The EU AI Act’s headline fines have not started flowing yet. But data-protection authorities and consumer-protection regulators have been enforcing against AI systems for years. Here is the record so far. Every entry links to the primary regulator’s own file.

  • 13 – AI-washing cases filed by the FTC
  • €7.1B – Cumulative GDPR fines since May 2018
  • 30+ bn – Face images in the largest sanctioned AI database

Regulators are not waiting for a horizontal AI act. They are using the tools they already have: GDPR for data, consumer-protection statutes for advertising and deception, and sectoral statutes for lending, hiring, and health. The most consistent enforcement themes so far are unsubstantiated efficacy claims, unlawful biometric collection, transparency failures under GDPR, and misuse of AI-powered decisioning against consumers. Ethosure gives regulated enterprises the evidence trail that answers every one of them at once.

(Note: you can download this factsheet – no registration required.  The link is in the toolbar inside the document window.  On the right hand side, look for the “PDF” icon – that’s how you can download an save to your personal drive.)

If you’d like to be notified when we publish or update resources like this factsheet, sign up for our newsletter.  We monitor AI news, regulations, and the industry at large and share the details on a monthly basis.


Subscribe to Ethosure's Newsletter to get monthly updates on AI Governance

We don’t spam! Read our privacy policy for more info.

Subscribe to Ethosure's Newsletter to get monthly updates on AI Governance

We don’t spam! Read our privacy policy for more info.

See also  Unmanaged AI Agents Burn Budget.