Banned
10
Legal prohibition: a practice banned under Article 5 of the AI Act, or a final authority decision with no remediation path.
Aplikacje „nudify" i systemy AI generujące niekonsensualne treści intymne (NCII) oraz CSAM
Provider: Wpis kategorialny — wszyscy dostawcy i podmioty stosujące na rynku UE
Banned
Regulation (EU) 2026/1744 (Digital Omnibus on AI) inserted new points (ba) and (bb) into Article 5(1) of the AI Act, prohibiting the placing on the market, the putting into service and the use of AI systems that generate or manipulate realistic images, video and audio depicting the intimate parts of an identifiable person, or that person engaged in sexually explicit activity, without their explicit consent, as well as child sexual abuse material (CSAM). The ban is already part of the legal order — the regulation has been in force since 27 July 2026 — but it does not yet apply: it applies from 2 December 2026. Legislative track: provisional trilogue agreement on 7 May 2026, approval by the European Parliament (423 in favour, 57 against, 174 abstentions), final Council consent on 29 June 2026, act dated 8 July 2026 and published in the Official Journal on 24 July 2026. Breaches of the Article 5 prohibitions fall in the AI Act's top penalty tier: up to EUR 35 million or 7% of worldwide turnover.[1][2][3][4][5]
- Legal basis
- New points (ba) and (bb) in Article 5(1) of Regulation (EU) 2024/1689 (AI Act), inserted by Regulation (EU) 2026/1744 (Digital Omnibus on AI) of 8 July 2026, published in the Official Journal on 24 July 2026 and in force since 27 July 2026; the prohibition applies from 2 December 2026. Penalties for the Article 5 prohibited practices follow from Article 99(3) AI Act (up to EUR 35 million or 7% of worldwide turnover) — it was not separately verified whether the omnibus amended Article 99.
- Territorial scope
- EU (not EEA — the AI Act has not yet been incorporated into the EEA Agreement; an EEA Joint Committee decision is pending)
- Last status change
- 2026-07-27
- Declared compliance date
- 2026-12-02
Zdalna identyfikacja biometryczna w czasie rzeczywistym w przestrzeni publicznej do celów ścigania — kategoria praktyk AI
Provider: nie dotyczy (kategoria praktyk)
Banned
The use of 'real-time' remote biometric identification systems in publicly accessible spaces for law enforcement purposes is prohibited unless and in so far as strictly necessary for one of three objectives: the targeted search for specific victims of abduction, trafficking or sexual exploitation and for missing persons; the prevention of a specific, substantial and imminent threat to life or physical safety, or a genuine and present or genuine and foreseeable threat of a terrorist attack; or the localisation or identification of a person suspected of an Annex II offence punishable in the Member State concerned by a custodial sentence or a detention order for a maximum period of at least four years. Relying on an exception requires prior authorisation by a judicial or independent administrative authority with binding decision-making power, a fundamental rights impact assessment (Article 27), registration in the EU database (Article 49), and notification of the market surveillance authority and the national data protection authority; the Member State must lay down detailed national rules, and use must confirm the identity of the specifically targeted individual. The ban does not cover post-remote biometric identification, which is classified as high-risk (Annex III, point 1(a)) and whose obligations the Digital Omnibus deferred to 2027-12-02. Applicable since 2025-02-02; fines up to EUR 35 million or 7% of turnover.[6][7][8][9][10][11][12][13][14][15]
- Legal basis
- Article 5(1)(h)(i)-(iii) of Regulation (EU) 2024/1689 (AI Act) together with the safeguards in Article 5(2)-(5) (proportionality, prior authorisation by a judicial or independent administrative authority, fundamental rights impact assessment under Article 27, registration under Article 49, notification of the market surveillance and data protection authorities, requirement of detailed national law); list of offences — Annex II; post-remote identification — Annex III, point 1(a) (high-risk, obligations deferred to 2027-12-02); applicable from 2025-02-02 under Article 113(a); penalties: Article 99(3) — up to EUR 35,000,000 or up to 7% of total worldwide annual turnover, whichever is higher; penalties from 2025-08-02 (Article 113(b)). Regulation (EU) 2026/1744 (Digital Omnibus on AI) amended Article 5(1) by adding points (ba) and (bb) and paragraphs 1a-1b, but did not amend the wording of point (h) or the safeguards in paragraphs 2-5; the lettering of point (h) is unchanged.
- Territorial scope
- EU (EEA-relevant text; incorporation into the EEA Agreement unconfirmed, and police cooperation lies largely outside the scope of that Agreement)
- Last status change
- 2025-02-02
- Declared compliance date
- not applicable
Wykorzystanie słabości grup wrażliwych (wiek, niepełnosprawność, sytuacja społeczna lub ekonomiczna) — kategoria praktyk AI
Provider: nie dotyczy (kategoria praktyk)
Banned
AI systems that exploit vulnerabilities of a natural person or a specific group due to their age, disability or a specific social or economic situation are prohibited where the objective or effect is to materially distort the behaviour of that person or of a person belonging to that group in a manner that causes or is reasonably likely to cause that person or another person significant harm. Unlike Article 5(1)(a), the provision requires no showing of subliminal, manipulative or deceptive techniques and no impairment of the ability to make an informed decision — exploiting the vulnerability itself suffices. As with point (a), intent is not a condition (Recital 29, provided the harm results from the manipulative or exploitative practices), and lawful practices in the context of medical treatment as well as common and legitimate commercial practices complying with applicable law fall outside the ban. The prohibition applies from 2025-02-02 and fines reach EUR 35 million or 7% of total worldwide annual turnover.[6][7][16][9][10][11][17][18]
- Legal basis
- Article 5(1)(b) of Regulation (EU) 2024/1689 (AI Act); Recital 29 (no intent requirement, provided the harm results from the manipulative or exploitative practices; exclusion of lawful medical practices and legitimate commercial practices); applicable from 2025-02-02 under Article 113(a); penalties: Article 99(3) — up to EUR 35,000,000 or up to 7% of total worldwide annual turnover, whichever is higher; penalties from 2025-08-02 (Article 113(b)). Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI; OJ of 2026-07-24, entry into force 2026-07-27) amended Article 5 of the AI Act by inserting new points (ba) and (bb) in paragraph 1 and new paragraphs 1a and 1b, but left point (b) unchanged; the new paragraphs 1a and 1b clarify only points (ba) and (bb) and do not affect the interpretation of point (b).
- Territorial scope
- EU (27 Member States); the act is marked as EEA-relevant — application in Norway, Iceland and Liechtenstein requires incorporation into the EEA Agreement by an EEA Joint Committee decision
- Last status change
- 2025-02-02
- Declared compliance date
- not applicable
Techniki podprogowe, celowo manipulacyjne lub wprowadzające w błąd — kategoria praktyk AI
Provider: nie dotyczy (kategoria praktyk)
Banned
AI systems deploying subliminal techniques beyond a person's consciousness, or purposefully manipulative or deceptive techniques, are prohibited where the objective or the effect is to materially distort the behaviour of a person or group by appreciably impairing their ability to make an informed decision, causing them to take a decision they would not otherwise have taken, and causing or being reasonably likely to cause significant harm to that person, another person or a group of persons. Intent to cause harm is not required — Recital 29 states that neither the provider nor the deployer need have such intention, provided that the harm results from the manipulative or exploitative practices themselves. Lawful practices in the context of medical treatment, such as psychological treatment of a mental disease or physical rehabilitation, and common and legitimate commercial practices, for example in advertising, fall outside the ban where they comply with applicable law. The prohibition applies from 2025-02-02, fines reach EUR 35 million or 7% of worldwide turnover, and under Article 2 it also covers providers established outside the EU where the system is placed on the Union market or its output is used in the EU.[6][7][16][9][10][11][19][20]
- Legal basis
- Article 5(1)(a) of Regulation (EU) 2024/1689 (AI Act); Recital 29 (no intent requirement, provided the harm results from the manipulative or exploitative practices; exclusion of lawful medical practices and legitimate commercial practices); personal and territorial scope — Article 2; applicable from 2025-02-02 under Article 113(a); penalties: Article 99(3) — up to EUR 35,000,000 or up to 7% of total worldwide annual turnover, whichever is higher, with the penalty rules applying from 2025-08-02 (Article 113(b)). Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI; OJ of 2026-07-24, in force from 2026-07-27) amended Article 5 by inserting new points (ba) and (bb) in paragraph 1 and new paragraphs 1a and 1b (non-consensual intimate material, CSAM), but left point (a) and Article 99 unchanged.
