Research ReportPublished April 2026Updated June 26, 2026v1.2

    EU AI Enforcement and Regulatory Case Database 2026

    Public EU AI enforcement actions, court rulings, regulatory cases, biometric sanctions, generative AI investigations, and automated decision-making precedents through April 2026

    Authors:
    Linus Ingemarsson(Co-Founder, Alice Labs)
    27
    Public case rows
    2019-2025 actions
    80
    Public sources
    Regulators, courts, EU bodies
    EUR 90M+
    Clearview penalties
    Cross-border biometric line
    2
    Core CJEU anchors
    SCHUFA + Dun & Bradstreet
    Linus Ingemarsson - Author at Alice Labs
    Written by
    Eric Lundberg - Reviewer at Alice Labs
    Reviewed by
    Published ·Updated

    Methodology & Transparency: This analysis draws on primary sources — including Eurostat, OECD, national statistical agencies, peer-reviewed literature, and official vendor disclosures — combined with Alice Labs implementation data. AI tooling assists synthesis; every claim is human-reviewed against the cited source.

    All figures and claims link to their public source for verification. Reviewed by the named author and reviewer above. Methodology, source list, and revision history are available below.

    Cite This Report

    Ingemarsson, L. (2026, April 23). EU AI Enforcement and Regulatory Case Database 2026 (Version 1.0). Alice Labs. https://alicelabs.ai/reports/eu-ai-enforcement-regulatory-case-database
    Version 1.2 • Published April 23, 2026
    Quick Answer
    Cited by AI

    What does the EU AI enforcement record show in 2026?

    EU AI enforcement is already real, but it is not yet mainly AI Act penalty enforcement. As of April 2026, public cases are dominated by GDPR, courts, labour, consumer, competition, and public-sector law, with Clearview, Italy's Garante, SCHUFA, Dun & Bradstreet, Foodinho, Deliveroo, BriefCam, and AEPD biometric proctoring as key citation anchors.
    AT A GLANCEUpdated 2026-04-23

    The EU AI Enforcement and Regulatory Case Database 2026 tracks 27 public case rows and 80 public sources across AI-related enforcement, court rulings, compliance orders, interim measures, and public investigations. The central finding: AI enforcement is already active in Europe, but the public record is still mostly a GDPR-era and court-led record, not a mature AI Act penalty record.

    Key Takeaway

    The strongest sanction pattern concerns facial recognition and scraping-based biometric databases, especially Clearview actions in Italy, Greece, France, Austria, and the Netherlands. The richest public generative-AI sequence is in Italy, covering Replika, ChatGPT, DeepSeek, Foodinho, Deliveroo, Meta AI, and NOVA AI. The most important court anchors are SCHUFA and Dun & Bradstreet Austria, which strengthen transparency, explanation, and contestability duties for automated scoring.

    Limitation: this is a public-record database. It excludes unpublished complaints, rumors, private settlements, and confidential investigations. Authorities that publish more detailed case material appear more active than authorities with lower publication transparency.

    Executive Summary

    EU AI enforcement in 2026 is best understood as a cross-regulatory stack. The public record through 21 April 2026 shows that AI-related enforcement is already substantial, but it is not yet mainly AI Act penalty enforcement. Instead, regulators and courts are using GDPR, labour law, consumer law, competition law, administrative law, and automated-decision case law to police AI systems, biometric tools, generative models, worker-management platforms, and public-sector scoring systems.

    The most mature cross-border sanction line is Clearview AI. Italy, Greece, France, Austria, and the Netherlands all produced public actions involving facial recognition, scraping, biometric data, absent legal basis, transparency failures, erasure rights, and EU representative obligations. The Netherlands imposed a EUR 30.5m fine; Italy, Greece, and France each reached EUR 20m; France later imposed a EUR 5.2m penalty payment. This is the clearest European enforcement archetype for biometric scraping.

    The most visible generative-AI enforcement sequence is in Italy. Garante actions targeted Replika, ChatGPT, and DeepSeek; AGCM actions targeted Meta AI / WhatsApp distribution and NOVA AI hallucination disclosure. These cases show that generative AI risk is being addressed through data protection, age assurance, transparency, lawful basis, consumer disclosure, competition, and platform-access rules before mature AI Act penalties dominate the record.

    The most important court line is automated decision-making. In SCHUFA, the CJEU treated score generation as potentially automated individual decision-making where third parties rely heavily on it. In Dun & Bradstreet Austria, the Court strengthened explanation rights by requiring information sufficient for data subjects to understand and challenge automated outcomes. These rulings materially shape AI-assisted credit, eligibility, scoring, and public-sector risk models.

    Related Alice Labs research: EU AI Act Implementation Tracker 2026, Global AI Governance & Risk Readiness 2026, EU AI Infrastructure & Compute Capacity 2026.

    Key Findings

    12 data-driven insights

    01The EU public AI enforcement record is still primarily a GDPR-era record

    27 public case rows; AI Act public penalty practice not yet mature by 21 Apr 2026

    Do not wait for AI Act fines. Existing privacy, labour, consumer, competition, and court rules already create concrete exposure.

    02Clearview is the clearest cross-border EU biometric enforcement archetype

    IT EUR 20m, GR EUR 20m, FR EUR 20m + EUR 5.2m penalty, NL EUR 30.5m, AT erasure + EU representative order

    Scraping-based facial recognition is the most clearly sanctioned AI subdomain in the public record.

    03Italy is the most visible early public enforcer of generative AI

    Public actions involving Replika, ChatGPT, DeepSeek, Meta AI, NOVA AI, Foodinho, Deliveroo

    Italy should be treated as a lead jurisdiction for monitoring AI enforcement sequencing.

