IAPP AIGG Europe 2026 — Reflections from Dublin

Published
12 Jun 2026
Read time
7 min read
Category

Convention Centre Dublin, 3–4 June 2026

I was in Dublin last week for an AI governance conference, and I’ll be honest, I wasn’t sure what to expect.  I went to an IAPP conference in Brussels in 2022 which was great. I came to this one for the vibe: where is the EU up to with AI regulation and what might that mean for Australia plus to get a little more immersed in AI governance. Two days later I came away with more questions than answers. The thread running through most of it was that AI regulation is genuinely hard, and the gap between writing rules and actually implementing them is bigger than most people want to admit.

What follows are some thoughts on what any of it means for Australian practitioners who are still waiting for a framework of their own.

What’s happening with the EU AI Act (or the Case for Regulation … kind of)

Irish MEP Michael McNamara opened the conference with a question: “Who honestly believes regulation is what is truly holding back AI in Europe?” Not many hands went up.

It’s the argument that dominates the AI debate, and the favourite of most US tech companies and the current US government. Regulation kills speed. Rules create friction. The countries that move fastest win, and any government that slows things down give a competitive advantage to any country who won’t. The current US disposition, treating AI governance as an obstacle to competitiveness and a hand-brake on innovation is the clearest expression of this view. It has put real pressure on how Europe talks about its own approach.

McNamara’s point wasn’t that this argument is wrong, rather that regulation may not be the problem.  Europe’s real constraints aren’t legal, they’re structural. They are about not having the computing power needed to train and run large AI models competitively, around access to venture capital and energy constraints.

“Europe will have to navigate this environment and make some difficult choices. But if Europe doesn’t want to just write the rules for technology, but actually own its own future, then those choices are unavoidable.” — MEP Michael McNamara

Hours after this keynote, the European Commission released its new Technological Sovereignty Package, covering chips, cloud and AI infrastructure.  In effect, this is the investment in the physical building blocks of AI that McNamara had referred to, which the EU has now realised is as important as the regulation.

But turning back again to the regulation …. Lucilla Sioli from the EU AI Office was direct about where the European Commission stands: the AI Act isn’t a brake on innovation, it’s a foundation for trust, and trust is what drives adoption. “For us, the AI Act is not opposed to innovation. It is very much about enabling adoption because people need to trust the technology.”

Writing regulations and owning the technology are different ambitions, and Europe has been doing the former while falling behind on the latter, but is now moving ahead on both.  

For me, the focus on the AI Act as something that will help rather than hinder AI adoption by building trust in a fragmented and challenging space really resonated.

The US Approach

In strangely coincidental timing, the White House chose the same week as the conference to make some change in this space after staying resolutely in favour of non-intervention..

 On 2 June 2026, President Trump signed an executive order titled “Promoting Advanced Artificial Intelligence Innovation and Security” directing federal agencies to establish a framework for the secure deployment of frontier AI models.  This framework includes a process by which developers would voluntarily provide the government with early access to models for up to 30 days before public release.  The Order also explicitly bars the government from creating a mandatory licensing or preclearance requirement for new AI models.

Three days later, on 5 June, President Trump separately issued a National Security Presidential Memorandum on AI in the National Security Enterprise, establishing a new framework on the procurement and use of AI for defence and intelligence purposes.

The combined effect is an approach that wants the capability benefits of frontier AI for the US government, particularly for cybersecurity and defence, while remaining deeply reluctant to impose the kind of pre-market obligations that would give it meaningful leverage over what gets built.

The US approach remains simple in execution: move fast, keep government out of the way, and trust that American companies will maintain the lead (and act appropriately in what they’re doing). But some form of rules is not entirely out of the question. Commentary at the time of signing noted that the new Order lets the White House “kick the can down the road” while it considers longer-term rules for cutting-edge models and AI’s advanced cybersecurity capabilities.

The EU’s Answer

The US model treats regulation as a cost to be minimised. The EU model treats it as infrastructure. The same way roads and power grids are preconditions for commerce, a legal framework that gives people confidence in AI systems is, in this view, a precondition for adoption at scale. Without it, the technology might be available but people won’t use it, or won’t use it in ways that create real value.

From Dublin, watching this play out in real time, the contrast with the European position was striking but not entirely simple. That framing, deferred decisions dressed as frameworks, clashed with the vibe in the room in Dublin, where practitioners are working hard to implement something I think we all believe in (even though it is late, frustrating and hard). The US may be moving faster. But the question of whether it’s building anything durable is one the Dublin sessions certainly question.

Final Thoughts

The EU has made its choice: regulation is enabling infrastructure, not an obstacle or a handbrake on innovation. Human and broader societal rights are fundamentally important and should be protected in a proactive way, rather than relying on the market (and tech bro’s) to ‘’do the right thing.” The US has made a different choice, treating governance as a drag on competitiveness and largely stepping back from it. Whether the EU can actually implement its preferred approach is a separate question, and after two days in Dublin, I think the honest answer is: not yet, but they’re working on it and are going to give it a really good crack.

For Australian practitioners, neither model is particularly comfortable. We’ve been waiting years for meaningful privacy reform which to be honest should be far easier to implement that AI specific laws. We’re effectively governing AI relying on the existing legal remedies, developed in a different world and time without starting down the tricky path of AI specific regulation.

The clearest message from my two days in Dublin was that the gap between designing regulation and implementing it is wider than anticipated and will take longer to implement that predicted. But the difficulties the EU is navigating aren’t evidence that the approach is wrong, they’re just what detailed implementation looks like down at the nuts and bolts level of a technology that is moving at lightning speed. And, although frustrated and a little burnt out, there certainly seemed to be great commitment to the EU AI regulation project.

It’s not clear when or if Australian regulators will make the move to regulate AI in a specific way. And if they do proceed, whether they will follow the path of the EU. But if they do, the EU’s experience, the issues as much as the progress, will be the most useful body of evidence they will have. 

We in Australia are currently in an odd position: too far behind to lead, but perhaps just far enough behind to avoid some of the mistakes. It would be great if Australians could feel that their government was working towards a solution that put their rights and interests and protecting them from harm at the centre. 

Ready to turn insight into action?
Connect with Privacy 108.

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
Privacy 108 collects your name and contact details to respond to your enquiry and communicate with you about it. If you do not provide this information, we may be unable to respond. We do not disclose this information to third parties. For more information about how we handle your personal information, including how to access or correct it or make a complaint, please see our Privacy Policy or contact us at hello@privacy108.com.au.
Related articles
Subscribe to our Newsletter

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

Privacy 108 collects your name and email to send you our newsletter. If you do not provide this information, we will be unable to send it to you. We may use third-party service providers (such as email marketing platforms) to distribute our communications. Some providers may store information overseas, including in the United States. For more information about how we handle your personal information, including how to access or correct it or make a complaint, please see our Privacy Policy or contact us at hello@privacy108.com.au. You can unsubscribe at any time using the link in our emails or by contacting hello@privacy108.com.au.