AI penalties, compared
What non-compliance actually costs in all 44 tracked jurisdictions, from 7 percent of worldwide turnover to nothing at all.
The fine is rarely the whole story. Europe leads on headline numbers, but China's real deterrent is losing the right to operate, and the sharpest US exposure is private litigation with statutory damages that stack per violation. Read the enforcement column with the deadline calendar beside it: a penalty only bites once the obligation is effective.
| Jurisdiction | Status | Penalties and enforcement |
|---|---|---|
| In force | Enforcement runs through the CAC and sector authorities under the Cybersecurity Law, Data Security Law, and Personal Information Protection Law. Sanctions include service suspension, takedowns, fines, and, after the 2026 Cybersecurity Law amendment, more immediate penalties for serious breaches. | |
| Phasing in | Up to EUR 35 million or 7% of worldwide annual turnover for prohibited practices; up to EUR 15 million or 3% for most other breaches; up to EUR 7.5 million or 1% for supplying incorrect information. The higher figure applies. | |
| In force | Administrative fines up to KRW 30 million (about USD 21,000) for failures such as not disclosing AI use or not appointing a domestic representative. The act emphasizes post-market oversight over pre-market approval. | |
| No comprehensive law | No AI-specific penalty regime. Enforcement flows through each regulator's existing powers, for example data-protection fines up to the higher of GBP 17.5 million or 4% of global turnover. | |
| No comprehensive law | No AI-specific federal penalties. Exposure runs through the FTC Act, sector regulators, and civil-rights and consumer-protection statutes. 'AI washing' (overstating what a system does) is an active FTC enforcement theme. | |
| No comprehensive law | No AI-specific penalties. Exposure runs through the Privacy Act, Australian Consumer Law, and sectoral statutes, each with its own enforcement regime. | |
| Proposed | The bill proposes administrative penalties and a civil-liability regime; specifics depend on the final enacted text. | |
| Lapsed / failed | No federal AI-specific penalties. Privacy regulators and provincial statutes provide the enforcement backstop. | |
| Partially in force | No direct penalties; obligations are implemented and enforced through each party's national legal system. | |
| In force | No significant punitive penalties; the government relies on guidance, cooperation duties, and publicity. | |
Mexico | Proposed | Data protection sanctions through the reconstituted privacy authority. No AI-specific penalties. |
| In force | Enforcement through existing consumer protection, competition, and data protection regimes coordinated under the regulation, rather than a standalone AI fine schedule. | |
Saudi Arabia | No comprehensive law | PDPL sanctions for data violations; supervisory and procurement consequences for departing from SDAIA expectations. No AI-specific fine schedule yet. |
| Proposed | No AI-specific penalties. FADP and sectoral enforcement apply, and FINMA supervision reaches AI in financial services. | |
| In force | None under the Basic Act itself. Enforcement will come through the sectoral statutes it directs regulators to adapt. | |
| Partially in force | Regulatory enforcement by zone and sector: DIFC Commissioner action, central bank supervisory measures, and PDPL sanctions, rather than a single AI fine schedule. | |
| In force | Administrative enforcement through the Ministry of Science and Technology, including registration refusal and orders against non-compliant systems. Pre-existing systems had 12 months from the effective date to comply. | |
| No comprehensive law | Data protection enforcement through the AAIP. No AI-specific penalties. | |
| Proposed | None AI-specific until the bill passes. | |
| Proposed | Data protection enforcement through the SIC. No AI-specific penalties. | |
| No comprehensive law | Data-protection sanctions under Law 151/2020. No AI-specific penalties. | |
| No comprehensive law | PDPO enforcement for data-protection breaches; supervisory action for regulated financial institutions. | |
| No comprehensive law | No AI-specific penalty regime; enforcement runs through IT law and data-protection law. | |
| Proposed | UU PDP administrative sanctions and, for serious violations, criminal provisions. No AI-specific penalties yet. | |
| No comprehensive law | No AI-specific penalties. Privacy Protection Authority enforcement and sectoral sanctions apply on their ordinary terms. | |
| Proposed | Data Protection Act enforcement applies now; the bill's penalty structure will be set in the legislative process. | |
| No comprehensive law | None for the guidelines. PDPA enforcement applies to data-protection breaches. | |
| No comprehensive law | No AI-specific penalties; enforcement runs through the Privacy Act and general statutes. | |
| Proposed | NDPA sanctions apply now. The pending bill would add license-based enforcement for high-risk systems. | |
| No comprehensive law | No AI-specific penalties; enforcement is through the Personal Data Protection Act and sector regulators. | |
| No comprehensive law | POPIA enforcement by the Information Regulator, including fines and, for some offenses, criminal liability. | |
| Proposed | PDPA penalties apply now, including administrative fines. No AI-specific penalty regime yet. | |
| Proposed | KVKK administrative fines and cybersecurity sanctions apply. No AI-specific penalties yet. | |
California | Partially in force | Vary by statute. The AI Transparency Act carries per-day civil penalties for noncompliance; the frontier act is enforced by the Attorney General. |
| Repealed / replaced | Up to $20,000 per violation; Attorney General enforcement; no private right of action. | |
Connecticut | Partially in force | Enforcement through the Attorney General and the CTDPA's mechanisms for the enacted measures. |
Illinois | In force | BIPA allows statutory damages per violation through a private right of action; Human Rights Act violations are enforced by the Illinois Department of Human Rights. |
Montana | In force | Not a penalty statute; it is a shield that invalidates overreaching restrictions. |
New York | Partially in force | Local Law 144 carries civil penalties per violation; the state frontier law is enforced by the Attorney General. |
Tennessee | In force | Class A misdemeanor plus civil liability under the ELVIS Act; private suits under SB 1580. |
| In force | Curable violations $10,000 to $12,000; uncurable violations $80,000 to $200,000; $2,000 to $40,000 per day for continuing violations. Attorney General enforcement only; no private right of action. | |
| In force | Administrative fines and enforcement by the Utah Division of Consumer Protection. | |
Virginia | Lapsed / failed | None AI-specific; VCDPA enforcement by the Attorney General. |
Washington | Partially in force | MHMD violations are enforceable by the Attorney General and through private suits under the Consumer Protection Act. |
No jurisdictions match those filters.









