AI Library

AI Library

Books for Reading AI

Choose a book, then read it in order from the table of contents.

Chinese Government AI Regulations cover

Contents

Chinese Government AI Regulations

Kim Kyung-jin, Attorney at Law

Chinese originals, translations, terms, issuing bodies, effective dates, administrative interpretations, and judicial materials

This edition orders Chinese AI-related laws, administrative regulations, military regulations, departmental rules, policy documents, and national standards by legal force. Each entry keeps the Chinese original text and adds an English translation or explanation, legal terms, issuing body, effective date, administrative interpretations, and judicial materials where available.

Fathers of Chinese AI cover

Table of Contents

Fathers of Chinese AI

Kim Kyung-jin, Attorney at Law

Ten lives behind China's AI ascent

This book follows Kai-Fu Lee, Robin Li, Jie Tang, Liang Wenfeng, Yang Zhilin, Yan Junjie, Wang Xiaochuan, Jingren Zhou, Shunyu Yao, and Yonghui Wu through the laboratories, companies, models, and policy environment that shaped Chinese AI.

How Far Has AI Entered Chinese Hospitals? cover

Table of Contents

How Far Has AI Entered Chinese Hospitals?

Kim Kyung-jin, Attorney at Law

A quiet shift in clinics, imaging rooms, and hospital administration

This book follows how artificial intelligence has entered Chinese hospitals, using Chinese and English materials together with original Chinese policy texts. It covers national policy, medical foundation models, clinical decision support, image reading, hospital information departments, traditional Chinese medicine, AI-native hospitals, the patient experience, hallucination and responsibility, regulation, and money. The final chapters collect major Chinese guidelines and the 84 health-sector AI application scenarios, with translated text and summaries.

Andrew Ng Biography cover

Table of Contents

Andrew Ng Biography

Kim Kyung-jin, Attorney at Law

A central figure in AI education and public learning

This book follows Andrew Ng from London, Hong Kong, Singapore, Carnegie Mellon, MIT, Berkeley, and Stanford to Google Brain, Coursera, Baidu, DeepLearning.AI, Landing AI, AI Fund, and Amazon. It reads his career through research, teaching, company building, and his practical view of AI.

Mykhailo Fedorov, Leading Figure of Ukraine's Drone War cover

Table of Contents

Mykhailo Fedorov, Leading Figure of Ukraine's Drone War

Kim Kyung-jin

From the State in a Smartphone to the Defense Ministry of the Drone War

This book follows Diia, IT Army, Starlink, UNITED24, Brave1, the Unmanned Systems Forces, drone procurement, and battlefield data to explain how Mykhailo Fedorov tied technology to state power in wartime Ukraine.

China’s Leading AI Firms and Government Agencies cover

Table of Contents

China’s Leading AI Firms and Government Agencies

Kim Kyung-jin

Policy, Companies, Data, and Hardware in China’s Intelligent Economy

This book follows China’s AI policy arc from the 2017 next-generation AI plan to AI+ and the 15th Five-Year Plan. It maps the roles of the State Council, NDRC, CAC, MIIT, and SAC, then reads DeepSeek, the AI Tigers, Alibaba, Tencent, Baidu, ByteDance, iFLYTEK, Huawei Ascend, East Data West Computing, manufacturing, education, consumption, and humanoid robotics as one connected system.

U.S. Department of War CDAO (Chief Digital and AI Officer) cover

Table of Contents

U.S. Department of War CDAO (Chief Digital and AI Officer)

Kim Kyung-jin, Attorney at Law

How the Military’s Brain Is Being Redesigned

From the moment in January 2026 when the U.S. Department of War declared data hoarding a national security threat, this book follows the birth of the CDAO (Chief Digital and Artificial Intelligence Office) and the five organizations it absorbed, Advana and the War Department Data Platform, the Open DAGIR procurement experiment, Project Maven and CJADC2 on the battlefield, and Responsible AI, allies, and critics — the story of how America is redesigning its military’s brain.

Science and Technology Commission of the CMC of the Communist Party of China cover

Table of Contents

Science and Technology Commission of the CMC of the Communist Party of China

Kim Kyung-jin

STC, Military-Civil Fusion, and China’s Military Technology Innovation

This English AI Library edition follows the CMC Science and Technology Commission, the Equipment Development Department, military-civil fusion, intelligentized warfare, emerging technology competition, and the institutional limits of China’s military innovation system.

The Chinese Communist Party School cover

Table of Contents

The Chinese Communist Party School

Kim Kyung-jin

Where Power Is Trained

This book follows the Chinese Communist Party school system from Ruijin and Yan'an to the Central Party School, the National Academy of Governance, provincial and county schools, young-official training classes, Cai Qi's leadership, and the Mwalimu Julius Nyerere Leadership School.

DARPA, America’s Defense Research Lab cover

Table of Contents

DARPA, America’s Defense Research Lab

Kim Kyung-jin

This book follows DARPA through its 2026 office reorganization, budget signals, AIxCC, AI Forge, RACER, LongShot, quantum computing, space robotics, battlefield medicine, and strategic-material programs, using official sources as the main trail.

