The European Commission says it is examining the privacy risks raised by research indicating data transfers and connections with tracking services in some artificial intelligence-based chatbots. Thomas Regnier confirmed that the matter is being reviewed, but the Commission has not announced a formal investigation, identified any companies concerned, or so far found a breach of EU law.
The European Commission is examining concerns about how some artificial intelligence services handle user data and connections with tracking systems used in advertising and online analytics. Thomas Regnier, the Commission spokesperson for technological sovereignty, defence, space and disinformation, confirmed at the 8 October briefing that these issues are being examined, after being asked about research flagging possible transfers of information to trackers even in certain situations where users reject non-essential cookies.
In brief
1.The Commission confirms that it is examining concerns regarding data protection and tracking associated with certain chatbots, but it has not announced a formal investigation.
2.Research by IMDEA Networks has flagged the presence of tracking mechanisms in conversational artificial intelligence services and the possible transmission to third parties of information related to conversations.
3.Researchers have raised questions about the compatibility of certain practices with the General Data Protection Regulation and ePrivacy rules, but these observations do not constitute findings by a regulatory authority.
4.The Commission points to the GDPR, the Digital Services Act and the Artificial Intelligence Act as parts of the relevant legal framework, with enforcement powers divided between national authorities and the EU level.
5.The Commission has not specified which companies are being examined, whether it will open formal proceedings or when a decision might follow.
The questions addressed to the Commission stemmed from research into the technical infrastructure used by generative chatbots and its relationship with online analytics and advertising systems. A study presented by IMDEA Networks in May 2026 analysed services such as ChatGPT, Claude, Grok and Perplexity AI and identified various forms of tracking by third-party companies. The researchers warned that, in certain configurations, information associated with conversations, such as titles, conversation addresses or other metadata, may reach tracking services together with identifiers that can be used to correlate a user's activity.
The authors described the findings as preliminary. They identified three main categories of risk: the transmission of information associated with conversations to third parties, the possibility of linking this information to the user's identity through persistent identifiers, and differences between the protection a user might believe privacy settings provide and the actual technical data flows. The research does not represent a finding by a data protection authority and does not, in itself, establish that the providers analysed have breached European law.
At the Commission briefing, the question focused in particular on the situation in which a user rejects non-essential cookies, but the service continues to make connections with systems that researchers classify as advertising-related trackers. The journalist asked whether this situation could raise issues under the General Data Protection Regulation and the ePrivacy Directive and whether stronger enforcement measures were needed.
Regnier replied that he could confirm that the Commission services are examining these matters. The wording used does not amount to opening an official investigation and does not identify a provider suspected of breaching the law. At the briefing, the Commission presented no findings of its own on the technical flows described by the researchers and did not confirm that the reported practices constitute breaches.
Legal powers are divided among several regimes. When personal data processing is involved, the General Data Protection Regulation remains the central framework, and its enforcement falls primarily to national data protection authorities. The European Data Protection Board has already clarified that the development and use of artificial intelligence models do not eliminate obligations concerning the existence of a legal basis for data processing, transparency towards data subjects and the lawfulness of the data used.
The ePrivacy Directive separately regulates access to information and the storage of information on users' devices, including through tracking technologies. Whether a particular technical connection breaches these rules nevertheless depends on how the service operates in practice, the information accessed or stored, the necessity of the technology and the consent or other applicable legal basis. The research that prompted the briefing questions raises this issue, but the Commission has made no legal finding concerning individual cases.
Regnier also indicated the Digital Services Act and the Artificial Intelligence Act as instruments that may become relevant depending on the service and practice being examined. The Digital Services Act contains rules concerning advertising on online platforms, while the Artificial Intelligence Act introduces specific obligations for providers of artificial intelligence models and systems. Exact applicability must be determined for each service and each type of activity.
For general-purpose artificial intelligence models, the Commission, through the AI Office, has its own powers to supervise and enforce the obligations laid down in the Artificial Intelligence Act. These powers include requesting information and documentation, evaluating models in the situations provided for by the regulation and, where applicable, imposing measures or penalties. Regnier also linked the current concerns to transparency regarding the data used to train models, an area in which the AI Office can verify compliance with the specific obligations of general-purpose model providers.
This role does not, however, transfer all privacy issues to the Artificial Intelligence Act. The lawfulness of personal data processing continues to be assessed primarily under the GDPR and ePrivacy rules, while the powers of the Commission, national data protection authorities and other supervisory authorities differ depending on the applicable rule.
The Commission stated that independent studies and research on artificial intelligence systems can contribute to its supervisory work. On 8 October, however, there was no announcement concerning the opening of formal proceedings, a list of providers concerned or a timetable for any measures. The next stage depends on the technical and legal assessment of the reported practices and on determining the competent authority for each possible breach.
Latest News
15:58
15:56
15:52
15:48
15:48
See more news