Skip to content
Topic Emerging debate

AI Act Violations

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

The content specifically addresses 'Non-compliance' as a distinct legal concept under the DSA/AI Act framework. This requires a dedicated topic to comprehensively cover violation types, determination procedures, consequences, and remediation mechanisms that are not fully captured by existing penalty or enforcement topics.

18 linked items 2 Enforcement16 News

Overview

2 sources · Jul 23, 2026

Legal Framework

The EU AI Act establishes a tiered compliance regime centred on risk classification. Article 5 prohibits certain AI practices outright, including manipulative or exploitative systems. Article 6 governs high-risk AI systems, requiring conformity assessment, risk management, data governance, and human oversight before market placement. Article 9 mandates a risk management system throughout the AI lifecycle. Articles 10 and 14 address data quality and human oversight respectively. Article 99 sets out the penalty structure: non-compliance with Article 5 prohibitions triggers fines up to €35 million or 7% of global turnover, while violations of high-risk obligations under Articles 6 to 15 carry fines up to €15 million or 3% of global turnover. Supplying incorrect information to notified bodies or national authorities can reach €7.5 million or 1% of global turnover under Article 99(4).

Key Developments

The Italian Data Protection Authority's enforcement against Luka Inc. illustrates how national authorities are already leveraging overlapping regulatory regimes to address AI violations before the AI Act's full application. The Garante imposed a €5,000,000 fine on Luka Inc. for its Replika chatbot, identifying risks to vulnerable users—particularly minors—and inadequate transparency about data processing and algorithmic logic. The decision demonstrates that authorities will examine whether AI systems manipulate user behaviour, process data without valid legal basis, and fail to protect minors. The Garante's action signals that enforcement agencies will not wait for the AI Act's complete implementation timeline but will use GDPR provisions—Articles 5, 6, 13, and 35—as interim enforcement tools against AI systems that would also violate Article 5 prohibitions on manipulative AI practices.

Practical Guidance

  • Classify AI systems by risk tier before deployment. Map each system against Article 5 prohibitions and Article 6 high-risk criteria. Systems interacting with vulnerable users require heightened scrutiny.
  • Implement Article 9 risk management throughout the lifecycle. Document risk identification, mitigation measures, and post-market monitoring. The Replika enforcement shows authorities expect evidence of ongoing risk assessment, not one-time review.
  • Ensure transparency and lawful basis for data processing. Provide clear information about algorithmic logic under GDPR Article 13 and conduct Data Protection Impact Assessments under Article 35 GDPR, especially where systems process personal data of minors.
  • Establish human oversight mechanisms per Article 14. Designate responsible personnel with authority to intervene, override, or shut down AI systems when risks materialise.
  • Prepare for cross-regulatory enforcement. Authorities are applying GDPR and consumer protection law concurrently. Compliance programmes must address overlapping obligations across data protection, AI, and consumer safety frameworks simultaneously.
Everything on this topic, by type links go to the exact provision / paragraph / section
Enforcement 2
Italian Data Protection Authority (Garante) Luka Inc.: Niet-naleving van de algemene principes voor gegevensverwerking. Italian Data Protection Authority (Garante) Apr 2025 NL Italian Data Protection Authority (Garante) Luka Inc.: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) Apr 2025
News 16
European Digital Rights The AI Act isn’t enough: closing the dangerous loopholes that enable rights violations European Digital Rights Nov 2025 CNIL The 2022 annual report of the CNIL CNIL May 2023 Datatilsynet De Deense beschermingsautoriteit (SA) heeft verklaard dat het gebruik van Google Analytics onrechtmatig is zonder aanvullende maatregelen. Datatilsynet Sep 2022 NL Datatilsynet Danish SA Declares Use of Google Analytics Unlawful Without Supplementary Measures Datatilsynet Sep 2022 Fair Trials Europol wordt gevraagd om persoonlijke gegevens over te dragen aan een Nederlandse activist. Fair Trials Sep 2022 NL Fair Trials Europol told to hand over personal data to Dutch activist Fair Trials Sep 2022 Hunton Andrews Kurth Irish Data Protection Commissioner Fines Instagram EUR 405M for Children Privacy Violations Hunton Andrews Kurth Sep 2022 Hunton Andrews Kurth De Ierse autoriteit voor gegevensbescherming heeft Instagram een boete van 405 miljoen euro opgelegd vanwege schendingen van de privacy van kinderen. Hunton Andrews Kurth Sep 2022 NL Hunton Andrews Kurth De CNIL stelt een boete van 60 miljoen euro voor aan een Frans bedrijf dat zich bezighoudt met advertentietechnologie, vanwege het niet naleven van de AVG (Algemene Verordening Gegevensbescherming). Hunton Andrews Kurth Aug 2022 NL Hunton Andrews Kurth CNIL Proposes 60 Million Euros Fine Against French AdTech Company For Non-Compliance with GDPR Hunton Andrews Kurth Aug 2022 eucrim HvJ: De PNR-richtlijn is geldig, mits deze beperkt blijft tot wat "strikt noodzakelijk" is. eucrim Aug 2022 NL eucrim CJEU: PNR Directive Valid if Limited to the “Strictly Necessary” eucrim Aug 2022 European Commission European Commission introduces AI liability redress proposal European Commission Sep 2022 European Commission De Europese Commissie presenteert een voorstel voor een regeling over aansprakelijkheid bij schade veroorzaakt door kunstmatige intelligentie. European Commission Sep 2022 NL White Label Consultancy Data Protection Officer or Chief Privacy Officer?The rise of the Data Protection Officer White Label Consultancy Jan 2022 The Markup Who Is Collecting Data from Your Car?Who Is Collecting Data from Your Car? The Markup Jul 2022