Methodology & Transparency: This analysis draws on primary sources — including Eurostat, OECD, national statistical agencies, peer-reviewed literature, and official vendor disclosures — combined with Alice Labs implementation data. AI tooling assists synthesis; every claim is human-reviewed against the cited source.
All figures and claims link to their public source for verification. Reviewed by the named author and reviewer above. Methodology, source list, and revision history are available below.
Cite This Report
Ingemarsson, L. (2026, April 23). EU AI Enforcement and Regulatory Case Database 2026 (Version 1.0). Alice Labs. https://alicelabs.ai/reports/eu-ai-enforcement-regulatory-case-database
What does the EU AI enforcement record show in 2026?
EU AI enforcement is already real, but it is not yet mainly AI Act penalty enforcement. As of April 2026, public cases are dominated by GDPR, courts, labour, consumer, competition, and public-sector law, with Clearview, Italy's Garante, SCHUFA, Dun & Bradstreet, Foodinho, Deliveroo, BriefCam, and AEPD biometric proctoring as key citation anchors.
The EU AI Enforcement and Regulatory Case Database 2026 tracks 27 public case rows and 80 public sources across AI-related enforcement, court rulings, compliance orders, interim measures, and public investigations. The central finding: AI enforcement is already active in Europe, but the public record is still mostly a GDPR-era and court-led record, not a mature AI Act penalty record.
The strongest sanction pattern concerns facial recognition and scraping-based biometric databases, especially Clearview actions in Italy, Greece, France, Austria, and the Netherlands. The richest public generative-AI sequence is in Italy, covering Replika, ChatGPT, DeepSeek, Foodinho, Deliveroo, Meta AI, and NOVA AI. The most important court anchors are SCHUFA and Dun & Bradstreet Austria, which strengthen transparency, explanation, and contestability duties for automated scoring.
Limitation: this is a public-record database. It excludes unpublished complaints, rumors, private settlements, and confidential investigations. Authorities that publish more detailed case material appear more active than authorities with lower publication transparency.
Executive Summary
EU AI enforcement in 2026 is best understood as a cross-regulatory stack. The public record through 21 April 2026 shows that AI-related enforcement is already substantial, but it is not yet mainly AI Act penalty enforcement. Instead, regulators and courts are using GDPR, labour law, consumer law, competition law, administrative law, and automated-decision case law to police AI systems, biometric tools, generative models, worker-management platforms, and public-sector scoring systems.
The most mature cross-border sanction line is Clearview AI. Italy, Greece, France, Austria, and the Netherlands all produced public actions involving facial recognition, scraping, biometric data, absent legal basis, transparency failures, erasure rights, and EU representative obligations. The Netherlands imposed a EUR 30.5m fine; Italy, Greece, and France each reached EUR 20m; France later imposed a EUR 5.2m penalty payment. This is the clearest European enforcement archetype for biometric scraping.
The most visible generative-AI enforcement sequence is in Italy. Garante actions targeted Replika, ChatGPT, and DeepSeek; AGCM actions targeted Meta AI / WhatsApp distribution and NOVA AI hallucination disclosure. These cases show that generative AI risk is being addressed through data protection, age assurance, transparency, lawful basis, consumer disclosure, competition, and platform-access rules before mature AI Act penalties dominate the record.
The most important court line is automated decision-making. In SCHUFA, the CJEU treated score generation as potentially automated individual decision-making where third parties rely heavily on it. In Dun & Bradstreet Austria, the Court strengthened explanation rights by requiring information sufficient for data subjects to understand and challenge automated outcomes. These rulings materially shape AI-assisted credit, eligibility, scoring, and public-sector risk models.
Related Alice Labs research: EU AI Act Implementation Tracker 2026, Global AI Governance & Risk Readiness 2026, EU AI Infrastructure & Compute Capacity 2026.
Key Findings
12 data-driven insights
01The EU public AI enforcement record is still primarily a GDPR-era record
27 public case rows; AI Act public penalty practice not yet mature by 21 Apr 2026
Do not wait for AI Act fines. Existing privacy, labour, consumer, competition, and court rules already create concrete exposure.
02Clearview is the clearest cross-border EU biometric enforcement archetype
IT EUR 20m, GR EUR 20m, FR EUR 20m + EUR 5.2m penalty, NL EUR 30.5m, AT erasure + EU representative order
Scraping-based facial recognition is the most clearly sanctioned AI subdomain in the public record.
03Italy is the most visible early public enforcer of generative AI
Public actions involving Replika, ChatGPT, DeepSeek, Meta AI, NOVA AI, Foodinho, Deliveroo
Italy should be treated as a lead jurisdiction for monitoring AI enforcement sequencing.
