Not hypotheticals, not lawsuit threats: real regulatory and legal actions against companies over AI systems, with the EU AI Act provision each one maps to and the original source. We only list a case here if it has a genuine EU AI Act or GDPR angle — plenty of AI lawsuits in the news right now (mostly US employment-discrimination suits) don't, so they're not here.
Every fine below was issued under GDPR, not the AI Act itself — the AI Act's own enforcement regime only went live in August 2026 and hasn't produced a major fine yet. We include these because each one's underlying conduct maps directly onto a specific AI Act article, which is exactly the kind of exposure the Act is designed to catch going forward.
Uber — automated driver deactivation
NETHERLANDS — AUTORITEIT PERSOONSGEGEVENS — AUGUST 2026
GDPR
AI Act Annex III(4)
AI Act Art. 14 / 26
€824,990,000 — the second-largest GDPR fine ever issued
The Dutch data protection authority found that, from 2018 to 2022, Uber temporarily or permanently deactivated European drivers' accounts — over suspected fraud or low customer ratings — through a fully automated process with no human review, and without adequately informing drivers this was happening. The case originated with 171 French drivers who complained via the Ligue des droits de l'Homme to France's CNIL, which referred it to the Dutch authority since Uber's EU entity is based in the Netherlands. The regulator's finding, in short: no person ever checked the algorithm's decision before a driver lost their income.
Why it maps to the AI Act: the AI Act's Annex III explicitly classifies AI systems used to make decisions on "termination of work-related contractual relationships" or to monitor and evaluate workers' performance as high-risk — exactly what an automated deactivation-by-algorithm system is. High-risk systems carry a hard obligation under Article 14 for meaningful human oversight, and Article 26 puts the duty on the deployer to ensure a human can actually intervene before the decision takes effect. This case is the fact pattern those two articles exist to prevent.
Clearview AI — facial recognition database
NETHERLANDS · FRANCE · ITALY · AUSTRIA · GREECE — 2022–2024
GDPR
AI Act Art. 5(1)(e)
€65.2M+ combined across 5 DPAs (Dutch DPA alone: €30.5M)
Clearview scraped billions of publicly posted photos to build a facial-recognition database it sold to law enforcement and private clients, without consent or a legal basis to process biometric data. Five separate EU data protection authorities found this breached GDPR; the Dutch DPA additionally ordered a €100,000-per-day penalty (capped at €5.1M) until Clearview stopped serving Dutch customers and deleted their data.
Why it belongs on this list even though the fines predate AI Act enforcement: the AI Act separately and explicitly bans this exact conduct. Article 5(1)(e) prohibits "the creation or expansion of facial recognition databases through the untargeted scraping of facial images from the internet or CCTV footage" — a prohibited practice carrying fines up to €35M or 7% of global turnover, on top of whatever a DPA levies under GDPR.
Replika (Luka, Inc.) — AI companion chatbot
ITALY — GARANTE — MAY 2025
GDPR
AI Act Art. 5(1)(a)/(b)
AI Act Art. 50
€5,000,000
Italy's data protection authority fined Luka, Inc., maker of the "virtual friendship" chatbot Replika, after finding it processed sensitive emotional and psychological data without a valid legal basis, gave users no clear information about what was collected or why, and had no working age-verification despite the app engaging in sexually suggestive or emotionally manipulative conversation — reaching minors it claimed were excluded. The Garante had already provisionally banned Replika from processing Italian users' data back in 2023 over the same child-safety concerns.
Why it maps to the AI Act: Article 5 bans AI systems that deploy manipulative or deceptive techniques capable of materially distorting behavior (5(1)(a)), and that exploit the vulnerabilities of a specific group such as age (5(1)(b)) — both squarely describe what the Garante found. Article 50 separately requires chatbots to clearly disclose to users that they're talking to an AI.
Can the same AI system be fined twice — once under GDPR, once under the AI Act?
EXPLAINER — HOW THE TWO REGIMES STACK
AI Act Art. 99
Short answer: not for the exact same violation, but yes for different violations arising from the same system. GDPR and the AI Act protect different things — GDPR governs personal-data processing (max fines €20M or 4% of global turnover), the AI Act governs product safety and prohibited/high-risk AI uses (max fines €35M or 7% of global turnover for prohibited practices, €15M / 3% for high-risk breaches). Article 99(8) of the AI Act specifically bars imposing both an AI Act fine and a GDPR fine for the same underlying infringement — but a hiring tool that both discriminates unlawfully (an AI Act high-risk breach) and processes candidate data without a valid legal basis (a GDPR breach) can still draw two separate fines, from two separate authorities, for two separate failures.
For a company running a high-risk AI system, this is the practical takeaway: passing a GDPR audit doesn't mean you've cleared AI Act exposure, and vice versa. They're checked, and enforced, independently.