AI and the Classroom cover

Table of Contents

AI and the Classroom

Kim Kyung-jin

The AI Teacher That Does Not Give Answers

From Estonia's AI Leap and Khanmigo to answer leakage, Korean AI digital textbooks, and teacher-in-the-loop classrooms, this book asks how AI can protect thinking instead of replacing it.

Spiderweb cover

Table of Contents

Spiderweb

Kim Kyung-jin

Ukraine's drone revolution that changed the map of war

A narrative account of Operation Spiderweb on June 1, 2025, and how Ukraine's drones reached deep inside Russia and changed military planning, intelligence work, and security assumptions.

The Architect of Contradictions cover

Table of Contents

The Architect of Contradictions

Kim Kyung-jin

Peter Thiel and the empire built by a man who hated competition

Peter Thiel, from a South African childhood to PayPal, Facebook, Palantir, politics, and the dream of defeating death.

Claude, GPT, Palantir, and the 2026 World War cover

8 readings

Claude, GPT, Palantir, and the 2026 World War

Kim Kyung-jin

How Artificial Intelligence Came to Pull the Trigger of War. Prologue, 3 Parts / 6 Chapters, Epilogue

A single name sits on the screen. An intelligence officer looks at it for twenty seconds, confirms only that it is a man, and moves on. Inside those twenty seconds a person dies, and the responsibility for deciding to kill him disappears. From Lavender over Gaza to Maven in Ukraine, Epic Furies over Iran, and target selection in the skies of Venezuela, this book follows the hand that chooses targets as it passes from human to machine in the wars of 2026.

China's Robotics Industry 2026: The Age of Mass Production and Real-World Deployment cover

25 readings

China's Robotics Industry 2026: The Age of Mass Production and Real-World Deployment

Kim Kyung-jin

From the humanoid mass-production race to U.S.-China hegemony: the state of China's robotics industry in 2026. Table of Contents, Preface, 7 Parts / 23 Chapters, Epilogue

In a factory in Shenzhen, hundreds of humanoid robots repeat the same motion. This book traces the mass-production race between Unitree and UBTECH, the Optimus supply chain, real-world deployment sites, and where Korea stands amid the U.S.-China tech hegemony.

Crossing the Adolescence of Technology Cover

15 Parts in Total

Crossing the Adolescence of Technology

Kim Kyung-jin

Dario Amodei, Anthropic, and the Struggle Toward Controllable Intelligence. Table of Contents, Preface, Prologue, 12 Chapters, Epilogue

The struggle of a physicist who lost his father to create controllable artificial intelligence. The story of Dario Amodei and Anthropic clashing with the Pentagon and the White House, shaking the era with the scaling law and Constitutional AI.

37 Concrete Codex Use Cases cover

Book-style reading

37 Concrete Codex Use Cases

Kim Kyung-jin

From morning briefings to agent swarms: 37 real-world workflow automations

This guide gathers 37 ways to connect Codex and AI agents to real work: personal routines, data processing, marketing, sales, documents, development, and browser control.

Share

2026 Beijing: The Dangerous Dance of Two Giants book cover

16 posts available

2026 Beijing: The Dangerous Dance of Two Giants

Kim Kyung-jin

Table of Contents, Introduction, 13 Chapters, Epilogue

This book reads the Beijing summit through Hormuz, rare earths, Taiwan, Boeing, soybeans, AI chips, and Korea’s exposure to the U.S.-China bargain.

Share

Leaving It to AI and Stepping Away cover

27 posts

Leaving It to AI and Stepping Away

Kim Kyung-jin

A Complete Beginner’s Guide to YOLO Mode. Table of contents and 26 chapters

A beginner-friendly online book on YOLO mode in Claude Code and Codex. It explains how to let AI read files, write code, run commands, and finish work while keeping rollback, Docker sandboxing, and safety checks close at hand.

Share

Artificial Intelligence Fighter, Artificial Intelligence Air Force book cover

43 posts available

Artificial Intelligence Fighter, Artificial Intelligence Air Force

Kim Kyung-jin

Table of Contents, Preface, 40 Chapters, Epilogue

Artificial Intelligence Fighter, Artificial Intelligence Air Force is an online AI Library book by Kim Kyung-jin. It covers AI fighters, autonomous air power, unmanned combat aircraft, CCA, MUM-T, sixth-generation fighters and is organized as Table of Contents, Preface, 40 Chapters, Epilogue.

Share

Artificial Intelligence on Trial book cover

26 posts available

Artificial Intelligence on Trial

Attorney Kyungjin Kim

Table of Contents, Preface, 21 Chapters, 3 Appendices

Artificial Intelligence on Trial is an online AI Library book by Attorney Kyungjin Kim. It covers artificial intelligence and law, AI liability, algorithmic judgment, courts and technology and is organized as Table of Contents, Preface, 21 Chapters, 3 Appendices.