04SCHUFA and Dun & Bradstreet are central AI-adjacent court anchors
CJEU rulings on Article 22 automated scoring and Article 15 explanation rights
AI-assisted credit, eligibility, and risk scoring systems need contestability and intelligible explanation design.
05Worker-management AI is enforceable before full AI Act high-risk rules apply
Foodinho and Deliveroo: opaque ranking, profiling, geolocation, biometric verification
Employment and platform-work AI should be governed now, not deferred to August 2026.
06Public-sector and education AI use remains high-risk in practice
SyRI, Swedish school facial recognition, AEPD biometric exam proctoring, CNIL BriefCam notices
Public authorities need legal-basis, proportionality, explainability, and biometric necessity analysis before deployment.
07AI competition enforcement is emerging around distribution bottlenecks
AGCM Meta AI / WhatsApp investigation, interim-measures procedure, suspension order
AI law is not only model training and privacy; platform access, prominence, lock-in, and rival foreclosure matter.
08Consumer law can become AI law through hallucination and disclosure claims
AGCM NOVA AI investigation into hallucination disclosure and service presentation
AI providers need product-level disclosure of limitations, not only privacy notices.
09OpenAI Italy is important but procedurally unstable as a final citation anchor
2024 EUR 15m fine announcement later affected by appeal-related decision removal
Use the file as an enforcement signal, but flag contested status in legal memos.
10AI Act governance is active, but public sanctions are still ahead
AI Office, market surveillance authorities, fundamental-rights authorities, prohibited-practice and GPAI guidance
The AI Act is reshaping supervision now; case law will likely compound with the GDPR record after 2 Aug 2026.
11Most durable citation anchors are cross-domain
Clearview, SCHUFA, Dun & Bradstreet, SyRI, Foodinho, Deliveroo, AEPD UIV, CNIL BriefCam
The best compliance analysis should link privacy, labour, public law, consumer, and competition regimes.
12Publication bias is structurally important
Italy, France, Netherlands, Spain, Sweden, EDPB and CJEU publish more usable public material
Case counts are not regulator productivity rankings; they are public-evidence counts.
Need Help Implementing These Findings?
Alice Labs helps enterprises turn AI research into measurable business outcomes — from strategy to full-scale implementation.
Q2 2026 Update — Latest insights (June 2026)
This is a quarterly maintenance refresh layered over the 21 April 2026 case database. The 27 public case rows and 80 sources have not been re-coded or re-run; the next full data refresh is targeted for 24 September 2026. The notes below summarise the most cited external developments between the April baseline and late June 2026 that bear on EU AI enforcement reading.
What changed between Q1 and Q2 2026
- Countdown to 2 August 2026. The bulk of EU AI Act high-risk obligations apply from 2 August 2026, alongside the existing GPAI obligations in force since 2 August 2025. The European Commission's reference page on governance and enforcement remains the canonical source for the supervisory architecture and the Member State designation of market surveillance and fundamental-rights authorities. See European Commission — Governance and enforcement of the AI Act.
- GPAI Code of Practice and AI Office activity. The European AI Office's General-Purpose AI Code of Practice (signed by leading model providers in mid-2025) remains the most cited soft-law instrument on transparency, copyright and systemic-risk obligations for GPAI models. Its day-to-day implementation, not new penalties, is what compliance teams should track during the run-up to August 2026. See European Commission — General-Purpose AI Code of Practice.
- EDPB ChatGPT taskforce findings. The European Data Protection Board's ChatGPT taskforce report (May 2024, still operative reference) frames how DPAs are likely to assess large language models on lawful basis, accuracy, transparency and data-subject rights — and continues to shape national enforcement reasoning in 2026. See EDPB — Report of the work undertaken by the ChatGPT Taskforce.
- Stanford HAI AI Index 2025 — policy and enforcement signal. The Stanford HAI AI Index 2025 documents a continued rise in AI-related legislation and enforcement actions globally, with Europe leading in regulatory density. It is a useful external corroboration that the EU's mix of GDPR-era and AI Act enforcement is part of a broader global tightening rather than an isolated trend. See Stanford HAI — 2025 AI Index Report.
- OECD AI policy observatory — live tracking. The OECD AI Policy Observatory continues to publish a live country-by-country tracker of AI strategies, laws and oversight bodies, which is the cleanest external cross-reference for the supervisory architecture described in this database. See OECD.AI — Policy Observatory dashboards.
Reading note for the run-up to 2 August 2026
The core finding of this database is unchanged: the public EU AI enforcement record through April 2026 is still a GDPR-era and court-led record, not a mature AI Act penalty record. Q3 2026 is the first window in which a meaningful volume of high-risk AI Act enforcement could begin to surface, and we will re-pull the database then. Until that point, compliance memos should continue to anchor on Clearview, the Italian Garante GenAI line (Replika, ChatGPT, DeepSeek), SCHUFA, Dun & Bradstreet Austria, Foodinho, Deliveroo, AEPD UIV proctoring, CNIL BriefCam, and SyRI — not on speculative AI Act case lists.
