Artificial Intelligence in Australia

Enforcement / fines

Australia has no general, cross-economy AI Act enforcement or penalty regime. AI-specific or AI-relevant obligations may nevertheless be enforced under existing legislation and sectoral instruments. The regulator, cause of action, available remedy and maximum penalty depend on the particular provision, the conduct, the date of contravention and the defendant.

  • A serious or repeated interference with privacy under the Privacy Act can attract a maximum civil penalty of AUD 2.5 million for a person other than a body corporate. For a body corporate, the maximum is the greater of AUD 50 million, three times the value of the benefit reasonably attributable to the conduct, or, if that value cannot be determined, 30% of adjusted turnover during the breach turnover period. Other Privacy Act contraventions have different consequences. The statutory tort for serious invasions of privacy also creates a private court pathway, subject to its elements, remedies, defences and exemptions.
  • Competition and consumer law. AI-related representations, sales practices or product conduct may engage the Australian Consumer Law and competition law. For many offence and civil-penalty provisions, the maximum corporate penalty for conduct on or after 28 March 2026 is the greater of AUD 100 million, three times the reasonably attributable benefit where that value can be determined, or 30% of adjusted turnover during the breach turnover period where it cannot. Other provisions have lower maxima. The general prohibition on misleading or deceptive conduct under the Australian Consumer Law is not itself a pecuniary-penalty provision, although related conduct may contravene civil-penalty provisions and injunctions, damages, compensation and other remedies may be available.
  • Online safety. Non-compliance with a standard, or with a direction to comply with a code, can result in civil-penalty proceedings. The maximum identified in eSafety’s regulatory guidance is 30,000 penalty units per contravention for an individual and five times that amount for a corporation. Different Online Safety Act contraventions may carry different maxima.
  • Other regimes. AI uses may also attract regulatory orders, licence consequences, remediation, compensation, injunctions, enforceable undertakings, disqualification, criminal liability or judicial and merits review under financial-services, health, workplace, discrimination, cybercrime, critical-infrastructure, administrative-law and other sectoral regimes. Penalty figures should be rechecked on the publication date and should never be applied without identifying the specific contravention.
Last modified 20 July 2026

The EU AI Act enforces compliance through a structured framework of fines and sanctions, varying in severity based on the nature of the non-compliance.

For non-compliance with prohibited AI practices, fines can reach up to EUR 35 million or 7% of the total worldwide annual turnover, whichever is higher.

This includes practices like manipulative AI systems, exploiting vulnerabilities, social scoring by public authorities, and unauthorized biometric identification in public spaces.

Breaches of high-risk AI system requirements can incur fines up to EUR 15 million or 3% of the total worldwide annual turnover.

These requirements include risk management, data governance, technical documentation, transparency, and cybersecurity. Other non-compliance issues, such as providing incorrect or misleading information, can result in fines up to EUR 7.5 million or 1% of the total worldwide annual turnover. This applies to breaches not covered by the highest or significant sanctions.

Enforcement / fines in Austria

Austria has not adopted specific national implementing provisions concerning rules on penalties and other enforcement measures under Article 99. Furthermore, no publicly available legislative drafts or proposals establishing such a penalty regime have been identified.

Last modified 28 July 2026

The Product Liability Directive has not been yet transposed into Belgian law. Belgium has until 9 December 2026 to formally transpose the new rules into national legislation.

The EU AI Act enforces compliance through a structured framework of fines and sanctions, varying in severity based on the nature of the non-compliance.

For non-compliance with prohibited AI practices, fines can reach up to EUR 35 million or 7% of the total worldwide annual turnover, whichever is higher.

This includes practices like manipulative AI systems, exploiting vulnerabilities, social scoring by public authorities, and unauthorized biometric identification in public spaces.

Breaches of high-risk AI system requirements can incur fines up to EUR 15 million or 3% of the total worldwide annual turnover.

These requirements include risk management, data governance, technical documentation, transparency, and cybersecurity. Other non-compliance issues, such as providing incorrect or misleading information, can result in fines up to EUR 7.5 million or 1% of the total worldwide annual turnover. This applies to breaches not covered by the highest or significant sanctions.

Belgium did not comply with the deadline of 2 August 2025 to lay down rules for penalties and fines for the AI Act, and to notify them to the European Commission.

Last modified 16 July 2026

Laws specifically addressing AI have not been introduced in Brazil yet. Draft Article 50 of the proposed Brazilian AI Bill specifies fines and other penalties for breaches of specific requirements of the proposed legislation. 

Last modified 7 July 2026

The EU AI Act enforces compliance through a structured framework of fines and sanctions, varying in severity based on the nature of the non-compliance.

For non-compliance with prohibited AI practices, fines can reach up to EUR 35 million or 7% of the total worldwide annual turnover, whichever is higher.

This includes practices like manipulative AI systems, exploiting vulnerabilities, social scoring by public authorities, and unauthorized biometric identification in public spaces.

Breaches of high-risk AI system requirements can incur fines up to EUR 15 million or 3% of the total worldwide annual turnover.

These requirements include risk management, data governance, technical documentation, transparency, and cybersecurity. Other non-compliance issues, such as providing incorrect or misleading information, can result in fines up to EUR 7.5 million or 1% of the total worldwide annual turnover. This applies to breaches not covered by the highest or significant sanctions.

Last modified 24 July 2026

National laws specifically addressing AI have not yet passed in Canada. Bill C-34, if enacted, would establish a significant enforcement regime for regulated social media services and chatbot services. The Digital Safety Commission would have the power to impose administrative monetary penalties of up to 6% of global revenue or CAD 25 million (whichever is higher) for individuals and up to 8% of global revenue for corporations. The revenue-based penalty structure means that penalties scale with company size. The Commission could also issue compliance orders directing operators to take or refrain from specific actions, enforceable as Federal Court orders.

Last modified 24 June 2026

Article 24 of the Chilean AI Bill establishes that the Agency will be responsible for the enforcement and sanctioning of the infringements established in the Chilean AI Bill. The infringements are categorised as follows:

  • Very serious: The commissioning or use, by an operator, of an AI system for unacceptable risk uses, resulting in fines up to UTM20,000 (approximately USD 1,38 million.).
  • Serious: Non-compliance, by an operator of high-risk uses of AI systems, resulting in fines up to UTM10,000 (approximately USD690,000).
  • Slight: Non-compliance, by an operator, with transparency obligations for limited-risk uses of AI systems, or any other breach of obligations under the law that does not have a specific sanction, resulting in fines up to UTM5,000 (approximately USD345,000).

