Mature programmes assume a regulator, a plaintiff or a journalist will one day ask hard questions. Preparing for that day is cheaper than improvising on it, and the record you built in earlier lessons is most of the preparation.
Who can come knocking
- EU: national market surveillance authorities for the AI Act, data-protection authorities for the GDPR, and the Commission's AI Office for general-purpose models. Fines under Article 99 scale to 7 percent of turnover for prohibited practices, 3 percent for most other breaches and 1 percent for supplying incorrect information.
- US federal: the FTC (unfair or deceptive practices; Rite Aid, DoNotPay), the EEOC (employment discrimination; iTutorGroup), the CFPB and banking regulators for credit, and private plaintiffs (Mobley v. Workday).
- US states: attorneys general enforce Texas TRAIGA (exclusively) and Colorado SB 26-189; New York City's DCWP enforces Local Law 144; Illinois adds Human Rights Act complaints. Executive Order 14365 created a Department of Justice task force to challenge state laws, which may change this landscape, but it does not pause enforcement in the meantime.
- Canada: the federal Privacy Commissioner (investigations and, if Bill C-36 passes, orders and penalties), Quebec's Commission d'accès à l'information (which can already fine under Law 25), provincial employment-standards officers for Ontario's posting rules, and human-rights tribunals.
Use cure periods
Several laws give you a chance to fix things before penalties bite. Texas TRAIGA requires the Attorney General to give written notice and a 60-day cure period; a documented cure bars the action. NYC and Colorado practice similarly favours organisations that can show prompt correction. That is only usable if you can find the problem, fix it and prove it quickly, which is what your incident process and record files are for.
When a letter arrives
- Do not delete anything. Preservation obligations start immediately.
- Route it to the AI compliance owner and counsel the same day.
- Assemble the record file for the system in question: inventory entry, classification reasoning, tests, oversight log, notices, vendor documents, incidents.
- Answer accurately and on time. Supplying wrong information is itself an offence under the EU AI Act (Article 99) and undermines every other defence.
- Notify your vendor (the contract clause from Level 3), your insurer, and if warranted affected people.
- Fix in parallel. Regulators weigh remediation heavily.
Appeals happen, and they are not the plan
In December 2024 Italy's data-protection authority fined OpenAI EUR 15 million over ChatGPT's training and transparency. In March 2026 the Court of Rome annulled the decision entirely, on grounds about the authority's procedure and jurisdiction rather than the substance. Two lessons: first, regulators' decisions can be contested and sometimes are wrong; second, OpenAI spent fifteen months and considerable resources to get there. For most organisations the better path is a record that makes the first decision favourable.
Litigation readiness
Private lawsuits turn on discovery. Assume your testing results, override logs and internal messages will be read by opposing counsel. That is an argument for doing the testing (absence looks worse) and for writing internal notes as if a judge will read them: factual, dated, and showing the decision taken.
Insurance and disclosure
Check whether your cyber or professional-liability cover excludes AI-related claims; many policies added exclusions in 2025 and 2026. Public companies and regulated firms should also check what their securities or sector regulators expect them to disclose about AI risk.