European regulators have now issued €5.88 billion in cumulative GDPR fines since 2018. The enforcement priorities have shifted. Dark patterns, AI compliance, and healthcare data are the new targets. And the EU AI Act's August 2026 deadline creates dual obligations for anyone running high-risk AI systems in their sales stack.
If you're using AI to score leads, enrich prospect data, or draft outbound, you're in scope. Here's what actually changed and what to do about it.
The €5.88B number is a lagging indicator, not a headline
Most of that total comes from a handful of mega-fines against Big Tech. Meta, Amazon, TikTok. The number gets quoted because it's big. But the number that matters for a five-person sales team is different: the volume of smaller enforcement actions is climbing.
Regulators in Spain, Italy, and the Netherlands have accelerated case throughput. The ICO in the UK has moved from advisory to enforcement on AI-specific guidance. What used to be a warning letter is now a fine.
The structural reason is procedural, not political. DPAs spent the first five years of GDPR building case templates, cross-border cooperation workflows, and internal triage criteria. That infrastructure now exists, which means the marginal cost of opening a case has fallen sharply. A regulator that once needed months to scope a complaint can now process it in weeks, and the same complaint-handling machinery that produced the mega-fines is being pointed at mid-market and small operators. The enforcement pipeline is no longer bottlenecked by capability — only by prioritization.
That shift matters for outbound because the highest-throughput categories are the ones small teams touch daily: consent validity, lawful basis for prospecting, and data subject request handling. These are not exotic AI cases. They are the routine mechanics of a cold email sequence, and they are exactly where a templated enforcement action is easiest to file.
We covered the SME exemption debate in our breakdown of the €5.88B GDPR fines and what changes when SME exemptions land. The short version: exemptions are still stalled. Don't build your compliance posture around a reform that hasn't passed.
Dark patterns are now a first-class enforcement category
Pre-checked consent boxes. Confusing opt-out flows. Burying unsubscribe links. These are dark patterns, and regulators have started treating them as standalone violations rather than aggravating factors. That shift matters because it changes the unit of enforcement: instead of asking whether a data subject validly consented, authorities now ask whether the design of the interface itself was engineered to produce consent that would not otherwise have been given. The two questions sound similar but lead to different evidence, different defences, and different penalties.
The regulatory logic rests on a fairly consistent test. Under the GDPR, consent must be freely given, specific, informed, and unambiguous — and the burden of proving that sits with the controller, not the complainant. When a supervisory authority examines a consent flow, it is effectively asking whether a reasonable user could have understood what they were agreeing to and refused it without disproportionate effort. Pre-ticked boxes fail that test because silence is treated as assent. Multi-step opt-outs fail it because withdrawal must be as easy as giving consent. Vague or bundled language fails it because specificity cannot be inferred from a general privacy policy.
For outbound sales, the practical implication is narrow but sharp. If your email footer has an unsubscribe link that requires a login, or a preference centre that takes four clicks to reach, you're exposed. If your landing page has a pre-ticked box that signs prospects up for a newsletter they didn't ask for, you're exposed. The same applies to AI-assisted enrichment: if you append inferred data to a prospect record and then rely on a consent flow that never mentioned enrichment, the design of that flow becomes the enforcement question, not the underlying data source.
We wrote about this in the €5.88B GDPR fines piece on AI enrichment and pre-checked boxes. The enforcement pattern is consistent: regulators look at the friction between a user's intent and the action they actually take. More friction equals more risk. Less friction on the opt-out side, and more explicit friction on the opt-in side, is the direction of travel.
Fix the obvious stuff. One-click unsubscribe. No pre-checked boxes. Clear language about what someone is signing up for. Then audit the flows you didn't design yourself — form builders, CRM defaults, and enrichment tools all ship with consent assumptions baked in. This isn't legal advice, but it's the baseline.
The EU AI Act deadline is August 2026. Here's what that means for your stack
The AI Act creates a two-tier compliance regime. High-risk AI systems face strict obligations: conformity assessments, technical documentation, human oversight requirements, and registration in an EU database. Limited-risk systems face transparency obligations. General-purpose AI models sit in a separate tier with their own documentation and copyright-disclosure duties, which matters if you're building on a foundation model rather than a purpose-built tool.