The bill states a specific judicial claims procedure for claims arising from the exercise of rights and obligations under the Chilean AI Bill, referring those claims to the procedure under Article 43 of Law No. 19,628 as amended by Law No. 21,719.

A person suffering damage because of the use of an AI system will be able to sue for:

  • The cessation of the acts that are generating the damage.
  • Compensation for damages.
  • The adoption of necessary measures to prevent the continuation of the infringement.
  • The publication of the judgment at the expense of the convicted party, by means of advertisements in a newspaper of the plaintiff’s choice.
Last modified 2 July 2026

The relevant regulatory authorities have the power to impose penalties for violation of certain provisions of the abovementioned provisions and measures based on the wider applicable laws and regulations of the PRC.

This said, the PRC authorities have broad powers in addition to fines which may have an impact on business activities and reputational risks, including the issuance of warnings, suspension of services or business licences, blocking and blacklisting.

Last modified 7 July 2026

The EU AI Act enforces compliance through a structured framework of fines and sanctions, varying in severity based on the nature of the non-compliance.

For non-compliance with prohibited AI practices, fines can reach up to EUR 35 million or 7% of the total worldwide annual turnover, whichever is higher.

This includes practices like manipulative AI systems, exploiting vulnerabilities, social scoring by public authorities, and unauthorized biometric identification in public spaces.

Breaches of high-risk AI system requirements can incur fines up to EUR 15 million or 3% of the total worldwide annual turnover.

These requirements include risk management, data governance, technical documentation, transparency, and cybersecurity. Other non-compliance issues, such as providing incorrect or misleading information, can result in fines up to EUR 7.5 million or 1% of the total worldwide annual turnover. This applies to breaches not covered by the highest or significant sanctions.

Croatia has not yet laid down national rules on penalties and fines under Article 99 of the EU AI Act, nor notified them to the Commission. The national penalty rules are expected to form part of the pending implementing law.

Last modified 24 July 2026

The EU AI Act enforces compliance through a structured framework of fines and sanctions, varying in severity based on the nature of the non-compliance.

For non-compliance with prohibited AI practices, fines can reach up to EUR 35 million or 7% of the total worldwide annual turnover, whichever is higher.

This includes practices like manipulative AI systems, exploiting vulnerabilities, social scoring by public authorities, and unauthorized biometric identification in public spaces.

Breaches of high-risk AI system requirements can incur fines up to EUR 15 million or 3% of the total worldwide annual turnover.

These requirements include risk management, data governance, technical documentation, transparency, and cybersecurity. Other non-compliance issues, such as providing incorrect or misleading information, can result in fines up to EUR 7.5 million or 1% of the total worldwide annual turnover. This applies to breaches not covered by the highest or significant sanctions.

No publicly available official information has been traced confirming that Cyprus laid down and notified the required national rules by the deadline of 2 August 2025 or ensured their proper implementation. Although the official AI Cyprus portal refers generally to the enforcement and sanctioning powers of the competent authorities, it does not identify any national legislative measure laying down the relevant penalties or any notification of such measures to the European Commission.

Last modified 22 July 2026

The EU AI Act enforces compliance through a structured framework of fines and sanctions, varying in severity based on the nature of the non-compliance.

For non-compliance with prohibited AI practices, fines can reach up to EUR 35 million or 7% of the total worldwide annual turnover, whichever is higher.

This includes practices like manipulative AI systems, exploiting vulnerabilities, social scoring by public authorities, and unauthorized biometric identification in public spaces.

Breaches of high-risk AI system requirements can incur fines up to EUR 15 million or 3% of the total worldwide annual turnover.

These requirements include risk management, data governance, technical documentation, transparency, and cybersecurity. Other non-compliance issues, such as providing incorrect or misleading information, can result in fines up to EUR 7.5 million or 1% of the total worldwide annual turnover. This applies to breaches not covered by the highest or significant sanctions.

Enforcement / fines in the Czech Republic

Based on the draft Czech AI Act (version updated on 26 June 2026), the Czech Republic adopts the choice described in Article 99(1) of the EU AI Act to grant market surveillance authorities the power to issue enforcement measures in the form of warnings. Section 25 of the draft Act introduces the concept of a 'Notice of Breach' under which, if a deployer or a notified body commits a minor breach of an obligation under the EU AI Act, the relevant authorities will first issue a notice and call for corrective action.

The Czech Republic established rules for sanctions and enforcement measures under Article 99 of the EU AI Act for the first time in the initial draft of the Czech Artificial Intelligence Act, published on 25 September 2025. The deadline for Member States to notify the European Commission of their proposed rules was set for 2 August 2025, pursuant to Article 99(2) of the EU AI Act. Therefore, it appears that the Czech Republic was at least one month delayed in notifying the EC.

Last modified 8 July 2026

The EU AI Act enforces compliance through a structured framework of fines and sanctions, varying in severity based on the nature of the non-compliance.

For non-compliance with prohibited AI practices, fines can reach up to EUR 35 million or 7% of the total worldwide annual turnover, whichever is higher.

This includes practices like manipulative AI systems, exploiting vulnerabilities, social scoring by public authorities, and unauthorized biometric identification in public spaces.

Breaches of high-risk AI system requirements can incur fines up to EUR 15 million or 3% of the total worldwide annual turnover.

These requirements include risk management, data governance, technical documentation, transparency, and cybersecurity. Other non-compliance issues, such as providing incorrect or misleading information, can result in fines up to EUR 7.5 million or 1% of the total worldwide annual turnover. This applies to breaches not covered by the highest or significant sanctions.

Enforcement / fines in Denmark

Under Law No. 467 of 14 May 2025, Danish authorities such as the Agency for Digital Government and the Danish Data Protection Agency are empowered to issue fines for violations of the EU AI Act. The law also authorizes the Minister for Digitalisation, in agreement with the Minister of Justice, to adopt rules enabling certain cases to be resolved without court proceedings through the issuance of administrative fine notices - provided the offender admits the violation and agrees to pay the fine within a specified deadline. As the law does not enter into force until 2 August 2025, no such rules have yet been adopted, and the administrative fine procedure has not been applied in practice.

