Public-data benchmarks

What the data actually shows.

Aggregated public statistics on AI compliance + enforcement across the EU + US, sourced from official agency publications, EDPB consolidated reports, ENISA annual threat landscapes, EIOPA + CFPB + EEOC + HUD enforcement data, and independent academic + practitioner trackers. Every number below has a primary source.

What this page is not

These are NOT Promethean customer statistics. We're pre-revenue + don't have aggregate customer data to publish honestly. When we do — with sufficient customer base for de-identified aggregation — that data will appear here clearly labeled as 'Promethean platform data' and distinguished from public agency data. Until then, every figure cited is from a public source linked directly below the stat.

GDPR enforcement

Cumulative GDPR fines (2018 → mid-2025)

€5.88B

Cumulative fines issued by EU DPAs under GDPR since enforcement began in May 2018. Source: EDPB consolidated enforcement tracker + national DPA annual reports aggregated by independent researchers.

GDPR Enforcement Tracker (CMS Hasche Sigle)

Largest single GDPR fine to date

€1.2B

Issued by the Irish Data Protection Commission against Meta Platforms Ireland (2023) for unlawful transfer of personal data to the US in violation of GDPR Art. 46. Largest single penalty under GDPR.

Irish Data Protection Commission

Annual EDPB consistency-opinion volume (2024)

~30 opinions

Opinions issued by the European Data Protection Board under GDPR Art. 64 for cross-border / consistency-mechanism cases. Trending upward as AI + cross-border enforcement matures.

EDPB annual report 2024

EU AI Act implementation

Member states with designated National Competent Authority (as of Aug 2025)

All 27

Required by AI Act Art. 70 by 2 August 2025. Most designations went to existing DPAs; some to sector-specific regulators (e.g. Spain's AESIA, Italy's AgID coordination). Coordination protocols still maturing.

European Commission — AI Office register

GPAI Code of Practice signatories (initial cohort)

~14 providers

Initial signatories to the voluntary GPAI Code of Practice ahead of the 2 August 2025 applicability date. Includes major foundation-model providers; non-exhaustive list maintained by the AI Office.

EU AI Office

Cybersecurity (NIS2 + ENISA)

EU notified incidents per year (ENISA Threat Landscape 2024)

~2,580

Aggregate cybersecurity incidents reported to EU CSIRTs in 2023-2024 timeframe. ENISA's annual Threat Landscape categorises by sector + impact severity. Healthcare + public administration consistently top affected sectors.

ENISA Threat Landscape 2024

NIS2 transposition status (as of Q4 2024)

20/27 member states transposed on time

Member states required to transpose Directive (EU) 2022/2555 by 17 October 2024. Seven member states slipped the deadline; the Commission opened infringement proceedings against late-transposing states.

European Commission infringement-procedure tracker

Insurance (EIOPA)

EIOPA AI-using insurers in EU motor + health (2023 survey)

~38% of surveyed insurers

EIOPA's 2023 BigData + AI survey covered 130 EU insurers across motor + health insurance. Substantial AI use in pricing + claims + fraud detection. Higher adoption in motor than health.

EIOPA — Use of BigData + AI by EU insurers

US enforcement (CFPB + EEOC + HUD)

EEOC settlements involving AI hiring tools (2022-2024)

~15 enforcement actions

Public-record EEOC consent decrees + settlements addressing AI-driven hiring tools. Mostly disparate-impact claims under Title VII. The 2024 iTutorGroup settlement ($365K) was an early high-profile case.

EEOC press releases (aggregated)

CFPB enforcement actions on algorithmic credit decisioning (2023-2025)

Increasing — several major settlements

CFPB has prioritised enforcement against algorithmic decisioning that produces disparate impact in credit + lending. Specific settlement amounts vary; the agency's 2023 Circular 2023-03 on adverse-action notices for AI-driven denials is frequently cited.

CFPB enforcement press releases