← Insights / Compliance

OpenAI Fine Annulled, But GDPR Enforcement on AI Intensifies: What UK Professional Services Need to Know

The headline looked like a victory for AI companies. On 18 March 2026, the Court of Rome annulled the €15 million fine Italy's data protection authority, the Garante, had imposed on OpenAI in November 2024. It was the only final GDPR enforcement action concerning generative AI in Europe at that poin

Compliance 26 July 2026 6 min read

OpenAI Fine Annulled, But GDPR Enforcement on AI Intensifies: What Professional Services Firms Need to Know

The headline looked like a victory for AI companies. On 18 March 2026, the Court of Rome annulled the €15 million fine Italy's data protection authority, the Garante, had imposed on OpenAI in November 2024. It was the only final GDPR enforcement action concerning generative AI in Europe at that point, and it disappeared — on procedural grounds — almost as quickly as it had arrived.

Do not mistake this for a loosening of the regulatory grip. If anything, the legal landscape around AI and data protection is becoming more complex, more consequential, and more global in its reach. For accountants, solicitors, HR consultancies, and marketing agencies operating across multiple jurisdictions, the compliance picture demands serious attention.

What the Annulment Actually Means

The Garante had cited OpenAI for processing personal data without an adequate legal basis, failing transparency obligations, and not implementing age verification for ChatGPT. The Court of Rome's annulment was procedural, not substantive. The court did not conclude that OpenAI's practices were lawful — it found fault with how the enforcement action was conducted.

The Garante has yet to decide whether to appeal. In the meantime, the core legal questions — what constitutes a valid legal basis for training AI on personal data, what transparency looks like in practice, how age verification should be handled — remain unresolved.

For professional services businesses, the takeaway is this: the absence of a confirmed fine does not mean absence of risk. It means the legal framework is still being worked out in real time, and your compliance strategy cannot wait for settled case law before it responds.

GDPR Enforcement Is Not Softening

While attention focused on the OpenAI ruling, enforcement activity elsewhere continued at pace. The Dutch Data Protection Authority fined Clearview AI €30.5 million in September 2024 for illegally scraping facial images from the internet without consent, and ordered the company to cease operations in the Netherlands. Several other European DPAs have taken similar action against Clearview, reflecting a coordinated stance against unlawful data collection practices.

The Irish Data Protection Commission intervened in August 2024 to halt X (formerly Twitter) from using EU users' public posts to train its Grok chatbot. No fine was levied, but the outcome — X agreeing to suspend the practice — illustrates that regulatory pressure does not need to culminate in a penalty to change how AI systems are built and operated.

The numbers tell their own story. Cumulative GDPR fines reached approximately €5.88 billion by January 2025. Over €3 billion was imposed in the first half of 2025 alone. This is not a framework in retreat.

The European Data Protection Board reinforced the regulatory architecture in December 2024 with Opinion 28/2024, establishing a Europe-wide framework on data protection requirements for AI model training and deployment. Any organisation using third-party AI tools — or building their own — should treat this as required reading.

The EU AI Act: Dates That Matter

Alongside GDPR enforcement, the EU AI Act is progressing through its phased implementation. The political agreement on the "AI Act Omnibus" was reached on 7 May 2026, with the final text entering into force in July 2026. Several obligations are now either active or approaching fast.

Prohibited AI practices — including social scoring systems and real-time biometric identification in public spaces — have been enforceable since 2 February 2025. National market surveillance authorities gained enforcement powers on 2 August 2026.

Transparency obligations for chatbots and AI-generated content labelling apply from 2 August 2026, with a limited grace period until 2 December 2026 for systems already on the market. If your firm uses AI-generated content in client-facing materials, or deploys chatbot tools for client intake or support, these obligations are directly relevant.

Obligations for providers of general-purpose AI models became applicable on 2 August 2025, supported by Commission guidelines and a voluntary Code of Practice published in July 2025.

Compliance deadlines for high-risk AI systems have been extended: standalone systems listed in Annex III must comply by 2 December 2027, and those embedded in regulated products under Annex I by 2 August 2028. HR firms using AI for recruitment screening, or financial advisers using algorithmic tools for client assessments, should note that these categories are explicitly within scope.

Importantly, the definition of SME-level accommodations has been extended to mid-cap companies — those with up to 750 employees and €150 million in annual revenue. If your firm falls within that bracket, you may benefit from a more proportionate compliance pathway, but the obligations themselves still apply.

Implications Beyond Europe

Professional services firms operating internationally cannot treat EU regulation as someone else's concern.

In the UK, post-Brexit, the ICO continues to enforce UK GDPR with increasing attention to AI. The UK government's AI regulation approach remains sector-led rather than horizontal, but the ICO has made clear that existing data protection law applies fully to AI systems. Firms serving both UK and EU clients face dual compliance requirements with nuanced differences between the two regimes.

In the United States, the regulatory environment is more fragmented — federal AI legislation remains pending — but state-level privacy laws and sector-specific rules from bodies such as the FTC and SEC are creating real compliance obligations. The EU's extraterritorial reach under GDPR means that US-headquartered firms with EU clients or EU-based data subjects are already within scope.

Across the Middle East, jurisdictions including the UAE and Saudi Arabia are developing their own AI governance frameworks, often drawing on EU regulatory thinking. In the Asia-Pacific region, Australia's Privacy Act reforms and Singapore's Model AI Governance Framework are shaping expectations for responsible AI use. Professional services firms with cross-border operations need to map their AI tools and data flows across each relevant jurisdiction, not just the one where they are headquartered.

What Professional Services Firms Should Be Doing Now

The compliance priorities are clear, even if the legal landscape remains unsettled.

First, audit your AI use. Identify every tool your firm uses that processes personal data — from AI-assisted contract review to automated HR screening to client-facing chatbots. Map the legal bases for that processing and assess whether your current approach is defensible under GDPR and, where applicable, the EU AI Act.

Second, review your transparency obligations. If you use AI to generate client-facing content or to make or assist decisions that affect clients or employees, your disclosure and labelling obligations may already apply.

Third, assess your risk categorisation. If your firm falls within the scope of high-risk AI system requirements — particularly in HR, legal, or financial advice functions — begin your compliance roadmap now, even where extended deadlines apply.

Fourth, monitor enforcement closely. The Garante's decision on whether to appeal the OpenAI annulment, future DPA actions on AI training data, and national enforcement under the AI Act will all shape what compliance looks like in practice over the next 12 to 24 months.


AI compliance is no longer a peripheral concern for professional services businesses. It is a core operational risk, and the pace of regulatory development means that organisations acting late will find themselves exposed.

Ops Intel works with professional services firms globally to navigate AI compliance obligations across GDPR, the EU AI Act, and international data protection regimes. If you need clarity on where your firm stands — and what to do about it — get in touch with the Ops Intel team today.

Work with Ops Intel

Need help navigating AI compliance?

We build AI compliance frameworks and automation systems for professional services firms worldwide. Book a free 30-minute call or email us directly.

Call Now Claim Your Free Audit