Share

PALANTIR book cover

16 posts available

PALANTIR: War, Surveillance, Artificial Intelligence

Attorney Kyungjin Kim

Table of Contents, Preface, 14 Chapters

PALANTIR: War, Surveillance, Artificial Intelligence is an online AI Library book by Attorney Kyungjin Kim. It covers Palantir, war, surveillance, artificial intelligence, data analytics, national security and is organized as Table of Contents, Preface, 14 Chapters.

Share

Brain Readers: Neuralink and the Final Human Revolution book cover

21 posts available

Brain Readers: Neuralink and the Final Human Revolution

Kim Kyung-jin

Table of Contents, Prologue, 18 Chapters, Epilogue

Brain Readers: Neuralink and the Final Human Revolution is an online AI Library book by Kim Kyung-jin. It follows Neuralink, brain-computer interfaces, brain data, medicine, neurorights, and the future of human enhancement.

Share

Artificial Intelligence and the Reshaping of Society book cover

16 posts available

Artificial Intelligence and the Reshaping of Society

Kim Kyung-jin

Table of Contents, Preface, 13 Chapters, Epilogue

Artificial Intelligence and the Reshaping of Society is an online AI Library book by Kim Kyung-jin. It follows how artificial intelligence changes work, education, inequality, cities, democracy, and human relationships.

Share

The Jensen Huang Story book cover

16 posts available

The Jensen Huang Story

Kim Kyung-jin

Table of Contents, Preface, 13 Chapters, Epilogue

The Jensen Huang Story is an online AI Library book by Kim Kyung-jin. It covers Jensen Huang, NVIDIA, GPUs, AI chips, and the AI industry.

Share

Ten Questions AI Poses to Humanity book cover

12 posts available

Ten Questions AI Poses to Humanity

Kim Kyung-jin

Table of Contents, Preface, 10 Chapters

Ten Questions AI Poses to Humanity is an online AI Library book by Kim Kyung-jin. It asks how artificial intelligence changes truth, weapons, work, data, identity, and human control.

Share

Malaysia and the Malacca Strait book cover

23 posts available

Malaysia and the Malacca Strait: Whoever Controls It Controls the World

Kim Kyung-jin

Table of Contents, Preface, 20 Chapters, Epilogue

Malaysia and the Malacca Strait is an online AI Library book by Kim Kyung-jin. It covers Malaysia, the Malacca Strait, maritime logistics, geopolitics, global trade, and Southeast Asia’s strategic future.

Share

Georgia history and culture travel book cover

24 posts available

A Journey Through Georgia’s History and Culture

Kim Kyung-jin

Table of Contents, Preface, 17 Chapters, 4 Appendices, Epilogue

A Journey Through Georgia’s History and Culture is an online AI Library book by Kim Kyung-jin. It covers Georgia’s history, culture, religion, politics, travel, and the Caucasus crossroads between Europe and Asia.

Share

Reading Armenia book cover

13 posts available

Reading Armenia: A Thousand Prayers, One Mountain

Kim Kyung-jin

Table of Contents, Preface, 10 Chapters, Epilogue

Reading Armenia: A Thousand Prayers, One Mountain is an online AI Library book by Kim Kyung-jin. It covers Armenian history, faith, Mount Ararat, cultural memory, travel, and the endurance of a small nation.

Share

Mastering Claude Code book cover

41 posts available

Mastering Claude Code

Kim Kyung-jin

Table of Contents, Preface, Chapters, Appendices

Mastering Claude Code is an online AI Library book by Kim Kyung-jin. It covers Claude Code setup, commands, workflows, automation, agents, and practical methods for using Claude Code in real work.

Share

Claude Cowork and Agent manual book cover

11 posts available

Claude Cowork and Agent Utilization Manual

Kim Kyung-jin

Table of Contents, Preface, 8 Chapters, Closing Note

Claude Cowork and Agent Utilization Manual is an online AI Library book by Kim Kyung-jin. It covers Claude Code, AI agents, coding automation, work automation, and practical agent-based collaboration.

Share

2026 U.S.-Iran War and the Global Energy Crisis book cover

39 posts available

The 2026 U.S.-Iran War and the Global Energy Crisis

Kim Kyung-jin

Table of Contents, Preface, Chapters and Appendices

The 2026 U.S.-Iran War and the Global Energy Crisis is an online AI Library book by Kim Kyung-jin. It covers war, oil, the Strait of Hormuz, maritime security, energy markets, and the global consequences of conflict.

Share

The Traces Han Dong-hoon Left on South Korea book cover

13 posts available

The Traces Han Dong-hoon Left on South Korea

Kim Kyung-jin

Table of Contents, Prologue, Chapters, Epilogue

The Traces Han Dong-hoon Left on South Korea is an online AI Library book by Kim Kyung-jin. It examines his record in justice policy, immigration reform, public institutions, and the structural questions facing South Korea.

