Guide · Enforcement & exposure

Hiding your AI system isn’t hiding the risk.

A sceptical manager’s objection deserves a direct answer: is any of this actually enforced? It is. Set the EU AI Act aside for a moment — no penalty has yet been reported under it — and the EU has already imposed billions of euros in penalties on AI, algorithmic and data-driven systems, under the GDPR, competition law, the Digital Services Act, the Digital Markets Act and the ePrivacy rules. Concealing a system inside your organisation does not remove that risk. It changes only when the risk surfaces, and how hard it lands.

Answer first

No one has yet been fined under the AI Act. That is not a reason to relax.

Two facts sit side by side. First, enforcement is already happening. Setting the AI Act aside, the EU has already imposed billions of euros in penalties on AI, algorithmic and data-driven systems. The AI Act has not issued its first penalty — but it is the most recent instrument in a body of enforcement that has been active for years, not a departure from a quiet past.

Second, concealing a system does not reduce its risk. Where a system sits on the transparency scale — from a radically open, publicly scrutinised platform to a concealed in-house build — changes the shape and the timing of the risk, not whether it exists. Governance is what converts latent, undiscovered risk into managed, defensible risk.

A system you cannot see is not a system without risk. It is a system whose risk you have chosen not to measure.

Part one · the enforcement reality

Set the AI Act aside. The EU already sanctions algorithms.

Begin with the exception. As at 04-08-2026, no penalty had been publicly reported under the EU AI Act — and that is structural, not reassuring. Enforcement has only just begun: the national market surveillance authorities and their penalty powers became applicable on 02-08-2026, and before that date only the Article 5 prohibitions were operative. By March 2026 only 8 of the 27 Member States had designated their competent authority. And the Digital Omnibus on AI — Regulation (EU) 2026/1744, in force since 27-07-2026 — deferred the principal high-risk duties to 02-12-2027 (stand-alone Annex III systems) and 02-08-2028 (Annex I). The ceiling for a prohibited practice is up to 7% of worldwide annual turnover. The silence is a commencement calendar, not a policy of leniency.

Bar lengths are indicative of order of magnitude, not drawn to exact proportion. The AI Act is shown pending because no penalty has yet been reported under it: its penalty powers became applicable only on 02-08-2026, whereas every other regime here has already imposed penalties, and in most cases the courts have upheld them.

Under the GDPR, the reach runs from the largest platforms to the smallest vendors. Clearview AI, which built a facial-recognition database by scraping images from the open web, was fined 30.5 million euros by the Dutch data-protection authority in September 2024 for processing biometric data without a lawful basis; the penalty was not appealed and is now final, and Clearview has drawn further penalties of around 20 million euros each in Italy, Greece and France. The household names sit alongside it: LinkedIn was fined 310 million euros over the lawful basis for its behavioural advertising; TikTok, 345 million euros over children’s default settings, back in September 2023; and Meta, 251 million euros over a 2018 data breach. Each is under appeal, and each fine stands in the meantime.

One case is often cited as a reprieve. It is not one. The Italian regulator fined OpenAI 15 million euros over the lawful basis and transparency of ChatGPT’s training data. A court in Rome annulled that fine in March 2026 — but on a question of jurisdiction under the GDPR one-stop-shop mechanism, not on the merits. The conduct was never cleared, and the Irish authority may still pursue it. An annulment on jurisdiction is not a finding of innocence.

Move to competition law and the figures rise. The European Commission fined Google 2.42 billion euros for using its search results to favour its own shopping service; on 10-09-2024 the Court of Justice, the EU’s highest court, upheld the penalty at final instance. The same law reaches the smallest sellers: two online poster retailers agreed not to undercut one another and enforced the deal with automated repricing software. The UK competition authority penalised the arrangement in 2016 — one seller was fined roughly 160,000 pounds and one of its directors was disqualified for five years. Automating the price did not launder the agreement, a point the case study below turns on. And the two bodies of law now meet: in Meta v Bundeskartellamt (2023), the Court of Justice confirmed that a competition regulator may treat a company’s data practices as a competition question, holding that data is “a significant parameter of competition”.

The newest instruments have already issued their first penalties, and every one concerns algorithmic conduct. The first-ever fine under the Digital Services Act — 120 million euros — was imposed on X over a verification dark pattern and restrictions on researcher access; X has appealed. Temu was fined 200 million euros over the risk of illegal products, a risk amplified by its recommender systems. The first fines under the Digital Markets Act followed the same pattern: in April 2025 the Commission fined Apple 500 million euros for restricting how developers steer users to cheaper options, and Meta 200 million euros over its “consent or pay” advertising model. Apple has appealed the fine; separately, on 08-07-2026 it lost its challenge to being designated a gatekeeper, and remains one.

Finally, the penalties that are not even data-protection law. Advertising cookies dropped without consent fall under the ePrivacy rules, not the GDPR. In December 2020 the French regulator fined Google 100 million euros and Amazon 35 million euros on that basis; France’s supreme administrative court, the Conseil d’État, upheld both. The cookie penalties alone run to hundreds of millions of euros, and the courts have upheld them.

Three conclusions carry Part 1. The first fine under the Digital Services Act and the first under the Digital Markets Act have all been issued, and every one concerns algorithmic conduct. The cookie penalties are not even data-protection law, yet the regulator imposed hundreds of millions of euros under the ePrivacy rules and the courts upheld them. And the AI Act has not yet been enforced — while everything around it already has. For the shape of the Act itself, see the EU AI Act, explained.

