CRX | October 13-15, 2026 | Up to 17 CPEs | In-person & virtual options available | Register Now!

Customers
Login
Optro's logo

September 21, 2026 11 min read

AI fines and incidents: What the record shows

In the past 12 months, 40% of organizations reported inaccurate AI outputs and 22% faced legal claims tied to AI use, according to Optro research published in The AI oversight gap. Those consequences arrived while most AI governance programs were still being formalized.

Search for "AI fines" and you’ll find a short list, and that list may be a bit misleading. Almost none of the enforcement actions on the public record so far were brought under a law with "AI" in the name. They arrived through the GDPR, the FTC Act, the Age Discrimination in Employment Act, and ordinary breach-of-contract exposure.

Existing law already reaches AI use, which means your exposure depends less on the AI-specific rulebook than on whether your current controls can defend an AI-driven decision.

Why tracking AI fines loses sight of your real exposure

Most organizations are looking for AI exposure in the wrong place. They scan for AI-specific statutes, find few that apply yet, and conclude the risk is still theoretical. Meanwhile, the conditions that produce incidents are already in place.

Our research in The AI oversight gap found that:

  • 25% of organizations report comprehensive visibility into how employees use AI
  • 35% describe shadow AI as pervasive or widespread, and another 45% describe it as moderate
  • 58% of leaders believe their AI governance controls are keeping pace with adoption, while 18% have active mitigation covering most or all identified risks

The gap between what leaders believe about their controls and what those controls actually cover is where incidents originate. A separate finding from IBM's 2025 Cost of a Data Breach Report points the same direction: 13% of organizations reported breaches of AI models or applications, and 97% of those lacked proper AI access controls.

For the full data set behind these figures, see our breakdown of AI governance statistics for 2026.

AI incidents already on the public record

The cases below are not projections. Each one is documented, and each one traces back to a control that was missing rather than a law that was novel.

A chatbot's invented policy became a binding commitment

An airline’s support chatbot told a customer about a bereavement-fare discount that did not exist. When the customer sought the refund, the airline argued it should not be held to what the bot said. A tribunal disagreed and found the airline liable.

The finding matters beyond the dollar amount. An AI system speaking on your behalf is speaking for you, and the position that the model is a separate entity responsible for its own output did not survive contact with a tribunal.

An AI-assisted audit report failed the standard it was auditing against

A company delivered a government-commissioned report reviewing a welfare-penalty IT system. The report contained a fabricated court quote and citations to academic papers that do not exist, traced to undisclosed use of GPT-4o. The company partially refunded the fee, reported at approximately AU$440,000.

The failure happened inside an assurance engagement. Whatever review process the report passed through, it did not catch fabricated sources before delivery to a government client.

A model with a known error rate stayed in production

A lawsuit alleges that UnitedHealth and its NaviHealth subsidiary used an AI model with a reported error rate near 90% to deny post-acute care claims for elderly patients, and that the model remained in use because so few denials were appealed. The allegations have not been resolved in court.

The pattern in the allegation is the one worth noting: a problem was identified, and nothing in the organization required anyone to act on it.

Where AI fines are actually landing

The enforcement record so far runs through general-purpose law. Regulators have not needed new authority to reach AI use.

Channel

Law actually used

Case

Outcome

Privacy and data protection

GDPR, enforced by Italy's Garante

OpenAI training-data processing

€15 million fine

Consumer protection

FTC Act Section 5, unfair or deceptive practices, under "Operation AI Comply"

DoNotPay, Workado, and an ADA-compliance marketer, each for overstated AI product claims

$193,000 and advertising restrictions; consent order; $1 million, respectively

Employment discrimination

Age Discrimination in Employment Act, enforced by the EEOC

iTutorGroup, whose AI hiring tool automatically rejected older applicants

$365,000 settlement and monitoring

Employment discrimination, ongoing

Employment discrimination law, private collective action

Mobley v. Workday, alleging algorithmic bias in applicant screening

Active litigation; notable because the vendor, not only the employer, is a defendant

None of these actions required a law written specifically for AI. The absence of AI-specific enforcement in your jurisdiction tells you very little about your actual exposure.

AI regulation deadlines have moved to later dates

The compliance calendar shifted in 2026, and the direction of travel was consistently toward later dates rather than tighter ones.