Share

The Han Dong-hoon Story book cover

39 posts available

The Han Dong-hoon Story

Kim Kyung-jin

Table of Contents, Prologue, Chapters, Epilogue

The Han Dong-hoon Story is an online AI Library book by Kim Kyung-jin. It traces Han Dong-hoon’s life, public career, political choices, and the changing landscape of South Korean conservative politics.

Share

Beyond the Glass Ceiling cover

39 entries

Beyond the Glass Ceiling

Kim Kyung-jin

Table of contents, prologue, 31 chapters, epilogue, 5 appendices

A political biography tracing Sanae Takaichi’s rise from Nara to Japan’s premiership, through party struggles, security policy, diplomacy, and the meaning of Japan’s first female prime minister.

Share

AI Hegemony War book cover

8 posts available

AI Hegemony War

Kim Kyung-jin

Table of Contents, 7 Chapters

An online AI Library book by Kim Kyung-jin on AI superintelligence, the U.S.-China technology race, Europe and Korea’s AI laws, and international AI governance.

Share

Sam Altman Biography: Pioneer of the AI Revolution cover

22 posts

Sam Altman Biography: Pioneer of the AI Revolution

Kim Kyung-jin, Kim Kyung-ran

Table of contents, preface, 7 parts, 20 chapters

An online biography following Sam Altman’s childhood, startups, Y Combinator, OpenAI, ChatGPT, the 2023 board crisis, and his sense of responsibility in the AI era.

Share

From Chaiwala to Prime Minister cover

13 entries

From Chaiwala to Prime Minister

Kim Kyung-jin

Table of contents, preface, 10 chapters, epilogue

A political biography tracing Narendra Modi from a chai-selling boy in Vadnagar to RSS organizer, Gujarat chief minister, and three-term prime minister, while reading modern India, Korea-India relations, and the risks of a rising power.

Share

AI Classroom: Your Grades Will Change book cover

26 posts available

AI Classroom: Your Grades Will Change

Kim Kyung-jin

Table of Contents, Preface, 24 Sections

An online AI Library book by Kim Kyung-jin on how AI can support elementary, middle, and high school learning, teaching, assessment, and educational equity.

Share

Military Artificial Intelligence cover

17 entries

Military Artificial Intelligence

Kim Kyung-jin and Kim Won-tae

Table of contents, preface, 14 chapters, epilogue

A full-length study of military artificial intelligence, from autonomous weapons, drones, command systems, logistics, and cyber defense to the strategies of the United States, China, Israel, Korea, and global defense AI companies.

Share

Global Case Studies in Introducing AI into Public Administration book cover

25 posts available

Global Case Studies in Introducing AI into Public Administration

Kim Kyung-jin

Table of Contents, 23 Chapters, Epilogue

An online AI Library book by Kim Kyung-jin on public-sector AI adoption, national strategies, administrative services, governance, and future policy tasks.

Share

Seven Misunderstandings About the Arctic Route book cover

10 posts available

Seven Misunderstandings About the Arctic Route

Kim Kyung-jin

Table of Contents, Preface, 7 Chapters, Epilogue

An online AI Library book by Kim Kyung-jin on seven common misunderstandings about the Arctic Route, including speed, liner service, insurance, safety rules, year-round access, carbon impact, and infrastructure.

Share

Artificial Intelligence Election cover

14 posts

Artificial Intelligence Election

Kim Kyung-jin

Table of contents, author preface, 11 chapters, closing essay

An online book on campaign messaging, publicity materials, digital campaigning, data analysis, campaign operations, disinformation defense, legal risk, and ready-to-use prompts.

Share

Demis Hassabis book cover

34 posts available

Demis Hassabis, Father of Google’s Artificial Intelligence

Kim Kyung-ran, Kim Kyung-jin

Table of Contents, Author’s Preface, 31 Chapters, Epilogue

Demis Hassabis, Father of Google’s Artificial Intelligence is an online AI Library book by Kim Kyung-ran, Kim Kyung-jin. It covers Demis Hassabis, Google DeepMind, artificial intelligence, AlphaGo, AI research and is organized as Table of Contents, Author’s Preface, 31 Chapters, Epilogue.

Share

The Dhammapada 423 Verses book cover

28 posts available

The Dhammapada: 423 Verses

Kim Kyung-jin

Table of Contents, Editor’s Note, 26 Chapters, 423 Verses

An online AI Library book by Kim Kyung-jin. This edition arranges all 423 verses of the Dhammapada into 26 chapters for slow, poetic reading.

Share

Nano Banana Pro Practical Prompt Book cover

24 posts

Nano Banana Pro Practical Prompt Book

Kim Kyung-jin

6 parts, 22 chapters, classroom prompt appendix

An online book for using Nano Banana Pro in classes and real work, covering image generation, editing, text rendering, character consistency, business use cases, and monetization.

Share

Liberal Arts AI for College Students book cover

16 posts available

Liberal Arts AI for College Students

Kim Kyung-jin

Table of Contents, Preface, 13 Chapters, Closing Essay

An online AI Library textbook for college students. It introduces AI history, daily use, document work, research, images, presentations, video, productivity, learning, careers, copyright, and governance.

