Thanks! Paras 110-113 are very interesting in that 'knowledge' and 'control' of content are disaggregated, and providers don't merely lose the hosting immunity if they algorithmically choose content - they also lose the benefit of the prohibition on general monitoring.
Gabriela Zanfir-Fortuna
@gzf.bsky.social
Data Protection Geek. Co-author of the big GDPR OUP Commentary🇷🇴🇪🇺🇺🇸 US-based, former Brussels bubbler. Writes about data protection law and policy, AI governance through a Global lens (& sometimes democracy) Strictly personal views. www.pdpecho.com.
Liability is a function of the underlying law so it will differ between defamation, hate speech, harassment, data protection, copyright infringement, etc. This is significant in that it takes away an EU-wide shield, and exposes providers to liability under different domestic laws.
A European Commission proposal could create one of Europe’s largest privacy and national-security risks in decades. techletters.substack.com/p/the-europe...
The European Commission is turning Google Search into a privacy and national-security risk
The European Commission is preparing to compel Google to stream search data to third-party companies through an automated API. It is doing this under the Digital Markets Act, a regulation with a sound...
blog.lukaszolejnik.com
Data protection law does not define responsibilities for users’ data, but for individuals’ fundamental rights and how they are impacted through the processing of their data. A fundamental difference that creates a sequence of wrong interpretations of data protection law.
Join FPF CEO @julespolonetsky.bsky.social polonetsky.bsky.social and FPF VP for Global Privacy @gzf.bsky.social for a LinkedIn Live discussion marking 10 years of the adoption of the GDPR. 🗓️ Today, Friday April 17th at 12 noon ET 🔗Sign-up here: linkedin.com/events/74498...
after much deliberation and giving AI the benefit of the doubt, Wikipedia editors have had enough of AI slop. New policy bans LLM generated content, periodt www.404media.co/wikipedia-ba...
Wikipedia Bans AI-Generated Content
“In recent months, more and more administrative reports centered on LLM-related issues, and editors were being overwhelmed.”
404media.co
This is why tech neutral rules like the GDPR (which, by the way, fully applies to AI agents whenever they touch personal data) are generally a better idea 💡
Could agents be the next stumbling block for Europe’s AI rules?
With everything happening in the world today, these are the top 3 news I got on X when I opened it 👀 And I have almost zero interest in American sport (I guess this is also what happens when the algorithm forgets you due to inactivity 🤖)
2026 is a "perfect storm" for global privacy, says FPF VP of Global Privacy, @gzf.bsky.social. Her latest blog breaks down how three converging forces will shape global data protection and privacy. Read more below. fpf.org/blog/2026-a-...
2026: A Year at the Crossroads for Global Data Protection and Privacy
Three forces are reshaping global data protection in 2026: GDPR’s reopening, rapid AI development, and expanding digital regulation amid geopolitics.
fpf.org
Here’s a conundrum for you: fit the two red lines Anthropic didn’t want to forgo into the EU AI Act’s red lines under Article 5. 🦗 🦗 🦗 First thing: military use, out of scope. But even as dual use technology: 🦗 🦗 🦗 Should egregious red lines not be spelled out? Or is it an oversight?
Privacy regulators from four continents have aligned around a clear position that AI-generated sexualized deepfakes are a data protection violation. For Grok, already under investigation in multiple jurisdictions, that alignment increases the likelihood of sustained and parallel regulatory action.
Privacy Regulators in 61 Countries Back Enforcement Against AI Deepfakes
Regulators remind platforms that creation of non-consensual intimate imagery can constitute a criminal offence in many jurisdictions, reports Ramsha Jahangir.
techpolicy.press
This week, we launched a blog series exploring the "Red lines" drawn by the AI Act, a year after they became applicable. Among our takeaways, we noted that the Act does not prohibit technology per se, but uses or practices of technology that pose unacceptable risk.1🧵 LINK: fpf.org/blog/red-lin...
My magazines this week 🫠 * But since I’m deep into these conversations at my job, at least they remind me the job is kind of relevant? 🤷♀️ 🧐
Amazing resource Cc @gzf.bsky.social
Data Protection Map update for International Data Protection Day. As of the end of 2025, 172 countries and self governing jurisdictions around the world have adopted comprehensive data protection legislation. Five countries adopted comprehensive data protection for the first time in 2025.