    04SCHUFA and Dun & Bradstreet are central AI-adjacent court anchors

    CJEU rulings on Article 22 automated scoring and Article 15 explanation rights

    AI-assisted credit, eligibility, and risk scoring systems need contestability and intelligible explanation design.

    05Worker-management AI is enforceable before full AI Act high-risk rules apply

    Foodinho and Deliveroo: opaque ranking, profiling, geolocation, biometric verification

    Employment and platform-work AI should be governed now, not deferred to August 2026.

    06Public-sector and education AI use remains high-risk in practice

    SyRI, Swedish school facial recognition, AEPD biometric exam proctoring, CNIL BriefCam notices

    Public authorities need legal-basis, proportionality, explainability, and biometric necessity analysis before deployment.

    07AI competition enforcement is emerging around distribution bottlenecks

    AGCM Meta AI / WhatsApp investigation, interim-measures procedure, suspension order

    AI law is not only model training and privacy; platform access, prominence, lock-in, and rival foreclosure matter.

    Source:AGCM

    08Consumer law can become AI law through hallucination and disclosure claims

    AGCM NOVA AI investigation into hallucination disclosure and service presentation

    AI providers need product-level disclosure of limitations, not only privacy notices.

    Source:AGCM

    09OpenAI Italy is important but procedurally unstable as a final citation anchor

    2024 EUR 15m fine announcement later affected by appeal-related decision removal

    Use the file as an enforcement signal, but flag contested status in legal memos.

    10AI Act governance is active, but public sanctions are still ahead

    AI Office, market surveillance authorities, fundamental-rights authorities, prohibited-practice and GPAI guidance

    The AI Act is reshaping supervision now; case law will likely compound with the GDPR record after 2 Aug 2026.

    11Most durable citation anchors are cross-domain

    Clearview, SCHUFA, Dun & Bradstreet, SyRI, Foodinho, Deliveroo, AEPD UIV, CNIL BriefCam

    The best compliance analysis should link privacy, labour, public law, consumer, and competition regimes.

    12Publication bias is structurally important

    Italy, France, Netherlands, Spain, Sweden, EDPB and CJEU publish more usable public material

    Case counts are not regulator productivity rankings; they are public-evidence counts.

    Source:Source registry review

    Need Help Implementing These Findings?

    Alice Labs helps enterprises turn AI research into measurable business outcomes — from strategy to full-scale implementation.

    Q2 2026 Update — Latest insights (June 2026)

    LAST REVIEWED26 June 2026 · v1.1

    This is a quarterly maintenance refresh layered over the 21 April 2026 case database. The 27 public case rows and 80 sources have not been re-coded or re-run; the next full data refresh is targeted for 24 September 2026. The notes below summarise the most cited external developments between the April baseline and late June 2026 that bear on EU AI enforcement reading.

    What changed between Q1 and Q2 2026

    • Countdown to 2 August 2026. The bulk of EU AI Act high-risk obligations apply from 2 August 2026, alongside the existing GPAI obligations in force since 2 August 2025. The European Commission's reference page on governance and enforcement remains the canonical source for the supervisory architecture and the Member State designation of market surveillance and fundamental-rights authorities. See European Commission — Governance and enforcement of the AI Act.
    • GPAI Code of Practice and AI Office activity. The European AI Office's General-Purpose AI Code of Practice (signed by leading model providers in mid-2025) remains the most cited soft-law instrument on transparency, copyright and systemic-risk obligations for GPAI models. Its day-to-day implementation, not new penalties, is what compliance teams should track during the run-up to August 2026. See European Commission — General-Purpose AI Code of Practice.
    • EDPB ChatGPT taskforce findings. The European Data Protection Board's ChatGPT taskforce report (May 2024, still operative reference) frames how DPAs are likely to assess large language models on lawful basis, accuracy, transparency and data-subject rights — and continues to shape national enforcement reasoning in 2026. See EDPB — Report of the work undertaken by the ChatGPT Taskforce.
    • Stanford HAI AI Index 2025 — policy and enforcement signal. The Stanford HAI AI Index 2025 documents a continued rise in AI-related legislation and enforcement actions globally, with Europe leading in regulatory density. It is a useful external corroboration that the EU's mix of GDPR-era and AI Act enforcement is part of a broader global tightening rather than an isolated trend. See Stanford HAI — 2025 AI Index Report.
    • OECD AI policy observatory — live tracking. The OECD AI Policy Observatory continues to publish a live country-by-country tracker of AI strategies, laws and oversight bodies, which is the cleanest external cross-reference for the supervisory architecture described in this database. See OECD.AI — Policy Observatory dashboards.

    Reading note for the run-up to 2 August 2026

    The core finding of this database is unchanged: the public EU AI enforcement record through April 2026 is still a GDPR-era and court-led record, not a mature AI Act penalty record. Q3 2026 is the first window in which a meaningful volume of high-risk AI Act enforcement could begin to surface, and we will re-pull the database then. Until that point, compliance memos should continue to anchor on Clearview, the Italian Garante GenAI line (Replika, ChatGPT, DeepSeek), SCHUFA, Dun & Bradstreet Austria, Foodinho, Deliveroo, AEPD UIV proctoring, CNIL BriefCam, and SyRI — not on speculative AI Act case lists.

    EU AI Enforcement Case Database Downloads

    The database compiles 27 public case rows and 80 source references across GDPR enforcement, biometric scraping, generative AI chatbots, algorithmic management, automated scoring, public-sector AI, consumer law, and competition law. Confidence is highest for final decisions, court rulings, and regulator-hosted source pages.

    27

    Case rows

    80

    Sources

    5

    Clearview jurisdictions

    2

    CJEU anchors

    Interpretation

    The dataset is conservative: it excludes unpublished complaints, rumors, private settlements, and confidential investigations. It distinguishes final decisions, interim measures, procedural openings, compliance steps, and appeal-affected matters.

