July 21, 2026
By Natalie Sutherland CIPP/E
With the adoption of artificial intelligence across key operations, data privacy regulation can no longer afford to operate in a silo. For years, organisations have deployed highly complex machine learning systems into governance practices on a seemingly "set-and-forget" basis.
By treating an evolving, partially autonomous tool as a static compliance shortcut, the market has cut corners it wasn't prepared to manage. Now, the systemic cracks are showing, and humans are trying to blame the technology for the resulting chaos.
The regulatory alarm rang on 16 and 17 July 2026. Citing a massive surge in the volume and complexity of data protection complaints driven by widespread AI usage, the European Data Protection Board (EDPB) called on the European Commission to establish a formal legal basis for cross-regulatory information sharing.
Digital governance has evolved past isolated jurisdictions; data protection, competition, and consumer laws are now intertwined. By demanding a statutory gateway to exchange confidential enforcement data, the EDPB has issued a legislative Klaxon: single-silo regulators can no longer govern digital spaces alone.

During the high-level meeting in Dublin on 16 and 17 July 2026, the European Data Protection Board (EDPB) called for a clear, harmonised EU legal basis for sharing information among regulators with entirely different operational competences.
While this call fundamentally triggers the core GDPR principle of Lawfulness, Fairness, and Transparency (Article 5(1)(a)), it highlights a current consideration in recent legislation. The issue is not that Data Protection Authorities (DPAs) lack a lawful basis to process data under Article 6; their public mandates cover that. The true operational crisis lies in the statutory walls of Professional Secrecy (Article 54(2)).
Currently, strict confidentiality rules prevent a DPA from legally sharing internal investigation details with adjacent digital authorities, such as competition or consumer protection boards.
This has created an environment where corporate actors have safely played a game of regulatory divide-and-conquer. Organisations have engaged in the rapid deployment of AI, running up a massive compliance tab while casually promising strict "Human-in-the-Loop" (HITL) safety protocols. But when foreseeable systemic failures happen, such as model drift or unauthorised web-scraping, the blame gets shifted to AI.
Because AI models cross borders and sectors, a single deployment can simultaneously violate privacy, breach financial consumer protections, and distort market competition. The EDPB’s Dublin declaration is a direct warning that the regulatory grace extended during the era of voluntary opt-in has run out.
By demanding a dedicated EU legislative framework to legally bypass secrecy silos and share enforcement data, the EDPB is preparing to demand compliance as standard from an operational level for all organisations. Regulators no longer have the capacity to police complex digital ecosystems alone; they are actively building the legal architecture to hand accountability back to the organisations that cut corners, ending the era of siloed evasion.
The Deep Dive: The Intersection of Data Privacy Consultancy, AI, and Multilateral Governance
The governance landscape has experienced a massive surge in using AI to automate data classification, continuously monitor access, and attempt compliance at scale. While this allows teams to maintain high productivity outputs, it simultaneously amplifies the need for rigorous operational oversight to mitigate the constant potential for data breaches.
When AI is deployed blindly to automate classification, the risk of Personal Data or Special Category Data (SCD) being leaked or transferred without appropriate encryption-in-transit is skyrocketing, exposing organisations to massive regulatory fines from the ICO in the UK or the CNIL in France, for example.
To add to the complexity, organisations are struggling with internal structural silos, leaving them ill-equipped to handle modern, overlapping legislation. In these operational gaps, harmful practices have historically gone unchecked, until a complex multi-sector complaint arrives. Take, for example, a data leak involving an injury sustained by an inmate in prison. This scenario instantly triggers an overlap between general processing rules, law enforcement processing rules, and medical Special Category Data (SCD).
Historically, statutory walls like Section 132 of the UK Data Protection Act 2018 (the UK's equivalent to the EU's Article 54(2) professional secrecy wall) have forced regulators to operate in isolated silos, creating short-term loopholes that organisations exploited to navigate around compliance undetected. But the grace period for these structural gaps is over.
Just as regulators are building external legislative bridges to share enforcement data across domains, internal corporate teams must immediately commence the work to eliminate their own operational silos. Legal, IT, and Risk compliance can no longer look at data pipelines through a single lens; they must mirror the regulators and build a unified, cross-functional collaborative model.
Actions we can take while they debate:
While the European Commission and regulators debate formal, cross-regulatory gateways, in-house counsel and Data Governance teams cannot afford to wait. Moving away from top-down mandates that leave frontline workers exposed, organisations must pivot to a bottom-up framework, building compliance directly into the operational foundation.
As legislators debate the boundaries of cross-agency cooperation, one outcome is clear: unified digital regulation is inevitable. The boundary-less nature of machine learning has permanently broken individual regulatory silos.
True resilience in this shifting landscape will not be achieved by top-down directives or treating "Human-in-the-Loop" frameworks as mere paperwork exercises. Instead, it presents a rare opportunity for forward-thinking organisations to embed robust compliance practices directly into their operational foundations today.
By architecting compliance from the ground up, businesses can ensure that when these new, interconnected legislative frameworks formally take effect, their entire structures are already standing on solid, unshakeable ground.