AI Act Violations
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.The content specifically addresses 'Non-compliance' as a distinct legal concept under the DSA/AI Act framework. This requires a dedicated topic to comprehensively cover violation types, determination procedures, consequences, and remediation mechanisms that are not fully captured by existing penalty or enforcement topics.
Overview
2 sources · Jul 23, 2026Legal Framework
The EU AI Act establishes a tiered compliance regime centred on risk classification. Article 5 prohibits certain AI practices outright, including manipulative or exploitative systems. Article 6 governs high-risk AI systems, requiring conformity assessment, risk management, data governance, and human oversight before market placement. Article 9 mandates a risk management system throughout the AI lifecycle. Articles 10 and 14 address data quality and human oversight respectively. Article 99 sets out the penalty structure: non-compliance with Article 5 prohibitions triggers fines up to €35 million or 7% of global turnover, while violations of high-risk obligations under Articles 6 to 15 carry fines up to €15 million or 3% of global turnover. Supplying incorrect information to notified bodies or national authorities can reach €7.5 million or 1% of global turnover under Article 99(4).
Key Developments
The Italian Data Protection Authority's enforcement against Luka Inc. illustrates how national authorities are already leveraging overlapping regulatory regimes to address AI violations before the AI Act's full application. The Garante imposed a €5,000,000 fine on Luka Inc. for its Replika chatbot, identifying risks to vulnerable users—particularly minors—and inadequate transparency about data processing and algorithmic logic. The decision demonstrates that authorities will examine whether AI systems manipulate user behaviour, process data without valid legal basis, and fail to protect minors. The Garante's action signals that enforcement agencies will not wait for the AI Act's complete implementation timeline but will use GDPR provisions—Articles 5, 6, 13, and 35—as interim enforcement tools against AI systems that would also violate Article 5 prohibitions on manipulative AI practices.
Practical Guidance
- Classify AI systems by risk tier before deployment. Map each system against Article 5 prohibitions and Article 6 high-risk criteria. Systems interacting with vulnerable users require heightened scrutiny.
- Implement Article 9 risk management throughout the lifecycle. Document risk identification, mitigation measures, and post-market monitoring. The Replika enforcement shows authorities expect evidence of ongoing risk assessment, not one-time review.
- Ensure transparency and lawful basis for data processing. Provide clear information about algorithmic logic under GDPR Article 13 and conduct Data Protection Impact Assessments under Article 35 GDPR, especially where systems process personal data of minors.
- Establish human oversight mechanisms per Article 14. Designate responsible personnel with authority to intervene, override, or shut down AI systems when risks materialise.
- Prepare for cross-regulatory enforcement. Authorities are applying GDPR and consumer protection law concurrently. Compliance programmes must address overlapping obligations across data protection, AI, and consumer safety frameworks simultaneously.