Skip to content
Topic Emerging debate

AI Act Violations

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

The content specifically addresses 'Non-compliance' as a distinct legal concept under the DSA/AI Act framework. This requires a dedicated topic to comprehensively cover violation types, determination procedures, consequences, and remediation mechanisms that are not fully captured by existing penalty or enforcement topics.

6 linked items 2 Enforcement4 News

Overview

2 sources · Sep 8, 2026

Legal Framework

AI Act violations are governed primarily by Articles 99 through 102 of the AI Act, which establish the penalty regime and administrative fine ceilings for non-compliance. Article 99 sets maximum fines at €35 million or 7% of worldwide annual turnover for violations involving prohibited AI practices, and €15 million or 3% for breaches of obligations concerning high-risk AI systems and transparency requirements. Article 100 addresses fines for notified bodies, while Article 101 covers fines for Union institutions, agencies, and bodies. Article 102 provides the general framework for administrative fines, requiring that competent authorities exercise their powers under conditions set by Member State law.

The enforcement architecture also relies on Article 74, which designates national competent authorities and market surveillance authorities, and Article 75, which establishes the procedural framework for enforcement cooperation. Market surveillance authorities possess corrective powers under Article 68, including the authority to require providers to bring non-compliant systems into conformity, restrict or prohibit their availability, or order recalls.

Key Developments

Enforcement remains in its earliest stages, with data protection authorities increasingly invoking AI Act provisions alongside GDPR enforcement. The Italian Data Protection Authority's action against Luka Inc. over the Replika chatbot illustrates the emerging pattern of DPAs leveraging both data protection and AI regulatory frameworks simultaneously, resulting in a €5,000,000 fine. This signals that AI Act violations will frequently be detected and sanctioned through the intersection of data protection supervision and AI-specific market surveillance.

No binding court interpretation of the AI Act's penalty provisions has yet emerged. The enforcement examples available reflect administrative decisions rather than judicial rulings, leaving the proportionality assessment and the interaction between GDPR fines and AI Act fines largely untested before courts.

Status of the Debate

This topic is an emerging debate. The doctrinal status is clear: scholarship and commentary are running ahead of binding authority. No court has yet interpreted the AI Act's penalty provisions, and no judicial split is on record. The open questions—particularly how administrative fines under the AI Act interact with parallel GDPR penalties, and how "worldwide annual turnover" is calculated for non-EU providers—will only be resolved through national court rulings and, ultimately, preliminary references to the CJEU.

Practical Guidance

  • Map your AI system classification under Article 6 to determine whether your system is prohibited, high-risk, or subject to limited transparency obligations—this determines your maximum exposure under Article 99.
  • Establish a documented conformity assessment for high-risk systems before market placement, as the absence of this assessment is a direct violation triggering the highest fine tier.
  • Monitor DPA enforcement signals in jurisdictions where data protection authorities also serve as AI Act competent authorities, as these authorities are positioned to enforce both regimes simultaneously.
  • Maintain corrective action readiness under Article 68, since market surveillance authorities can order restrictions, prohibitions, or recalls without prior judicial proceedings.
  • Calculate turnover exposure using the provider's worldwide consolidated figures, as the AI Act's percentage-based fines apply to global annual turnover, not EU-only revenue.
Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section