Last modified 21 July 2025

The EU AI Act enforces compliance through a structured framework of fines and sanctions, varying in severity based on the nature of the non-compliance.

For non-compliance with prohibited AI practices, fines can reach up to EUR 35 million or 7% of the total worldwide annual turnover, whichever is higher.

This includes practices like manipulative AI systems, exploiting vulnerabilities, social scoring by public authorities, and unauthorized biometric identification in public spaces.

Breaches of high-risk AI system requirements can incur fines up to EUR 15 million or 3% of the total worldwide annual turnover.

These requirements include risk management, data governance, technical documentation, transparency, and cybersecurity. Other non-compliance issues, such as providing incorrect or misleading information, can result in fines up to EUR 7.5 million or 1% of the total worldwide annual turnover. This applies to breaches not covered by the highest or significant sanctions.

While Estonia’s AI Action Plan envisages national implementation measures for the EU AI Act, including rules on the handling of infringements and the imposition of penalties, no publicly adopted implementing act setting out Estonia’s Article 99 enforcement and penalties framework has been identified as of July 2026.

Last modified 23 July 2026

The EU AI Act enforces compliance through a structured framework of fines and sanctions, varying in severity based on the nature of the non-compliance.

For non-compliance with prohibited AI practices, fines can reach up to EUR 35 million or 7% of the total worldwide annual turnover, whichever is higher.

This includes practices like manipulative AI systems, exploiting vulnerabilities, social scoring by public authorities, and unauthorized biometric identification in public spaces.

Breaches of high-risk AI system requirements can incur fines up to EUR 15 million or 3% of the total worldwide annual turnover.

These requirements include risk management, data governance, technical documentation, transparency, and cybersecurity. Other non-compliance issues, such as providing incorrect or misleading information, can result in fines up to EUR 7.5 million or 1% of the total worldwide annual turnover. This applies to breaches not covered by the highest or significant sanctions.

Last modified 11 February 2026

The EU AI Act enforces compliance through a structured framework of fines and sanctions, varying in severity based on the nature of the non-compliance.

For non-compliance with prohibited AI practices, fines can reach up to EUR 35 million or 7% of the total worldwide annual turnover, whichever is higher.

This includes practices like manipulative AI systems, exploiting vulnerabilities, social scoring by public authorities, and unauthorized biometric identification in public spaces.

Breaches of high-risk AI system requirements can incur fines up to EUR 15 million or 3% of the total worldwide annual turnover.

These requirements include risk management, data governance, technical documentation, transparency, and cybersecurity. Other non-compliance issues, such as providing incorrect or misleading information, can result in fines up to EUR 7.5 million or 1% of the total worldwide annual turnover. This applies to breaches not covered by the highest or significant sanctions.

Enforcement / fines in Finland

According to the Act on the Supervision of Certain AI Systems (1377/2025), administrative fines are generally imposed by the competent market surveillance authority for each case. However, if the authority determines that the sanction should exceed EUR 100,000, it must refer the matter to the AI Systems Supervision Sanction Board, as it does not have the authority to impose fines above this threshold.

Last modified 24 July 2026

The EU AI Act enforces compliance through a structured framework of fines and sanctions, varying in severity based on the nature of the non-compliance.

For non-compliance with prohibited AI practices, fines can reach up to EUR 35 million or 7% of the total worldwide annual turnover, whichever is higher.

This includes practices like manipulative AI systems, exploiting vulnerabilities, social scoring by public authorities, and unauthorized biometric identification in public spaces.

Breaches of high-risk AI system requirements can incur fines up to EUR 15 million or 3% of the total worldwide annual turnover.

These requirements include risk management, data governance, technical documentation, transparency, and cybersecurity. Other non-compliance issues, such as providing incorrect or misleading information, can result in fines up to EUR 7.5 million or 1% of the total worldwide annual turnover. This applies to breaches not covered by the highest or significant sanctions.

In France, the rules on penalties applicable to infringements of the EU AI Act had not been laid down, nor notified to the Commission, by the 2 August 2025 deadline set by Article 99 of the EU AI Act (read with Recital 179). The national penalty and enforcement provisions are contained in Article 24 of the DDADUE. The French penalty framework is accordingly expected to be adopted, implemented and notified to the Commission in the course of 2026.

Last modified 20 July 2026

The EU AI Act enforces compliance through a structured framework of fines and sanctions, varying in severity based on the nature of the non-compliance.

For non-compliance with prohibited AI practices, fines can reach up to EUR 35 million or 7% of the total worldwide annual turnover, whichever is higher.

This includes practices like manipulative AI systems, exploiting vulnerabilities, social scoring by public authorities, and unauthorized biometric identification in public spaces.

Breaches of high-risk AI system requirements can incur fines up to EUR 15 million or 3% of the total worldwide annual turnover.

These requirements include risk management, data governance, technical documentation, transparency, and cybersecurity. Other non-compliance issues, such as providing incorrect or misleading information, can result in fines up to EUR 7.5 million or 1% of the total worldwide annual turnover. This applies to breaches not covered by the highest or significant sanctions.

Enforcement / fines in Germany

The fine ceilings set out in Article 99 of the EU AI Act apply directly in Germany. In addition, section 15 of the KI-MIG creates national fine provisions for breaches that are not already sanctioned under Article 99(3) to (5) of the EU AI Act. This covers, for example, failures to provide certain information or documentation, or to carry out a fundamental rights impact assessment under Article 27 of the EU AI Act. Such breaches may be sanctioned with a fine of up to EUR 50,000. The general German Administrative Offences Act (Gesetz über OrdnungswidrigkeitenOWiG) applies to these proceedings unless the KI-MIG provides otherwise. The administrative authorities competent for the fine proceedings are the market surveillance and notifying authorities within their respective remits, and no fines are imposed on public bodies within the meaning of the Federal Data Protection Act. As the implementing act is not yet in force, these rules remain subject to the outstanding Bundesrat proceedings.

Last modified 17 July 2026

The EU AI Act enforces compliance through a structured framework of fines and sanctions, varying in severity based on the nature of the non-compliance.

For non-compliance with prohibited AI practices, fines can reach up to EUR 35 million or 7% of the total worldwide annual turnover, whichever is higher.

This includes practices like manipulative AI systems, exploiting vulnerabilities, social scoring by public authorities, and unauthorized biometric identification in public spaces.

Breaches of high-risk AI system requirements can incur fines up to EUR 15 million or 3% of the total worldwide annual turnover.

