Edition

This is a permanent edition. It carries the briefing exactly as published on this date and does not change.

DPC Ireland publishes AI Insights Report detailing supervision of AI products and services from 2021 to 2025

The DPC on 25 September 2026 published its AI Insights Report, detailing its supervision of Artificial Intelligence products and services between 2021 and 2025. This report covers engagements with controllers on approximately 180 AI products and services, assessing thousands of pages of documentation. The DPC secured significant improvements in data protection compliance across areas like lawful basis and transparency.

The DPC's Technology Multinational Supervision Unit within its Supervision Function gathered insights from supervising AI creation, training, and deployment by companies including Airbnb, Apple, Google, Meta, and OpenAI. The DPC supervised a range of AI types, including Large Language Models (LLMs), age assurance technologies, facial recognition systems, recommender systems, and personalisation engines. This involved assessing thousands of pages of briefings, risk assessments, technical and organisational measures, and compliance documentation. The report demonstrates that innovation and rigorous data protection are not mutually exclusive. The DPC Supervision Function secured significant improvements in data protection compliance concerning lawful basis, transparency, data minimisation, and child protection. The report also highlights the DPC’s focus on the application of Legitimate Interests as a legal basis for AI training and the necessity of robust Transparency for novel technology often involving opaque and complex processing operations. While most AI engagements led to recommendations, the report also shows the DPC’s readiness to intervene urgently when risks to individuals’ rights are unsatisfactorily mitigated. The DPC views early regulatory engagement as the most effective path to sustainable, responsible, and data protection and privacy centric innovation.

The rapid development of Generative AI and other advanced technologies continues to challenge existing data protection frameworks, driving regulators like the DPC to publish insights from their supervisory activities.

Data Protection Commission AI Insights Report

Who this binds
This report provides guidelines for controllers engaged in the creation, training, and deployment of Artificial Intelligence products and services within the EU, who are legally bound by the GDPR.
What changed
The report clarifies the DPC’s expectations regarding data protection compliance for AI products and services, particularly concerning lawful basis, transparency, and risk mitigation, based on its supervision of approximately 180 AI products and services between 2021 and 2025.
What to check
Organisations developing or deploying AI should review the DPC’s insights on lawful basis, transparency, and risk mitigation, particularly for Legitimate Interests and novel technologies.
What this does not mean
This report does not introduce new legal obligations beyond those already established by the GDPR, nor does it specifically address the upcoming EU AI Act.

Send this to your team

The Data Protection Commission published its AI Insights Report on 25 September 2026, detailing its supervision of approximately 180 AI products and services between 2021 and 2025, and providing guidelines for controllers on data protection compliance for AI.

Today's question

A data protection officer is reviewing the DPC Ireland's AI Insights Report. According to the report, which legal basis for processing is specifically highlighted as being applied for AI training?

  1. Legitimate Interests
  2. Contractual necessity
  3. Public interest
  4. Consent

Answer this question on the site

Worth knowing

  1. UK NHS staff removed over Noah Woods data breach

    The removal of ten NHS staff members for accessing Noah Woods' data demonstrates that individual accountability for unauthorised access to patient records is a real and enforced risk for healthcare employees.

  2. IMY Sweden Director General discusses GDPR changes and supervisory decisions at Nordic Privacy Arena

    Organisations operating in Sweden should review IMY's recent supervisory decisions and guidance, as discussed by its Director General, to ensure alignment with current regulatory expectations and interpretations of the GDPR.

  3. Datatilsynet Denmark issues severe criticism to 51 municipalities in Chromebook case

    Public sector organisations, particularly those in education, must ensure their use of cloud based services and devices like Chromebooks complies with data protection regulations to avoid regulatory criticism.

Compiled that morning from regulator, court and authority sources. Primary sources are linked on every story.