Find the Right GRC Solution

Search and compare GRC technology built for the problems you’re trying to solve

Irish DPC Details Five Years of AI Oversight in New Report

Irish DPC Details Five Years of AI Oversight in New Report

By
Key Takeaways
  • DPC Supervised Approximately 180 AI Products and Services: Between 2021 and 2025, Ireland’s Data Protection Commission engaged with controllers on the creation, launch, and deployment of approximately 180 AI products and services.
  • Oversight Extended Well Beyond Generative AI: The DPC’s work covered large language models, recommender systems, facial recognition, age assurance, personalization, AI agents, and other technologies.
  • Supervision Led to Compliance Improvements: The regulator said its engagements secured improvements in lawful basis, transparency, data minimization, and the protection of children.
  • AI Training and Transparency Remain Key Concerns: The DPC identified legitimate interests as a legal basis for AI training and transparency around novel and complex processing as particular areas of focus.
  • DPC Is Prepared to Intervene: While most engagements resulted in recommendations, the regulator said it intervened urgently when risks to individuals’ rights were not satisfactorily mitigated.
Deep Dive

Ireland’s Data Protection Commission spent 5 years looking under the hood of AI systems before putting much of what it had seen into a single report. From 2021 through 2025, the regulator engaged with controllers over the creation, launch, and deployment of approximately 180 AI products and services. Behind that number sat thousands of pages of briefings, risk assessments, descriptions of technical and organizational measures, and compliance documentation. The work stretched from large language models and recommender systems to facial recognition, age assurance, personalization, and AI agents.

The DPC’s AI Insights Report draws those engagements together for the first time, offering a view of AI regulation from an authority that has spent the past several years unusually close to the companies building the technology.

Ireland gives the DPC that position. Many of the world’s largest technology companies maintain their European headquarters there, making the commission the EU lead supervisory authority for a number of major technology companies under Europe’s data protection framework. Its Supervision Function has engaged with companies including Airbnb, Apple, DeepSeek, Google, LinkedIn, Meta, Microsoft, OpenAI, Pinterest, TikTok, and X, formerly Twitter, as they created, trained, and deployed AI.

The volume of that work increased significantly between 2021 and 2025, according to the DPC, driven in part by the rapid development of generative AI. But the report is useful precisely because it does not treat AI as though it began with the arrival of the chatbot. The systems that reached the regulator were doing many different things, and the data protection questions often appeared long before a user ever typed a prompt.

Across those engagements, the DPC said its Supervision Function secured significant improvements in compliance around lawful basis, transparency, data minimization, and the protection of children. Most engagements resulted in recommendations.

The recurring problems are revealing. New technology may change what can be done with personal data, but it does not make the old questions disappear. Why is the information being processed? What information is actually necessary? What has the person been told? And when a company says it has a lawful reason for using personal data, does that reason withstand scrutiny?

The DPC identified the use of legitimate interests as a legal basis for AI training as a critical area of focus. It also placed particular emphasis on transparency, an obligation made considerably harder when the processing itself can be novel, opaque, and technically complex. A privacy notice may contain a great deal of information and still leave a person with little understanding of what is actually happening to their data.

That tension runs through much of the regulatory work described in the report. The DPC’s conclusion is not that innovation and rigorous data protection sit on opposite sides of a line. Its experience supervising large language models, recommender systems, and other AI technologies led it to the opposite position: the two can coexist, but only when data protection is treated as part of the system being built rather than paperwork attached to it afterward.

Although the majority of the engagements covered by the report resulted in recommendations, the DPC said it was prepared to intervene urgently when risks to individuals’ rights had not been satisfactorily mitigated. That distinction matters. Supervision can be collaborative without being passive, and early engagement with a regulator does not remove the possibility of intervention when the safeguards prove inadequate.

The report consequently reads as more than an account of what the DPC did between 2021 and 2025. The commission also intends it as guidance for controllers deciding how to approach the next generation of AI products.

Its lesson is a practical one. The moment to answer difficult questions about training data, transparency, children’s protections, data minimization, and lawful basis is while there is still time to change the system. The DPC describes early regulatory engagement as the most effective route toward sustainable, responsible, and privacy-centered innovation.

For organizations building AI, that shifts regulatory engagement away from the end of development, when compliance problems have already hardened into architecture. By then, a question that might once have required a policy change can require a product change instead. The DPC’s 5 years of supervision suggest that regulators would rather have that conversation earlier.

The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

🔒
Cancel anytime
Full archive access
Custom alerts

Oops! Something went wrong