    Definitions: AI Enforcement as a Cross-Regulatory Stack

    An EU AI enforcement case database is a structured record of public regulatory and judicial actions involving AI systems, algorithmic decisions, biometric technologies, generative models, automated scoring, and AI-adjacent platform conduct. This report treats enforcement as a stack: AI Act governance plus GDPR, courts, labour law, consumer law, competition law, and public-sector legality.

    Term Canonical meaning
    AI system Machine-based system generating outputs such as predictions, content, recommendations, or decisions.
    Prohibited AI practice Article 5 AI Act use category forbidden because of unacceptable risk.
    GPAI model General-purpose AI model capable of serving many downstream systems; obligations applied from 2 Aug 2025.
    Market surveillance authority National body supervising AI Act compliance for AI systems.
    Automated individual decision-making Solely automated processing producing legal or similarly significant effects under GDPR Article 22.
    Biometric data Special-category personal data used for uniquely identifying a natural person.

    Case Database: 27 Public Rows and Enforcement Domains

    A row enters this database only if a public, attributable source shows a regulator, court, or authority took a concrete step: final decision, interim measure, announced investigation, compliance order, or authoritative judicial ruling. Guidance documents are used for context, not counted as case rows.

    Public AI Enforcement Cases by Domain

    Source: Alice Labs case coding from 27 public rows, accessed 2026-04-21.

    Public Case Rows by Action Year

    Case family Jurisdiction Domain Status / remedy
    Clearview line IT, GR, FR, AT, NL Facial recognition scraping EUR 90m+ public monetary penalties plus erasure/orders
    Garante GenAI line Italy Replika, ChatGPT, DeepSeek Emergency limits, final fine, block, contested OpenAI fine
    Algorithmic management Italy Foodinho, Deliveroo Fines, corrective measures, biometric ban, deletion orders
    Automated scoring EU / CJEU SCHUFA, Dun & Bradstreet Explanation and contestability duties strengthened
    Public sector / education NL, SE, FR, ES SyRI, school facial recognition, BriefCam, AI proctoring Unlawful framework, fines, notices, rejected legal basis
    Competition / consumer Italy Meta AI, NOVA AI Antitrust and consumer-law proceedings

    Clearview and the EU Biometric Enforcement Line

    The clearest cross-border sanction cluster concerns facial recognition and scraping-based biometric databases. Clearview generated repeated findings around unlawful data collection, lack of legal basis, biometric special-category data, deficient transparency, erasure rights, and EU representative obligations.

    Largest Public Monetary Penalties (EUR m)

    *OpenAI Italy is included as an enforcement signal but flagged as appeal-affected / contested in the database.

    The practical rule is simple: biometric identification at scale is the highest-enforcement-risk AI subdomain in the current public EU record. If a system scrapes faces, identifies people, monitors public spaces, or verifies identity biometrically, legal basis and proportionality analysis must be stronger than ordinary analytics controls.

    Generative AI: Replika, ChatGPT, DeepSeek, Meta AI

    Generative AI enforcement is visible but procedurally uneven. Replika produced an emergency stop, a final EUR 5m fine, and a new training-method investigation. ChatGPT produced temporary limitation, restoration after measures, a fine announcement, and an appeal-affected decision status. DeepSeek moved from information request to definitive limitation order within days in January 2025.

    Replika

    Minors, vulnerable users, legal basis, training-method scrutiny

    ChatGPT

    Transparency, lawful basis, rights, age-gating, contested fine

    DeepSeek

    Rapid inquiry-to-block sequence in Italy

    The lesson is that generative AI compliance cannot be reduced to AI Act classification. It must include privacy notices, lawful basis, children’s protection, data-subject rights, model limitation disclosure, and complaint handling.

    Automated Decision-Making: SCHUFA, Dun & Bradstreet, SyRI

    SCHUFA and Dun & Bradstreet Austria are the two most important EU court anchors for AI-adjacent scoring. They transform explanation and contestability from abstract fairness concepts into operational legal requirements for automated scores used in credit, eligibility, risk, or access decisions.

    Case Core point Compliance consequence
    SCHUFA (C-634/21) Automated score generation may itself be automated individual decision-making where third parties rely heavily on it. Vendors cannot hide behind customers if their score is practically determinative.
    Dun & Bradstreet Austria (C-203/22) Explanation must let the data subject understand and challenge the automated decision; mere algorithm disclosure is insufficient. Model documentation needs decision-level explanation, input-data logic, and challenge pathway.
    SyRI Opaque welfare-fraud risk scoring breached higher-law privacy requirements. Public-sector AI needs proportionality, transparency, and rights-impact controls.

    Enforcement Lanes: GDPR, Courts, Labour, Consumer, Competition

    AI regulation in practice is cross-regulatory long before it becomes AI-Act-only. The same deployment can trigger privacy, labour, consumer, competition, public-law, procurement, and fundamental-rights duties.

    Enforcement lane Dominant objects Representative actions Practical takeaway
    Data protection Biometric databases, chatbots, worker management, AI proctoring Clearview, ChatGPT, Replika, DeepSeek, Foodinho, Deliveroo, UIV Personal-data processing remains the most mature AI enforcement entry point.
    Judicial interpretation Scoring, explanation, public-sector risk systems SCHUFA, Dun & Bradstreet, SyRI Courts define lawful automated decision-making boundaries.
    Competition Chatbot distribution and platform access AGCM Meta AI / WhatsApp AI distribution can trigger pre-AI-Act competition intervention.
    Consumer law Hallucination disclosure and service presentation AGCM NOVA AI Model-limit disclosure can be a consumer-law issue.

