Skip to content

Regulatory

EUR 30.5 million.

The largest amount in our European claims dataset was not handed down by a civil court. It came from a data protection authority.

Contemporary glass building lit at dusk on a Swiss campus.

Thirty million five hundred thousand euros, in the Netherlands, for biometric collection and processing carried out without consent. Against the rest of the dataset, that single case weighs more than five hundred times the second known amount.

Three of the seventeen cases fall into this category: personal data and compliance. They are also the ones whose cost is most predictable, because an administrative fine is computed on a published scale, whereas a civil loss is negotiated.

For a director, the lesson is simple: the first creditor of an agent gone wrong is not necessarily the customer who suffered. It is often the regulator — and it does not need a victim to file a complaint before acting.

For an insurer, that predictability is good news. A risk whose scale is known is a risk that can be priced. What remains is to know, agent by agent, which data it touches and on what legal basis.

This is one of the five dimensions we measure: exposure. Not the compliance declared on a questionnaire, but what the system actually reaches.

Source: European Agentic AI Loss Database, compiled by Garenzia from the public OECD AIM screening and the AI Incident Database.

Get your first agent assessed.

Get an agent assessed