These requirements include risk management, data governance, technical documentation, transparency, and cybersecurity. Other non-compliance issues, such as providing incorrect or misleading information, can result in fines up to EUR 7.5 million or 1% of the total worldwide annual turnover. This applies to breaches not covered by the highest or significant sanctions.

Enforcement / fines in Greece

Although Greece initially failed to meet the 2 August 2025 deadline for adopting national rules on penalties and enforcement measures, the Greek AI Act Implementation Law addresses this omission by establishing the national enforcement and sanctions regime required under Article 99 of the AI Act. As part of that regime, the Law confers additional administrative corrective and sanctioning powers on the HDPA and the other designated market surveillance authorities, alongside the market surveillance powers already provided for under the AI Act and Regulation (EU) 2019/1020.

More specifically, the competent authorities may issue warnings where an AI system intended to be placed on the market or put into service is likely to infringe the AI Act or the Greek AI Act Implementation Law. Where an infringement has already occurred, they may issue reprimands or binding compliance orders requiring operators to bring the AI system into compliance in a specified manner or within a specified period.

The Law further empowers the HDPA and the other market surveillance authorities to impose the administrative fines provided for in Article 99 of the AI Act to both private and public entities. In addition, they may threaten or impose periodic penalty payments when operators do not comply with competent authorities’ binding compliance orders, of up to two per cent of the undertaking’s average daily worldwide turnover or income during the preceding financial year. However, the practical application of the sanctions regime may give rise to interpretative questions, particularly as regards the delineation of competences between the designated authorities and the coexistence of the AI Act enforcement regime with existing national sector-specific legislation. Notably, these corrective and sanctioning measures may also be imposed on public sector bodies, ensuring that public authorities deploying or operating AI systems are subject to the same enforcement tools.

When exercising their sanctioning powers, the competent authorities must ensure that penalties are effective, proportionate and dissuasive in each individual case.

In addition, the Greek AI Act Implementation Law further enhances the enforcement powers of the HDPA by incorporating, mutatis mutandis, the investigative and corrective powers provided under Articles 15(4) and 15(5) of Law 4624/2019. These powers enable the HDPA to issue warnings and binding compliance orders, impose temporary or permanent restrictions or prohibitions, require the surrender of documentation and technical systems, seize relevant equipment and records, and order the discontinuation, freezing or destruction of data and related filing systems where necessary to remedy non-compliance.

The Greek AI Act Implementation Law further reinforces compliance through a mandatory publication regime for enforcement decisions. The HDPA and the other market surveillance authorities must publish sanctioning decisions identifying the infringement, the sanctions imposed and the infringing party.

Finally, the Greek AI Act Implementation Law enables the HDPA and the other designated market surveillance authorities to recover the costs incurred in investigating and establishing instances of non-compliance. Recoverable costs include, among others, the costs of testing AI systems, implementing market surveillance measures and managing non-compliant products prior to their placement on the market.

Last modified 24 July 2026

Laws specifically addressing AI have not yet been introduced in Hong Kong. 

Failure to comply with Hong Kong’s personal data protection law (the Personal Data (Privacy) Ordinance (Cap. 486)) when using AI will be subject to sanctions under that law. The PCPD’s ongoing compliance reviews of organisations using AI (most recently covering 60 organisations in 2026) demonstrate active oversight of personal data privacy compliance practices in AI contexts under the existing legal framework.

Compliance with industry-specific AI guidelines (e.g., in the financial services sectors) may be supervised and enforced in the usual way by the relevant industry regulators.

Last modified 3 July 2026

The EU AI Act enforces compliance through a structured framework of fines and sanctions, varying in severity based on the nature of the non-compliance.

For non-compliance with prohibited AI practices, fines can reach up to EUR 35 million or 7% of the total worldwide annual turnover, whichever is higher.

This includes practices like manipulative AI systems, exploiting vulnerabilities, social scoring by public authorities, and unauthorized biometric identification in public spaces.

Breaches of high-risk AI system requirements can incur fines up to EUR 15 million or 3% of the total worldwide annual turnover.

These requirements include risk management, data governance, technical documentation, transparency, and cybersecurity. Other non-compliance issues, such as providing incorrect or misleading information, can result in fines up to EUR 7.5 million or 1% of the total worldwide annual turnover. This applies to breaches not covered by the highest or significant sanctions.

Last modified 24 July 2025

India currently lacks legislation specific to AI. Consequently, there is no specific or standardised list of enforcement actions/fines vis-à-vis AI-related offences.

Penalties and enforcement mechanisms are contextual and can vary depending on the nature of offence. For instance, use of an individual’s personal data for AI training models could trigger privacy violation (resulting in fines under the DPDPA), or use of content without licences could result in copyright infringement claims (resulting in civil or criminal actions). Similarly, use of AI for deepfakes, identity theft or creation of unlawful content can trigger liability under the IT Act, as well as the criminal laws of India, resulting in fines, imprisonment or both. Sector-specific regulations may also be invoked if the use contravenes the relevant regulations.

Last modified 13 July 2026

The EU AI Act enforces compliance through a structured framework of fines and sanctions, varying in severity based on the nature of the non-compliance.

For non-compliance with prohibited AI practices, fines can reach up to EUR 35 million or 7% of the total worldwide annual turnover, whichever is higher.

This includes practices like manipulative AI systems, exploiting vulnerabilities, social scoring by public authorities, and unauthorized biometric identification in public spaces.

Breaches of high-risk AI system requirements can incur fines up to EUR 15 million or 3% of the total worldwide annual turnover.

These requirements include risk management, data governance, technical documentation, transparency, and cybersecurity. Other non-compliance issues, such as providing incorrect or misleading information, can result in fines up to EUR 7.5 million or 1% of the total worldwide annual turnover. This applies to breaches not covered by the highest or significant sanctions.

Last modified 23 July 2025

There are currently no AI‑specific penalties. As such, enforcement and penalties relating to the creation, dissemination and/or use of AI are currently governed by related violations in non-AI legislation.

Last modified 8 July 2026

The EU AI Act enforces compliance through a structured framework of fines and sanctions, varying in severity based on the nature of the non-compliance.

For non-compliance with prohibited AI practices, fines can reach up to EUR 35 million or 7% of the total worldwide annual turnover, whichever is higher.