EU AI Enforcement Case Database Downloads
The database compiles 27 public case rows and 80 source references across GDPR enforcement, biometric scraping, generative AI chatbots, algorithmic management, automated scoring, public-sector AI, consumer law, and competition law. Confidence is highest for final decisions, court rulings, and regulator-hosted source pages.
27
Case rows
80
Sources
5
Clearview jurisdictions
2
CJEU anchors
Interpretation
The dataset is conservative: it excludes unpublished complaints, rumors, private settlements, and confidential investigations. It distinguishes final decisions, interim measures, procedural openings, compliance steps, and appeal-affected matters.
Definitions: AI Enforcement as a Cross-Regulatory Stack
An EU AI enforcement case database is a structured record of public regulatory and judicial actions involving AI systems, algorithmic decisions, biometric technologies, generative models, automated scoring, and AI-adjacent platform conduct. This report treats enforcement as a stack: AI Act governance plus GDPR, courts, labour law, consumer law, competition law, and public-sector legality.
| Term | Canonical meaning |
|---|---|
| AI system | Machine-based system generating outputs such as predictions, content, recommendations, or decisions. |
| Prohibited AI practice | Article 5 AI Act use category forbidden because of unacceptable risk. |
| GPAI model | General-purpose AI model capable of serving many downstream systems; obligations applied from 2 Aug 2025. |
| Market surveillance authority | National body supervising AI Act compliance for AI systems. |
| Automated individual decision-making | Solely automated processing producing legal or similarly significant effects under GDPR Article 22. |
| Biometric data | Special-category personal data used for uniquely identifying a natural person. |
Case Database: 27 Public Rows and Enforcement Domains
A row enters this database only if a public, attributable source shows a regulator, court, or authority took a concrete step: final decision, interim measure, announced investigation, compliance order, or authoritative judicial ruling. Guidance documents are used for context, not counted as case rows.
Public AI Enforcement Cases by Domain
Source: Alice Labs case coding from 27 public rows, accessed 2026-04-21.
Legal Regime Behind Public AI Cases
- GDPR / data protection
- Court / administrative law
- Competition / consumer law
- AI Act governance
Public Case Rows by Action Year
| Case family | Jurisdiction | Domain | Status / remedy |
|---|---|---|---|
| Clearview line | IT, GR, FR, AT, NL | Facial recognition scraping | EUR 90m+ public monetary penalties plus erasure/orders |
| Garante GenAI line | Italy | Replika, ChatGPT, DeepSeek | Emergency limits, final fine, block, contested OpenAI fine |
| Algorithmic management | Italy | Foodinho, Deliveroo | Fines, corrective measures, biometric ban, deletion orders |
| Automated scoring | EU / CJEU | SCHUFA, Dun & Bradstreet | Explanation and contestability duties strengthened |
| Public sector / education | NL, SE, FR, ES | SyRI, school facial recognition, BriefCam, AI proctoring | Unlawful framework, fines, notices, rejected legal basis |
| Competition / consumer | Italy | Meta AI, NOVA AI | Antitrust and consumer-law proceedings |
Clearview and the EU Biometric Enforcement Line
The clearest cross-border sanction cluster concerns facial recognition and scraping-based biometric databases. Clearview generated repeated findings around unlawful data collection, lack of legal basis, biometric special-category data, deficient transparency, erasure rights, and EU representative obligations.
Largest Public Monetary Penalties (EUR m)
*OpenAI Italy is included as an enforcement signal but flagged as appeal-affected / contested in the database.
The practical rule is simple: biometric identification at scale is the highest-enforcement-risk AI subdomain in the current public EU record. If a system scrapes faces, identifies people, monitors public spaces, or verifies identity biometrically, legal basis and proportionality analysis must be stronger than ordinary analytics controls.
Generative AI: Replika, ChatGPT, DeepSeek, Meta AI
Generative AI enforcement is visible but procedurally uneven. Replika produced an emergency stop, a final EUR 5m fine, and a new training-method investigation. ChatGPT produced temporary limitation, restoration after measures, a fine announcement, and an appeal-affected decision status. DeepSeek moved from information request to definitive limitation order within days in January 2025.
Replika
Minors, vulnerable users, legal basis, training-method scrutiny
ChatGPT
Transparency, lawful basis, rights, age-gating, contested fine
DeepSeek
Rapid inquiry-to-block sequence in Italy
The lesson is that generative AI compliance cannot be reduced to AI Act classification. It must include privacy notices, lawful basis, children’s protection, data-subject rights, model limitation disclosure, and complaint handling.