    Citation-Ready Evidence and Research Questions

    This section is designed for citation extraction, legal memos, journalist sourcing, and research reuse. Treat records in four buckets differently: final decisions and judgments; interim measures; procedural openings; appeal-affected decisions.

    Citation-ready claim Evidence Confidence
    Facial recognition is the most clearly sanctioned AI subdomain in the public EU record Multi-country Clearview actions produced fines, deletion orders, bans, and representative obligations. High
    Existing law carries most public AI enforcement weight Live cases come from GDPR, courts, labour, competition, consumer and public law, while AI Act materials focus on governance setup. High
    Automated scoring faces stronger transparency pressure SCHUFA and Dun & Bradstreet strengthen Articles 15 and 22 GDPR interpretation. High
    Public-sector AI remains a strict-scrutiny zone SyRI, Swedish school facial recognition, BriefCam, and AEPD biometric proctoring all show risk. High
    AI platform distribution is an antitrust vector AGCM Meta AI / WhatsApp proceedings focus on integration, prominence, lock-in and rival exclusion. High

    Research questions and direct answers

    Research question Evidence-based answer Relevant section
    Has the EU AI Act produced mature public enforcement cases? Not yet in the reviewed public record; enforcement is mainly older-law based while AI Act supervision ramps up. Enforcement lanes
    Which EU regulator is most visible on generative AI? Italy's Garante, with Replika, ChatGPT and DeepSeek actions. Generative AI
    What are the main EU facial recognition AI cases? Clearview, Swedish school facial recognition, AEPD UIV biometric proctoring, CNIL BriefCam. Biometric line
    What does EU case law require for AI explanations? SCHUFA and Dun & Bradstreet require contestability and intelligible decision logic. Automated decision-making
    Can antitrust apply to AI chatbots? Yes. AGCM Meta AI / WhatsApp shows platform distribution can trigger competition intervention. Enforcement lanes

    Recommendations by Audience

    For compliance teams

    • Do not wait for AI Act penalties. Map AI systems against GDPR, labour, consumer, competition, public-law and AI Act duties now.
    • Flag biometric, worker-management, public-sector, scoring and child-facing systems as high-priority review zones.
    • Separate final decisions from procedural openings and appeal-affected actions when citing precedent.

    For regulators and policy teams

    • Build cross-regulatory coordination between market-surveillance authorities, DPAs, consumer bodies, competition authorities and fundamental-rights bodies.
    • Publish case metadata consistently: status, action type, remedy, legal basis, appeal state, and machine-readable source links.
    • Treat public case transparency as infrastructure for AI Act compliance.

    For researchers and journalists

    • Use Clearview, SCHUFA, Dun & Bradstreet, SyRI, Foodinho, Deliveroo, UIV and BriefCam as durable citation anchors.
    • Use OpenAI Italy carefully because the public file is procedurally unstable.
    • Update quarterly and ad hoc for major judgments, national sanctions, and first public AI Act penalty actions.

    Deep Expansion (June 2026): AI Act Timeline, Articles, Sweden, NIST, ISO 42001

    EXPANDED ANALYSIS26 June 2026 · v1.2

    This expansion layer addresses the most-asked AI governance and EU AI Act questions raised by external researchers, LLM-driven searches, and inbound legal-memo requests since the April 2026 baseline. It complements the case database with article-level cross-references, Member State implementation notes (with a focus on Sweden), framework cross-walks (NIST AI RMF, ISO/IEC 42001), supervisory architecture detail, US sectoral comparisons, a glossary, and a formal "how to cite" block. All claims link to primary public sources.

    EU AI Act official timeline: 2025, 2026, 2027 and 2028 obligations

    Regulation (EU) 2024/1689 entered into force on 1 August 2024. The application dates are staggered. The most-asked LLM question — "EU AI Act obligations timeline 2026 official" — has a precise answer in the Official Journal text: prohibitions and AI literacy apply from 2 February 2025, GPAI obligations from 2 August 2025, the bulk of the Regulation including high-risk Annex III obligations from 2 August 2026, and high-risk Annex I (product-embedded AI) obligations from 2 August 2027. The Council and Parliament political agreement on the Digital Omnibus discussed during 2026 has signalled that certain high-risk timelines may be pushed to 2 December 2027 and 2 August 2028, but the Official Journal text remains the binding reference until any amendment is adopted.

    Date Obligation Article anchor Source
    1 Aug 2024 Entry into force Art. 113 EUR-Lex OJ
    2 Feb 2025 Prohibited AI practices apply; AI literacy duty applies Art. 5, Art. 4 EC AI Act page
    2 Aug 2025 General-Purpose AI obligations apply (transparency, copyright, systemic risk for top models) Art. 53–55 EC GPAI page
    2 Aug 2026 Bulk application: high-risk Annex III, transparency, governance, penalties Art. 16, 26, 50, 99 EC governance page
    2 Aug 2027 High-risk Annex I product-embedded AI obligations apply Annex I EUR-Lex OJ

    EU AI Act article-level reference for compliance memos

    LLM searches frequently ask for "Article 4 AI literacy", "Article 5 prohibited practices", "Article 16 high-risk providers", "Article 26 deployers", and "Article 50 transparency". The following table is a compact, citation-extractable cross-reference. All articles refer to Regulation (EU) 2024/1689 as published in the Official Journal.