- Territorial scope
- EU (27 Member States); the act is marked as EEA-relevant — application in Norway, Iceland and Liechtenstein requires incorporation into the EEA Agreement by an EEA Joint Committee decision
- Last status change
- 2025-02-02
- Declared compliance date
- not applicable
Scoring społeczny (social scoring) — kategoria praktyk AI
Provider: nie dotyczy (kategoria praktyk)
Banned
The placing on the market, putting into service and use of AI systems for the evaluation or classification of natural persons or groups over a certain period of time, based on their social behaviour or known, inferred or predicted personal or personality characteristics, is prohibited. The ban is triggered where the resulting social score leads to either or both of two alternative consequences: (i) detrimental or unfavourable treatment in social contexts unrelated to those in which the data was originally generated or collected, or (ii) treatment that is unjustified or disproportionate to the behaviour and its gravity — the second limb also applies within the original context. The provision itself contains no exceptions and binds both public and private actors, but the Regulation's general scope exclusions in Art. 2 apply to it (including national security, military and defence purposes, research and development prior to placing on the market, and purely personal non-professional activity). The ban applies from 2025-02-02, with fines of up to EUR 35 million or 7% of total worldwide annual turnover, and up to EUR 1.5 million for Union institutions, bodies, offices and agencies.[6][7][8][9][10][11][21][2]
- Legal basis
- Article 5(1)(c) of Regulation (EU) 2024/1689 (AI Act); applicable from 2025-02-02 under Article 113(a); penalties: Article 99(3) — up to EUR 35,000,000 or up to 7% of total worldwide annual turnover, whichever is higher, and for Union institutions, bodies, offices and agencies Article 100(2) — up to EUR 1,500,000 imposed by the EDPS; the Chapter XII penalty regime applies from 2025-08-02 (Article 113(b)). The Digital Omnibus (Regulation (EU) 2026/1744) did not amend the wording of Article 5(1)(c) — in the consolidated text as of 2026-07-27 it is marked as base text; it did amend Article 5 by adding points (ba) and (bb) and paragraphs 1a and 1b (applicable from 2026-12-02) and replaced Article 113(a) without changing the 2025-02-02 date for point (c).
- Territorial scope
- EU (27 Member States); the Regulation carries the "Text with EEA relevance" annotation, but extension to Norway, Iceland and Liechtenstein requires an EEA Joint Committee decision — its adoption could not be confirmed
- Last status change
- 2025-02-02
- Declared compliance date
- not applicable
Rozpoznawanie emocji w miejscu pracy i w instytucjach edukacyjnych — kategoria praktyk AI
Provider: nie dotyczy (kategoria praktyk)
Banned
The placing on the market, putting into service for this specific purpose, and use of AI systems to infer emotions of a natural person in the areas of workplace and education institutions is prohibited; the only exception in the provision itself covers systems intended to be put in place or on the market for medical or safety reasons, while the therapeutic-use example comes from Recital 44 rather than from the provision. Recital 44 grounds the ban in the limited reliability, the lack of specificity and the limited generalisability of such systems, the considerable variation of emotional expression across cultures and situations, the risk of discriminatory outcomes, and the power imbalance in employer-employee and school-student relationships. The notion of emotion recognition system does not cover physical states such as pain or fatigue — for example systems detecting fatigue of pilots or drivers — nor the mere detection of readily apparent expressions, gestures or movements, unless these are used to infer emotions (Recital 18). Outside workplace and education, emotion recognition is not banned but classified as high-risk (Annex III, point 1(c)), whose obligations the Digital Omnibus deferred to 2027-12-02; the prohibition has applied since 2025-02-02, with fines up to EUR 35 million or 7% of turnover.[6][7][22][9][10][11][13][23][24][25]
- Legal basis
- Article 5(1)(f) of Regulation (EU) 2024/1689 (AI Act) together with the medical and safety exception contained in that provision; Recital 44 (rationale of the ban and the therapeutic-use example); Recital 18 (boundary of the notion: physical states and the mere detection of expressions, gestures or movements fall outside); definition of emotion recognition system in Article 3(39); outside workplace and education — Annex III, point 1(c) (high-risk, obligations deferred to 2027-12-02); the prohibition applies from 2025-02-02 under Article 113(a); penalties: Article 99(3) — up to EUR 35,000,000 or up to 7% of total worldwide annual turnover, whichever is higher; penalties from 2025-08-02 (Article 113(b)). The Digital Omnibus on AI (Regulation (EU) 2026/1744 of 2026-07-08, OJ of 2026-07-24) amended Article 5 by inserting new points (ba) and (bb) and paragraphs 1a and 1b, but both new paragraphs are expressly confined to points (ba) and (bb), and the wording of point (f) is unchanged.
- Territorial scope
- EU (EEA-relevant text; incorporation into the EEA Agreement unconfirmed)
- Last status change
- 2025-02-02
- Declared compliance date
- not applicable
Predictive policing wobec osób fizycznych oparty na profilowaniu — kategoria praktyk AI
Provider: nie dotyczy (kategoria praktyk)
Banned
AI systems that assess or predict the risk of a natural person committing a criminal offence based solely on profiling that person or on assessing their personality traits and characteristics are prohibited; the ban does not apply to AI systems supporting the human assessment of a person's involvement in criminal activity where that assessment is already based on objective and verifiable facts directly linked to a criminal activity. Recital 42 excludes risk analytics not based on profiling of natural persons — for example assessing the likelihood of financial fraud by undertakings, or predicting the localisation of narcotics or illicit goods by customs authorities on the basis of known trafficking routes. The ban covers natural persons, not legal persons, and in principle does not extend to place-based crime prediction; where a location risk score becomes an element of profiling a specific individual, for instance by linking that person to residence in a high-crime area, the Commission guidelines treat the system as person-based and caught by the prohibition (paras 212-213). Applicable since 2025-02-02; fines up to EUR 35 million or 7% of total worldwide annual turnover, whichever is higher.[6][7][26][9][10][11][27][28]
- Legal basis
- Article 5(1)(d) of Regulation (EU) 2024/1689 (AI Act), with the carve-out set out in the same provision and in Recital 42; Commission guidelines on prohibited practices, section 5.3.1 paras 212-213 (place-based prediction in principle outside the ban unless it becomes an element of profiling an individual); applicable from 2025-02-02 under Article 113(a); penalties: Article 99(3) — up to EUR 35,000,000 or up to 7% of total worldwide annual turnover, whichever is higher; the penalty rules apply from 2025-08-02 (Article 113(b)). The Digital Omnibus on AI (Regulation (EU) 2026/1744 of 2026-07-08, OJ of 2026-07-24, in force from 2026-07-27) amended Article 5 by inserting new points (ba) and (bb) and paragraphs 1a and 1b, which are expressly confined to those new points; it did not amend the wording or lettering of point (d), nor Article 99.
- Territorial scope
- EU (EEA-relevant text; incorporation into the EEA Agreement unconfirmed)
- Last status change
- 2025-02-02
- Declared compliance date
- not applicable
Nieukierunkowane pobieranie wizerunków twarzy z internetu lub CCTV do baz rozpoznawania twarzy — kategoria praktyk AI
Provider: nie dotyczy (kategoria praktyk)
Banned
The placing on the market, putting into service for this specific purpose, and use of AI systems that create or expand facial recognition databases through the untargeted scraping of facial images from the internet or CCTV footage is prohibited. The provision itself contains no exception clause — unlike point (h), which provides exceptions for law enforcement — and what matters is that the collection is mass-scale and untargeted, unconnected to a specific person or purpose; the general scope exclusions of the Regulation do apply, namely Article 2(6) (systems developed and put into service for the sole purpose of scientific research and development) and Article 2(3) (military, defence and national security purposes). Independently of the AI Act, the practice generally breaches the GDPR, as confirmed among others by the Italian Garante's injunction order against Clearview AI of 2022-02-10 (doc. web no. 9751362). Applicable since 2025-02-02; the ban also covers non-EU providers placing such systems on the market or putting them into service in the Union (Article 2(1)); fines up to EUR 35 million or 7% of turnover.[6][7][8][9][10][11][29][30][18][31][32]
- Legal basis
- Article 5(1)(e) of Regulation (EU) 2024/1689 (AI Act); Recital 43; exclusions from the scope of the Regulation: Article 2(6) (sole purpose of scientific research and development) and Article 2(3) (military, defence and national security purposes); the personal scope covers non-EU providers — Article 2(1); applicable from 2025-02-02 under Article 113(a); penalties: Article 99(3) — up to EUR 35,000,000 or up to 7% of total worldwide annual turnover, whichever is higher; the penalty rules apply from 2025-08-02 (Article 113(b)). The GDPR applies in parallel. The Digital Omnibus on AI (Regulation (EU) 2026/1744 of 2026-07-08, OJ of 2026-07-24) did not amend the wording or lettering of Article 5(1)(e), nor Article 99, nor the date of application of the Article 5 prohibitions; it did extend Article 5(1) with new points (ba) and (bb) (generation and manipulation of non-consensual intimate material and of child sexual abuse material) and paragraphs 1a-1b confined to those new points.
