AI Fines and Lawsuits
Are Already Happening
Most companies fail for predictable, preventable reasons.
Enforcement Events
Cleo AI
Allegedly deceived consumers about how much money they could access and how quickly — core product claims were unsupported.
accessiBe
Allegedly misrepresented that its AI-powered accessibility tool could make websites fully compliant with WCAG — a claim the product could not substantiate.
DoNotPay
Marketed as 'the world's first AI lawyer' without testing whether outputs matched human-lawyer expertise.
Luka / Replika
Unlawful personal-data processing and deficient age-verification safeguards for users of an AI chatbot.
Air AI
Falsely claimed conversational AI could replace human customer service reps and generate substantial earnings. Misled small businesses with false refund guarantees. Consumers lost up to $250,000 each.
$18M judgment largely suspended due to inability to pay; $50,000 actually collected. Permanent business-opportunity ban.
Cox Media Group
Falsely claimed AI-powered 'Active Listening' service could target ads based on conversations captured from consumers' smart devices. No voice data was actually used — the service was resold email lists. Also falsely claimed consumers had opted in.
CMG paid $880,000; MindSift $25,000; 1010 Digital Works $25,000. May 2026.
NGL Labs
Falsely claimed AI-powered content moderation protected young users on its anonymous messaging app. Ban on offering anonymous messaging apps to under-18 users.
$4.5M FTC redress plus $500K Los Angeles DA civil penalty. July 2024.
iTutorGroup
AI-powered hiring system automatically screened out applicants based on age, violating the Age Discrimination in Employment Act.
$365,000 paid to affected applicants. Settled with anti-discrimination policy, training, and EEOC monitoring.
Elegant Enterprise
AI-generated job advertisements contained unlawful citizenship-status restrictions. Settlement required ending the practice and training obligations.
No monetary penalty stated; settlement focused on training and compliance. February 2026.
Content at Scale AI
Marketed AI content detection tool with unsubstantiated efficacy claims. Required to substantiate claims, retain evidence, and notify consumers.
No monetary penalty; consent order with compliance reporting. April 2025.
Workday, Inc.
Class action alleging Workday's AI applicant screening tools discriminate based on race, age, and disability. Court denied Workday's motion to dismiss FEHA claims in June 2026, ruling AI tool vendors can be held directly liable as employers' agents.
Class certified May 2025. June 2026 order allowed FEHA and ADA claims to proceed. No settlement or final judgment yet. Potential landmark case for AI vendor liability.
NYC Local Law 144
NYC Local Law 144: $500–$1,500 per day per violation
Dec 2025 NYS Comptroller audit found DCWP enforcement 'ineffective' — 17 violations found by auditors vs 1 by DCWP in same 32 companies. DCWP committed to proactive enforcement from Jan 2026. First real fines issued Q4 2025. A Manhattan staffing agency paid ~$18,000 for running an AI resume screener without a bias audit.
New York Algorithmic Pricing Disclosure Act
New York Algorithmic Pricing Disclosure Act: $1,000 per violation
Texas Responsible AI Governance Act (TRAIGA)
Texas Responsible AI Governance Act (TRAIGA): $10,000–$12,000 per curable violation; $80,000–$200,000 per uncurable violation; $2,000–$40,000 per day for continuing violations
No enforcement actions publicly announced as of July 2026. AG complaint portal is live. Intent-based liability standard makes enforcement selective. Safe harbor for NIST AI RMF compliance.
Colorado AI Act (SB 24-205 / replaced by SB 26-189)
Colorado AI Act (SB 24-205 / replaced by SB 26-189): Up to $20,000 per violation under Colorado Consumer Protection Act
Federal court paused enforcement of SB 24-205 on April 27, 2026. Governor Polis signed SB 26-189 on May 14, 2026, repealing and reenacting as a narrower ADMT regime effective January 1, 2027. 60-day cure period available. No private right of action.
EU AI Act
EU AI Act: Up to €35M or 7% global annual turnover (prohibited AI); €15M or 3% (high-risk obligations); €7.5M or 1.5% (misleading information)
Prohibited AI provisions enforced since Feb 2025. GPAI obligations since Aug 2025. Full high-risk (Annex III) enforcement from Aug 2, 2026. Extraterritorial — applies to US companies placing AI on EU market.
Federal AI Hiring Risk
Federal law already applies to AI hiring. Companies are being sued BEFORE fines exist.
Key Statement
"AI does not reduce liability. It amplifies it."
Workday and iTutorGroup cases demonstrate that AI hiring systems face immediate federal liability under Title VII and Age Discrimination in Employment Act — without waiting for new AI-specific regulations.
Mobley v. Workday
Active federal lawsuit. Class certified May 2025. June 2026 order allowed FEHA and ADA claims to proceed. Alleges AI screening discriminates by race, age, and disability.
EEOC v. iTutorGroup
Settled enforcement. AI automatically rejected applicants over 55. $365,000 paid to affected applicants. Violated Age Discrimination in Employment Act.
Enforcement Patterns
Most AI enforcement is triggered by data misuse and unsupported claims, not model architecture
Federal lawsuits are emerging before regulatory fines exist
Hiring AI is the highest immediate legal risk surface
Per-violation penalties scale with usage (NYC LL144: $500-$1,500/day)
Small and mid-size companies are already being targeted (DoNotPay: $193k)
AI does not reduce liability. It amplifies it.
Why Companies Actually Get Fined or Sued
Each failure mode maps to real enforcement cases above.
No Audit Trail
AI systems deployed without evidence of testing, validation, or decision logging
No Bias Testing
Hiring AI used without bias audits or disparate impact analysis
Automated Filtering Without Oversight
AI makes final decisions without human review or explainability
Unsupported AI Claims
Marketing AI capabilities without validation or evidence
No Disclosure
Failure to notify users/candidates that AI is being used
Data Misuse
Unlawful collection, processing, or transfer of personal data
HAIEC Prevention Layer
Static Engine
- • No audit trail
- • Automated filtering
- • Data misuse
Runtime Testing
- • No bias testing
- • Unsupported claims
- • Automated filtering
NYC LL144 Module
- • No bias testing
- • No disclosure
- • Hiring discrimination
Compliance Wizard
- • Unsupported claims
- • No disclosure
Audit Orchestrator
- • No audit trail
- • Federal hiring risk
Decision Pipeline
- • Automated filtering
Don't Become the Next Case Study
Federal lawsuits and FTC enforcement are already happening. Check your exposure before regulators do.