Next week’s India AI Impact Summit is framed around “democratizing AI.” But as India expands AI-driven surveillance, predictive policing, and welfare automation, minorities and marginalized communities are bearing the costs, writes Tavishi.
India’s Global AI Pitch Masks A Troubling Reality At Home
Without regulatory oversight and guardrails, AI in India will continue to function less as a public good and more as a tool of oppression, writes Tavishi.
techpolicy.press
All events of the #AIImpactSummit in New Delhi will be live-streamed throughout next week and you can watch them here: m.youtube.com/@indiaai India certainly wins at accessibility and inclusiveness. 👀 Is this what a touch of the Global Majority looks like on AI Governance? 🤞
IndiaAI
IndiaAI Mission, an initiative by MeitY, is building a robust, inclusive AI ecosystem through democratized compute, high-quality data, talent, R&D, startup support, industry collaboration & ethical AI...
m.youtube.com
[EN] @gzf.bsky.social joined us last week to discuss proposed changes to the EU legal framework for #AI and digital services open.substack.com/pub/masterso... #GDPR #AIAct
Gabriela Zanfir-Fortuna: GDPR changes, AI Act hangover, Russmedia
Listen now | The Digital Omnibus in its context, birth defects of the AI Act, South Korea, Russmedia
open.substack.com
This is how important the Chief Privacy Officer job is. www.nytimes.com/2026/02/13/t...
Homeland Security Wants Social Media Sites to Expose Anti-ICE Accounts
nytimes.com
The most important question about AI isn't determining whether the machine thinks — it's whether interacting with it displaces the conditions under which we think, writes Eryk Salvaggio.
The Illusion of AGI, or What Language Models Can Do Without Thought
It is not simple stubbornness that LLMs are not “intelligent,” much less a form of “general” intelligence, writes Eryk Salvaggio.
buff.ly
Casey - have you come across Joseph Weizenbaum’s Computer Power and Human Reason? He is the creator of the first chatbot, Eliza, at MIT in the 60s. He pulled the plug in horror after seeing the deep paychological impact of talking to the bot on his team 🙃
The thing about Laura Codruta Kovesi is that she weeds out corruption like no one else I’ve ever seen in my life. Her EPPO is also behind the Le Pen trial, the EEAS/College of Europe muddy case and now this: www.lalibre.be/internationa...
La Commission européenne et la SFPIM perquisitionnées suite à une vente de biens immobiliers à l'État belge
L'enquête porterait sur des irrégularités constatées dans la vente de bâtiments acquis par la Société fédérale de portefeuille et d'investissement...
lalibre.be
Esta americana quere agradecer a Marimar, Maria la Del Barrio, Corazon Salvaje, Cafe con Aroma de Mujer y todas las telenovelas which ella watched en Rumania cuando era una nena y thanks to which ella ahora comprende so much Espanol 💃 Gracias, gracias, gracias ☺️
There seem to be millions of people who believe that if they ask an AI chatbot to "brainstorm" about a topic and then ask it to write a "first draft," it will still be a human-made work if they edit it. I'm sorry, but it won't.
I've been thinking a lot lately about being human, about what is unique in the way we absorb the world and we are in the world, which is beyond computability. 1/2 Detroit Institute of Arts, Contemporary Anishinaabe Art exhibition (Norval Morriseau, “Bear, Fish, Bird - Interdependence”)
This feels less like a privacy perfect storm and more like an infrastructure reckoning. Once AI workloads and cross-border data flows collide with GDPR reform, control of compute and models becomes the real pressure point. Data localization isn’t just regulatory anymore—it’s strategic.
Last week @ellamarkianos.bsky.social pitched me on the idea of trying to replace herself with a bot. Ella is irreplaceable, but her piece on building "Claudella" is sharp, funny and moving www.platformer.news/journalism-j...
The U.S. privacy landscape has transitioned from a period of legislative expansion to one of regulatory maturation. Our latest retrospective highlights four key trends in privacy law enforcement in 2025. Read more. fpf.org/blog/fpf-ret...
FPF Retrospective: U.S. Privacy Enforcement in 2025
The U.S. privacy law landscape continues to mature as new laws go into effect, cure periods expire, and regulators interpret the law through enforcement actions and guidance. State attorneys general a...
fpf.org
... increased data sharing within complex AI agent models / tools and - for a lack of better word - "social medialisation" of chatbots with detailed profiles of users, using this for ads and the related pressure to keep users online for longer.