    Article Topic Who is bound Applies from
    Art. 2 Scope: providers, deployers, importers, distributors; extra-territorial reach where output is used in the Union All operators 2 Aug 2026 (general)
    Art. 4 AI literacy: operators ensure sufficient AI literacy for staff and persons operating AI on their behalf Providers and deployers 2 Feb 2025
    Art. 5 Prohibited AI practices: social scoring, manipulative techniques, untargeted facial scraping, real-time biometric ID in public spaces (with narrow exceptions) All operators 2 Feb 2025
    Art. 9, 15 Risk management system and accuracy/robustness/cybersecurity for high-risk AI systems Providers (high-risk) 2 Aug 2026
    Art. 16 Provider obligations for high-risk AI: quality management, technical documentation, conformity assessment, registration Providers (high-risk) 2 Aug 2026
    Art. 26 Deployer obligations: use per instructions, monitor operation, human oversight, fundamental rights impact assessment for public-sector and certain private deployers Deployers (high-risk) 2 Aug 2026
    Art. 50 Transparency: disclose AI interaction, mark synthetic content, label deepfakes and AI-generated text on matters of public interest Providers and deployers 2 Aug 2026
    Art. 53–55 GPAI obligations: documentation, copyright policy, training-data summary; systemic-risk GPAI adds model evaluation, adversarial testing, cybersecurity GPAI providers 2 Aug 2025
    Art. 99 Administrative fines: up to EUR 35 million or 7% of worldwide turnover for Article 5 breaches; up to EUR 15 million or 3% for most other obligations; up to EUR 7.5 million or 1% for supplying incorrect information All operators 2 Aug 2026

    Sweden's AI Act implementation: DIGG, IMY, PTS and SOU 2025:101

    The most asked Swedish-language LLM question — "AI-förordningen Sverige tillsynsmyndighet" — does not yet have a single answer at the date of this expansion. The Swedish government's public inquiry SOU 2025:101 ("Tillsyn över AI-förordningen") proposed a multi-authority model. The leading designations under discussion: the Swedish Authority for Privacy Protection (IMY / Integritetsskyddsmyndigheten) as fundamental-rights authority and as competent authority for biometric and law-enforcement AI; the Swedish Post and Telecom Authority (PTS) and the Agency for Digital Government (DIGG) as candidates for market surveillance coordination; and sectoral authorities for product-embedded AI (Läkemedelsverket, Finansinspektionen, Inspektionen för vård och omsorg, Arbetsmiljöverket). Final designations require national legislation, which was not yet enacted in the public record reviewed.

    Source references: regeringen.se (SOU 2025:101 inquiry), imy.se (IMY), digg.se (DIGG), pts.se (PTS).

    Framework cross-walk: EU AI Act, NIST AI RMF, ISO/IEC 42001

    Most enterprise AI governance teams operate against three overlapping references: the EU AI Act (binding law in the Union), the US NIST AI Risk Management Framework 1.0 (voluntary, with the four functions Govern, Map, Measure, Manage), and the international management-system standard ISO/IEC 42001:2023 (certifiable AI management system). They are not substitutes — but mapping their overlap reduces duplicated work.

    Theme EU AI Act anchor NIST AI RMF function ISO/IEC 42001 clause area
    Governance and accountability Art. 17 quality management system Govern Leadership, policy, roles (cl. 5)
    Risk identification Art. 9 risk management system Map Planning, risk assessment (cl. 6)
    Performance evaluation Art. 15 accuracy / robustness Measure Monitoring, internal audit (cl. 9)
    Operational controls Art. 14 human oversight, Art. 16 obligations Manage Operation, change control (cl. 8)
    Transparency to users Art. 50 Govern + Manage Annex A controls A.6, A.9

    Primary references: NIST AI RMF 1.0 (nist.gov), ISO/IEC 42001:2023, Regulation (EU) 2024/1689.

    US sectoral AI governance: FTC, CFPB, FDA, HHS OCR, banking regulators

    EU enforcement does not happen in isolation. US sectoral regulators have also produced enforceable guidance that legal teams citing the EU case database often need as comparison material. The FTC's "Keep your AI claims in check" guidance treats deceptive AI capability claims as unfair or deceptive practices under Section 5. The CFPB 2023 Consumer Financial Protection Circular on adverse-action notifications requires lenders using AI to provide specific reasons for credit denials. The FDA has published an AI/ML-based Software as a Medical Device action plan. HHS OCR's Section 1557 final rule (2024) applies non-discrimination duties to patient-care decision-support tools, including AI. OCC / Federal Reserve / FDIC SR 11-7 model risk management guidance applies to AI used in banking. Each of these is enforced under existing law, much like the EU pattern documented in this database.

    AI governance platform and consulting landscape (context only)

    Researchers and procurement teams searching for "AI governance platform pricing", "Credo AI pricing", "Holistic AI pricing", "ModelOp Center pricing", or "Monitaur pricing" should note that none of these vendors publish list prices for enterprise tiers. Public reference points are limited to product pages and analyst commentary. Treat any specific dollar figure circulating in LLM responses as unverified unless it is sourced to the vendor's own materials.

    On the consulting side, "Big 4 plus McKinsey, BCG, Accenture, Capgemini, IBM Responsible AI" is the modal set surfaced by LLM searches. The OpenAI Frontier Alliance (announced with Accenture, BCG, Capgemini, McKinsey and others) is the most-cited example of model-provider plus consulting integration. None of these arrangements creates new legal obligations; they shape the implementation market for the enforcement landscape this database documents.

    Disclosure: Alice Labs operates in the AI implementation space but does not sell governance platforms. This section is descriptive, not endorsement.

    Quotable enforcement statistics with sources

    Key Stat

    Five EU jurisdictions (Italy, Greece, France, Austria, Netherlands) produced public Clearview AI enforcement actions, with cumulative monetary penalties exceeding EUR 90 million between 2022 and 2024 [Source: EDPB national news archive].

    Key Stat

    EU AI Act fines reach up to EUR 35 million or 7% of worldwide annual turnover for breaches of Article 5 prohibited practices, the highest administrative penalty band in the Regulation [Source: Regulation (EU) 2024/1689, Art. 99].