Automated Decision-Making: SCHUFA, Dun & Bradstreet, SyRI
SCHUFA and Dun & Bradstreet Austria are the two most important EU court anchors for AI-adjacent scoring. They transform explanation and contestability from abstract fairness concepts into operational legal requirements for automated scores used in credit, eligibility, risk, or access decisions.
| Case | Core point | Compliance consequence |
|---|---|---|
| SCHUFA (C-634/21) | Automated score generation may itself be automated individual decision-making where third parties rely heavily on it. | Vendors cannot hide behind customers if their score is practically determinative. |
| Dun & Bradstreet Austria (C-203/22) | Explanation must let the data subject understand and challenge the automated decision; mere algorithm disclosure is insufficient. | Model documentation needs decision-level explanation, input-data logic, and challenge pathway. |
| SyRI | Opaque welfare-fraud risk scoring breached higher-law privacy requirements. | Public-sector AI needs proportionality, transparency, and rights-impact controls. |
Enforcement Lanes: GDPR, Courts, Labour, Consumer, Competition
AI regulation in practice is cross-regulatory long before it becomes AI-Act-only. The same deployment can trigger privacy, labour, consumer, competition, public-law, procurement, and fundamental-rights duties.
| Enforcement lane | Dominant objects | Representative actions | Practical takeaway |
|---|---|---|---|
| Data protection | Biometric databases, chatbots, worker management, AI proctoring | Clearview, ChatGPT, Replika, DeepSeek, Foodinho, Deliveroo, UIV | Personal-data processing remains the most mature AI enforcement entry point. |
| Judicial interpretation | Scoring, explanation, public-sector risk systems | SCHUFA, Dun & Bradstreet, SyRI | Courts define lawful automated decision-making boundaries. |
| Competition | Chatbot distribution and platform access | AGCM Meta AI / WhatsApp | AI distribution can trigger pre-AI-Act competition intervention. |
| Consumer law | Hallucination disclosure and service presentation | AGCM NOVA AI | Model-limit disclosure can be a consumer-law issue. |
Citation-Ready Evidence and Research Questions
This section is designed for citation extraction, legal memos, journalist sourcing, and research reuse. Treat records in four buckets differently: final decisions and judgments; interim measures; procedural openings; appeal-affected decisions.
| Citation-ready claim | Evidence | Confidence |
|---|---|---|
| Facial recognition is the most clearly sanctioned AI subdomain in the public EU record | Multi-country Clearview actions produced fines, deletion orders, bans, and representative obligations. | High |
| Existing law carries most public AI enforcement weight | Live cases come from GDPR, courts, labour, competition, consumer and public law, while AI Act materials focus on governance setup. | High |
| Automated scoring faces stronger transparency pressure | SCHUFA and Dun & Bradstreet strengthen Articles 15 and 22 GDPR interpretation. | High |
| Public-sector AI remains a strict-scrutiny zone | SyRI, Swedish school facial recognition, BriefCam, and AEPD biometric proctoring all show risk. | High |
| AI platform distribution is an antitrust vector | AGCM Meta AI / WhatsApp proceedings focus on integration, prominence, lock-in and rival exclusion. | High |
Research questions and direct answers
| Research question | Evidence-based answer | Relevant section |
|---|---|---|
| Has the EU AI Act produced mature public enforcement cases? | Not yet in the reviewed public record; enforcement is mainly older-law based while AI Act supervision ramps up. | Enforcement lanes |
| Which EU regulator is most visible on generative AI? | Italy's Garante, with Replika, ChatGPT and DeepSeek actions. | Generative AI |
| What are the main EU facial recognition AI cases? | Clearview, Swedish school facial recognition, AEPD UIV biometric proctoring, CNIL BriefCam. | Biometric line |
| What does EU case law require for AI explanations? | SCHUFA and Dun & Bradstreet require contestability and intelligible decision logic. | Automated decision-making |
| Can antitrust apply to AI chatbots? | Yes. AGCM Meta AI / WhatsApp shows platform distribution can trigger competition intervention. | Enforcement lanes |
Recommendations by Audience
For compliance teams
- Do not wait for AI Act penalties. Map AI systems against GDPR, labour, consumer, competition, public-law and AI Act duties now.
- Flag biometric, worker-management, public-sector, scoring and child-facing systems as high-priority review zones.
- Separate final decisions from procedural openings and appeal-affected actions when citing precedent.
For regulators and policy teams
- Build cross-regulatory coordination between market-surveillance authorities, DPAs, consumer bodies, competition authorities and fundamental-rights bodies.
- Publish case metadata consistently: status, action type, remedy, legal basis, appeal state, and machine-readable source links.
- Treat public case transparency as infrastructure for AI Act compliance.