- Territorial scope
- EU (EEA-relevant text; incorporation into the EEA Agreement unconfirmed)
- Last status change
- 2025-02-02
- Declared compliance date
- not applicable
Kategoryzacja biometryczna wnioskująca o cechach wrażliwych — kategoria praktyk AI
Provider: nie dotyczy (kategoria praktyk)
Banned
The placing on the market, putting into service for this specific purpose, and use of biometric categorisation systems that individually categorise natural persons on the basis of their biometric data to deduce or infer race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation is prohibited; the ban applies from 2025-02-02. It does not cover the labelling or filtering of lawfully acquired biometric datasets, such as images, nor the categorising of biometric data in the area of law enforcement. The list of attributes is exhaustive and largely mirrors the GDPR Article 9 special categories, though it omits health and genetic data. Biometric categorisation beyond that list is not banned: where it infers other sensitive or protected attributes it is classified as high-risk (Annex III, point 1(b)), whose obligations the Digital Omnibus deferred to 2027-12-02, while sorting by neutral features such as hair or eye colour (Recital 30) falls outside both regimes.[6][7][8][9][10][11][19][23][33][24][29]
- Legal basis
- Article 5(1)(g) of Regulation (EU) 2024/1689 (AI Act) together with the carve-out contained in that provision (labelling and filtering of lawfully acquired datasets, and categorising of biometric data in the area of law enforcement); Recital 30; Annex III, point 1(b) for categorisation according to other sensitive or protected attributes; applicable from 2025-02-02 under Article 113(a); penalties: Article 99(3) — up to EUR 35,000,000 or up to 7% of total worldwide annual turnover, whichever is higher; penalties from 2025-08-02 (Article 113(b)). The Digital Omnibus — Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence (OJ of 2026-07-24, in force from 2026-07-27) — did not amend the wording of point (g); it added new points (ba) and (bb) and paragraphs 1a and 1b to Article 5, without affecting the 2025-02-02 application date or Article 99. Deferral of high-risk obligations: Annex III to 2027-12-02, Annex I Section A to 2028-08-02.
- Territorial scope
- EU (27 Member States); the act is marked as EEA-relevant — application in Norway, Iceland and Liechtenstein requires incorporation into the EEA Agreement by an EEA Joint Committee decision
- Last status change
- 2025-02-02
- Declared compliance date
- not applicable
Clearview AI
Provider: Clearview AI Inc. (USA)
Banned
Clearview AI offered biometric search over a database of facial images scraped from the internet - more than 10 billion images according to the Italian Garante's 2022 decision. Four authorities issued fines and cease-processing orders: the Garante EUR 20 million (injunction order 2022-02-10, press release 2022-03-09), Greece's HDPA EUR 20 million (decision 35/2022 of 2022-07-13), the Dutch AP EUR 30.5 million (decision 2024-05-16, published 2024-09-03) together with four orders backed by penalty payments of up to EUR 5.1 million, and France's CNIL EUR 20 million (decision of 2022-10-17) plus EUR 5.2 million from the liquidation of the periodic penalty payment (2023; the CNIL has taken the sanction page down, so the French strand has no live primary source today). The company did not object to the Dutch decision and therefore cannot appeal it, has not complied with the orders and has not paid the fines; in September 2024 the AP announced it would examine the personal liability of its directors, and no public outcome has followed. Since 2025-02-02 the practice itself is additionally banned outright in the EU under AI Act Article 5(1)(e), which prohibits creating or expanding facial recognition databases through the untargeted scraping of images from the internet or CCTV footage; Regulation 2026/1744 (Digital Omnibus, in force since 2026-07-27) did not alter that provision.[34][35][36][32][7][37]
- Legal basis
- GDPR Art. 5(1)(a), 6, 9, 12, 14, 15, 27; AI Act (Reg. 2024/1689) Art. 5(1)(e) - prohibition applicable since 2025-02-02
- Territorial scope
- EU (categorical prohibition under the AI Act); EEA - under the GDPR; national decisions: Italy, France, Greece, Netherlands
- Last status change
- 2025-02-02
- Declared compliance date
- not applicable
Blocked by a regulator
3
An enforcement measure by a supervisory authority — the tool is effectively unavailable while the case is pending.
FaceBoarding — rozpoznawanie twarzy pasażerów przy wejściu do strefy zastrzeżonej i do wyjść na lotnisku Milano Linate
Provider: SEA — Società per Azioni Esercizi Aeroportuali S.p.A. (administrator danych, operator lotniska)
Blocked by a regulator
The FaceBoarding system, deployed by airport operator SEA S.p.A. at Milan Linate, ran from 7 May 2024 to 16 September 2025: by order no. 489 of 11 September 2025 the Italian Garante imposed a provisional limitation of processing (GDPR Article 58(2)(f)), SEA switched the system off on 16 September (statement of 17 September) and deleted the data by 8 October 2025. In its decision of 12 March 2026 the authority declared the processing unlawful: biometric templates were stored centrally and unencrypted on SEA's servers, so passengers had no exclusive control over their own template; it also faulted information shortcomings, excessive retention and the processing of data of passengers not enrolled in the service at hybrid gates — in the Garante's view even processing shorter than 1.5 seconds is processing of biometric data, and there is no de minimis threshold for special-category data. The decision is declaratory (GDPR Article 57(1)(a)), closes the proceeding and contains neither a forward-looking ban nor a fine — one point of the operative part is redacted in the published version ([OMISSIS]) — and under EDPB Opinion 11/2024, cited by the authority, an architecture in which the biometric template remains solely in the passenger's hands is permissible. As of 14 August 2026 the service remains switched off: SEA's suspension notice is still published and announces no resumption.[38][39][40][41][42]
- Legal basis
- GDPR Articles 5(1)(a), (e) and (f) and Articles 6, 13, 25 and 32 — a declaratory finding of unlawful processing of biometric data under GDPR Article 57(1)(a), without corrective measures under Article 58(2); previously a provisional limitation of processing (GDPR Article 58(2)(f)) by order no. 489 of 11 September 2025. The assessment relies on EDPB Opinion 11/2024 (the central template storage scenario was rejected).
- Territorial scope
- Italy — Milan Linate airport
- Last status change
- 2026-03-12
- Declared compliance date
- not applicable
Clothoff — serwis i bot "deep nude" (generowanie fałszywych nagich zdjęć i filmów)
Provider: Spółka z siedzibą na Brytyjskich Wyspach Dziewiczych (operator Clothoff; Garante nie ujawnił nazwy w komunikacie)
Blocked by a regulator
On 1 October 2025 the Italian Garante ordered, as a matter of urgency and with immediate effect, a provisional limitation on the processing of Italian users' personal data by the company operating Clothoff, a generative-AI service that produces fake nude images and videos ("deep nude") from uploaded photographs. The authority noted that anyone, including minors, could use the app, that the service applied no mechanism allowing the consent of the depicted person to be verified and did not label the output as artificial, and that this creates high risks to dignity and privacy, particularly of minors; it simultaneously opened a wider investigation covering all "nudify" applications. The measure binds the service operator rather than internet providers, however, so it does not make Clothoff technically unreachable from Italian territory. In a 6 May 2026 statement the authority reaffirmed the earlier Clothoff block and repeated its request for the power to cut off access from Italy to such platforms directly.[43][44][45][28][2][46]
- Legal basis
- GDPR Art. 58(2)(f) — temporary limitation of processing, imposed by the Garante under the urgency procedure (the press release does not cite article numbers, referring to "elevati rischi" to fundamental rights and freedoms). From December 2026 such systems will additionally be covered by the Article 5(1)(ba) AI Act prohibition introduced by Regulation (EU) 2026/1744 (Digital Omnibus on AI; adopted 8 July 2026, OJ of 2026-07-24, in force from 2026-07-27) — in Commission terminology "Prohibition 9", expressly covering "nudification" applications. The Commission states the application date at month level (December 2026); the exact day is not confirmed in the verified sources, so this entry gives no day-level date.
