Four AI Enforcement Cases Every UK Business Should Read
· By Peter Lowe
Category: Governance
What do real AI enforcement cases teach UK businesses? Four ICO and EU cases and the practical lessons to check your own exposure against.
Regulators rarely tell you where the line is in a guidance document. They tell you through enforcement.
Over the past three years, four data protection cases have done more to shape what UK and EU regulators expect from businesses using AI than any policy paper. Two are squarely about AI. Two are about data protection more broadly — but their lessons apply directly to how you buy, run and oversee AI. Between them they involve penalties running into the tens of millions of pounds and euros, though only one of the four is actually settled. The rest are still being fought, which is part of the point: the regulators are testing the boundaries in real time, and the direction of travel is already clear.
Here is each case — what happened, what the regulator decided and where it now stands, what it means for your business, and a question you can answer honestly to work out whether you carry the same exposure.
None of this needs a lawyer to read. Some of it may need one to act on, and I will be clear about which.
## Case 1: Clearview AI — “publicly available” is not the same as “yours to use”
**What happened.** Clearview, a US company, scraped billions of photos from the internet — including from the social media accounts of UK residents — without asking anyone. It built those images into a facial recognition database and sold access to law enforcement agencies.
**What the regulator decided.** In 2022 the ICO fined Clearview £7.5m and ordered it to stop collecting UK residents’ data and delete what it already held. Clearview appealed, arguing that a US company serving foreign law enforcement sat outside UK law. In October 2025 the Upper Tribunal ruled that the ICO does have jurisdiction — then sent the case back to a lower tribunal to decide whether the fine itself stands, and Clearview has said it will appeal again. So the principle is now settled even though the penalty is not.
**What it means for you.** Three things. First, data being publicly available online does not make it lawful for you to use. If you scrape, collect or buy datasets that include personal information, the people in that data still have rights, wherever you found it. Second, UK data protection law follows the person, not the company. If your AI processes data about people in the UK, UK law applies — even if your business or your supplier sits abroad. The reverse holds too: if you have EU customers, EU rules reach you. Third, the kind of database Clearview built is now banned outright under the EU AI Act, whose ban on scraping facial images to build recognition databases took effect in February 2025. What drew an enforcement action three years ago is a flat prohibition today. Where regulators fine, they often later ban.
**Self-check:** *Are any of our AI tools — including anything we’ve built in-house — using data where we couldn’t show, in writing, that we had the right to use it?*
## Case 2: TikTok — knowing and doing nothing is worse than not knowing
**What happened.** TikTok allowed up to an estimated 1.4 million UK children under 13 to use the platform without proper parental consent. The ICO’s investigation found that concerns had been raised internally with senior staff about under-13s not being removed — and that TikTok had not responded adequately.
**What the regulator decided.** The ICO issued a £12.7m fine in 2023. TikTok is appealing, and the substantive appeal is still working through the tribunals, so this one is not final either.
**What it means for you.** First, anything that could reach children, vulnerable people or other protected groups draws the closest regulatory attention. If your platform, app or tool could plausibly be used by under-18s — even if they are not your intended audience — you have extra obligations under the ICO’s Children’s Code. Second, and this is the part that turned a large fine into a larger one: the ICO treated “knew and did nothing” as an aggravating factor. Staff had flagged the problem through proper channels and been ignored. That reads across directly to how you handle internal warnings about AI. If someone flags that the recruitment tool looks biased, or the chatbot is mishandling vulnerable customers, the worst response is to note it and move on. Record the concern, record what you did, and either fix it or write down why you decided not to. Doing nothing, on the record, is the expensive option.
**Self-check:** *Has anyone — staff, customer or supplier — raised a concern about how one of our AI tools behaves? If so, can we show what we did about it?*
## Case 3: Capita — your supplier’s failure can become your problem
**What happened.** An employee at Capita, a large UK outsourcer, downloaded a malicious file. Capita did not isolate the compromised device for 58 hours, and in that window the attackers moved through its systems. Data belonging to around 6.6 million people was taken — much of it personal data Capita held on behalf of its clients.
**What the regulator decided.** The ICO initially proposed a £45m fine. Capita admitted liability, agreed a voluntary settlement and waived its right to appeal, and the final penalty landed at £14m in October 2025 (£8m for Capita plc, £6m for its pensions arm). This is the one case of the four that is fully settled.
**What it means for you.** First, the security of an AI tool is only as good as the security around it — the people, devices, suppliers and processes it sits inside. AI does not run in a sealed box. Second, and this matters for procurement: a signed data processing agreement does not hand your legal responsibility to the supplier. Capita was the processor for many clients, but those clients — as controllers — carried exposure too. You can outsource the work. You cannot outsource the accountability. Third, and most practical: how you respond to a breach directly affects what it costs you. Capita’s fine came down substantially because it engaged with the investigation and admitted the failures. Knowing that in advance should shape your incident plan now. Stonewalling a regulator is the most expensive move available.
