Skip to main content
Praxikon

Knowledge layer

What a ruling does to a provision

A ruling does not change the text of a provision. It changes what we know that text means. On this page that distinction sits in the data and not only in a note: every entry states which obligation it bears on and whether it interprets, narrows, broadens, confirms or contradicts it.

Register kept since: 13 August 2026

rulings recorded
7
under the AI Act
0
as GDPR context
7
obligations touched
4

There is no case law on the AI Act yet

On the verification date of this register there is no judgment of a court and no decision of a supervisory authority under the AI Act itself that we can check against a primary source. That is the state of affairs and not an omission: the enforcement powers for general-purpose AI models and for the Article 50 transparency duties only became active on 2 August 2026. We do not fill that gap with an expectation, an announcement or a case that comes close.

What does sit below is the GDPR context that was already in our enforcement tracker: decisions of European supervisory authorities about AI practices, taken under a different instrument. They show how authorities look at such practices. They do not interpret any provision of the AI Act, they therefore carry the relation "illustrates" only, and the guard behind this page refuses a GDPR case that claims anything else.

The two time axes, and how you look back with them

The provision keeps its date of application. That a court rules on it in 2027 does not move when the provision started to apply. What does move is the date on which we recorded the reading. That is why every ruling here carries two dates: the date of the decision itself, and the date we recorded it.

  1. 1.query the graph with a pin on both axes: /api/v1/entities?effective_at=...&known_at=... returns the text as it applied at that moment and as we knew it then;
  2. 2.query this register with the same date: /api/v1/enforcement?known_at=... returns the rulings we had recorded at that moment, and nothing that arrived afterwards;
  3. 3.those two beside each other are the state of that moment: the provision as it applied, plus the reading as we knew it then, without today knowledge running through it.

The five relations, and the sixth that is context

interprets
Explains the provision without moving its reach. The text stays the same, the reading gets sharper.
narrows
The provision reaches less far than the text alone suggested. A dossier built on the wider reading afterwards describes a state that no longer holds.
broadens
The provision reaches further than the text alone suggested. What stayed out of view falls under it after all.
confirms
Confirms a reading that already held. Nothing moves, and that is itself a fact: the reading has now been tested.
contradicts
Contradicts a published reading. We then show both sources with their hierarchy and do not choose for you.
illustrates
Shows how the same practice was treated under a different instrument. This does not interpret the provision and does not move its meaning.

Recorded rulings and decisions

GDPR contextITannulled

Italian authority fines OpenAI 15 million euros

Body:
Garante per la protezione dei dati personali (supervisory authority)
Reference:
Garante, docweb 10085432
Decided:
20 December 2024
Recorded by us:
13 August 2026

The Garante closed its ChatGPT investigation with a 15 million euro fine for training on personal data without an appropriate legal basis and inadequate information. The Court of Rome annulled the fine on 18 March 2026: after OpenAI established itself in Ireland, jurisdiction ran through the one-stop-shop mechanism, and the court never reached the substantive allegations. Since 2 August 2025, GPAI models carry their own documentation and transparency duties under the AI Act, enforced by the AI Office rather than national privacy authorities.

What this ruling does to which provision

  • illustrates: Article 53: GPAI model providers

    A fine over training a model on personal data, under the GDPR, later annulled on the question of jurisdiction. The documentation and transparency duties for GPAI models sit in Article 53 of the AI Act and are enforced by the AI Office; this decision says nothing about how they are to be read.

    Garante, besluit van 2 november 2024, bekendgemaakt op 20 december 2024, docweb 10085432

Open the primary source (Garante, besluit 2 november 2024, bekendgemaakt 20 december 2024)

praxikon:eu:gdpr:ruling:it-garante-openai-2024

GDPR contextNLfinal

Dutch DPA fines Clearview AI 30.5 million euros

Body:
Autoriteit Persoonsgegevens (AP) (supervisory authority)
Reference:
Autoriteit Persoonsgegevens, boetebesluit Clearview AI
Decided:
3 September 2024
Recorded by us:
13 August 2026

The Dutch DPA fined Clearview AI 30.5 million euros for building an illegal database of billions of facial images, including of Dutch citizens. The DPA also explicitly warned that use of Clearview by Dutch organisations is prohibited. This scraping practice now also falls under the Article 5 prohibition of the AI Act.

What this ruling does to which provision

  • illustrates: Article 5: prohibited practices

    The Dutch authority fined the same database and additionally warned that use by Dutch organisations is prohibited. That warning rests on the GDPR; the Article 5 prohibition on untargeted scraping of facial images in the AI Act stands separately from it.

    Autoriteit Persoonsgegevens, boetebesluit bekendgemaakt op 3 september 2024

Open the primary source (Autoriteit Persoonsgegevens, boetebesluit, bekendgemaakt 3 september 2024)

praxikon:eu:gdpr:ruling:nl-ap-clearview-2024

GDPR contextFRfinal

CNIL fines Amazon France Logistique 32 million euros for employee monitoring

Body:
Commission Nationale de l’Informatique et des Libertés (CNIL) (supervisory authority)
Reference:
CNIL SAN-2023-021
Decided:
27 December 2023
Recorded by us:
13 August 2026

The CNIL fined Amazon France Logistique 32 million euros for an excessively intrusive system that tracked warehouse workers’ activity via scanners down to the second. Under the AI Act, algorithmic monitoring of workers is a high-risk use (Annex III, employment), with obligations applying from 2 December 2027.