- Territorial scope
- Italy (data of Italian users)
- Last status change
- 2025-10-01
- Declared compliance date
- unknown
DeepSeek (aplikacja i modele)
Provider: Hangzhou DeepSeek Artificial Intelligence / Beijing DeepSeek Artificial Intelligence (Chiny)
Blocked by a regulator
On 2025-01-30 Italy's Garante imposed a limitation on the processing of Italian users' data by Hangzhou DeepSeek and Beijing DeepSeek, finding their reply to its information request entirely unsatisfactory; the companies had argued they do not operate in Italy and are not subject to EU law. The app was removed from the Apple and Google stores in Italy and remains unavailable there (as of January 2026), although the website is technically reachable; the Garante's proceeding is still open, with no final decision and no fine. On 2025-06-27 Berlin data protection commissioner Meike Kamp notified Apple and Google that the app is illegal content under DSA Article 16, alleging unlawful data transfers to China (GDPR Art. 46(1)), after an earlier request of 2025-05-06 to withdraw voluntarily was ignored, and in coordination with the authorities of Baden-Wuerttemberg, Rhineland-Palatinate and Bremen and with the Bundesnetzagentur - however, a notice under DSA Article 16 is not binding, Apple and Google did not act on it, and the app remains available in German stores. Investigations or regulatory steps were also recorded in Ireland, Belgium, the Netherlands, France, Spain, Portugal, Greece, Luxembourg, Poland, Lithuania and Croatia among others, and the EDPB widened its ChatGPT taskforce into a general AI enforcement group; in a separate consumer-law track Italy's AGCM, by decision no. 31784 (PS12942) of 2025-12-16, published in its bulletin and reported in the press on 2026-01-05, closed the case without finding an infringement, accepting DeepSeek's commitments to warn about hallucinations (non-compliance with a commitment decision carries a fine of EUR 10,000 to EUR 10 million under the Italian Consumer Code).[47][48][49][50][51][52]
- Legal basis
- GDPR Art. 58(2)(f) (limitation on processing), Art. 44-46 (third-country transfers), Art. 5, 6, 13-14; DSA (Reg. 2022/2065) Art. 16 - notice of illegal content to app stores (non-binding); Italian Consumer Code Art. 27(7) - AGCM commitment decision
- Territorial scope
- Italy (block in force - app removed from stores), Germany (notice to app stores with no effect - app still available); investigations and regulatory steps in Ireland, Belgium, the Netherlands, France, Spain, Portugal, Greece, Luxembourg, Poland, Lithuania and Croatia among others
- Last status change
- 2025-01-30
- Declared compliance date
- no provider statement
Withheld by the provider
5
The provider does not offer the product in the EU or EEA. No formal order by an authority.
Siri AI (nowa generacja Siri z Apple Intelligence) w iOS 27 i iPadOS 27
Provider: Apple Inc.
Withheld by the provider
On 2026-06-08 Apple announced it would not make the new Siri AI available to EU users with iOS 27 and iPadOS 27, citing EU regulators' interpretation of the Digital Markets Act which, in Apple's view, would force it to give any voice assistant direct access to users' private data. The exclusion also covers a new app for revisiting conversations, expanded Visual Intelligence, integrated writing tools, Siri mode in Camera and watchOS 27 (which requires a paired iPhone with Siri AI); in the EU Siri AI is to be available on macOS 27 and visionOS 27. This is a unilateral provider decision, not an authority order: Apple states there is currently no timeline for EU availability, and the controlled-access mechanism it proposed for competing assistants ("Trusted System Agent") was, according to Apple, rejected by regulators. The European Commission disputed that justification, stating on 2026-06-09 that the DMA contains no provisions prohibiting Apple from introducing new products or services in the EU and that Apple had not put forward a DMA-compliant interoperability proposal.[53][54][55][56]
- Legal basis
- Regulation (EU) 2022/1925 (Digital Markets Act, DMA) — gatekeeper interoperability obligations; no authority decision or order — the exclusion was imposed unilaterally by the provider.
- Territorial scope
- EU (27 Member States); the exclusion covers iOS 27, iPadOS 27 and the dependent watchOS 27 — it does not cover macOS 27 or visionOS 27
- Last status change
- 2026-06-08
- Declared compliance date
- no provider statement
Sora / Sora 2
Provider: OpenAI
Withheld by the provider
Sora's first generation, available outside Europe from December 2024, reached the EU, EEA and Switzerland on 27-28 February 2025 for ChatGPT Plus and Pro subscribers; the delay was linked to regulatory questions around AI-generated content and data protection, but OpenAI gave no official reason. Sora 2 with its social app, launched on 2025-09-30 in the US and Canada, was never made available in the EU - at the Android launch of 2025-11-04 the official market list covered Canada, Japan, Korea, Taiwan, Thailand, the US and Vietnam, with no EU country. OpenAI announced the wind-down on 2026-03-24: the app and web experience were shut down worldwide on 2026-04-26, while the sora-2 and sora-2-pro models in the Videos API still run until the announced removal on 2026-09-24. This is a historical entry - EU unavailability never stemmed from a regulatory order but from a vendor decision, and the consumer product now runs nowhere.[57][58][59][60][61][62][63][64][65]
- Legal basis
- No regulatory order. Originally a delayed regional launch (vendor decision), then a global business decision by OpenAI to wind the product down, justified by redirecting compute toward coding tools and enterprise customers.
- Territorial scope
- EU + EEA + Switzerland (historically); currently a global shutdown
- Last status change
- 2026-04-26
- Declared compliance date
- 2026-09-24
Personal Intelligence (Gemini)
Provider: Google
Withheld by the provider
NEEDS VERIFICATION
Personal Intelligence — a Gemini app feature that draws on the user's Gmail, Calendar, Drive, Photos and YouTube — launched in the United States on 27 March 2026 and reached the rest of the world on 14 April 2026, excluding the European Economic Area, Switzerland and the United Kingdom; Android Police also lists Nigeria and South Korea among the exclusions, jurisdictions outside the GDPR area, which makes an explanation resting on GDPR alone incomplete. The feature is optional and requires user opt-in, works only with personal Google accounts, and at launch covered AI Plus, Pro and Ultra subscribers, with free users announced to follow; Google's product page confirms the exclusion of users under 18 and of Workspace and Workspace for Education accounts but does not list excluded regions. Google published no justification for the EEA exclusion and no availability date, and the finding rests solely on consistent reporting by several independent outlets, with no confirmation from a vendor primary source. The position as of 14 August 2026 remains unconfirmed: NokiaPowerUser reported on 7 May 2026 that the feature had started in Europe, but the report stands alone, the description it cites concerns a different feature (memory of past chats), and the outlets that covered the original exclusion have not reported it being lifted.[66][67][68][69][70][71]
- Legal basis
- No regulatory order. A unilateral regional exclusion by the vendor with no officially stated legal basis. Regulatory context cited by commentators: Regulation 2016/679 (GDPR) regarding combining data across services, and Regulation 2024/1689 (AI Act); the list of excluded countries nonetheless extends beyond the GDPR's territorial scope.
- Territorial scope
- EEA + Switzerland + United Kingdom (Android Police also lists Nigeria and South Korea)
- Last status change
- 2026-04-14
- Declared compliance date
- no provider statement
Google Flow (Veo)
Provider: Google
Withheld by the provider
Google Flow - the video production tool built on the Veo model - is available in the EU; Google's help page lists Germany, France, Italy, Spain, Poland and the Netherlands among supported countries, and on 10 July 2025 the service expanded to 76 further countries, reaching over 140 markets. The restriction is feature-level, not country-level: the Avatars feature remains unavailable in the EEA, Switzerland and the United Kingdom, while editing of user-uploaded video is unavailable in the EEA, Switzerland, the United Kingdom and some U.S. states, showing that the latter restriction is not exclusively European. Google states no legal basis and no date for lifting them, and the date they took effect could not be established; the help page's language versions are not synchronised - the Avatars paragraph appears only in the English version, while "some U.S. states" appears in the Polish and German versions but not the English one. Several publications describe Flow as unavailable in the EU; these most likely describe an earlier stage of the rollout - verification against Google's help page on 14 August 2026 indicates the service works in EU states, making this a partial case: a feature restriction, not a block on the tool.[72][73][74][75][76]
- Legal basis
- No regulatory order. Feature restrictions imposed unilaterally by the vendor with no stated legal basis; both available sources belong to Google and no non-vendor confirmation was obtained. Regulatory context: Regulation 2016/679 (GDPR) and Article 50 of Regulation 2024/1689 (AI Act) - the synthetic-content labelling duty applicable from 2026-08-02.
