GDPR Enforcement Against AI in 2026: The Cases That Are Shaping AI Regulation
In March 2023, Italy's data protection authority, the Garante, blocked ChatGPT from operating in Italy over GDPR concerns — and OpenAI brought it back within a month after committing to specific transparency measures. That episode was the first major salvo. By 2026, GDPR enforcement against AI companies has become a structured, multi-regulator campaign with real financial consequences.
European data protection authorities (DPAs) have moved from exploratory investigation to active enforcement against AI companies in 2026. The GDPR — which applies to any company processing personal data of EU residents, regardless of where the company is established — is proving to be the most effective existing legal tool for AI accountability in Europe.
GDPR (General Data Protection Regulation) — Regulation (EU) 2016/679, the EU's comprehensive data protection law. Applies to any processing of personal data of individuals in the EU. Violations can result in fines of up to 4% of global annual turnover or €20 million, whichever is higher. Companies outside the EU must comply when processing EU residents' personal data.
Lawful Basis for Processing — GDPR Article 6 requires that every processing activity has a lawful basis. The six bases include consent, contract, legal obligation, vital interests, public task, and legitimate interests. AI companies using personal data for training must identify and document a lawful basis — and that basis must hold up to DPA scrutiny.
The Italian Garante vs OpenAI: The Template for AI Enforcement
The Italian data protection authority's 2023 action against OpenAI established a template that other European DPAs have referenced and built on. The Garante's concerns covered several GDPR dimensions:
- Lack of transparency: ChatGPT users and third parties whose data had been scraped from the internet to train the model had not been informed of this processing, violating GDPR Articles 13 and 14 (transparency requirements).
- Absence of a lawful basis for training data: OpenAI could not demonstrate a clear lawful basis under GDPR Article 6 for using personal data scraped from the internet for model training.
- No age verification: ChatGPT was accessible to minors without adequate age-gating, raising concerns under GDPR's special protections for children's data.
- Inaccuracy of outputs: ChatGPT sometimes generated false information about real people, implicating GDPR Article 5(1)(d) (data accuracy principle) and the rights of individuals to correct inaccurate data held about them.
OpenAI's response — implementing a transparency notice, age verification measures, and an opt-out mechanism for Italians — allowed the service to resume. But the Garante's investigation is ongoing, and a formal sanction decision is expected in 2026. The fine, if issued, could be a reference point for the entire industry.
The Irish DPC and the Main Establishment Principle
Under GDPR's "one-stop-shop" mechanism, companies with EU establishments are primarily supervised by the DPA in the country of their main EU establishment. Many US tech companies, including Meta, Apple, Microsoft, and Google, have their main EU establishment in Ireland, making the Irish Data Protection Commission (DPC) their lead supervisory authority.
OpenAI established an EU presence in Ireland in 2023. This means the Irish DPC has primary GDPR jurisdiction over OpenAI's EU operations. Other European DPAs can still raise concerns, but a coordinated enforcement action would be led by the DPC and require agreement from other DPAs.
The Irish DPC's record on major GDPR enforcement has been criticised by other European DPAs and the European Data Protection Board (EDPB) for being slow — though several large fines have now been issued including a €1.2 billion fine against Meta in 2023. In 2026, the DPC's handling of AI investigations is under increased pressure from other national DPAs who want coordinated, faster action.
Lawful Basis: The Central Battleground for AI Training Data
The fundamental GDPR challenge for AI companies is establishing a lawful basis for using personal data to train their models. The practical options:
Consent (Article 6(1)(a)): The GDPR's gold standard, but deeply impractical for training on scraped web data. Obtaining valid consent from every individual whose personal data appears in training datasets is effectively impossible at scale. Several DPAs have indicated that consent is required for certain types of training data, particularly sensitive categories (Article 9 data such as health information, political views, or religious beliefs).
Legitimate Interests (Article 6(1)(f)): The most commonly invoked basis by AI companies. Legitimate interests allows processing when the controller's (or a third party's) legitimate interests override the data subject's rights. AI companies argue that training on publicly available data serves legitimate interests in developing useful technology. DPAs have been sceptical: the "interests override" assessment must be conducted per data subject category and type of processing, and blanket legitimate interests claims for entire training datasets have not been accepted.
Scientific Research Exemption (Article 89): GDPR allows some flexibility for processing for scientific research purposes, subject to safeguards. Some AI companies have attempted to invoke this basis, but DPAs have questioned whether commercial AI development qualifies as "scientific research" for these purposes.
Data Subject Rights Against AI Systems: The Emerging Frontier
GDPR grants data subjects specific rights including access (Article 15), rectification (Article 16), erasure ("right to be forgotten," Article 17), and objection (Article 21). Enforcing these rights against AI systems creates novel technical challenges:
Can an individual request deletion of their personal data from an AI model's training set? Technical experts debate whether trained models "contain" personal data in a form that can be identified and deleted — or whether the data has been transformed into model weights that cannot be specifically attributed to any individual. The EDPB's 2024 opinion on AI and data subject rights recognised this complexity but held that data controllers (AI companies) remain responsible for finding technical solutions, rather than pleading impossibility.
The right to explanation — Article 22's limitation on solely automated decision-making — is particularly relevant for AI systems that make or contribute to decisions affecting individuals (loan approvals, job screening, risk scoring). AI companies must be able to provide meaningful explanations for automated decisions, which requires a level of model interpretability that many current AI architectures do not natively support.
Frequently Asked Questions
Does GDPR apply to US AI companies that don't have EU offices?
Yes. GDPR applies to any company that processes personal data of EU residents, regardless of where the company is established. A US AI company without EU offices that collects data from EU users, or trains models on data scraped from EU residents' public profiles, is subject to GDPR. The company must designate an EU representative and comply with the full GDPR framework.
What is the lawful basis AI companies use for training their models on internet data?
Most AI companies invoke 'legitimate interests' under GDPR Article 6(1)(f). But DPAs have scrutinised this basis heavily and have not accepted blanket claims that training on all publicly available data automatically satisfies the legitimate interests test. A case-by-case assessment of data type, necessity, and the balance against data subject rights is required. For sensitive data categories (health, political, religious), legitimate interests alone is insufficient.
Can individuals demand removal of their personal data from an AI model?
The legal right exists — GDPR Article 17 provides a right to erasure. The technical challenge is that trained models may not contain personal data in a form that can be specifically identified and deleted. The EDPB has held that this technical difficulty does not extinguish the right; AI companies must develop and implement technical mechanisms to honour erasure requests. Some companies offer opt-out mechanisms for excluding data from training.
What fines can GDPR authorities impose on AI companies?
GDPR fines can reach the higher of 4% of global annual turnover or €20 million per violation. For a large AI company with billions in global revenue, 4% of global turnover could represent billions of euros in exposure. Notable precedents: Meta was fined €1.2 billion by the Irish DPC in 2023 for GDPR violations. The Italian Garante's ongoing OpenAI investigation is expected to produce a sanction in 2026.
This article is published by an independent news publication for informational purposes only and does not represent or claim affiliation with any government body, international organization, or official authority.