What this ruling does to which provision

  • illustrates: Annex III: high-risk AI

    Algorithmic monitoring of warehouse workers, decided under the GDPR. Under the AI Act this kind of use falls in the employment category of Annex III, with obligations applying from 2 December 2027; this decision concerns none of those obligations.

    CNIL, besluit SAN-2023-021 van 27 december 2023

Open the primary source (CNIL, besluit SAN-2023-021)

praxikon:eu:gdpr:ruling:fr-cnil-amazon-2023

GDPR contextITwithdrawn

Italian authority imposes temporary limitation on ChatGPT

Body:
Garante per la protezione dei dati personali (supervisory authority)
Reference:
Garante, docweb 9870832
Decided:
30 March 2023
Recorded by us:
13 August 2026

The Garante imposed a temporary processing limitation on OpenAI for ChatGPT over the lack of a legal basis and of age verification. The limitation was lifted at the end of April 2023 after OpenAI took measures. The case showed early on that European authorities can directly affect generative AI; the transparency and information duties for such systems now sit in Article 50 of the AI Act.

What this ruling does to which provision

  • illustrates: Article 50: transparency

    A temporary processing limitation on a generative system, imposed and later lifted under the GDPR. The transparency and information duties for such systems sit in Article 50 of the AI Act; this measure does not rest on it.

    Garante, maatregel van 30 maart 2023, docweb 9870832

Open the primary source (Garante, maatregel 30 maart 2023)

praxikon:eu:gdpr:ruling:it-garante-chatgpt-2023

GDPR contextELfinal

Greek authority fines Clearview AI 20 million euros

Body:
Hellenic Data Protection Authority (supervisory authority)
Reference:
HDPA 35/2022
Decided:
13 July 2022
Recorded by us:
13 August 2026

The Greek authority fined Clearview AI 20 million euros for processing biometric data of Greek citizens without a lawful basis. The same practice, building a facial recognition database through scraping, now falls under the Article 5 prohibition of the AI Act.

What this ruling does to which provision

  • illustrates: Article 5: prohibited practices

    A second authority, the same practice, the same outcome under the GDPR. That two authorities reached a fine independently says something about the practice and nothing about how Article 5 of the AI Act is to be read.

    HDPA, besluit 35/2022 van 13 juli 2022

Open the primary source (HDPA, besluit 35/2022, 13 juli 2022)

praxikon:eu:gdpr:ruling:el-hdpa-clearview-2022

GDPR contextITfinal

Italian authority fines Clearview AI 20 million euros

Body:
Garante per la protezione dei dati personali (supervisory authority)
Reference:
Garante, docweb 9751362
Decided:
9 March 2022
Recorded by us:
13 August 2026

The Garante fined Clearview AI 20 million euros for collecting facial images from the internet without a legal basis to build a biometric search database. Untargeted scraping of facial images to build facial recognition databases has been explicitly prohibited under Article 5 of the AI Act since 2 February 2025.

What this ruling does to which provision

  • illustrates: Article 5: prohibited practices

    Untargeted collection of facial images for a biometric search database, decided under the GDPR. The same practice has been prohibited in as many words by Article 5 of the AI Act since 2 February 2025; this decision is not about that provision.

    Garante, besluit van 10 februari 2022, docweb 9751362

Open the primary source (Garante, besluit 10 februari 2022)

praxikon:eu:gdpr:ruling:it-garante-clearview-2022

GDPR contextHUfinal

Hungarian authority fines bank for AI voice analysis of customer calls

Body:
Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH) (supervisory authority)
Reference:
NAIH-85-3/2022
Decided:
8 February 2022
Recorded by us:
13 August 2026

The NAIH imposed a fine of 250 million forints (around 700,000 euros) on a bank that automatically analysed customer service calls for emotion with AI, without a valid legal basis and without informing customers. Emotion recognition in the workplace and in education now falls under the Article 5 prohibition of the AI Act; in customer contact the Article 50 transparency duties apply.

What this ruling does to which provision

  • illustrates: Article 5: prohibited practices

    Emotion recognition from speech, decided under the GDPR. The AI Act prohibits emotion recognition in the workplace and in education in Article 5; this decision concerned customer contact and rests on a different instrument, so it does not interpret Article 5.

    NAIH-85-3/2022, boetebesluit over geautomatiseerde emotieanalyse van klantgesprekken

  • illustrates: Article 50: transparency

    The customers did not know an AI analysis ran on their call. Under the AI Act the information duty for such systems sits in Article 50; this decision rests on the GDPR and says nothing about how Article 50 is to be read.

    NAIH-85-3/2022, onderdeel over het niet informeren van de betrokken klanten

Open the primary source (NAIH besluit NAIH-85-3/2022)

praxikon:eu:gdpr:ruling:hu-naih-budapest-bank-2022

For AI agents and integrations

This register is available as data as well, with the same identifiers and the same relations as on this page. You can filter on reference moment (known_at), on obligation and on country.

Open the tracker as JSONTo the enforcement tracker