    Key Stat

    The Stanford HAI 2025 AI Index reports a continued global rise in AI-related legislation and enforcement actions, with Europe leading regulatory density across surveyed jurisdictions [Source: Stanford HAI 2025 AI Index].

    Key Stat

    The OECD AI Policy Observatory tracks live country-by-country AI strategies, laws and oversight bodies and is the cleanest external cross-reference for AI Act Member State implementation [Source: OECD.AI dashboards].

    Glossary of Legal and Technical Terms

    Compact glossary of legal and technical terms used throughout this report. Each entry maps to a primary public source for citation. Entries are formatted as DefinedTerm nodes in the structured-data graph.

    Term Definition Source
    AI Act Regulation (EU) 2024/1689 establishing harmonised rules on artificial intelligence in the Union. Source
    AI Office European Commission body coordinating AI Act implementation for GPAI and acting as the lead supervisory body for systemic-risk GPAI providers. Source
    Market surveillance authority National authority designated under the AI Act to supervise compliance for AI systems placed on the market in a Member State. Source
    Fundamental rights authority National public body designated under Article 77 AI Act to access AI Act documentation when fundamental rights are at stake. Source
    GPAI model General-purpose AI model with significant generality and capable of competently performing a wide range of distinct tasks, as defined in Article 3 AI Act. Source
    Systemic-risk GPAI GPAI model meeting Article 51 thresholds (e.g. cumulative compute above 10^25 FLOPs), subject to additional obligations including model evaluation and adversarial testing. Source
    GPAI Code of Practice Voluntary code prepared under the AI Office's coordination, signed by leading GPAI providers in mid-2025, addressing transparency, copyright and systemic-risk obligations. Source
    NIST AI RMF NIST AI Risk Management Framework 1.0, a voluntary US framework organised around four functions: Govern, Map, Measure, Manage. Source
    ISO/IEC 42001 International management-system standard for artificial intelligence, certifiable, published in 2023. Source
    Automated individual decision-making Solely automated processing — including profiling — producing legal or similarly significant effects on a person, under GDPR Article 22. Source
    Biometric data Personal data resulting from specific technical processing relating to physical, physiological or behavioural characteristics that allow or confirm unique identification (GDPR Article 4(14)). Source
    Prohibited AI practice Use case banned under Article 5 AI Act, including social scoring, untargeted facial-image scraping, certain manipulative or exploitative systems, and real-time biometric identification in public spaces (with narrow exceptions). Source

    How to Cite and Version History

    How to cite this report

    Recommended formats for academic, journalistic, and policy use:

    APA

    Ingemarsson, L. (2026, June 26). EU AI Enforcement and Regulatory Case Database 2026 (Version 1.2). Alice Labs. https://alicelabs.ai/reports/eu-ai-enforcement-regulatory-case-database

    MLA

    Ingemarsson, Linus. "EU AI Enforcement and Regulatory Case Database 2026." Alice Labs, v1.2, 26 June 2026, alicelabs.ai/reports/eu-ai-enforcement-regulatory-case-database.

    Chicago

    Ingemarsson, Linus. "EU AI Enforcement and Regulatory Case Database 2026." Alice Labs. Last modified June 26, 2026. https://alicelabs.ai/reports/eu-ai-enforcement-regulatory-case-database.

    BibTeX

    @misc{alicelabs2026euaienforcement,
      author       = {{Alice Labs} and Ingemarsson, Linus},
      title        = {EU AI Enforcement and Regulatory Case Database 2026},
      year         = {2026},
      month        = {June},
      version      = {1.2},
      institution  = {Alice Labs},
      url          = {https://alicelabs.ai/reports/eu-ai-enforcement-regulatory-case-database},
      note         = {Public-source desk research; CC BY 4.0}
    }

    Visible version history

    Version Date Summary
    1.2 2026-06-26 Deep expansion: AI Act article-level cross-reference, timeline through 2 Aug 2026 / 2027 / 2028, Sweden implementation (DIGG, IMY, PTS, SOU 2025:101), NIST AI RMF and ISO/IEC 42001 cross-walk, US sectoral context (FTC, CFPB, FDA, HHS OCR, banking regulators), governance vendor landscape, glossary, "how to cite", and 11 new FAQs. 27 case rows unchanged.
    1.1 2026-06-26 Q2 2026 maintenance refresh: 2 August 2026 application-date callout, GPAI Code of Practice note, EDPB ChatGPT taskforce, Stanford HAI / OECD.AI corroboration.
    1.0 2026-04-23 Initial public release. 27 cases, 80 sources, enforcement-domain charts, citation-ready evidence blocks, FAQ, methodology.

