Data Protection Commission publishes AI Insights Report

25th Mí Meán Fomhair 2026

The Data Protection Commission has published a new report detailing the DPC’s supervision of Artificial Intelligence products and services between 2021 and 2025. The report details a significant increase in AI-related engagements, driven in part by the rapid development of Generative AI in recent years.

As the EU Lead Supervisory Authority for many of the world’s leading technology companies with European Headquarters located in Ireland, the Data Protection Commission occupies a unique regulatory vantage point at the intersection of rapid technological evolution and fundamental rights protection.

The DPC's Supervision Function has engaged in supervising the creation, training, and deployment of AI by companies, including Airbnb, Apple, Deepseek, Google, LinkedIn, Meta, Microsoft, OpenAI, Pinterest, TikTok, X (formerly Twitter), and others. The DPC has supervised a range of AI including LLMs, age assurance, facial recognition, recommender systems, personalisation, agents, and more. 

Between 2021 and 2025, the DPC engaged with controllers on the creation, launch, and deployment of approximately 180 AI products and services, and assessed thousands of pages of briefings, risk assessments, technical and organisational measures, and compliance documentation in relation to AI. 

This report presents the insights gathered by the Data Protection Commission’s Technology Multinational Supervision Unit within the DPC’s Supervision Function. Key findings highlight that innovation and rigorous data protection are not mutually exclusive. Through a large number of engagements involving different AI such as Large Language Models and recommender systems, the DPC Supervision Function has secured significant improvements in data protection compliance in the areas of lawful basis, transparency, data minimisation, and the protection of children.

The report demonstrates a number of critical areas of focus for the DPC, particularly the application of Legitimate Interests as a legal basis for AI training, and the necessity of robust Transparency for what is novel technology, often involving opaque and complex processing operations.

While the majority of AI engagements resulted in recommendations being issued, the report also demonstrates the DPC’s readiness to urgently intervene where risks to individuals’ rights are unsatisfactorily mitigated.  

Ultimately, this report serves as both a record of the DPC’s actions in regulating emerging technologies such as AI, and as guidelines for controllers, signifying that early regulatory engagement is the most effective path to sustainable, responsible, and data protection and privacy-centric innovation.

The Data Protection Commission Responsible Artificial Intelligence Innovation, Insights from the Data Protection Commission's Supervision of AI (2021-2025) (5.1MB), is available to download now.