Abstract architectural illustration of a circular governance chamber in deep navy blue, lit by a blue light shaft from above, surrounded by concentric amber structural rings — representing the global AI accountability forum at IAPP AI Governance Global Europe 2026 in Dublin.
|

What to Expect at IAPP AI Governance Global Europe 2026 — and Why It Matters More Than Ever After the Omnibus

On June 1, IAPP AI Governance Global Europe 2026 opens in Dublin. The conference runs through June 4 in the city’s Silicon Docks district, and the timing is not incidental.

Three weeks ago, the EU Council and Parliament reached provisional agreement on the AI Omnibus, reshaping the compliance timeline for high-risk AI systems. Ten months ago, the GPAI Code of Practice was published and entered into force. Agentic AI systems are being deployed by enterprises across Europe without a dedicated regulatory framework. The questions practitioners are carrying into Dublin are different from the ones they brought to the last cycle of governance conferences, and more urgent.

This is not a preview guide. It is a map of the three tensions the agenda reflects, and what they mean for any organization building or buying AI in the European market.


Why Dublin, why now

The location matters. Ireland hosts the European headquarters of most major AI providers, which means Dublin-based regulators have more direct experience with the practical friction between global AI deployment and European compliance requirements than almost any other jurisdiction on the continent.

The conference opens on June 3 with a keynote from Mark Little, journalist and entrepreneur, on technology and media impact on democracy. The closing session on June 4 features Simon McDougall, Niamh Hodnett, Andrew Strait and Gill Whitehead on anticipating future AI policy cycles. Between those two markers, the breakout agenda covers five days of workshops, practitioner sessions, and direct input from European regulators.

The most significant structural feature of this year’s agenda is the density of sessions on implementation. The GPAI Code is published and in force. The EU AI Act high-risk framework, adjusted by the Omnibus, has known timelines. The open question in 2026 is not what the rules will require, but how organizations actually build systems that comply with them.


Tension 1: The GPAI Code is in force. The enterprise gap is not closed.

The General-Purpose AI Code of Practice was published on July 10, 2025, and GPAI model obligations entered into application on August 2, 2025. The Code provides the framework that providers of large foundation models, including OpenAI, Google, Meta, and Anthropic, are expected to use to demonstrate compliance with the AI Act.

For the enterprises that deploy those models, the picture is more complicated.

The Code governs providers, not deployers. An organization that builds internal tools on top of a GPAI model, integrates it into customer-facing processes, or uses it in high-risk decision contexts is working in the space between provider obligations and deployer responsibilities. That space is large, and the Code does not close it.

The IAPP sessions “From Principles to Practice: Navigating the AI Act’s GPAI Code of Practice” and “How the Digital Omnibus is Reshaping AI Standards” address this directly. The practical question both sessions will need to answer is how an enterprise compliance team translates Code provisions into internal controls for systems that use third-party models. The Code establishes what a provider must document, monitor, and disclose. It does not tell a deployer how to audit for compliance with those provisions, or how to structure contractual protections when the provider is a large platform and the deployer has limited negotiating leverage.


Tension 2: Agentic AI is deployed. Governance frameworks are not.

This is the fastest-moving area in the agenda, and the one where the gap between practice and policy is most visible.

AI agents, meaning systems that act autonomously over sequences of tasks, access tools, and take decisions with minimal human intervention, are no longer a future consideration. They are in production. Enterprise teams are using them for knowledge work, customer interaction, and increasingly for workflows that touch personal data, financial decisions, and operational systems.

The EU AI Act does not have a dedicated framework for agentic systems. The general provisions on high-risk AI, human oversight, and transparency apply where they apply, but multi-step autonomous workflows can span several regulatory categories simultaneously, with varying human oversight requirements at each step.

The IAPP has four dedicated sessions on agentic AI governance: “Human Out of the Loop? Practical Governance Strategies for the Agentic AI Era,” “Step Aside, Human, But Do Not Misstep: How to Use and Govern Agentic AI Safely,” “Supervising the Unsleeping: Overseeing Agentic AI When it Cannot be Fully Human,” and “Who Watches the Watchers: Governance for Human in the Loop.”