This includes practices like manipulative AI systems, exploiting vulnerabilities, social scoring by public authorities, and unauthorized biometric identification in public spaces.

Breaches of high-risk AI system requirements can incur fines up to EUR 15 million or 3% of the total worldwide annual turnover.

These requirements include risk management, data governance, technical documentation, transparency, and cybersecurity. Other non-compliance issues, such as providing incorrect or misleading information, can result in fines up to EUR 7.5 million or 1% of the total worldwide annual turnover. This applies to breaches not covered by the highest or significant sanctions.

As noted in the Law / Proposed Law section, the effectiveness of the Italian enforcement framework remains largely dependent on the adoption of secondary and implementing legislation. In this respect, the draft implementing decree (only preliminarily approved by the Council of Ministers on 10 June 2026), appears broadly aligned with the framework established by the EU AI Act (mirroring the tiered and proportionate system of penalties). The draft decree also makes use of the flexibility afforded by the EU AI Act by establishing statutory maximum penalties that, in certain cases, are lower than the corresponding EU thresholds. Finally, the competent national authorities are required to submit an annual report on their activities to the Presidency of the Council of Ministers.

Last modified 7 August 2026

The AI Act does not contain any penal provisions.

Last modified 29 June 2026

The EU AI Act enforces compliance through a structured framework of fines and sanctions, varying in severity based on the nature of the non-compliance.

For non-compliance with prohibited AI practices, fines can reach up to EUR 35 million or 7% of the total worldwide annual turnover, whichever is higher.

This includes practices like manipulative AI systems, exploiting vulnerabilities, social scoring by public authorities, and unauthorized biometric identification in public spaces.

Breaches of high-risk AI system requirements can incur fines up to EUR 15 million or 3% of the total worldwide annual turnover.

These requirements include risk management, data governance, technical documentation, transparency, and cybersecurity. Other non-compliance issues, such as providing incorrect or misleading information, can result in fines up to EUR 7.5 million or 1% of the total worldwide annual turnover. This applies to breaches not covered by the highest or significant sanctions.

Last modified 14 July 2025

The EU AI Act enforces compliance through a structured framework of fines and sanctions, varying in severity based on the nature of the non-compliance.

For non-compliance with prohibited AI practices, fines can reach up to EUR 35 million or 7% of the total worldwide annual turnover, whichever is higher.

This includes practices like manipulative AI systems, exploiting vulnerabilities, social scoring by public authorities, and unauthorized biometric identification in public spaces.

Breaches of high-risk AI system requirements can incur fines up to EUR 15 million or 3% of the total worldwide annual turnover.

These requirements include risk management, data governance, technical documentation, transparency, and cybersecurity. Other non-compliance issues, such as providing incorrect or misleading information, can result in fines up to EUR 7.5 million or 1% of the total worldwide annual turnover. This applies to breaches not covered by the highest or significant sanctions.

Lithuania does not appear to have met the 2 August 2025 deadline under Article 99 of Regulation (EU) 2024/1689, by which Member States were required to establish and implement national rules on penalties and fines, and notify those rules to the European Commission.

Although Lithuania adopted Laws No. XV-105 and XV-106, establishing the principal national competent authorities and related institutional arrangements, the separate legislation required to establish the full national framework for penalties and other enforcement measures remained pending before the Seimas as at 7 August 2026. In particular, Draft Law No. XVP-1564 had not yet been enacted. Publicly available sources also do not confirm that Lithuania notified the Commission of a complete Article 99 penalties framework by the applicable deadline.

Last modified 7 August 2025

The EU AI Act enforces compliance through a structured framework of fines and sanctions, varying in severity based on the nature of the non-compliance.

For non-compliance with prohibited AI practices, fines can reach up to EUR 35 million or 7% of the total worldwide annual turnover, whichever is higher.

This includes practices like manipulative AI systems, exploiting vulnerabilities, social scoring by public authorities, and unauthorized biometric identification in public spaces.

Breaches of high-risk AI system requirements can incur fines up to EUR 15 million or 3% of the total worldwide annual turnover.

These requirements include risk management, data governance, technical documentation, transparency, and cybersecurity. Other non-compliance issues, such as providing incorrect or misleading information, can result in fines up to EUR 7.5 million or 1% of the total worldwide annual turnover. This applies to breaches not covered by the highest or significant sanctions.

Enforcement / fines in Luxembourg

The Luxembourg Bill currently being discussed, if adopted in its current wording, will grant Luxembourg market surveillance authorities the power to impose the administrative fines for non-compliance provided for in the EU AI Act.

According to the Luxembourg Bill, decisions from the competent authorities can be appealed to the Administrative Court.

Last modified 23 July 2025

The EU AI Act enforces compliance through a structured framework of fines and sanctions, varying in severity based on the nature of the non-compliance.

For non-compliance with prohibited AI practices, fines can reach up to EUR 35 million or 7% of the total worldwide annual turnover, whichever is higher.

This includes practices like manipulative AI systems, exploiting vulnerabilities, social scoring by public authorities, and unauthorized biometric identification in public spaces.

Breaches of high-risk AI system requirements can incur fines up to EUR 15 million or 3% of the total worldwide annual turnover.

These requirements include risk management, data governance, technical documentation, transparency, and cybersecurity. Other non-compliance issues, such as providing incorrect or misleading information, can result in fines up to EUR 7.5 million or 1% of the total worldwide annual turnover. This applies to breaches not covered by the highest or significant sanctions.

Enforcement / fines in Malta

Malta has supplemented the enforcement framework established under Chapter XII of the EU AI Act through Subsidiary Legislation 591.05 and Subsidiary Legislation 586.14.

Under Subsidiary Legislation 591.05, the MDIA is empowered to institute enforcement proceedings in relation to infringements of the EU AI Act and the Artificial Intelligence Regulations (Subsidiary Legislation 591.05). Without prejudice to the penalties established under the EU AI Act itself, the MDIA may impose administrative penalties of up to EUR 350,000 per infringement or, where the infringer is an undertaking, up to 1% of its total worldwide annual turnover for the preceding financial year, whichever is higher. The MDIA may also impose daily penalties of up to EUR 12,000 for continuing infringements, issue warnings and reprimands, require remedial measures to be taken, and adopt other non-monetary enforcement measures. Proceedings must generally be initiated by the MDIA within two years from the date on which the alleged infringement was committed.