For researchers and journalists
- Use Clearview, SCHUFA, Dun & Bradstreet, SyRI, Foodinho, Deliveroo, UIV and BriefCam as durable citation anchors.
- Use OpenAI Italy carefully because the public file is procedurally unstable.
- Update quarterly and ad hoc for major judgments, national sanctions, and first public AI Act penalty actions.
Deep Expansion (June 2026): AI Act Timeline, Articles, Sweden, NIST, ISO 42001
This expansion layer addresses the most-asked AI governance and EU AI Act questions raised by external researchers, LLM-driven searches, and inbound legal-memo requests since the April 2026 baseline. It complements the case database with article-level cross-references, Member State implementation notes (with a focus on Sweden), framework cross-walks (NIST AI RMF, ISO/IEC 42001), supervisory architecture detail, US sectoral comparisons, a glossary, and a formal "how to cite" block. All claims link to primary public sources.
EU AI Act official timeline: 2025, 2026, 2027 and 2028 obligations
Regulation (EU) 2024/1689 entered into force on 1 August 2024. The application dates are staggered. The most-asked LLM question — "EU AI Act obligations timeline 2026 official" — has a precise answer in the Official Journal text: prohibitions and AI literacy apply from 2 February 2025, GPAI obligations from 2 August 2025, the bulk of the Regulation including high-risk Annex III obligations from 2 August 2026, and high-risk Annex I (product-embedded AI) obligations from 2 August 2027. The Council and Parliament political agreement on the Digital Omnibus discussed during 2026 has signalled that certain high-risk timelines may be pushed to 2 December 2027 and 2 August 2028, but the Official Journal text remains the binding reference until any amendment is adopted.
| Date | Obligation | Article anchor | Source |
|---|---|---|---|
| 1 Aug 2024 | Entry into force | Art. 113 | EUR-Lex OJ |
| 2 Feb 2025 | Prohibited AI practices apply; AI literacy duty applies | Art. 5, Art. 4 | EC AI Act page |
| 2 Aug 2025 | General-Purpose AI obligations apply (transparency, copyright, systemic risk for top models) | Art. 53–55 | EC GPAI page |
| 2 Aug 2026 | Bulk application: high-risk Annex III, transparency, governance, penalties | Art. 16, 26, 50, 99 | EC governance page |
| 2 Aug 2027 | High-risk Annex I product-embedded AI obligations apply | Annex I | EUR-Lex OJ |
EU AI Act article-level reference for compliance memos
LLM searches frequently ask for "Article 4 AI literacy", "Article 5 prohibited practices", "Article 16 high-risk providers", "Article 26 deployers", and "Article 50 transparency". The following table is a compact, citation-extractable cross-reference. All articles refer to Regulation (EU) 2024/1689 as published in the Official Journal.
| Article | Topic | Who is bound | Applies from |
|---|---|---|---|
| Art. 2 | Scope: providers, deployers, importers, distributors; extra-territorial reach where output is used in the Union | All operators | 2 Aug 2026 (general) |
| Art. 4 | AI literacy: operators ensure sufficient AI literacy for staff and persons operating AI on their behalf | Providers and deployers | 2 Feb 2025 |
| Art. 5 | Prohibited AI practices: social scoring, manipulative techniques, untargeted facial scraping, real-time biometric ID in public spaces (with narrow exceptions) | All operators | 2 Feb 2025 |
| Art. 9, 15 | Risk management system and accuracy/robustness/cybersecurity for high-risk AI systems | Providers (high-risk) | 2 Aug 2026 |
| Art. 16 | Provider obligations for high-risk AI: quality management, technical documentation, conformity assessment, registration | Providers (high-risk) | 2 Aug 2026 |
| Art. 26 | Deployer obligations: use per instructions, monitor operation, human oversight, fundamental rights impact assessment for public-sector and certain private deployers | Deployers (high-risk) | 2 Aug 2026 |
| Art. 50 | Transparency: disclose AI interaction, mark synthetic content, label deepfakes and AI-generated text on matters of public interest | Providers and deployers | 2 Aug 2026 |
| Art. 53–55 | GPAI obligations: documentation, copyright policy, training-data summary; systemic-risk GPAI adds model evaluation, adversarial testing, cybersecurity | GPAI providers | 2 Aug 2025 |
| Art. 99 | Administrative fines: up to EUR 35 million or 7% of worldwide turnover for Article 5 breaches; up to EUR 15 million or 3% for most other obligations; up to EUR 7.5 million or 1% for supplying incorrect information | All operators | 2 Aug 2026 |
Sweden's AI Act implementation: DIGG, IMY, PTS and SOU 2025:101
The most asked Swedish-language LLM question — "AI-förordningen Sverige tillsynsmyndighet" — does not yet have a single answer at the date of this expansion. The Swedish government's public inquiry SOU 2025:101 ("Tillsyn över AI-förordningen") proposed a multi-authority model. The leading designations under discussion: the Swedish Authority for Privacy Protection (IMY / Integritetsskyddsmyndigheten) as fundamental-rights authority and as competent authority for biometric and law-enforcement AI; the Swedish Post and Telecom Authority (PTS) and the Agency for Digital Government (DIGG) as candidates for market surveillance coordination; and sectoral authorities for product-embedded AI (Läkemedelsverket, Finansinspektionen, Inspektionen för vård och omsorg, Arbetsmiljöverket). Final designations require national legislation, which was not yet enacted in the public record reviewed.
