What was published
On 25 September 2026 the Irish Data Protection Commission published «Responsible Artificial Intelligence Innovation», the record of the supervision carried out by its Technology Multinational Supervision Unit between 2021 and 2025. It is not a decision and it is not guidance: it is an account of what the authority asked, of whom, and with what result.
The number that matters is 180: that is how many AI products and services the DPC engaged on with controllers over five years, reading thousands of pages of briefings, risk assessments, technical and organisational measures and compliance documentation. The list of companies is what you would expect from the lead authority for the European headquarters of the large platforms: among others Airbnb, Apple, Deepseek, Google, LinkedIn, Meta, Microsoft, OpenAI, Pinterest, TikTok and X.
- Large language models.
- Age assurance systems.
- Facial recognition.
- Recommender and personalisation systems.
- Agents.
For a DPO the value of the document is not the list of names. It is that an authority states in writing the two issues it returned to most often: legitimate interest as the legal basis for training, and transparency for opaque and complex processing. Those are exactly the two boxes a client fills in at speed when adopting an AI tool, and it is useful to know in advance that they are the first two someone will read.
What the report is not
It is not guidance and it binds nobody: it is an activity report, and the DPC presents it as such. Citing it to a client as a source of obligations is a mistake, and unnecessary: it is worth more read for what it is — the index of questions from an authority that has handled more files on these systems than anyone else in Europe.
The conclusion the DPC draws is the uncomfortable one for latecomers: most engagements ended in recommendations rather than enforcement, but that is because the conversation started before launch. Where risk was not mitigated, the authority says it intervened urgently. For daily practice that means one thing: the impact assessment on an AI system must be done while the system can still be changed, not once it is live.
Official source:Data Protection Commission — DPC publishes AI Insights Report (25/09/2026)Official source:Responsible Artificial Intelligence Innovation — Insights from the DPC's Supervision of AI (2021-2025), PDFLooking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free