For AI systems falling within the competence of the IDPC under Subsidiary Legislation 586.14, the IDPC is empowered to take enforcement action in respect of infringements of the EU AI Act and Subsidiary Legislation 586.14. Such powers include the imposition of administrative penalties, warnings and other corrective measures, as well as requiring operators to cease infringing conduct and implement remedial actions. Decisions of the IDPC may be appealed to the Information and Data Protection Appeals Tribunal.

Both Subsidiary Legislation 591.05 and Subsidiary Legislation 586.14 provide that, when determining whether to impose an administrative penalty and its amount, regard must be had to factors such as the nature, gravity and duration of the infringement, the number of affected persons, the degree of cooperation with the competent authority, the operator's level of responsibility, any previous penalties imposed, and whether the infringement was intentional or negligent. Public authorities and bodies may also be subject to administrative penalties of up to EUR 50,000 per infringement and daily penalties of up to EUR 50 for continuing infringements.

Last modified 24 July 2025

Laws specifically addressing AI have not been introduced in Mauritius yet.

Last modified 6 July 2026

Laws specifically addressing AI have not been introduced in Mexico yet. Article 24 of the AI Bill specifies sanctions for infringement including potential fines of up to 5% of annual income (Article 24(ii)).

Last modified 4 July 2026

Laws specifically addressing AI have not been introduced in Morocco yet, so there are no AI-specific enforcement regimes or fines.

Last modified 24 June 2026

The EU AI Act enforces compliance through a structured framework of fines and sanctions, varying in severity based on the nature of the non-compliance.

For non-compliance with prohibited AI practices, fines can reach up to EUR 35 million or 7% of the total worldwide annual turnover, whichever is higher.

This includes practices like manipulative AI systems, exploiting vulnerabilities, social scoring by public authorities, and unauthorized biometric identification in public spaces.

Breaches of high-risk AI system requirements can incur fines up to EUR 15 million or 3% of the total worldwide annual turnover.

These requirements include risk management, data governance, technical documentation, transparency, and cybersecurity. Other non-compliance issues, such as providing incorrect or misleading information, can result in fines up to EUR 7.5 million or 1% of the total worldwide annual turnover. This applies to breaches not covered by the highest or significant sanctions.

Last modified 23 July 2025

Laws specifically addressing AI have not been introduced in New Zealand yet, so there are no AI-specific enforcement regimes or fines. However, enforcement and fines under existing legislation could be applied in the AI context. Under the Privacy Act, the Privacy Commissioner may issue compliance notices and issue fines up to NZD 10,000 for certain breaches (for example, for a failure to notify a notifiable privacy breach to the Privacy Commissioner) and refer matters to the Human Rights Review Tribunal. The Biometrics Code is enforceable under the Privacy Act’s complaints and compliance mechanisms. The Human Rights Act 1993 provides for complaints to the Human Rights Commission and proceedings before the Human Rights Review Tribunal, and the Tribunal can award damages for privacy breaches. The Fair Trading Act 1986 and Commerce Act 1986 provide for pecuniary penalties, injunctions, and compensation orders. The FMA has enforcement powers under the Financial Markets Conduct Act 2013. The Harmful Digital Communications Act 2015 creates criminal offences with penalties including imprisonment of up to two years and fines of up to NZD 50,000 for individuals or NZD 200,000 for bodies corporate.

Last modified 8 July 2026

A standalone AI law has not yet been enacted in Nigeria, so there are no AI-specific enforcement provisions or fines. Nigerian regulators may exercise enforcement powers in respect of non-compliance by persons and organisations within their regulatory sphere of influence on matters relating to AI and emerging technologies.

Last modified 2 July 2026

In the Norwegian proposal for the Norway AI Act, breaches of the EU AI Act can be sanctioned with coercive fines. This proposal is based on Article 99(1) of the EU AI Act, which allows for the possibility of laying down rules on alternative sanctions that are not directly specified in the Act.

There was a 2 August 2025 deadline for EU Member States to lay down rules for penalties and fines, notify them to the Commission, and ensure that they are properly implemented (Recital 179 and Article 99 of the EU AI Act). This deadline has not been met in Norway. Rules on enforcement measures and coercive fines have been proposed as part of the Norway AI Act, and compliance with Article 99 is expected following implementation of the Act.

Last modified 5 August 2026

To date, the AI Law and AI Regulation do not establish a specific sanctions regime for non-compliance with their provisions on artificial intelligence. However, the use of AI systems in a manner that infringes other applicable legal frameworks (for example, regarding personal data protection, consumer protection, non-discrimination, digital security, among others) may give rise to sanctions imposed by the relevant competent authorities, as well as potential civil or administrative liability.  

Last modified 23 June 2026

The EU AI Act enforces compliance through a structured framework of fines and sanctions, varying in severity based on the nature of the non-compliance.

For non-compliance with prohibited AI practices, fines can reach up to EUR 35 million or 7% of the total worldwide annual turnover, whichever is higher.

This includes practices like manipulative AI systems, exploiting vulnerabilities, social scoring by public authorities, and unauthorized biometric identification in public spaces.

Breaches of high-risk AI system requirements can incur fines up to EUR 15 million or 3% of the total worldwide annual turnover.

These requirements include risk management, data governance, technical documentation, transparency, and cybersecurity. Other non-compliance issues, such as providing incorrect or misleading information, can result in fines up to EUR 7.5 million or 1% of the total worldwide annual turnover. This applies to breaches not covered by the highest or significant sanctions.

Last modified 23 July 2025

The EU AI Act enforces compliance through a structured framework of fines and sanctions, varying in severity based on the nature of the non-compliance.

For non-compliance with prohibited AI practices, fines can reach up to EUR 35 million or 7% of the total worldwide annual turnover, whichever is higher.

This includes practices like manipulative AI systems, exploiting vulnerabilities, social scoring by public authorities, and unauthorized biometric identification in public spaces.

Breaches of high-risk AI system requirements can incur fines up to EUR 15 million or 3% of the total worldwide annual turnover.

These requirements include risk management, data governance, technical documentation, transparency, and cybersecurity. Other non-compliance issues, such as providing incorrect or misleading information, can result in fines up to EUR 7.5 million or 1% of the total worldwide annual turnover. This applies to breaches not covered by the highest or significant sanctions.

Last modified 21 July 2026

The EU AI Act enforces compliance through a structured framework of fines and sanctions, varying in severity based on the nature of the non-compliance.