Case study · convertible facts

It is not only large platforms.

Consider an illustrative example — a non-dominant, mid-size online retailer, a composite rather than any real company. It builds an in-house dynamic-pricing system and presents it internally as a harmless efficiency tool. Three ordinary business decisions convert that tool into a cartel, with no dominant position, no written contract, and no proof that prices actually rose.

  1. A trade-fair understanding. A manager agrees with a competitor to set both systems never to undercut one another — a concerted practice, and the exact conduct penalised in the poster-sellers case above.
  2. A public signal. The retailer states publicly that it will always match a competitor’s price and never be the first to cut it — unlawful signalling.
  3. A shared feed. It subscribes to a “pricing-intelligence” service that returns the same recommended price to competing subscribers — coordination through software, of the kind the Court of Justice addressed in Eturas.

The exposure is a fine of up to 10% of worldwide turnover, disqualification of the directors involved, and follow-on damages. None of it required market power, and none of it required a signed agreement.

“The AI did it” is never a defence.

Responsibility for an automated decision sits with the organisation that deployed it, not with the software. That is the Ownership discipline — one of the four meta-competencies in the AI-era skills taxonomy: taking full professional responsibility for AI-assisted work.

Part two · the transparency scale

Concealing a system does not reduce its risk. It hides it.

Picture a scale. At one end sits a radically open AI system — live, public, and accessible: to the clients who license it, to the organisations that rely on it, and to the individuals whose data it holds. Any individual may make a data-access request; any client may demand the compliance pack; any regulator or journalist may examine it. That openness invites scrutiny — and the same openness is what makes the system defensible. At the other end sits a concealed in-house build — inexpensive and quick to produce, now that software is nearly free to write — running inside an organisation and invisible to outsiders. No access requests, no client audits, no journalists. It appears safer.

It is not. The risk has not disappeared; it has become latent. Position on the transparency scale changes the risk’s shape and timing, not its existence.

The risk does not fall as a system becomes less visible. It only becomes harder to see — and heavier when it finally surfaces.

AspectAn open, scrutinised systemA concealed, in-house system
When the risk surfaces
OpenEarly, and continuously
ConcealedLate, and often at the least opportune moment
How it surfaces
OpenAccess request, audit, client review
ConcealedWhistleblower, dismissal dispute, leak, inspection
Severity when it lands
OpenCorrectable and survivable
ConcealedConcentrated, and sometimes existential
Evidence available to defend it
OpenBuilt in from the start
ConcealedUsually absent
Governance posture
OpenCompelled by exposure
ConcealedOmitted, on the assumption no outsider is watching

Take the open end first, as an archetype: a live, public, high-risk hiring-intelligence platform, open to the clients who license it and to the individuals in its database. Its exposure is continuous and visible — and precisely for that reason it is built to answer for itself.

The concealed end is where the exposure is greatest. Software is now cheap and fast to build, so a manager can commission an in-house tool — or buy one from a small agency that neither knows nor considers the Act — that quietly does something the law reaches: profiling job applicants, scoring employees to feed automated dismissal decisions, or credit-scoring prospects. Undisclosed to the people being assessed, in a performance-review or dismissal context, that sits at the boundary of high-risk use under Annex III (employment) — or, if it shades into social scoring, of an outright Article 5 prohibition. Precisely because it is concealed, it is the hardest for a regulator to detect — until a dismissed employee’s legal representative, a data-access request, or a leak exposes it. For where the Act draws these lines in the workplace, see AI for HR & talent acquisition and the EU AI Act, explained.

The decisive point

Bad faith is not required.

The central danger is not the manager acting in bad faith. It is the manager who builds the tool without ever asking whether it is permitted. There is no malice — only a good-faith initiative to accelerate a process by profiling or scoring people, taken in a room where no one holds the role of raising the question.

That is the argument for governance. Governance sets the foundations, so that the whole organisation understands what is permissible, what is possible, and what is prohibited outright — and, above all, who decides and who owns the decision — before a prohibited system is deployed by accident.

Governance is permission to build, not an obstacle to it.

This is the practical work of an AI management system, of the controls that answer the AI your staff already use without asking, and of a clear answer to a single question — who owns AI governance.

The resolution

Measured risk, or unmeasured risk.

The choice is not between a risky open system and a safe concealed one. It is between measured risk and unmeasured risk, and governance is how an organisation chooses to measure it. An open system pays its risk in small, survivable instalments — an access request here, an audit there. A concealed system defers the whole liability, and it falls due at once, usually through someone the organisation has wronged. The work is to move from deferred, unmeasured risk to managed, documented risk.

This guide is the evidence behind the wider case that ungoverned capability is not value but exposure — set out in the AI Value Equation, and mapped in full in the risks of AI.

A system you cannot see is not a system without risk. It is a system whose risk you have chosen not to measure.

Which of your systems are measured, and which are merely unseen?

Thirty minutes, an honest read of where your AI risk is latent rather than managed. No pitch.

In creating this guide, Kramer Consulting collaborated with Claude (Opus 4.8, Anthropic) to assist with research, drafting and editing. All AI-assisted and co-created content underwent thorough review and evaluation, and every enforcement fact was verified against primary sources. The final output accurately reflects Kramer Consulting’s understanding, expertise and intended meaning. While AI assistance was instrumental in the process, Kramer Consulting maintains full responsibility for the content, its accuracy and its presentation. This disclosure is made in the spirit of transparency and to acknowledge the role of AI in the creation process. The full account of how this site is made is on our transparency page.