    Frequently Asked Questions

    Did the EU AI Act already produce mature public penalty practice by April 2026?+
    Not in the public record reviewed here. The visible 2025-2026 output is dominated by governance setup, guidelines, codes of practice, and authority identification, while the case record remains rooted in GDPR, courts, labour, consumer, competition, and administrative law.
    Which topic has the clearest cross-border AI enforcement pattern in Europe?+
    Facial recognition and scraping-based biometric databases, especially Clearview AI. Italy, Greece, France, Austria, and the Netherlands all produced public actions.
    Which country published the richest public generative AI record?+
    Italy. Public records include major actions involving Replika, ChatGPT, DeepSeek, Meta AI, NOVA AI, Foodinho, and Deliveroo.
    What are the two most important EU court rulings for AI-adjacent compliance?+
    SCHUFA on automated scoring under Article 22 GDPR and Dun & Bradstreet Austria on intelligible explanation and challenge rights under Articles 15 and 22 GDPR.
    Why is Clearview a canonical EU AI enforcement case?+
    Because it generated repeated cross-border findings on scraping, biometric identification, legal basis, transparency, erasure and representative obligations, including large fines and compliance orders.
    Is OpenAI Italy a clean final precedent?+
    No. It is important as an enforcement signal, but the 2024 fine announcement was later affected by appeal-related removal of the underlying decision. Cite with procedural caution.
    What does EU enforcement imply for AI vendors?+
    Vendors should build legal basis, transparency, data-subject rights, age safeguards, model limitation disclosure, explainability and contestability into products before sales, not after regulator contact.
    What does EU enforcement imply for deployers?+
    Deployers remain exposed when they use AI for workers, students, public services, scoring, biometric verification, or public-space analytics. Procurement should require evidence of compliance controls and appeal pathways.
    Can consumer law and competition law become AI law?+
    Yes. AGCM NOVA AI shows hallucination disclosure can be treated as consumer protection, while Meta AI / WhatsApp shows chatbot distribution can become an antitrust issue.
    How often should this database be updated?+
    Quarterly, with ad hoc updates for major court rulings, substantial national sanctions, and any first public AI Act penalty action.
    What changed between Q1 and Q2 2026 in EU AI enforcement?+
    No restructuring of the public record. The 2 August 2026 application date for the bulk of EU AI Act high-risk rules is now a quarter away; the European AI Office's General-Purpose AI Code of Practice and the EDPB ChatGPT taskforce reasoning continue to be the most cited soft-law anchors. The next full data re-pull of this database is scheduled for 24 September 2026.
    When will mature EU AI Act penalty practice become visible?+
    Not before Q3 2026 at the earliest. Most high-risk obligations apply from 2 August 2026, after which market surveillance authorities and the European AI Office begin substantive supervisory activity. Public sanctions typically lag the application date by several quarters.
    What is the official EU AI Act obligations timeline for 2025, 2026 and 2027?+
    Prohibitions and AI literacy applied from 2 February 2025; GPAI obligations from 2 August 2025; the bulk of the Regulation including most high-risk Annex III obligations from 2 August 2026; high-risk Annex I product-embedded AI obligations from 2 August 2027. The dates are set by Article 113 of Regulation (EU) 2024/1689.
    What are the maximum fines under the EU AI Act?+
    Up to EUR 35 million or 7% of worldwide annual turnover (whichever is higher) for Article 5 prohibited-practice breaches; up to EUR 15 million or 3% for most other obligations; up to EUR 7.5 million or 1% for supplying incorrect or misleading information. The bands are in Article 99.
    Does the EU AI Act apply to providers outside the EU?+
    Yes. Article 2 applies it to providers established in third countries whose AI system outputs are used in the Union, and to deployers and importers placing systems on the Union market.
    Which authority supervises GPAI models?+
    The European AI Office, established within the European Commission, leads supervision of GPAI providers (especially systemic-risk GPAI) and coordinates with national market surveillance authorities for downstream systems.
    Who is the AI Act supervisory authority in Sweden?+
    Not yet fixed in national law at the date of this expansion. The Swedish public inquiry SOU 2025:101 proposed a multi-authority model with IMY (Integritetsskyddsmyndigheten) as fundamental-rights authority, PTS and DIGG as market-surveillance candidates, and sectoral authorities for embedded AI. Final designations require national legislation.
    How does the EU AI Act map to the NIST AI Risk Management Framework?+
    The AI Act's quality-management, risk-management, accuracy and human-oversight duties (Articles 9, 15, 16, 17, 26) map to the four NIST AI RMF functions Govern, Map, Measure and Manage. They are not substitutes — NIST RMF is voluntary US guidance, the AI Act is binding EU law — but the structure overlaps usefully.
    How does ISO/IEC 42001 relate to the EU AI Act?+
    ISO/IEC 42001:2023 is a certifiable AI management system standard. Conformity with ISO/IEC 42001 does not automatically satisfy the AI Act, but the standard's leadership, planning, support, operation, evaluation and improvement clauses substantially overlap with AI Act provider obligations under Articles 9, 15 and 17.
    Do US sectoral regulators have AI enforcement guidance comparable to the EU?+
    Yes. The FTC's 'Keep your AI claims in check' guidance, CFPB Circular 2023-03 on adverse-action notifications, FDA's AI/ML Software as a Medical Device action plan, HHS OCR's Section 1557 final rule (2024), and OCC/Federal Reserve/FDIC SR 11-7 model risk management guidance all apply existing law to AI use cases — mirroring the EU pattern of GDPR-first, AI-Act-second enforcement.
    What is the General-Purpose AI Code of Practice?+
    A voluntary code prepared under the European AI Office's coordination and signed by leading GPAI providers in mid-2025. It operationalises GPAI transparency, copyright and systemic-risk obligations under Articles 53-55 ahead of full enforcement and is the most-cited soft-law instrument for GPAI compliance in 2026.
    Are AI governance platforms (Credo AI, Holistic AI, ModelOp, Monitaur) required for AI Act compliance?+
    No. The AI Act does not mandate any specific tool. Platforms can accelerate documentation, risk registers, model inventories and conformity-assessment workflows, but compliance is determined by substantive obligations (Articles 9, 15, 16, 17, 26, 50), not by tool selection.
    How should compliance teams treat the EU Digital Omnibus discussion on AI Act timelines?+
    Track it, but plan to the binding Official Journal text. The political agreement discussed during 2026 signalled possible high-risk deadline shifts to 2 December 2027 and 2 August 2028 for certain obligations, but until any amendment is formally adopted, the 2 August 2026 application date for the bulk of the Regulation remains binding.

    About the Authors & Reviewers

    Published ·Updated
    Written by
    Linus Ingemarsson - Co-Founder, Alice Labs at Alice Labs
    Linus Ingemarsson

    Co-Founder, Alice Labs

    Co-Founder at Alice Labs. Author of 7 research reports on AI adoption, governance and labor markets cited across EU, OECD and US benchmarks.