For non-compliance with prohibited AI practices, fines can reach up to EUR 35 million or 7% of the total worldwide annual turnover, whichever is higher.

This includes practices like manipulative AI systems, exploiting vulnerabilities, social scoring by public authorities, and unauthorized biometric identification in public spaces.

Breaches of high-risk AI system requirements can incur fines up to EUR 15 million or 3% of the total worldwide annual turnover.

These requirements include risk management, data governance, technical documentation, transparency, and cybersecurity. Other non-compliance issues, such as providing incorrect or misleading information, can result in fines up to EUR 7.5 million or 1% of the total worldwide annual turnover. This applies to breaches not covered by the highest or significant sanctions.

Last modified 25 July 2025

Enforcement is primarily through general legislation:

PDPL Penalties:

  • Criminal penalties: imprisonment of up to two years and/or fines of up to SAR 3,000,000 for unlawful disclosure of sensitive data.
  • Administrative penalties: warnings or fines of up to SAR 5,000,000, which may be doubled for repeat violations.

Public‑sector information rules also impose administrative consequences for breach.

Last modified 19 June 2026

Laws specifically addressing AI have not yet been introduced in Singapore. 

Failure to comply with Singapore's personal data protection or IP laws when developing or using AI will be subject to sanctions and/or private legal actions under those laws.

Compliance with industry-specific AI guidelines (e.g. in the financial services sector) may be supervised and enforced in the usual way by the relevant industry regulators.

Last modified 4 August 2026

The EU AI Act enforces compliance through a structured framework of fines and sanctions, varying in severity based on the nature of the non-compliance.

For non-compliance with prohibited AI practices, fines can reach up to EUR 35 million or 7% of the total worldwide annual turnover, whichever is higher.

This includes practices like manipulative AI systems, exploiting vulnerabilities, social scoring by public authorities, and unauthorized biometric identification in public spaces.

Breaches of high-risk AI system requirements can incur fines up to EUR 15 million or 3% of the total worldwide annual turnover.

These requirements include risk management, data governance, technical documentation, transparency, and cybersecurity. Other non-compliance issues, such as providing incorrect or misleading information, can result in fines up to EUR 7.5 million or 1% of the total worldwide annual turnover. This applies to breaches not covered by the highest or significant sanctions.

Enforcement / fines in the Slovak Republic

The draft law establishes a comprehensive enforcement regime aligned with the EU AI Act. Supervisory authorities may conduct inspections, request documents and explanations, perform test purchases, access information systems and logs, and issue corrective measures aimed at remedying violations.

The Slovak draft law enforces compliance through warnings and fines varying in severity based on the nature of the non-compliance. The relevant authority can impose fines up to EUR 10 million or 4% of total worldwide annual turnover, whichever is higher.

It seems that Slovakia has failed to comply with the statutory deadline set forth under the EU AI Act to lay down rules on penalties and administrative fines, notify the European Commission thereof, and ensure their effective implementation.

Last modified 27 July 2026

The EU AI Act enforces compliance through a structured framework of fines and sanctions, varying in severity based on the nature of the non-compliance.

For non-compliance with prohibited AI practices, fines can reach up to EUR 35 million or 7% of the total worldwide annual turnover, whichever is higher.

This includes practices like manipulative AI systems, exploiting vulnerabilities, social scoring by public authorities, and unauthorized biometric identification in public spaces.

Breaches of high-risk AI system requirements can incur fines up to EUR 15 million or 3% of the total worldwide annual turnover.

These requirements include risk management, data governance, technical documentation, transparency, and cybersecurity. Other non-compliance issues, such as providing incorrect or misleading information, can result in fines up to EUR 7.5 million or 1% of the total worldwide annual turnover. This applies to breaches not covered by the highest or significant sanctions.

Slovenia did not meet the 2 August 2025 deadline under Article 99 of the EU AI Act. Although draft implementing legislation containing provisions on reporting penalties was published before the deadline, the legislation had not yet been enacted or implemented. The SLO AI Act, which contains provisions regarding the reporting of penalties, came into force on 21 November 2025.

The enforcement entities in Slovenia are all supervising authorities:

  • the Agency for Communication Networks and Services of the Republic of Slovenia (Agencija za komunikacijska omrežja in storitve Republike Slovenije);
  • the Information Commissioner (Informacijski pooblaščenec);
  • the Bank of Slovenia (Banka Slovenije);
  • the Insurance Supervisory Agency (Agencija za zavarovalni nadzor); and
  • the Market Inspectorate of the Republic of Slovenia (Tržni inšpektorat Republike Slovenije).
Last modified 20 July 2026

Laws specifically addressing AI have not been introduced in South Africa, so there are no AI-specific enforcement regimes or fines.

Last modified 5 August 2026

The AI Act provides authority to the Minister of MSIT to initiate investigations in cases where (i) MSIT learns of any actual or potential violation of the following obligations under the AI Act, or (ii) MSIT receives a report or civil complaint of such a violation: (i) obligation to label content created using generative AIs (Article 31, Paragraph (2)); (ii) obligation to provide notice to viewers or to label ‘deepfakes’ (Article 31, Paragraph (3)); (iii) obligation to secure safety of high-performance AIs and/or duty to report on measures taken by the AI business operators to secure such safety of high-performance AIs (Articles 32, Paragraphs (1) and (2)); and (iv) obligation to secure safety and reliability for high-impact AIs (Article 34, Paragraph (1)). Upon finding of any violation listed above, the Minister of MSIT may issue an order to suspend or correct the action in violation against the violator (Article 40, Paragraph (3)).

Furthermore, administrative fines may be imposed for the following: (i) failure to appoint a domestic agent may result in an administrative fine of up to KRW 30 million (Article 43, Paragraph (1), Item 2); (ii) failure to comply with the advance notification obligation for the high-impact AI or generative AI may result in an administrative fine of up to KRW 30 million (Article 43, Paragraph (1), Item 1); and (iii) failure to comply with the corrective orders may result in administrative fines of up to KRW 30 million (Article 43, Paragraph (1), Item 3).

Last modified 5 August 2026

The EU AI Act enforces compliance through a structured framework of fines and sanctions, varying in severity based on the nature of the non-compliance.

For non-compliance with prohibited AI practices, fines can reach up to EUR 35 million or 7% of the total worldwide annual turnover, whichever is higher.

