines under its specific powers. For many other AI Act breaches, enforcement is handled by the relevant national authority. In a prohibited-practice example, the provider or deployer that carried out the prohibited activity is the party potentially exposed; in a GPAI documentation case, responsibility normally rests with the model provider.

The Commission may also require corrective action, including measures affecting the availability of a non-compliant GPAI model, where the conditions in the AI Act are met. That is a legal enforcement option, not evidence that every non-compliant model will automatically be blocked.

Providers of GPAI models with systemic-risk obligations must perform model evaluations, identify and mitigate systemic risks, and report serious incidents. The Act does not establish a blanket rule requiring those evaluations to take place every month.

What ChatGPT, Claude and Gemini must distinguish

The practical impact of Article 50 is more specific than the shorthand “everything must be watermarked”. The exact duty depends on the type of system and on whether the organisation is the provider or the deployer. The wording of Article 50 in the AI Act is the relevant source.

  • Chatbots — providers of systems intended to interact directly with people must design them so that users are informed that they are interacting with an AI system, unless this is obvious from the circumstances and context.
  • Machine-generated outputs — providers of AI systems that generate synthetic audio, image, video or text must ensure that outputs are marked in a machine-readable format and detectable as artificially generated or manipulated, where Article 50 applies. This does not mean that every piece of synthetic content must display the same visible watermark.
  • Deepfakes and public-interest material — deployers are responsible for disclosing when image, audio or video content has been artificially generated or manipulated and constitutes a deepfake. Deployers that generate or manipulate text published to inform the public on matters of public interest also have a disclosure duty, subject to the conditions and exceptions in the Act.

These obligations are not a verified claim that every major vendor has added one identical built-in watermarking system to every model. ChatGPT, Claude and Gemini are examples of widely used services whose providers and commercial customers must assess which Article 50 duties apply to the particular product and use case. Product availability, subscription pricing, user totals and prompt volumes do not determine the legal classification by themselves.

The part small businesses missed: you are the deployer

Individuals are not the normal targets of Article 50 fines for simply using a consumer chatbot. But a European company that installs a ChatGPT-based support bot or an HR system built on Claude is a deployer. Depending on the system and use, the deployer may have to inform people that they are interacting with AI, disclose deepfakes or certain public-interest content, and meet other obligations under the Act. The provider, meanwhile, remains responsible for provider-level duties such as the applicable marking of generated outputs.

The Commission can request information or documentation from GPAI providers within its statutory investigative remit; that is different from an unrestricted power to demand any deployer's material “at any time”. National competent authorities may supervise deployers under the provisions assigned to them.

For a small agency, that means one practical task: ask your AI vendor or integration partner for the compliance paperwork before you sign, not after. The contract should make clear whether the vendor is the provider of a GPAI model, the provider of an AI system or only a technical intermediary, and which party handles user notices and content disclosures.

Why Europe's AI strategy is not just about frontier scale

EU policy is not measured only by whether European companies match US laboratories on raw compute. European AI firms, including Mistral AI, also compete through control over deployment, data handling and integration into specific business or industrial settings. That does not prove that Europe has stopped pursuing frontier capabilities, and individual product announcements should not be treated as evidence of a continent-wide strategic shift.

For European customers, the more concrete distinction is accountability: where data is processed, which provider supplies the model, which organisation deploys the system and who must provide a disclosure when generated content reaches the public. We have been tracking this regulatory context in our wider coverage of the AI Act for European readers.

What you will actually notice

Enforcement may show up as a chatbot saying “I'm an AI”, an image file carrying machine-readable provenance information, or a terms-of-service page explaining how a provider meets its obligations. For most Europeans, that is the AI Act — technical, divided between providers and deployers, and increasingly visible as the relevant deadlines take effect.

Could I personally be fined for using ChatGPT, Claude or Gemini in the EU?

Not for ordinary personal use of a chatbot. The penalty provisions primarily concern providers, undertakings and, in specific cases, commercial deployers or other organisations responsible for an infringement.

Can the EU actually restrict ChatGPT, Claude or Gemini?

The Commission has enforcement tools for GPAI providers, including requests for information, investigations, fines and corrective measures. Restrictions affecting a model can be considered where the conditions in the AI Act are met; they are not an automatic consequence of an ordinary compliance query.

Do open-source models like Llama or DeepSeek escape the rules?

Not automatically. The Act contains specific conditions and exemptions for certain free and open-source GPAI models, but those exemptions are not universal. Commercial availability, systemic-risk status and the provider's obligations must be assessed under the relevant provisions.

Discussion

No comments yet — be the first to share your thoughts.
X

Don't miss out!

Subscribe for the latest news and updates.