**Self-check:** *If our highest-risk AI supplier were breached tomorrow, would we hear in hours, days or weeks — and do we have a written plan for how we’d deal with the ICO if we were pulled into it?*
## Case 4: OpenAI — “everyone uses it” was never a defence
**What happened.** Italy’s data protection regulator investigated OpenAI, the maker of ChatGPT, and found it had collected personal data to train the model without a proper lawful basis, had not been clear with users about how their data was used, and lacked adequate age checks.
**What the regulator decided.** The Italian regulator fined OpenAI €15m in December 2024. OpenAI called it disproportionate and is appealing; there are reports the fine may since have been overturned on appeal, so treat the outcome as unsettled. The findings, though, are what matter for the rest of us.
**What it means for you.** First, for anyone using a third-party AI tool: the legal basis on which the underlying model was trained can become your problem too, not just the supplier’s. If you feed customer data into a tool whose training data turns out to be unlawful, you are closer to that exposure than you would like. This belongs at the top of any supplier check. Second, it retired a comfortable excuse. For a couple of years, “everyone’s using ChatGPT” and “it’s the industry standard” stood in for doing the homework. Popularity is not a lawful basis. Each business is responsible for its own due diligence on each tool. Third, the EU has moved faster on AI-specific rules than the UK, which as of early 2026 still had no single cross-economy AI law. If you have EU customers, plan to the stricter of the two regimes.
**Self-check:** *For our top three AI tools, do we have written answers on (a) the supplier’s lawful basis for processing personal data and (b) where the underlying model was trained?*
## The pattern across the four
Read together, the cases tell one story. Regulators are not trying to punish businesses for using AI. They are acting on carelessness — not knowing what you have, knowing about a problem and sitting on it, assuming the supplier had it covered, treating AI as someone else’s responsibility.
That is the encouraging part. None of these turned on deep technical knowledge or a sophisticated grasp of machine learning. They turned on ordinary governance: knowing what you have, asking suppliers the right questions, taking concerns seriously, and being able to show what you did. Every item on that list is something a UK business can act on this quarter without slowing down.
## The five-minute check
Take the four self-check questions above. Answer each one honestly — not the answer you’d give a regulator, the answer you’d give yourself. Then add a fifth: if a regulator asked us to demonstrate any of this in writing tomorrow, could we?
If the answer to any of them is “no” or “not sure,” you’ve found where a little management attention is worth spending — and, just as usefully, where it isn’t. If you can answer them cleanly, you’re in better shape than most, and you can get back to running the business.
## Where this needs a professional — and what kind
Most of the above you can work through yourself. Some of it — a genuinely high-risk tool, a live complaint, a question about lawful basis — is worth proper advice. When it is, the adviser you want is one who works to your commercial goals: someone who tells you how to do the thing compliantly, not simply that you can’t. A good specialist will still say no when no is the right answer — if you’re running one of the practices the EU AI Act now bans, “stop” is the correct advice — but they’ll hand you the compliant route to the same outcome rather than leaving you with a closed door. Choose the adviser who unblocks, not the one who exists to say no.
## Where to start this week
Pick the case closest to your business. If you build or use AI involving personal data, start with Clearview. If you have customers under 18, start with TikTok. If you rely on third-party AI suppliers handling customer data, start with Capita or OpenAI. Run the self-check. Find one specific gap. Close it. That is the whole task this week — one gap, not a programme.
If you’d rather work through the four cases with your leadership team — including what they mean for your specific sector and a written risk assessment at the end — Smart AI Studio runs an [AI governance workshop](/workshops/) for UK businesses getting ready for board-level AI conversations. The workshop is led by an AI governance expert, so dates depend on that specialist’s availability. [Book a call with Peter](/contact/) and we’ll talk through whether it’s a fit and when we could run it.
## Frequently asked questions
### What can UK businesses learn from recent AI enforcement cases?
The clearest lesson from recent AI enforcement cases is that regulators judge you on how you buy, run and oversee AI — not on whether you wrote a policy. Most penalties trace back to unclear accountability, weak supplier oversight, or processing personal data without a lawful basis.
### Do AI enforcement cases apply to small businesses?
Yes. UK GDPR and the [ICO’s enforcement expectations](https://ico.org.uk/action-weve-taken/enforcement/) apply regardless of size, and several cases involved third-party suppliers — meaning a small business can inherit risk from a tool it merely uses. Size reduces scrutiny, not liability.
### How do I reduce my risk from AI enforcement?
Pick the case closest to your business, run a short self-check, find one concrete gap and close it. Document your lawful basis, your supplier due diligence, and your human oversight — that record is what regulators look for first.
*Smart AI Studio works with UK business owners and leadership teams on practical AI adoption, including compliance, governance and risk. This article reflects the regulatory position as of July 2026 and is general guidance, not legal advice. Enforcement cases and AI regulation are moving quickly — several of the fines above are under appeal as this is written — so check the current position before acting. For specific compliance questions, consult a qualified solicitor or data protection specialist.*
This article was written by Peter Lowe. The ideas and opinions are his own; AI was used to assist with drafting and editing.