In The News — AI Governance Enforcement

Where AI governance is actually getting enforced — and what it's costing companies.

For a company the size of Meta, a $1.4 billion settlement is a rounding error. For a startup like Clearview AI, the same category of violation meant handing over nearly a quarter of the company just to survive the lawsuit. That gap is what governance is for — and the cases below are some of the major ones.

$1.57B
Aggregate Fines & Settlements, Last 2 Yrs
10
Major, Publicly Confirmed Cases
24
U.S. State Privacy Laws Now In Force
6+
New State AI/Privacy Laws Already Set For 2027

Fine/settlement total reflects face value, not necessarily cash collected — see methodology below. State law counts cover comprehensive U.S. privacy statutes only, on top of a parallel and accelerating body of AI-specific state law and the EU AI Act — see below.

Compiled July 2026 · covering the past 2 years · figures and dates verified against regulator filings and legal-press reporting

[ The Bigger Picture ]

This is just the beginning.

Ten cases is not the whole story — it's the visible tip of it. In 2025 alone, U.S. state legislatures enacted 145 separate AI-related bills, and 47 states introduced at least one. Four new comprehensive state privacy laws have already been signed in 2026, bringing the U.S. total in force to 24. Colorado's AI law, Texas's TRAIGA, and California's frontier-model transparency act all became enforceable this year, and the EU AI Act's high-risk obligations land in August 2026. At least six more state AI and privacy laws — including Colorado's revised automated-decision-making framework and California's automated decision-making rules — are already scheduled to take effect in 2027.

The regulatory floor is still being poured. A company operating without a documented AI governance framework isn't behind a settled body of law — it's behind a moving one, with the exposure compounding every legislative session.

Sources: Byte Back, "U.S. State Privacy Law Landscape Expands to 24 States," June 2026 · AI Laws by State, Quarterly Legislation Tracker · Baker Botts, "U.S. AI Law Update," Jan. 2026

[ Major Enforcement Actions — Last 2 Years ]

When it lands, it can hit hard.

United States — Texas AG

$1.4B

paid over 5 years — largest privacy settlement by a single state, ever

July 30, 2024

Meta Platforms, Inc.

Texas secured the largest biometric-privacy settlement on record after alleging Meta's "Tag Suggestions" facial-recognition feature captured the facial geometry of millions of Texans without the consent required under the state's Capture or Use of Biometric Identifier Act — the first case ever brought, and settled, under that law.

Source: Office of the Texas Attorney General, press release, July 30, 2024

United States — Illinois BIPA MDL

$51.75M

equity-based settlement — 23% of the company, because it lacked the cash

March 20, 2025 (final approval)

Clearview AI, Inc.

A federal court gave final approval to a nationwide class settlement over Clearview's scraping of billions of facial images without consent, in violation of Illinois' Biometric Information Privacy Act and related state laws. Lacking the cash for a traditional payout, Clearview settled by giving the class a 23% equity stake, valued at the time at roughly $51.75 million — a settlement structure that only exists because the alternative risked the company outright.

Source: The Record by Recorded Future News, "Clearview AI settles class-action privacy lawsuit," March 2025

United States — FTC

$48.6M

judgment largely suspended — most defendants unable to pay in full

January 27, 2026

Growth Cave, LLC

The FTC secured a judgment against Growth Cave and its co-CEOs for misrepresenting that its "AI software," GrowthBox, would automate nearly 100% of the work of running an online business — when, per the FTC's complaint, the tool actually required users to manually upload ads, set appointments, and send messages themselves.

Source: Federal Trade Commission, case timeline, Jan. 27, 2026

Netherlands — Dutch DPA

€30.5M

≈ $33.5M USD; plus up to €5.1M in non-compliance penalties

September 3, 2024

Clearview AI, Inc.

The Dutch data protection authority fined Clearview over its facial-recognition database of more than 30 billion images, finding the company had no valid legal basis under the GDPR to process biometric data and failed to honor individuals' access requests. The regulator separately warned that using Clearview's services is itself unlawful in the EU.

Source: Autoriteit Persoonsgegevens (Dutch DPA), official decision notice

United States — FTC

$18M

judgment largely suspended — $50K actually collected

March 2026

Air AI

The FTC settled with AI startup Air AI and its owners over deceptive marketing that promised entrepreneurs guaranteed income and business growth through an "AI-powered" product. Operators are banned for life from marketing or selling business opportunities.

Source: CFO Dive, "FTC settles with AI startup accused of bilking customers," March 2026

United States — FCC

$6M

forfeiture order

September 26, 2024

Steve Kramer

The FCC fined political consultant Steve Kramer for orchestrating a robocall campaign that used an AI voice-cloning tool to impersonate President Biden, telling New Hampshire primary voters not to vote. It was the agency's first enforcement action targeting generative-AI voter suppression.