Share

Legal Practice and Artificial Intelligence book cover

16 posts available

Legal Practice and Artificial Intelligence

Kim Kyung-jin

Table of Contents, Preface, 14 Parts

An online AI Library book by Kim Kyung-jin on legal research, drafting, evidence analysis, contract review, NotebookLM, and practical generative AI workflows for legal practice.

Share

Hello, I Am Kim Kyung-jin book cover

10 posts available

Hello, I Am Kim Kyung-jin

Kim Kyung-jin

Table of Contents, Preface, Recommendations, 6 Chapters, Closing

An online AI Library book on Kim Kyung-jin’s life, science and technology policy, parliamentary diplomacy, legislative battles, Dongdaemun vision, and proposals for Korea’s demographic future.

Share

Politics and People book cover

25 posts available

Politics and People

Kim Kyung-jin

Table of Contents, Prologue, 22 Chapters, Epilogue

An online AI Library book by Kim Kyung-jin on how politics begins with reading people, winning trust, keeping relationships, and enduring seasons of crisis.

Share

[AI Library] Chapter 7. GDPR and EU Regulation

Artificial Intelligence on Trial
Author
Attorney Kyungjin Kim
Date
2026-05-05 09:53
Views
799

Artificial Intelligence on Trial

Part 2. Algorithmic Discrimination and Regulatory Enforcement

Chapter 7. GDPR and EU Regulation

Attorney Kyungjin Kim

A. The Company That Stole 30 Billion Facial Photos (Clearview AI)

(1) Netherlands: 30.5 Million Euro Fine

On May 16, 2024, Aleid Wolfsen, chair of the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), signed the decision.

It imposed a fine of 30.5 million euros on Clearview AI, a facial recognition company headquartered in New York. When the decision was made public on September 3 of the same year, Wolfsen told reporters: "Facial recognition is a highly intrusive technology. You cannot simply unleash it on everyone in the world."

To understand what Clearview AI did, you first need to understand their business model.

The company crawls the internet collecting photos of people's faces. From Facebook, Instagram, LinkedIn, news sites, every publicly accessible webpage. Automated programs called crawlers perform this work. Each collected facial image is converted through an algorithm into a unique biometric code, a combination of numbers that can identify each person like a fingerprint. As of 2024, Clearview's database held more than 30 billion facial photos. The company's website boasted 50 billion.

This database was sold to law enforcement agencies.

When police capture a face from CCTV footage at a crime scene, they upload it to the Clearview system. The system searches through 30 billion photos for a matching face. It then reveals where that photo came from, the person's name, and which social media accounts are linked to them. A useful tool for criminal investigations.

The problem is that not a single one of the billions of people in this database knew their face was being collected. No one was ever asked for consent. The Dutch Data Protection Authority determined this violated multiple GDPR provisions.

First, a violation of Article 6. Processing personal data requires a lawful basis. It must fall under one of six grounds: consent, contract performance, legal obligation, legitimate interest, and so on. Clearview met none of them.

Second, a violation of Article 9. Biometric data is classified as sensitive information. It requires stricter protection. Collection itself is prohibited without explicit consent.

Third, a violation of Article 14. When personal data is collected from third parties, the data subject must be informed. Clearview never informed anyone.

Beyond the 30.5 million euro fine, the Dutch Data Protection Authority issued four corrective orders. If the violations are not stopped, an additional 5.1 million euros in penalty payments will be imposed. Chair Wolfsen went a step further: "We are now investigating whether we can hold company executives personally liable. Directors who knew about these violations and failed to prevent them can be held personally responsible."

Clearview's response was predictable. The company's chief legal officer, Jack Mulcaire, called the decision "unlawful, lacking due process, and unenforceable." His logic ran like this: Clearview has no establishment in the Netherlands. It has no customers in the EU. Therefore GDPR does not apply.

This is where the concept of GDPR's extraterritorial application comes in. Article 3 of GDPR stipulates that even companies outside the EU are subject to the law if they process the personal data of EU residents. The moment Clearview collected Dutch citizens' faces, the Dutch Data Protection Authority's jurisdiction was triggered. Clearview did not challenge the decision. It therefore lost its right to appeal. But it showed no intention of paying the fine either.

(2) Sanctions in the UK, France, and Italy

The Netherlands was not alone. Clearview AI faced a barrage of fines across Europe.

France's data protection authority, CNIL, imposed a 20 million euro fine on Clearview in October 2022. It also ordered the company to stop collecting and processing data of individuals within French territory and to delete data already collected.

Clearview was required to submit evidence of compliance within two months. In May 2023, CNIL announced that Clearview had failed to comply and imposed an additional fine of 5.2 million euros.

The European Data Protection Board (EDPB) confirmed in a 2023 report that Clearview had not submitted any evidence of compliance.

