A €45 million EU AI Act fine headline is circulating. Here's what's actually confirmed
Compliance blogs report a €45M AI Act penalty over training-data errors — unconfirmed by any official decision, though the fine authority behind it is real.
By David Lara, Founder
Founder-reviewed ·How we research and correct articles
If you’ve seen a headline this week about a €45 million EU AI Act fine levied on a company over “errors in its AI training data,” you’re not imagining it — the figure has been circulating across several compliance-industry blogs. It’s also, as of this writing, not something we could verify against an official European Commission enforcement decision, a market surveillance authority’s public register, or a wire report. Different outlets repeating the story don’t even agree on the underlying facts — some describe a German company penalized over training-data quality, others describe a US recruitment-AI vendor fined for transparency and human-oversight failures. That’s the signature of a number getting rounded, garbled, and passed along the compliance-content chain rather than a single confirmed enforcement case.
So this isn’t going to be “here’s what the €45 million fine teaches us.” It’s going to be the more useful version: what’s actually confirmed about EU AI Act fining authority right now, why a number in that range is entirely plausible whether or not this specific case is real, and what “AI training data” as a category of legal exposure genuinely means under the Act — because that part isn’t speculative at all.
What’s actually confirmed
The AI Act’s penalty structure has been written into the regulation for two years and isn’t in dispute: infringements of most obligations carry fines up to €15 million or 3% of global annual turnover, whichever is higher. Prohibited practices — the Act’s short list of AI uses banned outright, like certain forms of biometric categorization or manipulative dark-pattern systems — carry a steeper ceiling: up to €35 million or 7% of global turnover.
What changes on August 2, 2026 is that the European Commission’s AI Office gains the direct statutory authority to apply those penalties against general-purpose AI model providers specifically — before that date, the Office could request documentation and run evaluations, but lacked the power to compel and fine. National market surveillance authorities have broader standing over other AI system categories, but their own readiness varies by country heading into the same deadline (see the enforcement timeline piece for where that stands).
Put simply: as of late July 2026, the legal machinery to issue a fine at that scale is real and about to get sharper teeth. Whether any specific fine has actually been issued yet is a separate question from whether one legally could be — and that’s exactly the gap unverified headlines tend to fill with a specific, dramatic-sounding number.
What a real “training data” violation actually covers
Here’s the part worth taking seriously regardless of any single case: “errors in training data” isn’t a vague catch-all under the Act — it maps to specific, documented obligations. General-purpose AI model providers have to publish a sufficiently detailed public summary of the content used to train their model, using a template the AI Office maintains, and they have to demonstrate a policy for respecting EU copyright law, including honoring text-and-data-mining opt-outs. Failures here aren’t about whether the training data was factually “wrong” in some abstract sense — they’re about whether a provider can show what went into the model and that they respected the legal constraints on using it.
For a company building its own models or fine-tuning on proprietary or scraped data, that’s the specific exposure: undocumented provenance, ignored opt-out signals, or an inability to produce the required training-data summary on request. For a company merely using a third-party model via API, this obligation sits with the model provider, not the downstream user — a distinction worth keeping straight, since headline coverage tends to blur it.
What this means for your sending program
Almost none of this touches a cold-email or outreach program directly — sending isn’t a general-purpose AI model, and the AI Act’s training-data obligations are aimed at the handful of companies actually building foundation models, not the much larger number of companies using AI features on top of one. Where it does touch you: if your outreach stack includes an AI drafting or agent layer, and that layer surfaces to EU recipients in a way that looks like direct AI interaction, the transparency duty in Article 50 is the actual, confirmed obligation to check — not the training-data provisions this fine story is (possibly inaccurately) attached to.
That’s also the right place to point the general instinct this story teaches: verify the mechanism, not just the headline. A campaign drafted or personalized through Norbelys’s AI layer doesn’t build or fine-tune a general-purpose model at all — it calls out to one, the same way any AI-assisted product does — so the GPAI-specific obligations circulating in this fine story were never the relevant exposure for an outreach program in the first place. The confirmed obligation, if any, is Article 50’s disclosure duty, and only where an agent surfaces as something a recipient could mistake for a person, not where it drafts a message a human still reviews before it sends.
The broader lesson is a simple discipline, not a panic response: treat compliance news the way you’d treat a deliverability rumor in this industry — verify against a primary source before you change anything, but don’t wait for perfect confirmation to check whether the underlying rule already applies to you. The enforcement authority behind a fine like this is confirmed. The specific headline attached to it, this week, isn’t yet — and the difference matters for how you act on it, whether you’re evaluating Norbelys or any other vendor an unverified number is being pinned to.
How to actually verify a compliance headline like this one
The pattern is repeatable, and it’s the same discipline that separates a useful compliance read from a forwarded scare headline. Three checks, in order: first, does the story name a specific enforcing authority and a specific published decision, or does it cite “sources” and other compliance blogs repeating the same figure — the AI Act’s own penalty tiers are public and citable, so a real case should be too. Second, do independent outlets covering the same story agree on the basic facts (which company, which country, which violation) — divergent details across outlets covering “the same” fine is the strongest tell that a number got rounded and passed along rather than reported firsthand. Third, check the date against the enforcement timeline: a claimed GPAI-provider fine dated before the Commission actually held that statutory authority is definitionally impossible, no matter how many blogs repeat it.
None of this requires special access — every check above uses only publicly available regulatory text and cross-referencing multiple independent outlets, the same research discipline this piece applied to the €45 million figure itself.
FAQ
Frequently asked questions
Is the €45 million EU AI Act fine confirmed?
As of this writing, no — it isn't verifiable against an official European Commission enforcement decision, a market surveillance authority's public register, or a wire report, and different outlets repeating the figure don't agree on the underlying facts of the case.
Can the EU AI Act actually fine companies that amount, in principle?
Yes. The regulation's penalty tiers are confirmed and public: up to €15 million or 3% of global annual turnover for most infringements, and up to €35 million or 7% for prohibited practices — a €45 million figure would fall within the upper tier's range for a very large company.
When does the EU AI Office gain authority to fine general-purpose AI model providers directly?
August 2, 2026. Before that date the AI Office could request documentation and run evaluations but lacked the statutory power to compel and fine GPAI providers specifically; national market surveillance authorities have broader standing over other AI system categories on different timelines.