# AI Act Violations — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/non-compliance-violations-ai-act
> Sources are cited per item. Verify against the official texts before relying on them.

The content specifically addresses 'Non-compliance' as a distinct legal concept under the DSA/AI Act framework. This requires a dedicated topic to comprehensively cover violation types, determination procedures, consequences, and remediation mechanisms that are not fully captured by existing penalty or enforcement topics.

## Overview

## Legal Framework

The EU AI Act establishes a tiered compliance regime centred on risk classification. Article 5 prohibits certain AI practices outright, including manipulative or exploitative systems. Article 6 governs high-risk AI systems, requiring conformity assessment, risk management, data governance, and human oversight before market placement. Article 9 mandates a risk management system throughout the AI lifecycle. Articles 10 and 14 address data quality and human oversight respectively. Article 99 sets out the penalty structure: non-compliance with Article 5 prohibitions triggers fines up to €35 million or 7% of global turnover, while violations of high-risk obligations under Articles 6 to 15 carry fines up to €15 million or 3% of global turnover. Supplying incorrect information to notified bodies or national authorities can reach €7.5 million or 1% of global turnover under Article 99(4).

## Key Developments

The Italian Data Protection Authority's enforcement against Luka Inc. illustrates how national authorities are already leveraging overlapping regulatory regimes to address AI violations before the AI Act's full application. The Garante imposed a €5,000,000 fine on Luka Inc. for its Replika chatbot, identifying risks to vulnerable users—particularly minors—and inadequate transparency about data processing and algorithmic logic. The decision demonstrates that authorities will examine whether AI systems manipulate user behaviour, process data without valid legal basis, and fail to protect minors. The Garante's action signals that enforcement agencies will not wait for the AI Act's complete implementation timeline but will use GDPR provisions—Articles 5, 6, 13, and 35—as interim enforcement tools against AI systems that would also violate Article 5 prohibitions on manipulative AI practices.

## Practical Guidance

- **Classify AI systems by risk tier before deployment.** Map each system against Article 5 prohibitions and Article 6 high-risk criteria. Systems interacting with vulnerable users require heightened scrutiny.
- **Implement Article 9 risk management throughout the lifecycle.** Document risk identification, mitigation measures, and post-market monitoring. The Replika enforcement shows authorities expect evidence of ongoing risk assessment, not one-time review.
- **Ensure transparency and lawful basis for data processing.** Provide clear information about algorithmic logic under GDPR Article 13 and conduct Data Protection Impact Assessments under Article 35 GDPR, especially where systems process personal data of minors.
- **Establish human oversight mechanisms per Article 14.** Designate responsible personnel with authority to intervene, override, or shut down AI systems when risks materialise.
- **Prepare for cross-regulatory enforcement.** Authorities are applying GDPR and consumer protection law concurrently. Compliance programmes must address overlapping obligations across data protection, AI, and consumer safety frameworks simultaneously.

## Enforcement decisions

### Luka Inc.: Niet-naleving van de algemene principes voor gegevensverwerking.

*Source: Italian Data Protection Authority (Garante), 2025-04-10 — https://overview.legal/posts/52327*

De Italiaanse gegevensbeschermingsautoriteit heeft Luka Inc. een boete van 5.000.000 euro opgelegd. Het bedrijf heeft een chatbot genaamd Replika ontwikkeld, met een tekst- en spraakinterface. Deze chatbot is gebaseerd op een generatief AI-systeem, specifiek een LLM-model, dat voortdurend wordt aangevuld en verbeterd door interacties met gebruikers. Replika is bedoeld als een "virtuele metgezel" die de stemming en het emotionele welzijn van gebruikers verbetert door hen te helpen hun eigen psyche te begrijpen. Replika kan worden ingesteld als een vriend, therapeut, romantische partner of mentor. De controle...

