Under GDPR Article 83(5), infringements of specified GDPR provisions may be subject to fines of up to EUR 20,000,000 or 4% of worldwide annual turnover.
For prohibited AI practices, the cited compliance summaries identify maximum fines of EUR 35,000,000 or 7% of worldwide annual turnover.
The immediate legal position is one of operational uncertainty: a company cannot determine its obligations under the AI Act until every deployed tool has been inventoried and classified.
The AI Act is described as applying to companies that develop, purchase, or deploy AI systems in the European Union.
The lowest-risk scenario is administrative: the company establishes an inventory, assigns owners, classifies systems, and integrates review into procurement and operations.
Because the Grand Chamber ordered release and quashing of the conviction, Türkiye now has a compliance obligation covering both custody and conviction.
Osman Kavala’s position is no longer merely a detention dispute; the evidence indicates that his conviction itself is legally unsustainable.
The Grand Chamber’s finding changes the practical legal burden on the Turkish authorities. The evidence states that the Court examined the indictment, charges, evidence, trial, appeals, and conviction, and then found a “flagrant denial of justice.”
The case law in the evidence is the Kavala line of European Court judgments. In December 2019, the Court found unlawful detention and an ulterior purpose of silencing him as a human-rights defender. In July 2022, the Court found that Türkiye had breached its obligation to abide by the 2019 judgment. The latest Grand Chamber judgment goes further because it covers the entire Gezi proceedings and the conviction. It also finds violations of the right to a fair trial, freedom of expression and association, and the prohibition of inhuman and degrading treatment arising from the aggravated life sentence. The cited EU rules show how different legal instruments address enforcement, but they do not displace the Convention mechanism described in the news report. Those Regulations apply directly in every Member State, yet the evidence provides no basis for treating them as governing this ECHR compliance dispute.
For Kavala, the direct practical consequence is release without making it conditional on ordinary domestic criminal finality. For his conviction, the practical consequence is that the state must set it aside, not merely reconsider detention.
The broader legal significance is institutional rather than financial. The supported consequences are release, quashing of the conviction, remedial measures for judicial shortcomings, and intensified Council of Europe supervision. The next expected step is action by the Turkish authorities to release Kavala and set aside the conviction.
Article 35(3)(a) GDPR requires an impact assessment for systematic automated evaluation that produces legal or similarly significant effects.
Under Article 7, that authority may issue binding technical recommendations on the risk levels of AI systems.
Colombian deployers would be in the most difficult position because the bill regulates the use of AI, even where control rests with foreign developers. Although Bill 025 of 2026 is currently only before the Colombian House of Representatives, it would make AI adoption a compliance exercise. The legal issue is whether Colombia can allocate AI-related duties on a risk-based basis without overburdening actors that lack technical control. The decisive provisions are Articles 5 and 7 of Bill 025 of 2026, together with the impact-assessment model reflected in Article 35 GDPR.
The bill’s structure assigns duties to developers, providers and deployers according to the role they perform in relation to an AI system. Those duties include risk and impact assessments, transparency, human oversight and monitoring for systems affecting fundamental rights or protected interests.
The GDPR is a Regulation and therefore applies directly in every Member State. Article 35(7) GDPR indicates what an assessment must contain: a description of the processing, necessity, proportionality, risks, safeguards and compliance mechanisms. Article 35(9) GDPR also supports obtaining input from affected persons where appropriate. The Colombian bill would centralise risk-classification authority in an executive body. Under Article 5, it may update high-risk uses by reasoned administrative act following public consultation. That design raises a due-process concern because risk classification triggers enhanced legal obligations and may affect deployment. The evidence indicates that final intervention measures remain with the authorities that hold the relevant legal powers. Even so, classification must remain linked to clear legislative criteria and effective review. The Inter-American Court’s judgment in Velásquez Rodríguez v. Honduras is relevant because formal rights require enforceable state conditions. Suárez Peralta v. Ecuador points in the same direction for duties that require monitoring, investigation and enforcement capacity. Applied here, impact assessments and audits have limited legal force without technical expertise, infrastructure, information and budget.
The practical effect is not immediate sanctioning, because the bill is still pending before the Colombian House of Representatives. The market consequence is planning pressure for companies using AI in health, justice, security, surveillance and public services.
If enacted as described, the first disputes are likely to concern who controls the AI system and who can provide compliance evidence. A small Colombian company using a closed foreign model could be required to explain a system it cannot inspect. That mismatch is the bill’s central enforcement risk.