- Territorial scope
- EEA + Switzerland + UK (Avatars feature); EEA + Switzerland + UK + some U.S. states (editing of uploaded video); the service itself is available in EU states
- Last status change
- 2025-07-10
- Declared compliance date
- no provider statement
Llama (modele multimodalne, m.in. Llama 4)
Provider: Meta
Withheld by the provider
The Llama 4 Acceptable Use Policy withholds from individuals domiciled in the EU and from companies with a principal place of business in the EU the rights granted under Section 1(a) of the licence agreement; the restriction does not apply to end users of products or services incorporating those models, so a non-EU company may serve EU customers with Llama 4-based services. The clause first appeared with Llama 3.2 in September 2024 and carried over into Llama 4 (April 2025); Meta justified it by the unpredictability of the European regulatory environment. Both released Llama 4 models (Scout and Maverick) are natively multimodal, so the restriction covers the entire released family, while Behemoth remained a teacher model and was never publicly released. The restriction is modality- and generation-specific - it does not cover Llama 3.1 and earlier, nor the text-only Llama 3.2 1B/3B - and it is not a ban on distributing products in the EU but an exclusion from the scope of the licence granted; the clause was verified as still in force on 14 August 2026 in Meta's primary source.[77][78][79][80][81]
- Legal basis
- No regulatory order. A contractual clause in the Llama 4 Acceptable Use Policy, incorporated into the agreement by reference under Section 1.b.iv of the Llama 4 Community License Agreement; it withholds the rights granted under Section 1(a) of that agreement. The licence agreement body itself contains no EU exclusion (its only EEA reference identifies which Meta entity is the contracting party). Meta cites regulatory uncertainty linked to Regulation 2024/1689 (AI Act) and, earlier, Regulation 2016/679 (GDPR).
- Territorial scope
- EU (27 member states); a licensing restriction on licensees, not on end users
- Last status change
- 2025-04-05
- Declared compliance date
- no provider statement
Under investigation
9
A formally opened proceeding by an authority or court. The tool remains available.
Suno (generator muzyki AI)
Provider: Suno, Inc.
Under investigation
NEEDS VERIFICATION
GEMA sued Suno on 2025-01-21 before the Munich Regional Court I, and by judgment of 2026-07-31 (case 42 O 763/25) the 42nd civil chamber largely upheld claims for injunctive relief, for disclosure of information and for a declaratory order confirming entitlement to damages, the amount of which is to be determined once the disclosure obligation on revenues is met. The court found that six works at issue (including "Atemlos durch die Nacht", "Rasputin", "Forever Young", "Daddy Cool") are reproducible in the v3.5 and v4 models through memorisation of training data not covered by the text and data mining exception in § 44b UrhG, held that the mere offering of the model infringes the unnamed right of communication to the public under § 15(2) UrhG, and rejected the US fair use defence because all factors under 17 U.S.C. § 107 weighed against the defendant (outputs substantially similar to the originals, generated from non-specific prompts). The judgment is not final, Suno has not publicly confirmed whether it will appeal, and the service remains available in Germany — the ruling is not a ban on providing it; on 2026-08-06 Suno announced the introduction of watermarking and fingerprinting and cooperation with Audible Magic and Musixmatch, without referring to the judgment in that post. The low confidence stems from the judgment not being final and from the fact that the full operative wording, including the reach of the injunction, has not been published.[82][83][84][85][86][87][88][89]
- Legal basis
- German Copyright Act (UrhG) — reproduction right and the unnamed right of communication to the public (§ 15(2)); contested scope of the text and data mining exception (§ 44b UrhG, Art. 4 of Directive 2019/790); judgment of the Munich Regional Court I, case 42 O 763/25 of 2026-07-31, not final.
- Territorial scope
- Germany (effect of the judgment); precedential significance beyond Germany uncertain — in Member States with a broader TDM exception the outcome could differ, and the territorial reach may be tested on appeal
- Last status change
- 2026-07-31
- Declared compliance date
- unknown
Character.AI
Provider: Character Technologies Inc. (USA)
Under investigation
By decision No 10269571 of 2026-07-03, announced on 2026-07-09, Italy's Garante fined Character Technologies Inc. EUR 158,000 (about USD 180,500) for deficient privacy notices, a late data protection impact assessment (DPIA), late appointment of an EU representative, and ineffective age verification with insufficient safeguards for minors. The authority ordered the company to make age verification actually work, to introduce a cooling-off period preventing blocked minors from immediately re-registering, and to set minors' profiles to private by default; the company has 120 days from RECEIPT of the decision to report the measures adopted - counted from the decision date that falls around 2026-10-31, but the date of service is not public, so the actual deadline may be later. The service was neither blocked nor restricted and remains available in Italy and across the EU, which is why the entry is classified as a proceeding (a live corrective order with an open deadline) rather than blocked. Independently of the Garante decision, and in line with its 2025-10-29 announcement, the company has been removing open-ended chat for under-18 accounts since 2025-11-24 starting in the US, with other markets following, and is rolling out multi-layered age assurance with a third-party provider (Persona).[90][91][92][93][94][95]
- Legal basis
- GDPR Art. 5(2) (accountability), Art. 12(1), Art. 13(1)-(2), Art. 14(1)-(2) (transparency), Art. 24(1), Art. 25(2) (data protection by default), Art. 27(1) (EU representative), Art. 35(1) (DPIA), Art. 57, Art. 58(2)(d) and (i), Art. 83 (orders and administrative fine). Art. 8 GDPR does not appear in the decision.
- Territorial scope
- Italy (Garante decision); service available across the EU
- Last status change
- 2026-07-03
- Declared compliance date
- 2026-10-31
Myndoor — wtyczka do Slacka i Microsoft Teams szacująca stres i emocje pracowników metodą sentiment analysis
Provider: Myndoor S.r.l. (via Aldo Moro 5/3, 20088 Rosate, prow. Mediolan, Włochy)
Under investigation
By decision no. 342 of 14 May 2026 the Italian Garante challenged the Myndoor plug-in for Slack and Microsoft Teams, which used sentiment analysis to estimate employees' stress levels and emotional states from the content of their work messages. The authority acted as a GDPR supervisory authority and invoked Article 5(1)(f) of the AI Act — the ban on AI systems inferring emotions in the workplace — as supporting reasoning, without expressly finding an AI Act infringement; it held that the declared purpose of "preventive medicine, diagnosis and care" is radically precluded to the employer, and that making AI-inferred information about staff available to the employer must be prevented by technical and organisational measures. It is one of the first known European data protection authority decisions to invoke that ban, but the instrument used was a warning under GDPR Article 58(2)(a) — no fine, no deadline, no withdrawal order, appealable within 30 days — and the tool remains on the market, hence the status "proceeding" rather than "prohibited". In a letter of 24 December 2025 the company stated that, following infrastructure optimisation, the system architecture no longer collects personal data; the Garante issued the warning nonetheless, and the decision was published in the docweb database in early June 2026.[96][97][98][99]
- Legal basis
- GDPR Articles 5, 6, 9, 24, 25 and 88; the measure applied: a warning under GDPR Article 58(2)(a) in conjunction with Article 154(1)(f) of the Italian Data Protection Code (also Articles 2-ter and 113 of the Code). Article 5(1)(f) of Regulation (EU) 2024/1689 (AI Act) — the ban on AI systems inferring emotions in the workplace, applicable since 2 February 2025 — was invoked as supporting reasoning.
- Territorial scope
- Italy (national decision); the underlying Article 5(1)(f) AI Act ban applies across the EU
- Last status change
- 2026-05-14
- Declared compliance date
- not applicable
PimEyes
Provider: PimEyes (operator deklarujący siedzibę w Dubaju; kolejno deklarowane lokalizacje: Polska, Seszele, Belize, Dubaj)
Under investigation
PimEyes runs a facial search engine built on billions of images scraped from the public internet; the service remains available to EU users and is not subject to any blocking order (availability checked on 2026-08-14). On 2025-11-07 the Hamburg data protection authority (HmbBfDI) - more than five years after a complaint filed in July 2020 - found that the company operates unlawfully and does not answer access and erasure requests, but declined enforcement, citing the company's relocation to Dubai; the Polish competence strand was closed negatively, as noyb told the authority in July 2021 that Poland's UODO does not have the case, and the HmbBfDI itself later questioned whether Poland was competent. On 2026-04-30 noyb sued the authority for inaction before the Hamburg administrative court, arguing that the GDPR applies extraterritorially and that the authority could have frozen European funds, pursued management liability or ordered PimEyes' service providers to delete the data, as was done in the Clearview AI case; no judgment had been issued as of August 2026. In an update of 2026-07-08 noyb reported that the current operator had contacted the organisation and stated it acquired the PimEyes product from the previous owners only in 2022; PimEyes' practice matches the description in AI Act Art. 5(1)(e), but no market surveillance authority has yet applied that provision to the company, so the status remains proceeding rather than prohibited.[100][101][102][103][104][105][106][107]
- Legal basis
- GDPR Art. 3(2)(b) (extraterritorial scope - editorial qualification; German sources describe it as the Marktortprinzip), Art. 9 (biometric data), Art. 12, 15, 17, Art. 57-58 (supervisory authority duties); action for failure to act before the Hamburg administrative court
- Territorial scope
- EU (service available, no block); court proceeding in Germany (Hamburg), with an earlier, negatively closed competence strand in Poland (UODO)
- Last status change
- 2026-04-30
- Declared compliance date
- no provider statement
Worldcoin / World ID (Orb, World App)
Provider: Tools for Humanity Corporation (USA) / Tools for Humanity GmbH (Niemcy)
Under investigation
In March 2024 Spain's AEPD ordered Tools for Humanity to stop collecting and processing iris, eye and facial biometric data in Spain and to block data already captured - a provisional measure under GDPR Art. 66(1) for three months, prompted by data capture in shopping centres in exchange for cryptocurrency, the absence of age verification (data of persons from age 14) and doubts about the information given and the validity of consent; on 2024-03-26 Portugal's CNPD suspended data collection for 90 days. On 2024-06-04 the company gave a legally binding commitment not to resume activity in Spain until the end of 2024 or, if earlier, until the conclusion of Bavaria's BayLDA proceeding, which closed with a decision of 2024-12-19 ordering deletion of unlawfully collected iris codes and a compliant deletion procedure by 2025-01-19 (the company appealed) - the Spanish commitment thereby lapsed. In October 2025 Tools for Humanity GmbH became the controller for Orb operations towards users in Spain under GDPR Art. 56; on 2026-02-12 World resumed activity and opened locations in Barcelona; on 2026-02-13 the AEPD responded with an apercibimiento only, a preventive warning (file EXP202602591), without sanction or prohibition, stating that World ID likely constitutes processing of biometric data under GDPR Art. 9 requiring a stronger legal basis and a more robust DPIA; and on 2026-02-16 Tools for Humanity itself suspended operations in Spain. On 2026-06-30 the Audiencia Nacional, in judgment 304/2026 (ECLI:ES:AN:2026:2957), dismissed the company's appeal, retrospectively confirming the lawfulness of the already-lapsed 2024 measure and ordering it to pay costs; the judgment is open to cassation appeal, the World App remains available in the EU, there is currently no enforceable authority order, and we could not establish whether Orb scanning in Spain resumed between February and August 2026.[108][109][110][111][112][113][114][115][116][117]
- Legal basis
- GDPR Art. 66(1) (urgency procedure, provisional measures - applies only to the lapsed 2024 AEPD measure), Art. 5(1)(a), Art. 6, Art. 9 (biometric data), Art. 8 (children), Art. 17 (erasure - BayLDA order), Art. 58(2)(b) (AEPD warning of 2026-02-13), Art. 56 (one-stop-shop - TfH GmbH as controller since 10.2025)
- Territorial scope
- Spain (2024 measure lapsed; lawfulness upheld by court on 2026-06-30; Orb scanning paused by the company's own decision since 02.2026), Portugal (90-day suspension in 2024), Germany (BayLDA deletion order, under appeal). The World App remains available in the EU
- Last status change
- 2026-02-16
- Declared compliance date
- no provider statement
Whitebridge AI — generowane przez AI „raporty reputacyjne" o osobach, budowane ze zeskrobanych danych z sieci i mediów społecznościowych
Provider: UAB Whitebridge ai (kod rejestracyjny 306680556, Krivių g. 5, LT-01204 Wilno, Litwa; spółka zarejestrowana 14 lutego 2024 r.)
Under investigation
NEEDS VERIFICATION
The Lithuanian State Data Protection Inspectorate (VDAI) is investigating UAB Whitebridge ai, a Vilnius company selling AI-generated "reputation reports" on individuals compiled from data scraped from the web and social media. The case follows an administrative complaint by noyb of 29 September 2025 (not a lawsuit): the organisation alleges unlawfulness and inaccuracy of the data, processing of special-category data, a defective procedure for handling data subject rights — the company demanded a qualified electronic signature for access requests — and a business model that pressures people into paying to see their own data, including AI-generated and false content. VDAI publicly confirmed the investigation on 23 October 2025, and the service remains available without restrictions in the EU (checked on 14 August 2026). The VDAI register of 2026 decisions lists two decisions of 15 May 2026 concerning the company — no. 3R-882 (2.13-1.E), finding a breach of the right of access, and no. 3R-886 (2.13-1.E), finding no breach — but their texts could not be read because the authority's site blocks automated access and presents a CAPTCHA; they require manual confirmation, hence the low confidence rating and the status change date left at the public confirmation of the investigation.[118][119][120][121][122][123]
- Legal basis
- GDPR — Article 5 (lawfulness and accuracy), Article 9 (special categories of data), Article 12 (modalities for exercising data subject rights), Article 16 (rectification) — the scope of noyb's complaint; the proceeding is run by the Lithuanian supervisory authority VDAI under GDPR Articles 57–58. The unverified VDAI decisions of 15 May 2026 concerned Articles 15 and 17 GDPR.
- Territorial scope
- Lithuania (authority proceeding); service offered across the EU
- Last status change
- 2025-10-23
- Declared compliance date
- not applicable
Replika
Provider: Luka Inc. (USA)
Under investigation
NEEDS VERIFICATION
Italy's Garante imposed an urgent limitation on 2023-02-02 on Luka Inc.'s processing of Italian users' data (no age verification, risks to minors and people in emotional distress), then on 2023-06-22 suspended that limitation with effect from compliance with its orders - an updated privacy notice, an age gate at registration, a cooling-off period blocking birth-date corrections - after which the service returned to Italy. By decision of 2025-04-10, announced on 2025-05-19, the authority closed the proceeding with a EUR 5 million fine: until 2023-02-02 the company had identified no legal basis for processing, its privacy notice was inadequate, and the age verification mechanism introduced later remains deficient (birth date editable in the profile without verification, cooling-off circumvented via incognito mode and a change of e-mail address). In the same decision the Garante reserved the assessment of the lawfulness of processing across the whole lifecycle of the generative model behind Replika for a separate and autonomous proceeding. As of 2026-08-14 the service is available in Italy, and no 2026 source confirms whether that separate proceeding was formally opened or what became of any appeal against the fine - hence the low confidence rating.[124][125][126][127][128][129][130]
- Legal basis
- GDPR Art. 58(2)(f) in conjunction with Art. 5(8) of Garante Regulation No 1/2000 (provisional limitation of 2023-02-02); Art. 58(2)(d) (orders of 2023-06-22). Infringements established by the decision of 2025-04-10: GDPR Art. 5(1)(a) and (c), Art. 6, Art. 12, Art. 13, Art. 24 and Art. 25(1). Art. 8 and Art. 9 GDPR appeared only as suspected infringements in the 2023 interim measure and were not confirmed.
- Territorial scope
- Italy
- Last status change
- 2025-05-19
- Declared compliance date
- no provider statement
Grok — trening modeli LLM na publicznych postach z platformy X
Provider: X Internet Unlimited Company (dawniej Twitter International Unlimited Company) / xAI
Under investigation
On 8 August 2024 the DPC brought proceedings before the Irish High Court under section 134 of the Data Protection Act 2018 — the first such action taken as lead supervisory authority for the whole EU/EEA; X undertook to suspend processing of EU/EEA users' public posts from the 7 May–1 August 2024 period for Grok training and to delete that data, and on 4 September 2024 the court proceedings were struck out after the undertaking was made permanent. On 11 April 2025 the DPC opened a separate statutory inquiry under section 110 of the same Act, examining the lawfulness and transparency of processing EU/EEA users' public posts to train the Grok models; the controller is X Internet Unlimited Company, which notified the authority on 25 March 2025 of its renaming from Twitter International Unlimited Company effective 1 April 2025. On 17 February 2026 the DPC opened a second, separate section 110 inquiry into the same company, concerning the creation and publication on the X platform of non-consensual intimate or sexualised images of EU/EEA individuals, including children, generated with Grok — a different processing operation from training on posts. As of August 2026 the DPC has published no final decision in either matter; X and Grok remain available in the EU.[131][132][133][134][135]
- Legal basis
- Section 110 of the Irish Data Protection Act 2018 (basis for the inquiries opened on 11.04.2025 and 17.02.2026) and section 134 of the same Act (the court route used in 2024). In its statement of 11.04.2025 the DPC refers generally to key GDPR provisions, including the lawfulness and transparency of processing (Art. 5 and 6; the reference to Art. 12–14 is the editors' legal characterisation, not an enumeration by the authority). In the inquiry of 17.02.2026 the DPC cites GDPR Art. 5, 6, 25 and 35.
- Territorial scope
- EU + EEA
- Last status change
- 2025-04-11
- Declared compliance date
- unknown
PaLM 2 (model fundamentowy Google)
Provider: Google Ireland Ltd.
Under investigation
On 2024-09-12 the Irish DPC opened an own-volition cross-border statutory inquiry under section 110 of the Data Protection Act 2018 into Google Ireland Ltd. Its sole subject is whether Google complied with any obligation to carry out a data protection impact assessment (DPIA) under GDPR Art. 35 before processing the personal data of EU and EEA data subjects in developing the PaLM 2 foundation model; the inquiry does not challenge the availability of Google's services in the EU, and the model and services built on it remain available. The notice of commencement with a set of questions was served on Google in September 2024, the company's response arrived in October 2024, and the information gathering phase remained ongoing at the end of 2024; Google does not appear in the complete table of the DPC's ten final decisions for 2025, and the authority's 2026 communications contain no decision in this case. Confidence is medium because the last positive confirmation that the case is running dates from the end of 2024, while for 2025–2026 there is only confirmation that no final decision exists — the absence of any mention of PaLM 2 in the 2025 report is not evidence of closure, since that report's narrative section covers only selected inquiries that reached a key investigative stage in 2025.[136][137][138][139][140]
- Legal basis
- GDPR Art. 35 (obligation to carry out a data protection impact assessment); section 110 of the Irish Data Protection Act 2018 as the basis for opening the inquiry; GDPR Art. 60 — the DPC's role as lead supervisory authority in a cross-border case.
- Territorial scope
- EU + EEA
- Last status change
- 2024-09-12
- Declared compliance date
- unknown
Compliant — available
9
Closed cases: the product was restricted, the provider made changes, and it operates in the EU today.
Grok 4.5
Provider: SpaceXAI (dawniej xAI, spółka zależna SpaceX)
Compliant — available
Grok 4.5 launched on 2026-07-08 excluding the entire European Union - the model worked neither in the vendor's products nor in the API console; the vendor is SpaceXAI, operating under that name since around 2026-07-06/07, after SpaceX acquired xAI on 2026-02-02. No formal reason for the EU exclusion was given, only an announcement of availability in mid-July, while Austrian and German trade press linked the block to AI Act obligations for general-purpose AI models with systemic risk. Vendor release notes confirm the API console was opened to EU users, dated by secondary sources to 2026-07-17, and the vendor's announcement of 2026-07-22 states the model is live on grok.com, on X and in the iOS and Android apps - this time with no EU carve-out. As of 2026-08-14 Grok 4.5 is available in the EU; earlier claims of a "47 country" launch and of the data processing location are not supported by primary sources and have been removed from this description.[141][142][143][144][145][146][147][148][149]
- Legal basis
- No regulatory order. A unilateral regional delay by the vendor, linked by trade press to Regulation 2024/1689 (AI Act) obligations for GPAI models applicable from 2025-08-02. SpaceXAI did not officially state a legal basis for the EU exclusion.
- Territorial scope
- EU (27 member states)
- Last status change
- 2026-07-17
- Declared compliance date
- 2026-07-22
LinkedIn — trening własnych modeli generatywnych na danych członków
Provider: LinkedIn Ireland Unlimited Company (Microsoft)
Compliant — available
In September 2024 LinkedIn stated it was not enabling generative AI training on member data from the EEA, Switzerland and the UK — in the UK's case it had paused those plans after intervention by the British ICO. In March 2025 it notified the Irish DPC of its intention to start training on EU and EEA member data from early November 2025; following the authority's recommendations it made changes: enhanced transparency notices on the processing and the right to object, reduced scope and time period of the data used, exclusion of under-18s' data, filters excluding special category data (including trade union membership) and risk assessments. Training began on 2025-11-03 on an opt-out basis for members in the EU, EEA, Switzerland, the UK, Canada and Hong Kong — in the UK the same setting also covers sharing data with the affiliate Microsoft for its own model training. The DPC, whose statement of 2025-11-07 concerns only EU and EEA members, stressed that it had neither approved the practice nor found it compliant, and required LinkedIn to submit a compliance report within five months; that deadline fell around 2026-04-03 and as of August 2026 the authority has published no outcome of its assessment of that report.[150][151][152][153]
- Legal basis
- GDPR Art. 6(1)(f) (legitimate interest) and Art. 21 (right to object); GDPR Art. 9 as regards exclusion of special category data; DPC supervision as lead supervisory authority under GDPR Art. 56.
- Territorial scope
- EU + EEA + Switzerland (outside the EU also the UK, Canada and Hong Kong)
- Last status change
- 2025-11-03
- Declared compliance date
- not applicable
Recall (Copilot+ PC)
Provider: Microsoft
Compliant — available
Recall — the Copilot+ PC feature that saves screen snapshots and lets users search them in natural language — was redesigned after the 2024 wave of privacy criticism and reached general availability on 25 April 2025, with the European Economic Area excluded; in that announcement Microsoft said Recall would come to the EEA later in 2025, giving no reason for the delay. The feature started in the EEA on 30 July 2025 in the Release Preview channel for Windows 11 24H2, with broad availability announced for the August update; Microsoft documentation as of February 2026 still labels Recall a preview. An EEA-only mechanism was added: users can export their own snapshots to trusted apps and websites using a 32-character hexadecimal code shown during Recall setup, and losing the code forces a Recall reset that deletes the snapshots; administrative documentation confirms the export policy applies to EEA devices only, while developer documentation updated on 7 January 2026 narrows export to EEA devices running the latest Windows Insider preview build — a discrepancy that remains unresolved. Recall is off by default, requires user consent and Windows Hello authentication, and is removed by default on IT-managed devices.[154][155][156][157][158][159][160][161]
- Legal basis
- No regulatory order. The global rollout delay stemmed from privacy criticism and a security review, and Microsoft gave no reason for the additional EEA delay. The export mechanism was introduced for EEA devices only — Microsoft states no legal basis; interpretive context supplied by the editors, not by the vendor: Regulation 2022/1925 (DMA), including Art. 6(9) on end-user data portability, and Regulation 2016/679 (GDPR).
- Territorial scope
- EEA
- Last status change
- 2025-07-30
- Declared compliance date
- not applicable
Operator / ChatGPT agent
Provider: OpenAI
Compliant — available
Operator, announced on 23 January 2025 and released to ChatGPT Pro subscribers on 1 February 2025 in the United States only, opened to the EU, Switzerland, Norway, Iceland and Liechtenstein on 13 March 2025 for users aged 18 and over, and was shut down on 31 August 2025 after the launch of ChatGPT agent. Its successor - ChatGPT agent, launched 17 July 2025 - initially excluded the European Economic Area and Switzerland; on 23 July 2025 OpenAI announced the full rollout to Pro users in the EEA and Switzerland and the start of the rollout to Plus. OpenAI's help centre was still displaying the outdated 17 July note on 26 July 2025 saying the feature was unavailable in the EEA and Switzerland, despite reports of a quiet rollout on Plus and Team accounts in Italy, Spain, Germany and the Netherlands. As of 14 August 2026 the feature works in the EU as ChatGPT's agent mode and is available on paid plans only, with monthly limits.[162][163][164][165][166]
- Legal basis
- No regulatory order. A vendor-side regional delay with no officially stated legal basis; regulatory context: Regulation 2016/679 (GDPR) and preparation for Regulation 2024/1689 (AI Act).
