← All lessons
Level 5 · Optimized7 min read

Preparing for enforcement, investigations and appeals

Mature programmes assume a regulator, a plaintiff or a journalist will one day ask hard questions. Preparing for that day is cheaper than improvising on it, and the record you built in earlier lessons is most of the preparation.

Who can come knocking

  • EU: national market surveillance authorities for the AI Act, data-protection authorities for the GDPR, and the Commission's AI Office for general-purpose models. Fines under Article 99 scale to 7 percent of turnover for prohibited practices, 3 percent for most other breaches and 1 percent for supplying incorrect information.
  • US federal: the FTC (unfair or deceptive practices; Rite Aid, DoNotPay), the EEOC (employment discrimination; iTutorGroup), the CFPB and banking regulators for credit, and private plaintiffs (Mobley v. Workday).
  • US states: attorneys general enforce Texas TRAIGA (exclusively) and Colorado SB 26-189; New York City's DCWP enforces Local Law 144; Illinois adds Human Rights Act complaints. Executive Order 14365 created a Department of Justice task force to challenge state laws, which may change this landscape, but it does not pause enforcement in the meantime.
  • Canada: the federal Privacy Commissioner (investigations and, if Bill C-36 passes, orders and penalties), Quebec's Commission d'accès à l'information (which can already fine under Law 25), provincial employment-standards officers for Ontario's posting rules, and human-rights tribunals.

Use cure periods

Several laws give you a chance to fix things before penalties bite. Texas TRAIGA requires the Attorney General to give written notice and a 60-day cure period; a documented cure bars the action. NYC and Colorado practice similarly favours organisations that can show prompt correction. That is only usable if you can find the problem, fix it and prove it quickly, which is what your incident process and record files are for.

When a letter arrives

  • Do not delete anything. Preservation obligations start immediately.
  • Route it to the AI compliance owner and counsel the same day.
  • Assemble the record file for the system in question: inventory entry, classification reasoning, tests, oversight log, notices, vendor documents, incidents.
  • Answer accurately and on time. Supplying wrong information is itself an offence under the EU AI Act (Article 99) and undermines every other defence.
  • Notify your vendor (the contract clause from Level 3), your insurer, and if warranted affected people.
  • Fix in parallel. Regulators weigh remediation heavily.

Appeals happen, and they are not the plan

In December 2024 Italy's data-protection authority fined OpenAI EUR 15 million over ChatGPT's training and transparency. In March 2026 the Court of Rome annulled the decision entirely, on grounds about the authority's procedure and jurisdiction rather than the substance. Two lessons: first, regulators' decisions can be contested and sometimes are wrong; second, OpenAI spent fifteen months and considerable resources to get there. For most organisations the better path is a record that makes the first decision favourable.

Litigation readiness

Private lawsuits turn on discovery. Assume your testing results, override logs and internal messages will be read by opposing counsel. That is an argument for doing the testing (absence looks worse) and for writing internal notes as if a judge will read them: factual, dated, and showing the decision taken.

Insurance and disclosure

Check whether your cyber or professional-liability cover excludes AI-related claims; many policies added exclusions in 2025 and 2026. Public companies and regulated firms should also check what their securities or sector regulators expect them to disclose about AI risk.

What this means for you

Write a half-page 'if a regulator writes' procedure naming who receives it, who assembles the record file, and the rule not to delete anything. Check your insurance for AI exclusions this quarter. If you operate in Texas, make sure your incident process can produce a certified cure inside 60 days.

Real case

Fine2024 · EU

Italian Garante v. OpenAI — EUR 15 million ChatGPT fine (later annulled on appeal)

OpenAI appealed, calling the fine disproportionate. The Rome Tribunal suspended the fine in March 2025 and then, in judgment no. 4153/2026 filed 18 March 2026, annulled it, reported as finding that once OpenAI had an Irish establishment the GDPR 'one-stop-shop' made Ireland's DPC the lead authority, so the Garante lacked competence. The substantive findings were not endorsed; the corrective orders and campaign had already been carried out.

Read the case →

Related laws

Quick check · 3 questions

  1. 1.What does Texas TRAIGA require before the Attorney General can bring an action?

  2. 2.What happened to the Italian regulator's EUR 15 million fine against OpenAI?

  3. 3.What is the first rule when an enforcement letter arrives?

0 of 3 answered

Sources

Last reviewed Sep 25, 2026.

Educational information, not legal advice. Laws change and details depend on your situation — check the linked sources and talk to a qualified lawyer before acting. Last content review: 2026-09-25.

Spotted an error? Ask the tutor or email hello@myaiguide.pro.