Skip to content

Build1 publisher3 min readPublished

Ireland's DPC median of 6.2 years outlasts the AI Act's five-year window to fine

Ireland's DPC takes a median 6.2 years to decide a cross-border GDPR case, a LessWrong analysis finds. The AI Act gives the Commission five years from a violation to fine, and it requires the same investigation and response steps that take up most of the Irish cases.

The Engineer · Build desk

Photograph accompanying Ireland's DPC median of 6.2 years outlasts the AI Act's five-year window to fine
Photo: lesswrong.com

What happened

  • The author timed each of 69 DPC investigations decided between August 2019 and September 2026, from formal commencement to final decision.
  • Of the cross-border cases opened in 2018-2020, 66% were still open four and a half years after they began.
  • Google's real-time bidding inquiry at the DPC has been running for 7.3 years.
  • In 14 of the 15 cross-border cases that ended in fines, more than four-fifths of the elapsed time passed before any other EU regulator saw a draft decision.
  • An emergency step did change behaviour: after the DPC took X to the High Court in August 2024, the company agreed to stop training Grok on posts collected that summer.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • exposure OpenAI and Anthropic have their EU headquarters in Dublin, so any cross-border GDPR case against either one is led by the DPC and runs on its timelines.
  • precedent If most new American state AI laws follow the same investigate, fine and appeal model, as the author argues, the Irish delays are a fair guide to how slowly US enforcement will move.
  • capability Article 93 gives the Commission an emergency-style power to require mitigation or order a withdrawal, a tool that does not have to wait for the fine cycle to finish.

The 6.2-year figure is a survival median. Investigations that have not closed count as censored observations, so they hold the median up and stay in the sample [1]. In the 2018-2020 cohort, 14 cases are still open or discontinued, and the share decided stops rising with 43% of that cohort undecided [17]. A median over closed cases alone would leave out the slowest ones and report a shorter number. I think the author got this right. It is the part of the post I trust most.

The AI Act changes one piece of the structure. The Commission's AI Office enforces it, so cases skip the back-and-forth between national regulators that cross-border GDPR cases need [8]. The Irish procedural histories put that exchange inside the last fifth of each fined case [6]. Most of the time went to investigating, drafting and giving the company time to respond. The AI Act requires the same steps before the Commission can fine [7]. For the Irish number to transfer, the AI Office would have to run those steps at roughly the DPC's pace, against companies that fight draft decisions as hard as GDPR respondents do. The post does not include any AI Act case durations. Its argument rests on the shared procedure.

Procedural rules adopted in July 2026 set the Commission's limit. It has five years from a violation to impose a fine, or up to ten if investigative steps keep restarting the clock [9]. A case that ran the DPC median would pass the base limit by 1.2 years [1]. The real gap is wider. The limit starts at the violation, while the 6.2 years start at the formal opening of an investigation [3][9]. At Irish pace, an AI Act fine would land only if investigators kept restarting the clock toward the ten-year ceiling [9].

The post's title rests on Metaculus forecasts. By those forecasts, an investigation opened now that ran the median 6.2 years would give weakly general AI an 84% chance of arriving before the decision, and strong AGI 59% [11]. The same forecasts already put roughly 26% on weakly general AI having arrived, and 10% on strong AGI [19]. Those figures are a crowd's uncertainty about a milestone it cannot yet confirm has happened. The procedural finding holds without them.

The post ranks four forms of enforcement from weakest to strongest for AI safety: after-the-fact investigation, emergency orders, clear-cut duties such as reporting requirements, and approval before release [16]. Emergency orders already have a record in privacy. Italy's data protection agency blocked ChatGPT for a month, and it also blocked DeepSeek over privacy policy issues [14]. The author wrote that "oversight has to happen before a model ships" [18]. The Irish durations back the premise that fines arrive late. They do not show any regulator moving its effort to review before release. That step is still the author's recommendation [18].

What to watch

  • The AI Office's first formal fine proceeding under the July 2026 procedural rules, and how long it runs from opening to decision.
  • Any Commission use of Article 93 to require mitigation or withdrawal before an AI Act investigation concludes.
  • A final decision in Google's real-time bidding inquiry, now at 7.3 years.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories