← Back to Blog €5.88B in GDPR Fines and Counting—One Misconfigured AI Cold Email Setting Could Cost You £20k

€5.88B in GDPR Fines and Counting—One Misconfigured AI Cold Email Setting Could Cost You £20k

GDPR fines have reached €5.88 billion, with regulators now targeting AI systems and dark patterns. Here's what the EU AI Act's 2026 deadline means for your outbound.

GDPR fines have now passed €5.88 billion cumulatively since 2018. The enforcement priorities have shifted. Regulators are no longer just chasing the obvious data breaches. They're going after dark patterns, AI-driven processing, and healthcare data. And the EU AI Act's August 2026 compliance deadline is close enough that it should be on your calendar now, not next spring.

If you run outbound, this matters. Not because you're a healthcare company or a dark pattern factory. Because the tools you use to find prospects, score inboxes, and draft emails are increasingly AI systems. And the legislation governing them just got teeth.

The €5.88B number is a lagging indicator, not a headline

That figure is cumulative. It's been building for seven years. What's changed is the composition of the fines.

Early GDPR enforcement was dominated by security failures. Breaches, misconfigured databases, unencrypted records. The fines were large but predictable. You knew what you'd done wrong.

The current wave is different. Regulators are targeting how companies use data, not just whether they protect it. Dark patterns — pre-checked consent boxes, confusing opt-out flows, buried unsubscribe links — are now a primary enforcement target. So is AI-driven processing that lacks a lawful basis or transparency.

We wrote about this shift in our breakdown of how GDPR fines are now targeting AI enrichment and pre-checked boxes. The short version: if your outbound stack includes an AI enrichment tool that scrapes LinkedIn or infers email addresses without a clear lawful basis, you're in the blast radius.

And the healthcare data angle is worth noting. Health information gets special category protection under GDPR. If your ICP includes healthcare providers, pharma, or medtech, your prospect lists are carrying a higher compliance burden than you might think. A generic B2B list with a few hospital contacts isn't the same as a list of clinic managers with inferred specialities. One is a list. The other is regulated data.

The EU AI Act adds a second compliance layer in August 2026

GDPR governs data. The EU AI Act governs systems. If you're using AI to score leads, draft emails, or prioritise prospects, you're operating a high-risk AI system under the Act's definitions.

That triggers dual obligations. You need a lawful basis for processing under GDPR. And you need to meet the AI Act's transparency, human oversight, and risk management requirements.

The August 2026 deadline is not a soft launch. It's the compliance date for high-risk systems. If you're building or buying AI sales tools, you need to know which category they fall into.

Most outbound AI tools are not high-risk in the way a medical diagnostic AI is. But lead scoring and automated decision-making that affects individuals can qualify. The line is whether the system makes decisions that have a legal or similarly significant effect on a person. A cold email doesn't. A credit decision does. But a scoring model that determines whether someone gets contacted at all, or how they're prioritised, is closer to the line than most vendors admit.

We covered the ICO's AI code in a previous post on how a misconfigured scoring model could cost you £20k. That was UK-specific. The EU AI Act is broader and has more teeth.

What this means for your outbound setup

You don't need to become a compliance officer. You need to know where your stack sits.

Three practical checks:

We've written before about how 20 U.S. states now have privacy laws with no federal floor. The EU is stricter, but the direction of travel is the same. Compliance is becoming a product feature, not a legal afterthought.

What doesn't work: ignoring it and hoping

We've seen founders assume that because they're small, they're not a target. That was true in 2019. It's less true now.

Regulators have started targeting SMEs specifically. The fines are smaller, but the enforcement actions are real. And the reputational cost of a public GDPR finding is disproportionate for a small company.

We've also seen vendors claim their tool is "GDPR compliant" without explaining what that means. Compliance isn't a checkbox. It's a set of practices. If a vendor can't tell you where their data comes from, how consent is captured, and what happens when someone opts out, they're not compliant. They're just not yet caught.

The honest trade-off: full compliance takes time and costs money. You need to document your lawful basis, audit your data sources, and review your AI tools. For a solo founder running outbound to a few hundred prospects, that might be a few hours of work. For a team of five running thousands of emails a month, it's a project.

But the alternative is worse. A €20k fine is a bad quarter. A €200k fine is a business-ending event for most small teams.

What we'd do next

Audit your stack this week. List every tool that touches prospect data. For each one, write down where the data comes from and what the tool does with it. If you can't answer both questions, you've found your first problem.

Then check your consent flows. If your unsubscribe link is hard to find or your signup form has pre-checked boxes, fix that before a regulator does it for you.

And if you want a tool that keeps the human in the loop by design — no auto-send, no black-box scoring, no dark patterns — give MiraReach a try. We built it for founders who want to run outbound without running afoul of legislation.

— Mira

Share on X Share on LinkedIn
Until next time — keep sending emails that are worth reading.
M
Mira
Head of Content at MiraReach
★ The Solopreneur Playbook · Free

Find 50 customers in 12 minutes.

Five customer-discovery prompts. Eight cold-email templates that hit 8% reply rate. The honest math: manual = 4 hours, MiraReach = 12 minutes.

Read the playbook →