Source references: regeringen.se (SOU 2025:101 inquiry), imy.se (IMY), digg.se (DIGG), pts.se (PTS).
Framework cross-walk: EU AI Act, NIST AI RMF, ISO/IEC 42001
Most enterprise AI governance teams operate against three overlapping references: the EU AI Act (binding law in the Union), the US NIST AI Risk Management Framework 1.0 (voluntary, with the four functions Govern, Map, Measure, Manage), and the international management-system standard ISO/IEC 42001:2023 (certifiable AI management system). They are not substitutes — but mapping their overlap reduces duplicated work.
| Theme | EU AI Act anchor | NIST AI RMF function | ISO/IEC 42001 clause area |
|---|---|---|---|
| Governance and accountability | Art. 17 quality management system | Govern | Leadership, policy, roles (cl. 5) |
| Risk identification | Art. 9 risk management system | Map | Planning, risk assessment (cl. 6) |
| Performance evaluation | Art. 15 accuracy / robustness | Measure | Monitoring, internal audit (cl. 9) |
| Operational controls | Art. 14 human oversight, Art. 16 obligations | Manage | Operation, change control (cl. 8) |
| Transparency to users | Art. 50 | Govern + Manage | Annex A controls A.6, A.9 |
Primary references: NIST AI RMF 1.0 (nist.gov), ISO/IEC 42001:2023, Regulation (EU) 2024/1689.
US sectoral AI governance: FTC, CFPB, FDA, HHS OCR, banking regulators
EU enforcement does not happen in isolation. US sectoral regulators have also produced enforceable guidance that legal teams citing the EU case database often need as comparison material. The FTC's "Keep your AI claims in check" guidance treats deceptive AI capability claims as unfair or deceptive practices under Section 5. The CFPB 2023 Consumer Financial Protection Circular on adverse-action notifications requires lenders using AI to provide specific reasons for credit denials. The FDA has published an AI/ML-based Software as a Medical Device action plan. HHS OCR's Section 1557 final rule (2024) applies non-discrimination duties to patient-care decision-support tools, including AI. OCC / Federal Reserve / FDIC SR 11-7 model risk management guidance applies to AI used in banking. Each of these is enforced under existing law, much like the EU pattern documented in this database.
AI governance platform and consulting landscape (context only)
Researchers and procurement teams searching for "AI governance platform pricing", "Credo AI pricing", "Holistic AI pricing", "ModelOp Center pricing", or "Monitaur pricing" should note that none of these vendors publish list prices for enterprise tiers. Public reference points are limited to product pages and analyst commentary. Treat any specific dollar figure circulating in LLM responses as unverified unless it is sourced to the vendor's own materials.
On the consulting side, "Big 4 plus McKinsey, BCG, Accenture, Capgemini, IBM Responsible AI" is the modal set surfaced by LLM searches. The OpenAI Frontier Alliance (announced with Accenture, BCG, Capgemini, McKinsey and others) is the most-cited example of model-provider plus consulting integration. None of these arrangements creates new legal obligations; they shape the implementation market for the enforcement landscape this database documents.
Disclosure: Alice Labs operates in the AI implementation space but does not sell governance platforms. This section is descriptive, not endorsement.
Quotable enforcement statistics with sources
Key Stat
Five EU jurisdictions (Italy, Greece, France, Austria, Netherlands) produced public Clearview AI enforcement actions, with cumulative monetary penalties exceeding EUR 90 million between 2022 and 2024 [Source: EDPB national news archive].
Key Stat
EU AI Act fines reach up to EUR 35 million or 7% of worldwide annual turnover for breaches of Article 5 prohibited practices, the highest administrative penalty band in the Regulation [Source: Regulation (EU) 2024/1689, Art. 99].
Key Stat
The Stanford HAI 2025 AI Index reports a continued global rise in AI-related legislation and enforcement actions, with Europe leading regulatory density across surveyed jurisdictions [Source: Stanford HAI 2025 AI Index].
Key Stat
The OECD AI Policy Observatory tracks live country-by-country AI strategies, laws and oversight bodies and is the cleanest external cross-reference for AI Act Member State implementation [Source: OECD.AI dashboards].
