Your cookie preferences

EDPB guidance · Art. 7 GDPR

We use technical cookies essential for the platform to work (login, security, sessions). We would also like to use analytics cookies to understand how to improve it.

You can accept all, reject all, or choose which categories to switch on.Your consent is valid for 6 months and you can withdraw it at any time from the footer.

You will find everything in our privacy notice.

All news
Tech & AI September 25, 2026 6 min

180 AI products in five years: what the regulator asked

The Irish DPC publishes the record of its supervision of artificial intelligence from 2021 to 2025. It is not guidance, but it states in advance the two questions the authority will put to anyone deploying an AI system

What was published

On 25 September 2026 the Irish Data Protection Commission published «Responsible Artificial Intelligence Innovation», the record of the supervision carried out by its Technology Multinational Supervision Unit between 2021 and 2025. It is not a decision and it is not guidance: it is an account of what the authority asked, of whom, and with what result.

The number that matters is 180: that is how many AI products and services the DPC engaged on with controllers over five years, reading thousands of pages of briefings, risk assessments, technical and organisational measures and compliance documentation. The list of companies is what you would expect from the lead authority for the European headquarters of the large platforms: among others Airbnb, Apple, Deepseek, Google, LinkedIn, Meta, Microsoft, OpenAI, Pinterest, TikTok and X.

  • Large language models.
  • Age assurance systems.
  • Facial recognition.
  • Recommender and personalisation systems.
  • Agents.

For a DPO the value of the document is not the list of names. It is that an authority states in writing the two issues it returned to most often: legitimate interest as the legal basis for training, and transparency for opaque and complex processing. Those are exactly the two boxes a client fills in at speed when adopting an AI tool, and it is useful to know in advance that they are the first two someone will read.

What the report is not

It is not guidance and it binds nobody: it is an activity report, and the DPC presents it as such. Citing it to a client as a source of obligations is a mistake, and unnecessary: it is worth more read for what it is — the index of questions from an authority that has handled more files on these systems than anyone else in Europe.

The conclusion the DPC draws is the uncomfortable one for latecomers: most engagements ended in recommendations rather than enforcement, but that is because the conversation started before launch. Where risk was not mitigated, the authority says it intervened urgently. For daily practice that means one thing: the impact assessment on an AI system must be done while the system can still be changed, not once it is live.

Official source:Data Protection Commission — DPC publishes AI Insights Report (25/09/2026)Official source:Responsible Artificial Intelligence Innovation — Insights from the DPC's Supervision of AI (2021-2025), PDF

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Tech & AI
680customers contacted, and no intrusion into the systems

The request came from a real government domain

On 12 September 2026 Revolut confirmed it had disclosed customer data in response to fraudulent requests sent from a legitimate government agency email domain. The data included dates of birth, addresses, phone numbers, copies of passports and driving licences, verification selfies, account statements and transaction histories. Around 680 customers were contacted. This is not an intrusion into the systems: it is a personal data breach by unauthorised disclosure, and it turns on a procedure almost nobody has written down.

Sep 23, 2026New 6 min
Tech & AI
0passwords stolen, and that is the problem

French tax data stolen, and no passwords: that is what makes this one dangerous

On 14 August the French finance ministry announced that the tax administration's information system had been breached: a third party was able to consult and extract data on individuals and businesses. Identifiers and passwords appear untouched — which is precisely why the risk is not account takeover but phishing built on genuine tax data.

Aug 18, 2026 5 min
Tech & AI
4i momenti in cui si decide

The Dutch authority publishes a self-assessment for generative AI

Something was needed to hand the client who says "we switched on the AI in our software". The Dutch authority has published a self-assessment on generative AI systems: four moments, and in each one a decision that has to be documented.

Aug 18, 2026 4 min