LLM Training on Personal Data: Mass Enforcement Actions Expected
With the EDPB's July 2026 guidelines confirming that web scraping for AI training requires a lawful basis, and that AI models are not automatically "anonymous," DPAs are expected to launch coordinated enforcement against major LLM providers. OpenAI, Google DeepMind, Meta AI, and Anthropic all face open investigations across multiple EU jurisdictions. The key unresolved question: can legitimate interest (Article 6(1)(f)) ever justify training on billions of web pages containing personal data? The Italian Garante's 2023 ChatGPT ban foreshadowed a broader reckoning now reaching critical mass.
Right to Erasure vs. AI Models: The "Unlearning" Crisis
GDPR's right to erasure (Article 17) creates an unsolved technical problem for LLMs: how do you delete personal data from a trained model? Current "machine unlearning" techniques are immature and unproven at scale. Regulators will likely require either (a) proof that personal data cannot be extracted from models, (b) periodic model retraining excluding erasure requests, or (c) effective output filtering. Expect binding guidance defining what "erasure" means in the context of neural networks — potentially requiring costly retraining cycles. Companies that cannot demonstrate compliance may face orders to suspend processing.
AI-Generated Content About Real People: Accuracy Obligations Under Fire
LLMs routinely generate false information about real individuals — "AI hallucinations" that violate GDPR's accuracy principle (Article 5(1)(d)). After the DPC opened its inquiry into X/Grok for generating non-consensual images of real people (Feb 2026), regulators are expected to establish that AI outputs containing personal data must meet the same accuracy standards as any other data processing. This could force providers to implement robust factual grounding, disable person-specific outputs, or face systematic fines. The intersection of deepfakes, synthetic media, and GDPR accuracy will be a defining enforcement battleground through 2027.
AI Decision-Making: Article 22 Becomes the Central Battleground
As AI systems increasingly make or heavily influence decisions about people — credit scoring, hiring, insurance pricing, content moderation — GDPR Article 22's prohibition on "solely automated" decisions is being tested. The NOYB class action against CRIF (Jun 2026) signals the start of systematic challenges to AI-driven decision-making. With the AI Act now requiring human oversight for high-risk systems, expect DPAs to issue coordinated enforcement requiring meaningful human review — not just rubber-stamping AI outputs. Companies using LLMs for customer-facing decisions without genuine human-in-the-loop processes face significant liability.
US-EU Digital Decoupling: From Data Transfers to Digital Sovereignty
The Trump administration's systematic dismantling of US privacy safeguards — paralysing the PCLOB (Jan 2025), signalling hostility toward EU regulatory cooperation, and the Supreme Court's FTC independence ruling (Jun 2026) — has pushed the EU from "adequacy" thinking toward outright digital sovereignty. EU Member States are increasingly backing requirements that sensitive data remain on EU-based infrastructure. Major European institutions are migrating from US cloud providers. The political direction is clear: the era of frictionless US-EU data flows may be ending regardless of whether Schrems III succeeds formally.
US Retaliatory Measures Against EU Data Regulation
As the EU tightens requirements on US tech companies through GDPR, the AI Act, and the Digital Markets Act simultaneously, the US administration has signalled that EU digital regulation constitutes a trade barrier. Expect escalating tension: potential US trade measures targeting EU companies, political pressure to water down GDPR enforcement against American firms, and framing of EU privacy regulation as protectionism. The EU faces a difficult balancing act between maintaining fundamental rights standards and avoiding a full-scale transatlantic digital trade war.
Mandatory DPIAs for All AI Systems Processing Personal Data
With the AI Act's risk-based framework now fully applicable, regulators are expected to clarify that virtually all AI systems processing personal data require Data Protection Impact Assessments (Article 35). The combination of systematic profiling, new technologies, and large-scale processing means most LLM deployments will trigger mandatory DPIAs. Organisations deploying AI chatbots, recommendation systems, or content moderation tools without documented DPIAs face enforcement. Expect standardised DPIA templates specifically designed for generative AI systems.
ePrivacy Regulation Could Finally Be Adopted
The long-delayed ePrivacy Regulation — stalled since 2017 — faces further setbacks after EU Member States blocked the Commission's proposal to eliminate cookie banners in June 2026. The regulation would replace the Cookie Directive with stricter rules on electronic communications metadata, but disagreements over metadata retention and the cookie consent mechanism continue to delay progress.
AI Act Full Application Triggers GDPR Enforcement Wave
The EU AI Act reaches full application in August 2026, and regulators are expected to launch coordinated enforcement actions targeting AI systems that process personal data without adequate safeguards. Expect clarification on how GDPR rights — especially Article 22 on automated decisions — apply to high-risk AI systems, with stronger requirements for human review, transparency, and DPIAs before deployment.
DPA Cross-Border Enforcement Overhaul
The one-stop-shop mechanism has drawn sustained criticism — particularly the Irish DPC's handling of Big Tech cases. The European Commission published its GDPR evaluation in 2023, and a political agreement on additional procedural rules was reached in June 2025. The next phase is practical implementation, with likely follow-up guidance to accelerate cross-border enforcement and reduce bottlenecks at lead supervisory authorities.
Schrems III: DPF Annulment and Collapse of US Data Flows
NOYB has now formally filed a lawsuit before the CJEU seeking annulment of the EU–US Data Privacy Framework. With the US Supreme Court eliminating FTC independence, the PCLOB paralysed, and the Trump administration openly hostile to EU oversight mechanisms, the legal foundations of the adequacy decision are severely weakened. The CJEU invalidated Safe Harbor in 2015 and Privacy Shield in 2020 — a third invalidation appears increasingly inevitable. SCCs and BCRs are also affected since transfer impact assessments relied on the same US oversight bodies. Companies should prepare contingency plans for a world without a valid US adequacy decision.
Stricter Age Verification Requirements EU-Wide
Following Ireland's major fine against Meta over children's data (Instagram, 2022), and broader DSA enforcement, expect new EU-wide standards for age verification and parental consent mechanisms. The EDPB has signalled children's data as a top enforcement priority for 2025–2026. Coordinated enforcement actions across multiple DPAs are expected, potentially targeting social media platforms and gaming companies.
First €2 Billion+ GDPR Fine
With Meta's €1.2B fine setting a record in 2023, and multiple open investigations into Big Tech advertising ecosystems, a fine crossing the €2 billion threshold is plausible before 2027. This would require a proven Article 83(5) violation — systematic and intentional processing in breach of fundamental GDPR principles — with a company large enough to support a fine of 4% of global annual turnover at this level.
"Pay or Okay" Consent Models Ruled Invalid
Following NOYB's complaints against Meta and Schibsted over "Pay or Okay" consent walls — where users must pay for an ad-free experience or consent to tracking — regulators are expected to issue binding guidance declaring these models incompatible with freely given consent under GDPR Article 7. The EDPB has already expressed scepticism, and a definitive ruling could force publishers and platforms to find alternative business models.