Most sales tools fall into the limited-risk bucket. But the definition of "high-risk" is broader than people assume. It includes AI systems used for:
- Recruitment or hiring decisions
- Credit scoring or financial eligibility
- Access to essential services
- Law enforcement or migration
- Education or vocational training
If you're selling into any of those verticals and your AI tool makes or informs decisions about individuals, you may be in scope. If you're using AI to score inbound leads and route them to sales reps, that's probably limited-risk. But "probably" is doing a lot of work in that sentence.
The classification question is not static. A tool that ranks leads today can drift into high-risk territory if a customer repurposes it to screen applicants, and the Act places obligations on both providers and deployers. That means your customers' use cases can pull you into scope even when your own intent was narrow. The practical response is to document intended purpose, build use-case guardrails into your product, and keep an audit trail of how outputs inform decisions.
The August 2026 deadline is not far. Compliance work takes months. If you're building on top of an AI vendor, ask them what their AI Act posture is. If they don't have an answer, that's your answer.
Healthcare data is the third rail
Regulators have started treating healthcare data as a special category even when it's not obviously medical. A prospect list of "clinic managers in the UK" is fine. A prospect list that includes inferred health conditions, treatment histories, or prescription data is not.
The risk is in the enrichment layer. If your AI tool scrapes LinkedIn and infers that someone works in oncology, that's probably fine. If it cross-references public data to infer that someone is a patient, that's a problem.
The distinction matters because of how enforcement actually works. Most privacy authorities don't audit small sales teams directly. They respond to complaints, and complaints tend to originate from the individuals whose data was processed. A clinic manager who receives an outreach email referencing their professional role is unlikely to escalate. A patient who receives an email that implies the sender knows something about their medical history will escalate immediately — and that complaint lands with a regulator already primed to treat health-adjacent data as a priority category.
This is why the enrichment layer is where liability concentrates. Your CRM may hold nothing but names and job titles. But if the AI tool sitting between your data source and your outbound sequence is inferring, scoring, or appending attributes that touch on health, the processing is happening under your controllership regardless of where the inference occurred. Under GDPR, inferred data is still personal data, and special category rules attach to it the moment the inference is health-related — even if the inference is probabilistic, even if it's wrong, and even if you never acted on it.
We've seen this pattern in the July 2026 compliance fines roundup. The fines are smaller than the headline GDPR cases, but they're more frequent. And they're aimed at exactly the kind of operation a small sales team runs.
The practical takeaway for founders and small teams is to audit what your enrichment tools actually output, not just what you asked them to find. If the output includes fields you didn't request — health signals, life events, inferred conditions — that's the exposure. Disable those enrichments, document the decision, and keep a record of what your pipeline processes at each stage. The teams that get fined are rarely the ones processing the most data. They're the ones that never checked what their tools were doing with it.
What we'd do next
Audit your stack. Find every place AI touches prospect data — scoring models, enrichment APIs, intent signals, even the LLM drafting your first-touch emails. Map each one to a lawful basis, and be honest about whether consent was actually collected or merely assumed. Check your consent flows for dark patterns: pre-ticked boxes, buried opt-outs, and "accept all" buttons that dwarf the alternative are exactly the kind of interface choices regulators now treat as enforcement triggers rather than cosmetic issues. Ask your vendors about their AI Act timeline, and get answers in writing — if your enrichment provider can't explain its role under GDPR or its obligations as a deployer under the AI Act, that ambiguity becomes your liability, not theirs. Document what you find, including the gaps. A dated internal record of risks and remediation steps is worth more during an inquiry than a polished policy nobody follows.
None of this is glamorous. But the enforcement environment has shifted from "theoretical risk" to "active fines," and the targets are increasingly operational — how data flows into models, how consent is captured, how automated decisions are surfaced to the people they affect. The teams that treat compliance as a product requirement, not a legal afterthought, will be the ones still sending outbound in 2027.
If you want to see how MiraReach handles prospect scoring, enrichment, and drafting without auto-sending anything, give MiraReach a try. Every message waits for a human to press the button.
— Mira