Source: CyberScoop, "FCC hits operative behind New Hampshire robocall with $6 million fine," Sept. 2024

South Korea — PIPC

₩8.37B

≈ $5.7M USD combined

January 2025

Kakao Pay & Apple Distribution International

South Korea's privacy regulator fined Kakao Pay (₩5.968B) and Apple Distribution International (₩2.45B) after finding Kakao Pay transferred the data of roughly 40 million users to Alipay without proper consent — data Alipay then used to build an automated creditworthiness-scoring model tied to Apple Pay.

Source: IAPP, "South Korea's PIPC Flexes Its Muscles," June 2025

Italy — Garante

€5M

≈ $5.6M USD

May 19, 2025

Luka Inc. ("Replika")

Italy's data protection authority fined the maker of the Replika AI companion chatbot for processing user data without a valid legal basis, maintaining an unclear privacy policy, and failing to verify users' ages — leaving the door open for minors to access a chatbot capable of romantic and therapist-style roleplay. Garante also opened a separate inquiry into how the underlying model was trained.

Source: Buchanan Ingersoll & Rooney, "Emotional AI Company Fined for Privacy Violations," May 2025

United States — FCC

$1M

civil penalty (consent decree)

August 21, 2024

Lingo Telecom, LLC

The FCC settled with the voice service provider that transmitted the AI-generated deepfake Biden robocalls to New Hampshire voters, for failing to properly verify caller identity under the agency's STIR/SHAKEN authentication rules before carrying the spoofed, AI-voiced traffic.

Source: Telecompetitor, "FCC Settles Robocall Case for $1M," Aug. 2024

United States — FTC

$193K

consumer redress

February 2025 (final order)

DoNotPay, Inc.

The FTC settled charges that DoNotPay marketed its product as "the world's first robot lawyer," claiming its AI could substitute for a licensed attorney on legal documents and small-claims matters, without ever substantiating that the technology performed to that standard.

Source: AI Policy Desk, "FTC AI Enforcement Actions 2026: Real Cases," case record

[ Also Under Scrutiny — No Public Fine (Yet) ]

Enforcement without a price tag — for now.

Corrective order, no disclosed fine

China — CapCut/Jianying, Maoxiang, Dreamina ("Jimeng AI")

The Cyberspace Administration of China found these platforms failed to properly label AI-generated content under the country's new labeling rules (effective Sept. 1, 2025), ordering regulatory interviews, corrective action, and formal warnings. (April 2026)

Source: TechNode, "China penalizes AI platforms over failure to label AI-generated content," April 2026

Determination, no civil penalty

Australia — Kmart Australia Limited & Bunnings Group

The Office of the Australian Information Commissioner found both retailers' in-store facial-recognition systems breached the Privacy Act by scanning and matching customers' faces without consent. Both were ordered to apologize publicly and cease the practice — Australia's regulator cannot impose a direct civil penalty through this process. (Bunnings: Nov. 2024; Kmart: Sept. 2025)

Source: Bird & Bird, "OAIC Determines Kmart Breached the Privacy Act," Sept. 2025

European Union — AI Act phased rollout

European Union — AI Act Enforcement

The EU AI Act is enforceable in stages, not all at once. Bans on prohibited practices — social scoring, manipulative AI — became legally enforceable Feb. 2, 2025, carrying penalties up to €35M or 7% of global turnover; obligations for general-purpose AI models followed Aug. 2, 2025. The larger wave lands next: The remainder of the AI Act (except Article 6(1))starts to apply on Aug. 2, 2026 — weeks from this writing.

Source: "EU AI Act Implementation Timeline"

[ What This Means For You ]

Bias. Drift. Missing consent. Flat-out misrepresentation. It all can get fined.

Some of these were models that drifted, hallucinated, or showed bias nobody caught. Others were plain old deception — claims about what the AI could do that were never true. The failures vary, but nearly every one was preventable with governance work done early. An AI Governance Discovery engagement is built to find those gaps before a regulator does.

Methodology: enforcement entries are limited to actions with a publicly confirmed dollar or local-currency figure, sourced from regulator press releases, court filings, or established legal-press reporting, and cross-checked across at least two sources. Currency conversions are approximate as of the reporting date and will shift with exchange rates. The $1.57B aggregate figure sums the face-value fine, judgment, or settlement amount for each of the 10 confirmed cases — it is a "reported total," not a "cash collected" total: the FTC's $48.6M Growth Cave and $18M Air AI judgments are both largely suspended due to the defendants' inability to pay, and the Clearview Illinois settlement was paid in equity rather than cash. Several entries above (e.g., the Meta and Clearview settlements) stem from biometric-privacy statutes rather than AI-specific statutes, since most AI-specific enforcement regimes — including the EU AI Act's fine provisions — are still in early stages; they're included because the underlying conduct involved an AI or algorithmic system. The state privacy and AI law counts above reflect U.S. comprehensive statutes tracked as of July 2026 and are sourced separately, as cited in "The Bigger Picture" section. This page reflects the public record as of July 2026 and will be revisited periodically as new enforcement actions and new laws are announced; it is provided for general informational purposes and is not legal advice about any pending matter.

Baker Law PLLC

202 N Cedar Ave Ste #1
Owatonna, MN 55060