Italy's data protection authority (Garante) imposed 20 million euros in March 2022. The UK Information Commissioner's Office (ICO) imposed 7.5 million pounds (approximately 9 million euros) in May of the same year. The Greek Data Protection Authority also imposed sanctions in 2022. The cumulative total approached 100 million euros.

The UK case followed a legally complex path. When the ICO issued its fine and enforcement notice in May 2022, Clearview appealed. The company's argument was this: we only provide services to law enforcement and national security agencies outside the UK. Such activities fall outside the scope of GDPR. In October 2023, the First-tier Tribunal sided with Clearview, ruling that the ICO had no jurisdiction.

The ICO appealed. On January 31, 2025, the Upper Tribunal granted permission to appeal. Hearings took place from June 9 to 11 of the same year. Privacy International, a civil society organization, participated as an intervener. On October 6, 2025, the Upper Tribunal delivered its judgment. It accepted three of the ICO's four grounds of appeal.

The Upper Tribunal's reasoning addressed three key issues. First, whether Clearview's data processing relates to 'behavioral monitoring' of UK residents. The tribunal found that it does. The concept of 'behavioral monitoring' must be interpreted broadly. It includes not only real-time surveillance but also passive data collection, categorization, and storage for future profiling purposes. The very act of Clearview collecting facial images, generating biometric codes, and storing them in a database constitutes behavioral monitoring.

Second, whether Clearview is exempt from UK data protection law because it provides services to foreign law enforcement agencies. The tribunal found it is not. Clearview itself is not a law enforcement body. It is a private company providing a commercial service. It cannot claim exemption simply because its customers happen to be law enforcement agencies.

Third, whether the First-tier Tribunal misapplied the law. The Upper Tribunal found that it did. The case was remanded to the First-tier Tribunal. A hearing on the merits will proceed on the premise that the ICO has jurisdiction.

On December 19, 2025, the Upper Tribunal granted Clearview permission to proceed to the next stage of appeal. The case is set to move to the Court of Appeal. UK Information Commissioner John Edwards said: "The Upper Tribunal's decision confirms our ability to protect against the unauthorized collection of UK residents' data for use in a global online database."

(3) Limits and Effectiveness of GDPR's Extraterritorial Application

Fines totaling close to 100 million euros have been imposed across Europe. But there is one uncomfortable truth. Clearview has not paid a single cent.

This is the fundamental limitation of GDPR's extraterritorial application. The law applies to companies outside the EU. But if a company outside the EU has no assets within the EU, how can fines be collected? Clearview is in New York. It has no offices in Europe, no bank accounts, no equipment. The Dutch Data Protection Authority has nothing to seize.

That does not mean these sanctions are meaningless. They produce real effects.

First, market access is blocked. Clearview can no longer legally enter the EU market. Any organization within the EU that uses Clearview's services risks GDPR sanctions itself. Chair Wolfsen issued a clear warning: "Dutch organizations that use Clearview's services should expect a substantial fine from the Dutch Data Protection Authority."

Second, there is a de facto business ban. Clearview's website now states: "Clearview AI does not provide its technology in the EU, the UK, Australia, or Canada." This is not a voluntary withdrawal. It is a retreat under regulatory pressure.

In October 2025, the Austrian digital rights organization noyb (None of Your Business) tried a new strategy. It filed a criminal complaint with Austrian prosecutors. The charge: illegal collection of civilians' biometric data. noyb's argument was this: if administrative fines don't work, criminal prosecution must be attempted. If international arrest warrants are issued for Clearview executives, they will be unable to visit any European country.

This signals a new phase in data protection enforcement. A shift from administrative sanctions to criminal penalties. An expansion from fines against companies to personal accountability for individuals. The Clearview case exposes the gap between GDPR's ambition and reality. At the same time, it shows that creative attempts to close that gap are underway. But the fundamental question remains: how can regulators confined by borders control companies that transcend them in the digital age? Clearview proves that this question still has no answer.

B. Other GDPR Enforcement Cases

(1) Budapest Bank AI Credit Scoring Sanction

In 2022, Hungary's National Authority for Data Protection and Freedom of Information (NAIH) imposed a fine of approximately 250 million forints (about 670,000 euros) on Budapest Bank.

The reason: the bank used AI to analyze customer emotions during customer service calls.

The bank's system worked like this.

When a customer called the call center, the conversation was recorded. AI analyzed the recording to determine the customer's emotional state. Angry, satisfied, anxious. This information was added to the customer profile and used for future services and marketing.

The problem was that customers did not know. There was a notice that calls were being recorded. But there was no notice that AI was analyzing their emotions. Articles 12 through 14 of GDPR establish transparency obligations. Data subjects must be clearly informed about how their personal data is processed. Budapest Bank failed to meet this obligation.

A larger issue relates to Article 22 of GDPR. This provision concerns automated decision-making. Decisions that produce legal effects or significantly affect an individual must not be based solely on automated processing. The final decisions were made by human employees, yes. But if AI emotion analysis influenced those decisions, does that not circumvent the intent of Article 22?