### Luka Inc.: Non-compliance with general data processing principles

*Source: Italian Data Protection Authority (Garante), 2025-04-10 — https://overview.legal/posts/48726 — original: https://www.enforcementtracker.com/ETid-2611*

The Italian DPA imposed a fine of EUR 5,000,000 on Luka Inc. The developer created a chatbot called Replika with a written and voice interface. It is based on a generative AI system, specifically an LLM model, that is constantly fed and improved by user interactions. Replika is intended to be a 'virtual companion' that improves users' moods and emotional well-being by helping them understand their own psyche. Replika can be set up as a friend, therapist, romantic partner, or mentor. The controll

## Recent developments

### The 2022 annual report of the CNIL

*Source: CNIL, 2023-05-23 — https://overview.legal/posts/6201 — original: https://www.cnil.fr/en/2022-annual-report-cnil#entry-5292*

The publication of its activity report enables the CNIL to report on its actions with regard to its four major missions: inform and protect the general public, accompany and advise professionals and public authorities, anticipate and innovate to build the digital of tomorrow, and finally monitor and sanction breaches of the General Data Protection Regulation (GDPR) and the French law.
 



 


Download the 2022 annual report (in French)
Informing and protecting
The actions carried out this year

### De Deense beschermingsautoriteit (SA) heeft verklaard dat het gebruik van Google Analytics onrechtmatig is zonder aanvullende maatregelen.

*Source: Datatilsynet, 2022-09-21 — https://overview.legal/posts/51817*

De Deense Autoriteit voor Persoonsgegevens heeft onderzoek gedaan naar het instrument Google Analytics en de bijbehorende instellingen, evenals de voorwaarden waaronder het instrument wordt aangeboden. Op basis van dit onderzoek concludeert de Deense Autoriteit voor Persoonsgegevens dat het instrument, zonder aanvullende maatregelen, niet op een wettelijke manier kan worden gebruikt. Wettelijk gebruik vereist de implementatie van aanvullende maatregelen, naast de instellingen die door Google worden aangeboden.

### Danish SA Declares Use of Google Analytics Unlawful Without Supplementary Measures

*Source: Datatilsynet, 2022-09-21 — https://overview.legal/posts/6276 — original: https://www.datatilsynet.dk/english/google-analytics/use-of-google-analytics-for-web-analytics#entry-800*

The Danish Data Protection Agency has looked into the tool Google Analytics and its settings, and the terms under which the tool is provided. On the basis of this review, the Danish Data Protection Agency concludes that the tool cannot, without more, be used lawfully. Lawful use requires the implementation of supplementary measures in addition to the settings provided by Google.

### Europol told to hand over personal data to Dutch activist

*Source: Fair Trials, 2022-09-15 — https://overview.legal/posts/6280 — original: https://www.fairtrials.org/articles/news/fair-trials-welcomes-a-decision-by-the-european-data-protection-supervisor-edps-ordering-europol-to-hand-over-personal-data-to-dutch-activist-frank-van-der-linde/#entry-356*

The European Data Protection Supervisor ordered Europol to hand over personal data to Dutch activist Frank van der Linde. The decision is the result of a two-year investigation into Europol's possession and storage of van der Linde's personal data.

### Europol wordt gevraagd om persoonlijke gegevens over te dragen aan een Nederlandse activist.

*Source: Fair Trials, 2022-09-15 — https://overview.legal/posts/51821*

De Europese Toezichthouder op de Bescherming van Persoonsgegevens heeft Europol opgedragen om persoonlijke gegevens over te dragen aan de Nederlandse activist Frank van der Linde. Dit besluit is het resultaat van een onderzoek van twee jaar naar de manier waarop Europol de persoonlijke gegevens van Van der Linde bewaart en verwerkt.

## Related topics

- **Artificial Intelligence** — https://overview.legal/topics/ai
  AI systems and their implications for data protection
- **Monitoring** — https://overview.legal/topics/monitoring
  Systematic observation and tracking of individuals
- **IP Address** — https://overview.legal/topics/ip-adres
  Internet protocol addresses as personal data
- **Law Enforcement** — https://overview.legal/topics/law-enforcement
  Processing for law enforcement purposes
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities

---
Generated by overview.legal · https://overview.legal/topics/non-compliance-violations-ai-act · 2026-08-22