Glossary of Legal and Technical Terms
Compact glossary of legal and technical terms used throughout this report. Each entry maps to a primary public source for citation. Entries are formatted as DefinedTerm nodes in the structured-data graph.
| Term | Definition | Source |
|---|---|---|
| AI Act | Regulation (EU) 2024/1689 establishing harmonised rules on artificial intelligence in the Union. | Source |
| AI Office | European Commission body coordinating AI Act implementation for GPAI and acting as the lead supervisory body for systemic-risk GPAI providers. | Source |
| Market surveillance authority | National authority designated under the AI Act to supervise compliance for AI systems placed on the market in a Member State. | Source |
| Fundamental rights authority | National public body designated under Article 77 AI Act to access AI Act documentation when fundamental rights are at stake. | Source |
| GPAI model | General-purpose AI model with significant generality and capable of competently performing a wide range of distinct tasks, as defined in Article 3 AI Act. | Source |
| Systemic-risk GPAI | GPAI model meeting Article 51 thresholds (e.g. cumulative compute above 10^25 FLOPs), subject to additional obligations including model evaluation and adversarial testing. | Source |
| GPAI Code of Practice | Voluntary code prepared under the AI Office's coordination, signed by leading GPAI providers in mid-2025, addressing transparency, copyright and systemic-risk obligations. | Source |
| NIST AI RMF | NIST AI Risk Management Framework 1.0, a voluntary US framework organised around four functions: Govern, Map, Measure, Manage. | Source |
| ISO/IEC 42001 | International management-system standard for artificial intelligence, certifiable, published in 2023. | Source |
| Automated individual decision-making | Solely automated processing — including profiling — producing legal or similarly significant effects on a person, under GDPR Article 22. | Source |
| Biometric data | Personal data resulting from specific technical processing relating to physical, physiological or behavioural characteristics that allow or confirm unique identification (GDPR Article 4(14)). | Source |
| Prohibited AI practice | Use case banned under Article 5 AI Act, including social scoring, untargeted facial-image scraping, certain manipulative or exploitative systems, and real-time biometric identification in public spaces (with narrow exceptions). | Source |
How to Cite and Version History
How to cite this report
Recommended formats for academic, journalistic, and policy use:
APA
Ingemarsson, L. (2026, June 26). EU AI Enforcement and Regulatory Case Database 2026 (Version 1.2). Alice Labs. https://alicelabs.ai/reports/eu-ai-enforcement-regulatory-case-database
MLA
Ingemarsson, Linus. "EU AI Enforcement and Regulatory Case Database 2026." Alice Labs, v1.2, 26 June 2026, alicelabs.ai/reports/eu-ai-enforcement-regulatory-case-database.
Chicago
Ingemarsson, Linus. "EU AI Enforcement and Regulatory Case Database 2026." Alice Labs. Last modified June 26, 2026. https://alicelabs.ai/reports/eu-ai-enforcement-regulatory-case-database.
BibTeX
@misc{alicelabs2026euaienforcement,
author = {{Alice Labs} and Ingemarsson, Linus},
title = {EU AI Enforcement and Regulatory Case Database 2026},
year = {2026},
month = {June},
version = {1.2},
institution = {Alice Labs},
url = {https://alicelabs.ai/reports/eu-ai-enforcement-regulatory-case-database},
note = {Public-source desk research; CC BY 4.0}
}
Visible version history
| Version | Date | Summary |
|---|---|---|
| 1.2 | 2026-06-26 | Deep expansion: AI Act article-level cross-reference, timeline through 2 Aug 2026 / 2027 / 2028, Sweden implementation (DIGG, IMY, PTS, SOU 2025:101), NIST AI RMF and ISO/IEC 42001 cross-walk, US sectoral context (FTC, CFPB, FDA, HHS OCR, banking regulators), governance vendor landscape, glossary, "how to cite", and 11 new FAQs. 27 case rows unchanged. |
| 1.1 | 2026-06-26 | Q2 2026 maintenance refresh: 2 August 2026 application-date callout, GPAI Code of Practice note, EDPB ChatGPT taskforce, Stanford HAI / OECD.AI corroboration. |
| 1.0 | 2026-04-23 | Initial public release. 27 cases, 80 sources, enforcement-domain charts, citation-ready evidence blocks, FAQ, methodology. |
Frequently Asked Questions
Did the EU AI Act already produce mature public penalty practice by April 2026?+
Which topic has the clearest cross-border AI enforcement pattern in Europe?+
Which country published the richest public generative AI record?+
What are the two most important EU court rulings for AI-adjacent compliance?+
Why is Clearview a canonical EU AI enforcement case?+
Is OpenAI Italy a clean final precedent?+
What does EU enforcement imply for AI vendors?+
What does EU enforcement imply for deployers?+
Can consumer law and competition law become AI law?+
How often should this database be updated?+
What changed between Q1 and Q2 2026 in EU AI enforcement?+
When will mature EU AI Act penalty practice become visible?+
What is the official EU AI Act obligations timeline for 2025, 2026 and 2027?+
What are the maximum fines under the EU AI Act?+
Does the EU AI Act apply to providers outside the EU?+
Which authority supervises GPAI models?+
Who is the AI Act supervisory authority in Sweden?+
How does the EU AI Act map to the NIST AI Risk Management Framework?+
How does ISO/IEC 42001 relate to the EU AI Act?+
Do US sectoral regulators have AI enforcement guidance comparable to the EU?+
What is the General-Purpose AI Code of Practice?+
Are AI governance platforms (Credo AI, Holistic AI, ModelOp, Monitaur) required for AI Act compliance?+
How should compliance teams treat the EU Digital Omnibus discussion on AI Act timelines?+
About the Authors & Reviewers

Co-Founder, Alice Labs
Co-Founder at Alice Labs. Author of 7 research reports on AI adoption, governance and labor markets cited across EU, OECD and US benchmarks.