The Hungarian authority determined that it does. Even if AI does not make the decision directly, transparency obligations arise when AI profiling influences human decisions. This ruling became an important precedent. It established the principle that even when AI is used as an auxiliary tool, customers must be informed of its use.

(2) LinkedIn Data Processing Violation

On October 24, 2024, Ireland's Data Protection Commission (DPC) imposed a fine of 310 million euros on LinkedIn. The decision found that the Microsoft-owned business networking platform had violated the GDPR.

The case traces back six years. On August 20, 2018, the French digital rights organization La Quadrature du Net filed a complaint with France's data protection authority, CNIL.

The complaint alleged that LinkedIn was unlawfully using personal data for behavioral analysis and targeted advertising. CNIL transferred the complaint to Ireland's DPC because LinkedIn's European headquarters is in Dublin.

The investigation took six years.

What the DPC examined was how LinkedIn processed user data. LinkedIn collects two types of data.

First, there is first-party data that users provide directly: profile information, posts, connections, and so on.

Second, there is third-party data collected through partner organizations: records of users visiting other websites, app usage patterns, and similar information.

LinkedIn analyzes this data to identify behavioral patterns. What content does a user engage with? Which ads do they respond to? Based on this information, LinkedIn serves targeted advertising.

The problem was that LinkedIn lacked a lawful basis for this processing.

Article 6 of the GDPR limits the lawful bases for processing personal data to six. LinkedIn claimed three. First, consent (Article 6(1)(a)). The DPC found that the consent LinkedIn obtained was "not freely given, not sufficiently informed, not specific, and not unambiguous." Second, contractual necessity (Article 6(1)(b)). The DPC determined that behavioral analysis and targeted advertising were not contractually necessary to provide LinkedIn's service. Third, legitimate interests (Article 6(1)(f)). The DPC concluded that LinkedIn's interests were "overridden by the interests and fundamental rights and freedoms of the data subjects."

LinkedIn had processed personal data without a lawful basis. This is a violation of the most fundamental principle of the GDPR. DPC Deputy Commissioner Graham Doyle stated: "The lawfulness of processing is a fundamental aspect of data protection law. Processing personal data without an appropriate legal basis is a clear and serious violation of the data subjects' fundamental rights."

The 310 million euro fine was imposed for three separate violations. 105 million euros for the consent-related violation. 110 million euros for the legitimate interests violation. 95 million euros for breaching transparency obligations. Microsoft had already set aside 425 million dollars in 2023 as a provision for potential fines in this case. The actual penalty came in lower than that.

LinkedIn issued a statement: "We believe we have been in compliance with the GDPR. However, we are working to ensure our advertising practices meet this decision within its deadlines." The company did not clearly state whether it would appeal.

(3) Meta's Texas Settlement: $1.4 Billion for Facial Recognition

On July 30, 2024, Texas Attorney General Ken Paxton announced a historic settlement. Meta (formerly Facebook) agreed to pay $1.4 billion to the state of Texas. It was the largest privacy-related settlement with a single U.S. state in American history.

At the heart of this case was a feature called "Tag Suggestions." From 2011 to 2021, when users uploaded photos to Facebook, the platform automatically recognized faces and asked, "Is this [friend's name]?" It was a convenient feature. The problem was that it collected and stored facial geometry data without users' consent.

Texas enacted its biometric privacy law, the Capture or Use of Biometric Identifier Act (CUBI), in 2009. The law requires companies to obtain written consent before collecting an individual's biometric information. Facebook's Tag Suggestions feature did not meet this requirement.

Attorney General Paxton filed the lawsuit in February 2022. His argument was this: Facebook had illegally collected the biometric data of millions of Texas residents for a decade. This violated both CUBI and the Texas consumer protection statute. In the 2024 settlement, Meta did not admit liability. But it agreed to pay $1.4 billion, spread over five years, with $500 million due in the first year.

This case does not involve the GDPR. It is a sanction under U.S. state law. But it carries the same message. Unauthorized collection of biometric data is producing increasingly severe legal consequences worldwide.

Meta had already settled an Illinois BIPA (Biometric Information Privacy Act) class action for $650 million in 2020. Adding the $1.4 billion Texas settlement, the legal costs from the Tag Suggestions feature alone exceeded $2 billion. It was no coincidence that Meta discontinued the feature entirely in 2021.

C. The EU AI Act Framework

(1) Implementation Timeline and Penalty Structure

On August 1, 2024, the EU AI Act entered into force. It is the world's first comprehensive AI regulation. But entry into force does not mean immediate application. The law applies in phases, giving companies time to prepare.

The first application date was February 2, 2025. From that day, prohibited AI practices became illegal. What was banned? Social scoring, meaning systems that rate people based on their social behavior. Manipulative AI that exploits vulnerable groups. Real-time remote biometric identification for law enforcement purposes. These AI systems had to be removed from the EU market.

The second application date was August 2, 2025. Regulations for General-Purpose AI (GPAI) models began to apply. Large language models like ChatGPT, Claude, and Gemini fall into this category. Any new GPAI model released after this date must meet the law's requirements.