What moved:

  • The August 2, 2026 deadline for standalone high-risk AI systems under Annex III of the EU AI Act, covering hiring, credit scoring, and biometric identification, moved to December 2, 2027.
  • High-risk AI embedded in regulated products under Annex I moved to August 2, 2028
  • Colorado replaced its original AI Act with a narrower statute focused on disclosure and transparency around automated decision-making, signed May 14, 2026, taking effect January 1, 2027, subject to attorney general rulemaking

What did not move:

  • Prohibited-practice rules under the EU AI Act have been enforceable since February 2, 2025, with fines up to €35 million or 7% of global turnover
  • Transparency duties under Article 50 remain on the original timeline
  • The AI-literacy obligation under Article 4 remains on the original timeline, though the final Omnibus text softened its substance

A later deadline is not the same as reduced exposure. Every case in the preceding section proceeded without any of these deadlines being in force.

The control gaps behind these cases

Each incident above maps to a specific gap. None of them required an exotic failure.

No usable inventory of what is deployed

Shadow AI is not a fringe behavior, and the visibility data makes the problem concrete: three-quarters of organizations lack comprehensive visibility into employee AI use. Governance cannot reach systems nobody has recorded.

Optro builds a living inventory of every model, agent, and third-party application from intake through production, with ownership, data inputs, and risk classification tracked as they change. Unauthorized AI surfaces before it becomes a compliance or security gap rather than after an incident forces the question.

A policy exists, but nothing enforces it

A policy that lives in a document and a control that runs in a workflow are different things, and only one of them catches problems before delivery.

Optro maps 25 or more frameworks, including the EU AI Act, ISO 42001, and NIST AI RMF, with evidence linked directly to controls and gaps flagged automatically. Harmonized controls mean one piece of evidence satisfies requirements across multiple frameworks instead of being collected separately three times. For a fuller picture of what AI compliance requires of risk and security teams, see AI compliance explained for risk and security leaders.

A known problem surfaces and nothing happens

The UnitedHealth allegations describe a known error rate with no remediation path attached to it. Detecting a risk and assigning someone to fix it are separate acts, and programs fail at the assignment far more often than at the detection.

Optro provides automated risk-score recommendations and structured risk tracking that connect every flagged risk to its related controls and frameworks, so findings arrive with an owner and a route to remediation attached.

Vendor and third-party AI gets assumed away

Mobley v. Workday is the clearest available signal on this point. The platform, not only the companies deploying it, ended up as a defendant. "The vendor handled it" is a position, not a defense.

Third-party AI belongs in your third-party risk process with an actual assessment behind it. Our ebook 10 essential questions for your AI vendors provides a structured questionnaire covering data handling, governance, and security protocols, along with the answers you should expect. 

For governance of AI systems that connect to your own tooling, see our checklist for governing MCP server deployments.

What GRC, audit, and risk leaders should do next

The enforcement record is consistent on one point: general-purpose law already reaches AI use, and the organizations that got caught were not undone by regulatory novelty. They were undone by ordinary control failures happening inside a system nobody had fully inventoried.

Three moves address most of what the cases above expose:

  1. Build one living inventory of AI in use, not a spreadsheet that three teams maintain in parallel. Every other control depends on knowing what exists.
  2. Treat vendor and third-party AI as third-party risk. Run an assessment. The assumption that the vendor handled governance has already failed in litigation.
  3. Put a named external standard behind your program, such as NIST AI RMF or ISO/IEC 42001, so that "compliant" carries a definition beyond internal judgment.

For a step-by-step approach to standing up the program itself, see our guide to implementing an AI governance program.

AI inventory, framework compliance, and risk remediation in one system:
See our AI governance platform

You may also like to read

Agentic AI Governance: A Framework for AI Agents
AI governance

Agentic AI governance: A practical framework for governing autonomous AI agents

LEARN MORE
blue paint texture
AI governance

What the NAIC AI model bulletin actually asks insurers to prove

LEARN MORE
man in glasses sitting at desk
AI governance

AI governance definitions: The complete glossary for GRC teams

LEARN MORE

Discover why industry leaders choose Optro

SCHEDULE A DEMO
upward trending chart
confident business professional