bbieron@platformeconomyinsights.com

Austrian Privacy Advocates File Criminal Complaint Against Clearview AI

Nov 1, 2025

Report from Courthouse News

In Brief – Austrian data privacy advocacy group Nyob (None of Your Business) announced that it filed a criminal complaint with Austrian authorities aiming to have executives of US-based facial recognition firm Clearview AI held personally liable for amassing an allegedly illegal database of billions of photos of faces. Clearview AI, which describes itself as a search engine for faces posted online, developed its facial recognition technology using images gathered from social media websites. The service is now sold almost exclusively to law enforcement and government agencies. After the company burst onto the scene in 2020, privacy regulators in many countries, including several in Europe, fined the firm for violating national privacy and data protection regulations, including the EU’s General Data Protection Regulation. Noyb calls on Austrian prosecutors to hold Clearview AI’s corporate leadership personally liable and even send them to jail.

Context – Until OpenAI made Chat-GPT available, Clearview AI was the most notorious AI start-up. Although a small enterprise, it built facial recognition technology that outperformed giants like IBM, Microsoft, and Google. Under pressure from regulators, the company drastically pared back its business aspirations, agreeing to limit sales to government authorities, primarily in the US. Fights over extraterritorial jurisdiction of national laws regulating digital platforms are certain to grow as regulators attempt to enforce rapidly proliferating online regulations on small, entirely remote digital firms. For example, 4chan has filed suit in US federal court to block enforcement of the UK Online Safety Act on its business, arguing that it has no operations in the country. The UK’s Upper Tribunal recently rejected that argument from Clearview AI and sided with the UK Information Commissioner’s Office that the company was subject to the British GDPR. In the EU, the GDPR is primarily a civil law, but it does allow Member State privacy authorities to impose criminal penalties for certain violations of the regulation. If a US company executive is arrested for violating the law, it will accelerate the extra-territorial jurisdiction controversy.

View By Monthly
Latest Blog
European Commission Issues AI Content Notification Rules

Report from MediaPost In Brief – The AI transparency rules required by Article 50 of the EU’s AI Act have taken effect, requiring companies to clearly disclose when users are interacting with artificial intelligence or viewing AI-generated or manipulated images, audio...

More Follow-On Lawsuits for Google Likely After Latest DMA Fine

Report from Reuters In Brief – European lawyers and litigation financiers say that the European Commission’s recent decision to fine Google $1 billion for violating the Digital Markets Act (DMA) may add to the wave of private antitrust lawsuits that the search giant...

More Really Smart Tech People Call for International AI Governance

Report from the Washington Post In Brief – OpenAI and Anthropic have endorsed a petition urging the US government to help create an international regime to slow down and regulate the pace of “automated AI development.” It is signed by over 1,200 “employees of frontier...

Judge Dismisses Google’s DMCA Search Scraping Lawsuit

Report from MediaPost In Brief – Federal District Court Judge Yvonne Gonzalez Rogers has dismissed Google's complaint against the Texas-based company SerpApi for allegedly violating the Digital Millennium Copyright Act (DMCA) anti-circumvention provisions by evading...

Platform Economy Insights produces a short email four times a week that reviews two top stories with concise analysis. It is the best way to keep on top of the news you should know. Sign up for this free email here.

* indicates required