How a US AI facial recognition company ended up fined in four countries at once

1. The EU AI Act applies beyond the EU

The EU AI Act is the world’s first serious attempt to systematically regulate AI systems and AI-based products. Yet founders keep making the same assumption: if the entity isn’t in the EU, the office isn’t in the EU, and the investors aren’t in the EU, then surely none of this applies to them.

In reality, the EU AI Act applies extraterritorially – the law doesn’t care where your company is registered. It asks one question: is the product available to users in the EU? Since the EU market is one of the largest in the world and almost every startup treats it as a priority from day one, the answer is almost always yes – and the requirements apply to you.

 

2. Clearview AI: why having no EU presence did not help

Clearview AI is a US company that scraped billions of facial images from the open internet and social media and built a facial-search product on top of that database. It has no presence in the European Union. For years, the company argued that its clients were exclusively foreign law enforcement and intelligence agencies, that requests came through foreign IP addresses, and that European law simply didn’t apply. Regulators didn’t buy it.

 

3. Four countries, four fines — and all under the GDPR

Worth noting: all of this happened in 2022–2024, before the EU AI Act was even in force, so regulators had to fall back on the GDPR. Italy: €20 million (February 2022), Greece: €20 million (July 2022), France: €20 million (October 2022), the Netherlands: €30.5 million (September 2024).

 

4. What has changed under the EU AI Act

The AI Act splits all AI systems into four risk tiers, from minimal risk to practices that are banned outright. Mass-scraping faces from the internet or CCTV footage to build a facial-recognition database is now expressly prohibited under Article 5 of the AI Act – no exceptions, no proportionality test. This isn’t a high-risk category you can manage with documentation and an audit. It’s a red line, and the price of crossing it is no longer tens of millions under the GDPR – it’s up to €35 million or 7% of worldwide annual turnover for a single infringement.

 

5. What businesses should check now

To protect your business, start by taking a hard look at two things: whether your product is available to users in the EU, and which of the four risk tiers it falls into. Doing this early lets you pin down exactly which requirements and penalties apply to you.

Lawyers at REVERA Law Group are ready to help assess which risk tier your product falls into, and to guide your AI startup’s launch in the European market with full legal support at every step.

Write to us










    Send request