The concentration is not coincidental. Among the practitioners attending the conference, agentic AI is the issue where existing governance frameworks give the least guidance, and where organizational risk exposure is growing fastest. The sessions will likely surface a range of emerging practices rather than settled solutions, which is precisely what makes them worth tracking.

What the agenda signals is that the field is converging on a few shared questions: how to define the boundary of a governed agentic system, how to assign accountability across multi-model workflows, and how to document decisions made by systems that do not produce a single, auditable output.


Tension 3: AI Act and GDPR need to be read together. Most organizations are reading them separately.

The Thursday morning session “AI Act and GDPR Interplay” is on the agenda because the problem it addresses is unsolved in practice, not because it is theoretically interesting.

The EU AI Act is risk-based. It focuses on the category and use of an AI system, and sets obligations for providers and deployers based on that classification. The GDPR is rights-based. It focuses on the relationship between data processors, controllers, and data subjects, and sets obligations based on the nature and purpose of personal data processing.

Both frameworks apply to AI systems that process personal data, which is most enterprise AI. They apply simultaneously and from different angles. An AI system used in HR screening, for example, is subject to AI Act obligations as a high-risk system under Annex III, GDPR obligations as a system processing employee data, and potentially additional national labor law requirements. Each framework has its own logic, its own accountability structure, and its own documentation requirements.

Most organizations are approaching them sequentially, assigning AI Act compliance to one team and data protection compliance to another, without a unified governance layer that handles the intersection. The IAPP session “Pseudonymity and AI: The New Frontier of Responsible Data” addresses one of the sharpest specific problems in this overlap: pseudonymization practices that satisfy GDPR thresholds may still expose data subjects to re-identification risk in AI systems trained on large datasets. The GDPR analysis and the AI risk analysis lead to different conclusions using different methodologies.

Resolving the overlap requires an integrated governance architecture, not just parallel compliance tracks. Organizations that have not yet mapped the points of intersection between their AI Act obligations and their GDPR program are likely discovering those gaps during audits rather than before them.


What to bring home from Dublin

Three things are worth doing in the next two weeks, regardless of whether you attend the conference.

First, map your GPAI exposure. If your organization uses foundation models in any business process, document what role those models play, whether any use case involves high-risk categories under the AI Act, and what contractual provisions govern the provider relationship. The GPAI Code is in force. The deployer-side obligations are real even if they are less prescribed than the provider-side obligations.

Second, define your agentic AI perimeter. Identify any system in your environment that acts on sequences of tasks with reduced human oversight. For each one, assign an accountable owner, document the scope of the system’s decision authority, and establish a review cadence. The regulatory framework will catch up, but the liability exposure exists now.

Third, review whether your AI Act and GDPR compliance programs share a common data inventory and risk register, or run from separate documentation. If they are separate, plan to close that gap before the high-risk deadlines of December 2027 (Annex III) and August 2028 (Annex I).

The Dublin agenda does not solve these problems. What it does is bring together the practitioners who are closest to solving them, in the same rooms, at a moment when the regulatory timeline is finally clear and the pressure to move from planning to execution is concrete.


OneSynergy is a consulting network focused on AI strategy, governance, and digital transformation. If your organization is building an AI governance framework or preparing for EU AI Act compliance, we help teams move from assessment to execution. Get in touch.

Data in this article reflects publicly available sources as of May 22, 2026.

Sources

  • IAPP AI Governance Global Europe 2026, official agenda: iapp.org
  • IAPP AI Governance Global Europe 2026, conference overview: iapp.org
  • Latham & Watkins, “EU AI Act: GPAI Model Obligations in Force and Final GPAI Code of Practice in Place”: lw.com
  • European Commission, GPAI Code of Practice: digital-strategy.ec.europa.eu
  • EU AI Act implementation timeline: artificialintelligenceact.eu
  • OneSynergy, “The EU AI Omnibus Deal: What the May 7 Agreement Means for Your AI Compliance Timeline,” May 12, 2026: onesynergy.eu

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *