# AI Enforcement Actions — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/enforcement-actions-penalties-ai
> Sources are cited per item. Verify against the official texts before relying on them.

The Penalties section includes procedural aspects of how penalties are imposed, appealed, and enforced, which warrants a dedicated topic covering the administrative and procedural dimensions of penalty enforcement.

## Overview

## Legal Framework
The administrative enforcement of the AI Act is governed by Recital 168 AI Act. It establishes the foundational principle that compliance must be enforceable through sanctions. Member States are required to implement all necessary measures to ensure the AI Act is applied, including providing for effective, proportionate, and dissuasive penalties for infringements. The recital emphasizes the need to strengthen and harmonize administrative sanctions across the EU while respecting the principle of *non bis in idem*. Procedural aspects of enforcement, particularly jurisdiction, are informed by the principle in Recital 123 DSA, which clarifies that, for the sake of clarity and efficiency, supervisory and enforcement authority should generally lie with the competent authorities of the Member State where a provider has its main establishment.

## Practical Application
Recital 168 AI Act, as interpreted by authoritative commentary, mandates that national legislators create a robust enforcement regime. The requirement for "effective, proportionate and dissuasive" sanctions sets a high bar; fines must be significant enough to deter non-compliance, particularly for high-risk AI systems. The reference to harmonization indicates that while Member States design their penalty systems, disparities should be minimized to ensure a level playing field. The jurisdictional model referenced from the DSA suggests a "one-stop-shop" enforcement approach is likely for providers of AI systems, concentrating supervisory power with the authorities of the Member State of the main establishment to avoid fragmented enforcement.

## Key Considerations
*   **Proactive National Law Monitoring:** Organizations must closely monitor how their Member State of main establishment transposes the AI Act's penalty provisions into national law, as this will define the specific procedures, fine ceilings, and appeal mechanisms applicable to them.
*   **Prepare for Centralized Enforcement:** Compliance strategies and internal reporting lines should be structured with the understanding that primary enforcement authority will likely reside with a single national supervisory authority, based on the location of the provider's main establishment.

## Guidance

### Report on the use of SPE external experts in 2024

*Source: EDPB, edpb-report-20250313-support-pool-experts-programme-2024-en, 2025-03-18 — https://overview.legal/posts/50659 — original: https://www.edpb.europa.eu/documents/support-pool-of-experts/report-on-the-use-of-spe-external-experts-in-2024_en*

European Data Protection Board, Report on the use of SPE external experts in 2024, 2025.

### EDPB Annual Report 2025

*Source: EDPB, edpb-annual-report-2025-en, 2026-04-09 — https://overview.legal/posts/125683 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-annual-report-2025_en*

Clarity in action: Supporting stakeholders through guidance and dialogue Annual Report 2025 Foreword 3 Highlights 4 1. The EDPB Secretariat 6 1.1 Mission And Activities 8 2. European Data Protection Board – Activities in 2025 12 2.1 Bridging Fundamental Rights and Digital Innovation Through GDPR Compliance 12 2.1.1 Helsinki high-level meeting: enhanced clarity, support and engagement 12 2.1.2 Regulation on procedural rules and Omnibus regulation on the record of processing 14 2.1.3 Cross…

### EDPB Annual Report 2023

*Source: EDPB, edpb-annual-report-2023-en, 2024-04-23 — https://overview.legal/posts/125756 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-annual-report-2023_en*

EDPB Annual Report 2023 1 2023 ANNUAL REPORT SAFEGUARDING INDIVIDUALS' DIGITAL RIGHTS 2 FOREWORD 4 HIGHLIGHTS 2023 6 1. THE EDPB SECRETARIAT 8 1.1. MISSION AND ACTIVITIES IN 2023 9 1.2. RE-ORGANISING THE SECRETARIAT IN 2023 12 2. EUROPEAN DATA PROTECTION BOARD - ACTIVITIES IN 2023 14 2.1. BINDING DECISIONS 14 2.2. CONSISTENCY OPINIONS 19 2.3. GENERAL GUIDANCE 21 2.3.1. Guidelines 03/2022 on deceptive design patterns in social media platform interfaces: how to recognise and avoid them 21 2.3.2.…

### EDPB Work Programme 2023-2024

*Source: EDPB, edpb-work-programme-2023-2024-en, 2023-02-22 — https://overview.legal/posts/125868 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-work-programme-2023-2024_en*