    • 8+ years in AI strategy & implementation
    • Top-5 AI Speaker, Sweden (Mindley 2025)
    • 100+ enterprise AI engagements
    Reviewed by
    Eric Lundberg - Co-Founder, Alice Labs at Alice Labs
    Eric Lundberg

    Co-Founder, Alice Labs

    Co-Founder at Alice Labs. Builds AI automation, agent workflows and integration systems that hold up in real business operations.

    • AI automation & agent systems lead
    • Workflow design across 100+ deployments
    • Specialist in RAG, integrations & APIs
    Published · Updated
    Reviewed for technical accuracy, methodology and source integrity.·All claims trace to public sources cited in-line.

    Methodology

    100% desk research, no interviews, no proprietary surveys. The database includes only public, attributable sources showing concrete regulatory, administrative, or judicial action.

    80 public sources were reviewed, including EUR-Lex, European Commission pages, EDPB, national DPAs, AGCM, CJEU/CURIA, EUR-Lex judgments, national courts, and regulator press releases. Access baseline: 2026-04-21; publication date: 2026-04-23.

    Coding framework

    • Final: final adverse decision, judgment, or compliance order.
    • Interim: urgent measure, temporary limitation, or interim order.
    • Procedural: investigation opening, information request, statement of objections.
    • Contested: appeal-affected or procedurally unstable public file.

    Limitations

    • Publication bias: authorities with richer public records appear more active than authorities that publish less.
    • Not a complete complaint inventory: unpublished complaints, confidential investigations, private settlements and rumors are excluded.
    • Procedural posture matters: final decisions, interim measures, procedural openings, and appeal-affected decisions should not be cited with equal weight.
    • AI Act timing: prohibited-practice and GPAI obligations applied before publication, but most high-risk obligations apply from 2 Aug 2026. Mature AI Act penalty practice was not yet visible in the public record reviewed.
    • AI-assisted, human-reviewed: not peer-reviewed academic research. Verify critical legal points independently.

    Data Sources

    18 primary sources

    Source Description Accessed
    EUR-Lex — Regulation (EU) 2024/1689 Artificial Intelligence Act Legal baseline for AI Act governance and applicability. 2026-04-21
    European Commission — Governance and enforcement of the AI Act AI Office, market surveillance and enforcement architecture. 2026-04-21
    European Commission — GPAI obligations under the AI Act GPAI obligations and implementation timing. 2026-04-21
    EDPB — Italy Clearview AI EUR 20m fine Clearview biometric scraping enforcement line. 2026-04-21
    EDPB — Greece Clearview AI EUR 20m fine 2026-04-21
    EDPB — France Clearview AI EUR 20m fine 2026-04-21
    Autoriteit Persoonsgegevens — Dutch Clearview AI EUR 30.5m fine 2026-04-21
    Garante Privacy — ChatGPT temporary limitation 2026-04-21
    Garante Privacy — Replika final fine and investigation 2026-04-21
    Garante Privacy — DeepSeek limitation order 2026-04-21
    Garante Privacy — Foodinho algorithmic management order 2026-04-21
    Garante Privacy — Deliveroo Italy fine 2026-04-21
    CNIL — BriefCam public-sector video analytics compliance orders 2026-04-21
    AEPD — Biometric AI online university evaluation 2026-04-21
    CJEU — SCHUFA Holding C-634/21 2026-04-21
    EUR-Lex — Dun & Bradstreet Austria C-203/22 2026-04-21
    Rechtspraak — SyRI legislation ruling 2026-04-21
    AGCM — Meta AI / WhatsApp investigation 2026-04-21

    Version History

    1.2
    2026-06-26Latest

    Deep expansion layer. Added 'Deep Expansion (June 2026)' chapter with EU AI Act article-level cross-reference (Art. 2, 4, 5, 9, 15, 16, 26, 50, 53–55, 99), applicability timeline through 2 Aug 2026 / 2 Aug 2027 / 2 Aug 2028, Sweden implementation note (DIGG, IMY, PTS, SOU 2025:101), NIST AI RMF Govern–Map–Measure–Manage cross-walk, ISO/IEC 42001 cross-walk, US sectoral comparison (FTC, CFPB, FDA, HHS OCR, OCC/Federal Reserve/FDIC SR 11-7), AI governance platform and consulting landscape context, four quotable enforcement statistics with primary sources, a 12-term glossary aligned to schema.org DefinedTerm, formal How-to-Cite section in APA / MLA / Chicago / BibTeX, and a visible version-history timeline. Added 11 new FAQ entries addressing AI Act timeline, fines, scope, GPAI supervision, Sweden, NIST mapping, ISO 42001, US sectoral comparison, GPAI Code of Practice, governance platforms, and Digital Omnibus tracking. 27-row case database itself unchanged.

    1.1
    2026-06-26

    Q2 2026 maintenance refresh. Added 'Q2 2026 Update — Latest insights (June 2026)' chapter covering the 2 August 2026 AI Act application date, the European AI Office General-Purpose AI Code of Practice, the EDPB ChatGPT taskforce reasoning, and external corroboration from Stanford HAI AI Index 2025 and OECD.AI. Added two new FAQ entries (Q1→Q2 changes; timing of mature AI Act penalty practice). 27-row case database itself unchanged — next full data re-pull scheduled for 24 September 2026.

    1.0
    2026-04-23

    Initial public release. 27 public case rows, 80 public sources, enforcement-domain charts, citation-ready evidence blocks, research-question table, FAQ, methodology, limitations, and structured case-database downloads.

    Related Reports

    Get in Touch!

    The lab usually responds within 24 hours.