EU AI Act Enforcement June 2026: First Fines Under the New Regime
The EU AI Act entered full enforcement in 2025. In June 2026, regulators issued their first significant fines. Here is what happened, who got fined, and what it means for AI deployment globally.
The European Union's AI Act entered full enforcement in August 2025. In June 2026, regulators issued their first significant fines. The enforcement actions signal that the AI Act is not aspirational regulation — it has teeth. The fines targeted companies that failed to meet basic compliance requirements: risk classification, transparency disclosures, and authorization for prohibited practices. The amounts — ranging from 20 million to 35 million euros — are large enough to get attention. The First Enforcement Actions The European AI Office issued three significant enforcement actions in June 2026: A biometrics company was fined 35 million euros for deploying real-time facial recognition systems in public spaces without the required judicial authorization. The systems were installed in retail locations across three EU member states and were processing facial biometric data without individual consent or legal basis. The fine reflected both the severity of the violation (real-time biometric identification is prohibited without authorization) and the company's size. An HR technology provider was fined 20 million euros for deploying an AI hiring tool that had not undergone the required bias audit. The tool was used by over 200 EU companies to screen job applicants. The AI Office found that the tool produced statistically significant disparate impact across gender and ethnicity, and the provider had not conducted the bias audit required for high-risk AI systems. A social media platform was fined 28 million euros for deploying an AI recommendation system that had not been classified under the correct risk tier. The platform classified its recommendation algorithm as minimal risk when it should have been classified as limited risk, requiring transparency disclosures that the platform had not made. What the AI Act Requires The AI Act establishes a risk-based classification system: Unacceptable risk (prohibited): Social scoring, untargeted facial recognition, emotion recognition in workplaces and schools, AI systems that exploit vulnerabilities. High risk (heavily regulated): AI used in hiring, credit scoring, law enforcement, education, and critical infrastructure. Requires conformity assessments, bias audits, human oversight, and transparency documentation. Limited risk (transparency required): Chatbots, deepfakes, emotion recognition systems. Must disclose that users are interacting with AI. Minimal risk (no specific requirements): Most AI applications, including spam filters, game AI, and inventory management. The classification determines compliance requirements. The fines target companies that misclassify their systems or skip compliance steps. Global Implications The AI Act has extraterritorial scope. A US company that deploys an AI system affecting EU residents must comply. A Chinese company that sells AI tools to EU companies must comply. The AI Act is the de facto global standard for AI regulation. Companies outside the EU have responded in three ways: Full compliance: Some companies have implemented AI Act compliance globally, using EU standards as their baseline everywhere
EU-specific compliance: Some companies have created separate EU versions of their AI products that meet AI Act requirements while maintaining different versions elsewhere
Market exit: Some companies have chosen to remove AI features from EU products rather than comply with the transparency and audit requirements The enforcement actions in June 2026 have pushed more companies toward option 1 or 2. The fines are large enough to justify compliance costs, and the reputational risk of non-compliance is significant. What AI Deployers Should Do If you deploy AI systems that affect EU residents: Classify your AI systems according to the AI Act risk tiers. If you have not done this, start now.
Conduct conformity assessments for high-risk systems. This requires documentation of training data, bias testing, human oversight mechanisms, and technical specifications.
Implement transparency disclosures for limited-risk systems. Users must know they are interacting with AI.
Maintain records of AI system decisions, training data sources, and compliance documentation for at least 10 years.
Establish human oversight for high-risk systems. AI systems making consequential decisions must have human review capability. The AI Act is the most comprehensive AI regulation in the world. The first fines demonstrate that enforcement is real. Companies that treat AI compliance as optional are taking a significant financial risk.