AI Compliance Academy
⚖️ Real cases
Enforcement that actually happened. Each case: what went wrong, which rule applied, the outcome, and the lesson for a team like yours.
9 of 9 cases
- Ruling2026 · CA-federalMarketing, media & customer-facing AICanadian privacy regulators v. OpenAI — joint findings on ChatGPT training dataComplaint well-founded. The federal OPC treated it as conditionally resolved on the strength of OpenAI's commitments (filtering tools, clearer notices about accuracy and sources, improved access tools, quarterly reporting); the Quebec, BC and Alberta offices found the consent and retention issues unresolved. No fine was imposed — PIPEDA gives the OPC no penalty powers.
- Lawsuit2025 · US-federalHR & hiringMobley v. Workday — collective action over AI hiring screens (ongoing)Ongoing as of September 2026. In July 2024 the court refused to dismiss the case, accepting the agent theory. On 16 May 2025 it conditionally certified a nationwide ADEA collective of applicants aged 40+ rejected via Workday's platform since September 2020; the opt-in notice period closed on 7 March 2026. In June 2026 the court let California FEHA claims and a proxy-discrimination disability claim proceed. No trial date, judgment or settlement has been reported.
- Fine2024 · EUPublic sector & government suppliersClearview AI — EUR 90 million-plus in GDPR fines across EuropeFines totalling more than EUR 95 million across four countries (plus a UK ICO fine on separate grounds). Clearview has no EU establishment and is reported as having neither paid nor changed its practices, which is why the Dutch DPA is pursuing directors and warning customers that using the service is itself unlawful.
- Settlement2024 · US-federalLegal & professional servicesFTC v. DoNotPay — the 'robot lawyer' that was never tested against real lawyersProposed consent order announced 25 September 2024; finalised 11 February 2025 after a 5–0 Commission vote. DoNotPay must pay $193,000 in monetary relief, stop claiming its service performs like a real lawyer without evidence, and notify everyone who subscribed between 2021 and 2023 about the settlement.
- Fine2024 · EUMarketing, media & customer-facing AIItalian Garante v. OpenAI — EUR 15 million ChatGPT fine (later annulled on appeal)OpenAI appealed, calling the fine disproportionate. The Rome Tribunal suspended the fine in March 2025 and then, in judgment no. 4153/2026 filed 18 March 2026, annulled it, reported as finding that once OpenAI had an Irish establishment the GDPR 'one-stop-shop' made Ireland's DPC the lead authority, so the Garante lacked competence. The substantive findings were not endorsed; the corrective orders and campaign had already been carried out.
- Settlement2024 · US-federalFinance, credit & lendingLouis v. SafeRent — $2.275 million settlement over algorithmic tenant scoringSettlement approved by the court on 20 November 2024: SafeRent pays $2.275 million (up to $1.175 million to class members) and, for five years, will not produce a SafeRent Score or accept/deny recommendation for applicants using housing vouchers unless a fair-housing expert validates a new model. The court awarded $1.1 million in attorneys' fees.
- Ruling2024 · CA-BCMarketing, media & customer-facing AIMoffatt v. Air Canada — airline liable for its chatbot's wrong answerDecision 2024 BCCRT 149 (February 2024). Air Canada was ordered to pay C$812.02 in total: C$650.88 in damages (the fare difference) plus pre-judgment interest and tribunal fees. Small money, but the first widely reported ruling that a company answers for what its customer-facing AI says.
- Settlement2023 · US-federalHR & hiringEEOC v. iTutorGroup — hiring software that auto-rejected older applicantsSettlement announced 9 August 2023 (EEOC v. iTutorGroup, Inc., No. 1:22-cv-02565, E.D.N.Y.). iTutorGroup agreed to pay $365,000 to rejected applicants, adopt new anti-discrimination policies and training, stop asking for birth dates, invite previously rejected applicants to re-apply if US hiring resumes, and accept EEOC monitoring for five years. The company did not admit wrongdoing.
- Ban2023 · US-federalMarketing, media & customer-facing AIFTC v. Rite Aid — five-year ban on facial recognition surveillanceSettlement announced 19 December 2023. Rite Aid is banned from using facial recognition for surveillance for five years, must delete the images and any models built from them, must notify consumers before enrolling them in any future biometric system, run a comprehensive security programme with independent assessments for 20 years, and have its CEO certify compliance annually.