Ireland’s DPC turns AI supervision into an evidence test
Ireland’s Data Protection Commission report records AI supervision focused on evidence, transparency and rights-risk mitigation rather than new statutory deadlines.
Ireland’s Data Protection Commission (DPC) has published a report on its supervision of artificial intelligence products and services from 2021 to 2025. It records work across creation, training, launch and deployment, but does not create an EU AI Act instrument or a new deadline for AI providers.
The report covers large language models, age-assurance tools, facial recognition, recommender systems, personalisation and agents. Its signal is supervisory rather than legislative: the DPC is testing whether organisations can explain and evidence how their AI processing addresses risks to individuals’ rights.
The DPC’s supervisory signal
The DPC said its Technology Multinational Supervision Unit engaged with controllers on approximately 180 AI products and services. It assessed thousands of pages of briefings, risk assessments, technical and organisational measures and compliance documentation, in relation to companies including Airbnb, Apple, DeepSeek, Google, LinkedIn, Meta, Microsoft, OpenAI, Pinterest, TikTok and X.
The report identifies lawful basis, transparency, data minimisation and children’s protection as areas in which its engagements secured improvements. It gives particular attention to the use of legitimate interests as a legal basis for AI training and to transparency where processing is novel, opaque or complex.
Those references do not establish a single prescribed control for every AI system. They identify the evidence categories through which the DPC has examined different systems and the concerns that organisations should be prepared to address.
Transparency is a specific difficulty in complex processing. An organisation needs to explain the relevant processing in terms that connect its AI system to the data and purpose involved. The report does not prescribe a standard notice or specify a single method for making that explanation effective.
The source also does not classify the named systems under the EU AI Act or allocate responsibilities between model providers, deployers, controllers and processors. It records supervision of AI creation, training, launch and deployment by controllers.
From signal to control
The practical control is an evidence file organised around the DPC’s named concerns. It should bring together the lawful-basis analysis for AI training, the rationale for data minimisation, transparency material, measures addressing children’s protection, risk assessments and technical and organisational measures.
That is narrower than a general AI governance checklist. The report says the DPC reviewed these materials; it does not say that every engagement required the same document set or produced the same finding. Organisations should therefore be able to show how their own system was assessed and how identified risks were addressed, without treating the report as a new checklist of statutory obligations.
The lawful-basis issue is particularly concrete. Where legitimate interests is used for AI training, the organisation should be able to produce the analysis supporting that choice. The supplied report does not set out the legal test’s individual steps or say that legitimate interests is unavailable. It signals that the basis and its supporting reasoning are within supervisory focus.
The same distinction applies to transparency. A generic description of an AI feature does not, by itself, demonstrate that an organisation has addressed the DPC’s concern about complex processing. The relevant evidence is the transparency material connected to the system under review and the processing it performs.
The report’s coverage of approximately 180 products also limits what can be inferred about any one company or system. It names a range of organisations and technologies, but does not publish an outcome for each engagement, identify every risk assessment or say which technical and organisational measure addressed which concern.
The next supervisory test
Most engagements resulted in recommendations, the DPC said. It also said it was ready to intervene urgently where risks to individuals’ rights were not satisfactorily mitigated. Early engagement is presented as the most effective path to responsible, privacy-focused AI innovation, but the report does not remove the possibility of intervention.
The next test is therefore specific: whether an organisation can produce risk assessments, technical and organisational measures, compliance documentation and transparency material that support its treatment of lawful basis, minimisation, children’s protection and complex processing.
The DPC’s report does not establish an AI Act risk classification, a general-purpose AI obligation or a new compliance deadline. Its next supervisory question is whether the documented controls adequately mitigate risks to individuals’ rights.
Permanent link to this Atlas analysis
Related Atlas analysis
Continue with coverage connected by market, topic and operating context.
- European UnionEU AI Act Omnibus enters into force, adding nudification banTargeted AI Act amendments entered into force on 27 July 2026, adding a nudification ban and cybersecurity simplifications weeks before August high-risk obligations apply.
- BrazilBrazil orders takedown of 5,209 betting domainsBrazil’s MJSP and Finance Ministry tied thousands of domain blocks, platform notices and refund duties to Provisional Measure No. 1,394/2026.
- ColombiaColombia proposes more time to build open finance systemColombia’s Ministry of Finance proposes amending two decrees, giving the financial supervisor more time to standardise infrastructure and implement portability requirements.
Continue with Atlas
Move from this development into the relevant research, comparison and workflow.