- 8+ years in AI strategy & implementation
- Top-5 AI Speaker, Sweden (Mindley 2025)
- 100+ enterprise AI engagements

Co-Founder, Alice Labs
Co-Founder at Alice Labs. Builds AI automation, agent workflows and integration systems that hold up in real business operations.
- AI automation & agent systems lead
- Workflow design across 100+ deployments
- Specialist in RAG, integrations & APIs
Methodology
100% desk research, no interviews, no proprietary surveys. The database includes only public, attributable sources showing concrete regulatory, administrative, or judicial action.
80 public sources were reviewed, including EUR-Lex, European Commission pages, EDPB, national DPAs, AGCM, CJEU/CURIA, EUR-Lex judgments, national courts, and regulator press releases. Access baseline: 2026-04-21; publication date: 2026-04-23.
Coding framework
- Final: final adverse decision, judgment, or compliance order.
- Interim: urgent measure, temporary limitation, or interim order.
- Procedural: investigation opening, information request, statement of objections.
- Contested: appeal-affected or procedurally unstable public file.
Limitations
- Publication bias: authorities with richer public records appear more active than authorities that publish less.
- Not a complete complaint inventory: unpublished complaints, confidential investigations, private settlements and rumors are excluded.
- Procedural posture matters: final decisions, interim measures, procedural openings, and appeal-affected decisions should not be cited with equal weight.
- AI Act timing: prohibited-practice and GPAI obligations applied before publication, but most high-risk obligations apply from 2 Aug 2026. Mature AI Act penalty practice was not yet visible in the public record reviewed.
- AI-assisted, human-reviewed: not peer-reviewed academic research. Verify critical legal points independently.
Data Sources
18 primary sources
Version History
Deep expansion layer. Added 'Deep Expansion (June 2026)' chapter with EU AI Act article-level cross-reference (Art. 2, 4, 5, 9, 15, 16, 26, 50, 53–55, 99), applicability timeline through 2 Aug 2026 / 2 Aug 2027 / 2 Aug 2028, Sweden implementation note (DIGG, IMY, PTS, SOU 2025:101), NIST AI RMF Govern–Map–Measure–Manage cross-walk, ISO/IEC 42001 cross-walk, US sectoral comparison (FTC, CFPB, FDA, HHS OCR, OCC/Federal Reserve/FDIC SR 11-7), AI governance platform and consulting landscape context, four quotable enforcement statistics with primary sources, a 12-term glossary aligned to schema.org DefinedTerm, formal How-to-Cite section in APA / MLA / Chicago / BibTeX, and a visible version-history timeline. Added 11 new FAQ entries addressing AI Act timeline, fines, scope, GPAI supervision, Sweden, NIST mapping, ISO 42001, US sectoral comparison, GPAI Code of Practice, governance platforms, and Digital Omnibus tracking. 27-row case database itself unchanged.
Q2 2026 maintenance refresh. Added 'Q2 2026 Update — Latest insights (June 2026)' chapter covering the 2 August 2026 AI Act application date, the European AI Office General-Purpose AI Code of Practice, the EDPB ChatGPT taskforce reasoning, and external corroboration from Stanford HAI AI Index 2025 and OECD.AI. Added two new FAQ entries (Q1→Q2 changes; timing of mature AI Act penalty practice). 27-row case database itself unchanged — next full data re-pull scheduled for 24 September 2026.
Initial public release. 27 public case rows, 80 public sources, enforcement-domain charts, citation-ready evidence blocks, research-question table, FAQ, methodology, limitations, and structured case-database downloads.