- Territorial scope
- EU + EEA + Switzerland
- Last status change
- 2025-07-23
- Declared compliance date
- not applicable
Meta AI / trening modeli Llama na publicznych treściach z Facebooka i Instagrama
Provider: Meta Platforms Ireland Ltd.
Compliant — available
In March 2024 Meta notified the Irish DPC of its intention to train large language models on public content posted by adult EU/EEA users; following the regulator's concerns it paused the training in June 2024 and withheld Meta AI from Europe — there was no formal order, only a pause at the request of the DPC acting on behalf of European authorities. After EDPB Opinion 28/2024, adopted on 17 December 2024, and a set of changes (in-app and email notices, a simplified objection form working across all jurisdictions, de-identification, dataset and output filtering) Meta resumed training on 27 May 2025; the Meta AI assistant itself had already launched in Europe earlier, in March 2025. The DPC issued no formal approval — it refrained from further intervention and required an evaluation report for October 2025, the outcome of which has not been made public; the authority has published no further statement on the matter since 21 May 2025 (position as of 14 August 2026). The legal basis is contested by noyb, which filed complaints in 11 countries on 6 June 2024 and sent Meta a cease-and-desist letter on 14 May 2025; separately, the consumer association Verbraucherzentrale NRW, after its own cease-and-desist of 6 May 2025, applied for an injunction based on alleged GDPR and DMA violations — the Cologne Higher Regional Court rejected it on 23 May 2025 (case 15 UKl 2/25), holding that reliance on legitimate interest was permissible.[167][168][169][170][171][172][173][153]
- Legal basis
- GDPR Art. 6(1)(f) (legitimate interest) and Art. 21 (right to object); DPC supervision as lead supervisory authority under GDPR Art. 56; EDPB Opinion 28/2024 of 17 December 2024 on personal data processing in the context of AI models. The Verbraucherzentrale NRW proceedings before the Cologne court additionally alleged breaches of Regulation 2022/1925 (DMA).
- Territorial scope
- EU + EEA
- Last status change
- 2025-05-27
- Declared compliance date
- not applicable
Apple Intelligence (pakiet funkcji AI; geoblokada dotyczyla iOS/iPadOS)
Provider: Apple Inc.
Compliant — available
In June 2024 Apple announced it would not make Apple Intelligence available to EU iPhone and iPad users alongside the launch in other regions, citing the interoperability requirements of the Digital Markets Act (DMA); the restriction did not cover Macs and followed from no authority order — it was a provider decision, a geo-restriction. On 2025-02-21 Apple announced the features would come to the EU, and they reached EU iPhones and iPads with iOS 18.4 and iPadOS 18.4 released on 2025-03-31, which lifted the original geo-restriction; those features remain available in the EU. On 2026-06-08, however, Apple announced that with iOS 27 it will not release in the EU the new Siri app, expanded Visual Intelligence, integrated Writing Tools or Siri mode in Camera — a separate, still ongoing geo-restriction described in the entry apple-siri-ai-ue.[174][175][176][54][177]
- Legal basis
- Regulation (EU) 2022/1925 (Digital Markets Act, DMA) — gatekeeper interoperability obligations, in particular Art. 6(7); no authority decision or order — the restriction was imposed and lifted by the provider.
- Territorial scope
- EU (27 Member States); the original restriction covered iOS and iPadOS, not macOS
- Last status change
- 2025-03-31
- Declared compliance date
- not applicable
Meta AI (asystent)
Provider: Meta
Compliant — available
Meta AI launched across 41 European countries, including every EU member state, plus 21 overseas territories in March 2025 - more than a year after its US debut, which Meta attributed to the complexity of Europe's regulatory system. The European version launched stripped down: text chat only, in six languages, without memory and without image generation via the Imagine tool, justified by GDPR compliance, and the model released in the EU at that point was not trained on EU user data. That changed: following the Irish DPC's statement of 21 May 2025, Meta began training its models on public content from adult EU users on 27 May 2025 (with an objection option), and on 6 November 2025 it brought the standalone Meta AI app to Europe with the Vibes feed, image generation and animation, and short video. Whether the memory feature is available in the EU could not be established; a separate matter - the European Commission's antitrust investigation opened on 4 December 2025 into Meta's policy restricting rival AI providers' access to WhatsApp - does not concern the availability of Meta AI itself.[178][179][170][167][180][181][182]
- Legal basis
- No regulatory order affecting the availability of Meta AI. Delay and feature limitations justified by Meta on the grounds of Europe's complex regulatory environment and compliance with Regulation 2016/679 (GDPR); training on EU users' public content began after safeguards were agreed with the Irish DPC. Separately, the European Commission is running an antitrust investigation into rival AI providers' access to WhatsApp (EEA scope).
- Territorial scope
- 41 European countries, including all 27 EU member states, plus 21 overseas territories
- Last status change
- 2025-03-20
- Declared compliance date
- not applicable
Google Bard (obecnie Gemini)
Provider: Google Ireland Ltd. / Google LLC
Compliant — available
Bard's EU launch, planned for mid-June 2023, was halted after an informal intervention by the Irish DPC — Deputy Commissioner Graham Doyle noted the authority had received neither a detailed briefing nor a data protection impact assessment (DPIA) or supporting documentation. This was not an order or an administrative decision: Google itself paused the rollout and made changes ahead of launch, including increased transparency, the Bard Privacy Hub and control over Bard Activity retention (18 months by default, with options of 3 or 36 months or turning off saving of conversations); the DPC itself put it more narrowly as increased transparency and changes to controls for users. Bard launched in the EU on 2023-07-13, and Google undertook towards the DPC to carry out a review and provide the authority with a report three months after launch, while the authority announced continued engagement — the case did not close on launch day. Its successor, Gemini, is available in the EU and EEA without restrictions arising from this case; a separate DPC inquiry opened on 2024-09-12 concerns the PaLM 2 model and GDPR Art. 35 and does not restrict the availability of the services.[183][184][185][186][187][136]
- Legal basis
- GDPR Art. 35 (data protection impact assessment) and Art. 12–14 (information duties and transparency); informal intervention by the DPC as lead supervisory authority under GDPR Art. 56 — no administrative decision issued.
- Territorial scope
- EU (Gemini now also available in the EEA)
- Last status change
- 2023-07-13
- Declared compliance date
- not applicable
ChatGPT
Provider: OpenAI (od 2024-02-15 OpenAI Ireland Ltd. dla EOG)
Compliant — available
By a measure of 2023-03-30 (press release 2023-03-31) the Italian Garante imposed a temporary limitation on the processing of Italian users' data, alleging the absence of information notices, the absence of a legal basis for the mass collection of data to train algorithms, data inaccuracy and the lack of age verification; ChatGPT was unavailable in Italy. By a measure of 2023-04-11 the authority set out nine remedial measures, seven of which were to be implemented by 2023-04-30, and on 2023-04-28 OpenAI restored the service. The case was closed by measure no. 755 of 2024-11-02, announced by a press release of 2024-12-20: a EUR 15 million fine and an order to run a six-month information campaign on radio, television, print and the internet; in March 2025 the Court of Rome suspended enforcement of the fine on a precautionary basis. By judgment no. 4153/2026 of 2026-03-18 the same court annulled the fine and the order, upholding the first of OpenAI's ten grounds — the Garante's lack of competence over cross-border processing after the sole establishment was set up in Ireland on 2024-02-15, which moves the case into the one-stop-shop mechanism; the court did not rule on the substance of the GDPR allegations and no challenge to the judgment by the Garante has been confirmed as of August 2026.[188][189][190][191][192][193]
- Legal basis
- GDPR Art. 58(2)(f) (temporary limitation of processing) — basis of the 2023 block; GDPR Art. 5, 6, 12–14 and 33 — allegations in the 2024 decision; Art. 166(7) of the Italian data protection code — the information campaign order; GDPR Art. 55, 56 and 60 (one-stop-shop) — basis of the 2026 annulment.
- Territorial scope
- Italy
- Last status change
- 2023-04-28
- Declared compliance date
- not applicable