This includes practices like manipulative AI systems, exploiting vulnerabilities, social scoring by public authorities, and unauthorized biometric identification in public spaces.

Breaches of high-risk AI system requirements can incur fines up to EUR 15 million or 3% of the total worldwide annual turnover.

These requirements include risk management, data governance, technical documentation, transparency, and cybersecurity. Other non-compliance issues, such as providing incorrect or misleading information, can result in fines up to EUR 7.5 million or 1% of the total worldwide annual turnover. This applies to breaches not covered by the highest or significant sanctions.

Enforcement / fines in Spain

The Spanish Draft AI Bill sets out a graduated sanctions regime based on the severity of the infringement and the nature of the AI system involved:

  • Very serious infringements involving prohibited activities under the EU AI Act are punishable by fines up to EUR 35,000,000, or alternatively, up to 7% of the offender’s total worldwide annual turnover from the previous financial year, if this amount were higher.
  • Very serious infringements involving high-risk AI systems may result in fines up to EUR 15,000,000, or up to 3% of the global annual turnover, if this amount were higher.
  • Serious infringements are subject to penalties up to EUR 7,500,000, or up to 1% of global annual turnover, if this amount were higher.
  • Minor infringements are punishable by fines up to EUR 500,000, or up to 0.5% of global annual turnover, if this amount were higher.

Before launching a formal sanctioning procedure, authorities may open a preliminary investigation phase to assess responsibility. During this period, market surveillance authorities may request information from those involved. For minor infringements, authorities may require the adoption of corrective measures and, where these are implemented within the prescribed period and responsibility is acknowledged, conclude the case with a formal warning instead of continuing the sanctioning procedure.

Once formal sanctioning proceedings begin, the procedure will be conducted in accordance with the applicable administrative procedural rules.

Public sector entities are exempt from monetary penalties under Article 99.8 of the EU AI Regulation. However, in such cases, a formal reprimand will be issued, and, where appropriate, corrective measures may be imposed to cease the infringement or remedy its effects.

In addition to any financial sanctions, the competent authority may impose ancillary measures, including the withdrawal of the AI system, its disconnection, prohibition, restriction of commercialisation or other corrective measures considered necessary.

Last modified 22 July 2026

The EU AI Act enforces compliance through a structured framework of fines and sanctions, varying in severity based on the nature of the non-compliance.

For non-compliance with prohibited AI practices, fines can reach up to EUR 35 million or 7% of the total worldwide annual turnover, whichever is higher.

This includes practices like manipulative AI systems, exploiting vulnerabilities, social scoring by public authorities, and unauthorized biometric identification in public spaces.

Breaches of high-risk AI system requirements can incur fines up to EUR 15 million or 3% of the total worldwide annual turnover.

These requirements include risk management, data governance, technical documentation, transparency, and cybersecurity. Other non-compliance issues, such as providing incorrect or misleading information, can result in fines up to EUR 7.5 million or 1% of the total worldwide annual turnover. This applies to breaches not covered by the highest or significant sanctions.

Enforcement / fines in Sweden

While Sweden has appointed competent authorities under the AI Act, the implementing law has not yet been passed or proposed, and no rules for penalties and fines have been communicated. Accordingly, Sweden has not met the deadline for Member States to lay down rules on penalties and fines, notify them to the Commission, and ensure their implementation under Article 99.

Last modified 30 July 2026

At present, the Draft AI Law Principles (2025) preliminarily indicates that no criminal penalties are currently prescribed.

Last modified 4 July 2026

Laws specifically addressing AI have not been enacted in Türkiye yet; therefore, there is currently no enforcement or fines specific to use of AI.

Last modified 3 July 2026

There is no unified federal law or emirate level law in the UAE that has a primary focus on regulating AI (and therefore no published fines).

The Commissioner for Data Protection in the DIFC has the power to issue a general fine for not complying with the DIFC’s Data Protection Regulations in an amount the Commissioner considers to be appropriate and proportionate, taking into account the seriousness of the contravention and the risk of actual harm to any data subject.

Last modified 4 August 2025

In the UK, AI is primarily governed through the existing powers of regulators such as the Competition and Markets Authority (CMA) and ICO, alongside sector-specific regulators including the FCA and Ofcom.

In addition, the Digital Regulation Cooperation Forum (DRCF) was established to facilitate coordination between these regulators on cross-sector digital risks and has launched an AI and Digital Hub to support businesses developing and deploying innovative technologies.

The ICO, CMA, FCA and Ofcom have all become more active in addressing AI-related risks. The ICO has moved into active enforcement, including investigations into the use of personal data in AI systems and enforcement action relating to children’s data, while the CMA has focused on the consumer law implications of agentic AI and emphasised business accountability for AI agents (particularly consumer protection around misleading outputs, unfair commercial practices and accountability for automated customer journeys). The FCA has highlighted the transformative impact of AI on financial services and the growing risks of AI-enabled fraud (and has mentioned it will rely on existing frameworks such as Consumer Duty and Senior Managers and Certification Regime (SM&CR)), and Ofcom has used its powers under the Online Safety Act 2023 to investigate AI-generated harms and age-assurance failures. Across regulators, common priorities include transparency, accountability and governance in AI systems, protection of children and vulnerable users, and increased cross-regulator coordination through the DRCF.

Last modified 30 July 2026

Federal and state agencies can vary widely in how they enforce AI-related laws – not only because the laws themselves differ, but also due to the distinct enforcement powers that each agency holds.

For example, the DOJ and SEC jointly charged the founder of an AI startup with securities and wire fraud involving false claims about AI capabilities. Each agency sought several forms of relief, with the DOJ seeking a prison sentence and the SEC seeking civil fines.

The FTC’s cases involving deceptive marketing of AI tools have resulted in injunctions and sometimes monetary payments.

At the state level, enforcement is similarly fragmented, with available relief dependent on the agencies and laws involved. For example, Texas and Utah have enacted AI-specific laws that include statutory penalties:

  • Texas’s TRAIGA, which the Texas Attorney General enforces exclusively (with no private right of action) following a 60-day notice-and-cure period, and which authorizes civil penalties of USD 10,000 to 12,000 for curable violations, USD 80,000 to 200,000 for uncurable violations, and USD 2,000 to 40,000 per day for ongoing violations, in addition to injunctive relief, attorneys’ fees, and investigative costs
Last modified 29 July 2026

Continue reading

  • no results

Previous topic
Back to top