EDPB Work Programme 2023/2024 Adopted on 14 February 2023 The European Data Protection Board The European Data Protection Board (EDPB) is an independent European body established by the General Data Protection Regulation (GDPR). The EDPB has the following main tasks: To issue opinions, guidelines, recommendations and best practices to promote a common understanding of the GDPR and the Law Enforcement Directive (LED); To advise the European Commission on any issue related to the protection of…

## Recent developments

### Danish SA Declares Use of Google Analytics Unlawful Without Supplementary Measures

*Source: Datatilsynet, 2022-09-21 — https://overview.legal/posts/6276 — original: https://www.datatilsynet.dk/english/google-analytics/use-of-google-analytics-for-web-analytics#entry-800*

The Danish Data Protection Agency has looked into the tool Google Analytics and its settings, and the terms under which the tool is provided. On the basis of this review, the Danish Data Protection Agency concludes that the tool cannot, without more, be used lawfully. Lawful use requires the implementation of supplementary measures in addition to the settings provided by Google.

### De Deense beschermingsautoriteit (SA) heeft verklaard dat het gebruik van Google Analytics onrechtmatig is zonder aanvullende maatregelen.

*Source: Datatilsynet, 2022-09-21 — https://overview.legal/posts/51817*

De Deense Autoriteit voor Persoonsgegevens heeft onderzoek gedaan naar het instrument Google Analytics en de bijbehorende instellingen, evenals de voorwaarden waaronder het instrument wordt aangeboden. Op basis van dit onderzoek concludeert de Deense Autoriteit voor Persoonsgegevens dat het instrument, zonder aanvullende maatregelen, niet op een wettelijke manier kan worden gebruikt. Wettelijk gebruik vereist de implementatie van aanvullende maatregelen, naast de instellingen die door Google worden aangeboden.

### Irish Data Protection Commissioner Fines Instagram EUR 405M for Children Privacy Violations

*Source: Hunton Andrews Kurth, 2022-09-07 — https://overview.legal/posts/6284 — original: https://www.huntonprivacyblog.com/2022/09/07/irish-data-protection-commissioner-fines-instagram-for-children-privacy-violations/#entry-216*

> The fine is the result of an investigation that began in 2020 and focused on the company’s processing of children’s personal data. Based on press reports, the investigation focused on children between the ages of 13 and 17 who were allowed to operate business or creator Instagram accounts. As a result, children’s phone numbers and email addresses were publicly accessible.

### De Ierse autoriteit voor gegevensbescherming heeft Instagram een boete van 405 miljoen euro opgelegd vanwege schendingen van de privacy van kinderen.

*Source: Hunton Andrews Kurth, 2022-09-07 — https://overview.legal/posts/51825*

De boete is het resultaat van een onderzoek dat in 2020 is begonnen en zich richtte op de manier waarop het bedrijf persoonlijke gegevens van kinderen verwerkte. Op basis van berichten in de media richtte het onderzoek zich op kinderen tussen de 13 en 17 jaar oud die toestemming hadden om zakelijke of creatieve Instagram-accounts te gebruiken. Hierdoor waren telefoonnummers en e-mailadressen van kinderen openbaar toegankelijk.

### CNIL Proposes 60 Million Euros Fine Against French AdTech Company For Non-Compliance with GDPR

*Source: Hunton Andrews Kurth, 2022-08-05 — https://overview.legal/posts/6291 — original: https://www.huntonprivacyblog.com/2022/08/17/cnil-proposes-60-million-euros-fine-against-french-adtech-company-for-non-compliance-with-gdpr/#entry-12*

> The proposed fine follows complaints filed by privacy NGO ‘Privacy International’ against Criteo. […]
Under the CNIL’s sanction procedure, Criteo has the right to respond to the report, both with respect to the alleged infringements and the proposed sanction.

## Related topics

- **Artificial Intelligence** — https://overview.legal/topics/ai
  AI systems and their implications for data protection
- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities
- **Monitoring** — https://overview.legal/topics/monitoring
  Systematic observation and tracking of individuals
- **DPIA** — https://overview.legal/topics/dpia
  Data Protection Impact Assessment - systematic evaluation of processing risks
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing

---
Generated by overview.legal · https://overview.legal/topics/enforcement-actions-penalties-ai · 2026-08-22