The third application date is August 2, 2026. Regulations for high-risk AI systems will be fully enforced. The European Commission's AI Office will have full enforcement powers, including the authority to request information, access models, and order model recalls.

The fourth application date is August 2, 2027. The grace period for high-risk AI systems embedded in regulated products expires. GPAI models released before August 2, 2025 must also comply with the law by this date.

The penalty structure is divided into three tiers based on the severity of the violation. For the most serious violations, using prohibited AI practices, the maximum fine is 35 million euros or 7% of global annual revenue, whichever is higher. For violations of high-risk AI requirements, the maximum is 15 million euros or 3% of revenue. For providing false information, the maximum is 7.5 million euros or 1.5% of revenue. Industry lobbied for an enforcement moratorium. There were calls to "stop the clock." The European Commission refused, stating that the timeline was final and would not change. In 2025, however, the Commission's "Digital Simplification Package" proposed that the application date for high-risk rules could be adjusted by up to 16 months. This was intended to give companies time until standards and support tools are ready.

(2) High-Risk AI Regulatory Requirements

The EU AI Act adopts a risk-based approach. It does not regulate all AI equally. Regulatory intensity varies according to risk level. The strictest regulation applies to "high-risk" AI systems.

What qualifies an AI system as high-risk? It is AI used in sectors listed in the law's annexes.

Safety components of medical devices. AI used in educational institutions for student assessment or admission decisions.

AI used in employment processes for recruitment, promotion, or termination decisions.

AI used for credit scoring or insurance underwriting.

AI used in law enforcement for criminal risk assessment.

AI used in immigration management for visa application screening.

These high-risk AI systems must meet strict requirements before being placed on the market.

First, a risk management system must be established. A continuous process for identifying, analyzing, evaluating, and mitigating risks throughout the AI system's lifecycle is required.

Second, data governance is required. Training data quality must be managed, and bias must be prevented.

Third, technical documentation must be prepared. How the system works and what data it was trained on must be documented.

Fourth, transparency and explainability must be ensured. Users must be able to understand the AI's decisions.

Fifth, human oversight must be guaranteed. Even if AI operates autonomously, humans must be able to intervene.

Sixth, accuracy, resilience, and cybersecurity must be ensured. A conformity assessment must be completed before market placement. In some cases, a third-party assessment is required. Systems that meet the requirements can carry the CE mark. The CE mark is a mandatory condition for entering the EU market.

(3) Regulation of General-Purpose AI Models

General-Purpose AI (GPAI) models have their own separate regulatory framework.

What is a GPAI model? It is a general-purpose AI model capable of performing a variety of tasks: generating text, creating images, writing code, and more. ChatGPT is the most prominent example. The EU AI Act defines these models as those trained with computing power of 10^23 FLOP (floating-point operations) or more.

All GPAI model providers have transparency obligations. They must prepare and maintain technical documentation. They must establish copyright policies. They must publish a summary of training data. They must provide downstream providers with the information they need.

Some GPAI models are classified as posing 'systemic risk.'

These are models trained with 10^25 FLOP or more, or models with high-impact capabilities.

Providers of such models bear additional obligations.

They must conduct adversarial testing (red teaming).

They must report serious incidents to the AI Office.

They must implement reinforced cybersecurity measures.

They must report energy consumption.

On July 10, 2025, the European Commission published the GPAI Code of Practice. This is a voluntary tool that guides GPAI providers on how to comply with their legal obligations.

It consists of three chapters: transparency, copyright, and safety and security.

Companies that sign the Code of Practice receive a 'presumption of conformity.' In other words, they are deemed to be in compliance with the law.

This reduces the administrative burden and increases legal certainty. As of August 1, 2025, major AI companies including Amazon, Google, Microsoft, OpenAI, and Anthropic have signed on. Notably, xAI (Elon Musk's company) signed only the safety and security chapter, declining to sign the transparency and copyright chapters. The company must demonstrate compliance with those obligations through other means. The AI Office is housed within DG CONNECT at the European Commission. It holds supervisory authority over GPAI models. Full enforcement powers take effect on August 2, 2026. Until then, the AI Office works informally with providers to support compliance.

The multi-jurisdictional sanctions against Clearview AI revealed both the ambition and the limits of GDPR's extraterritorial reach. The EU AI Act was designed with that experience in mind. If AI companies want access to the EU market, they must follow EU rules. This is the 'Brussels Effect,' the phenomenon by which EU regulation becomes a global standard. Whether this effect will hold in the AI sector should become clear within the next few years.

Kim Kyung-jin

Attorney · Former Member of the National Assembly · AI Policy Researcher

kimkj.com

© 2026 Kim Kyung-jin. All rights reserved.

#KimKyungjin #AttorneyKyungjinKim #AILibrary #ArtificialIntelligence #AIOnTrial #AILitigation #Copyright #AIRegulation #GenerativeAI #AILaw
kimkj.com Home
Scroll to Top
kimkj.com Home