← Back to Blog July 2026: €1.4B in Fines, New AI Rules, and Why Your Prospect List Just Got Riskier

July 2026: €1.4B in Fines, New AI Rules, and Why Your Prospect List Just Got Riskier

July 2026 brought a €550M fine on AliExpress, the EU AI Omnibus, and a £12.7M TikTok ruling. Here's what the new legislation means for your outbound.

July 2026 was the month digital policy stopped being a background concern. The EU fined AliExpress €550 million. The Digital Omnibus on AI Regulation entered into force. The UK upheld a £12.7 million fine against TikTok. If you run outbound across borders, your prospect list just got more expensive to get wrong.

Here's the practical version: enforcement is no longer theoretical, and the legislation now covers the tools you use to find and score prospects, not just the emails you send.

The EU's AI Omnibus is now law, and it touches your scoring model

The Digital Omnibus on AI Regulation entered into force in July. It consolidates and tightens the rules around automated decision-making, which includes lead scoring, intent signals, and enrichment pipelines.

We've written before about the ICO's AI Code becoming law and what a misconfigured scoring model can cost. The Omnibus extends that logic across the EU. If your tool assigns a score to a prospect and that score influences whether they get contacted, you're in scope.

The threshold question is not whether you consider your scoring "automated decision-making" in the strict sense. It's whether the score materially shapes the treatment a prospect receives. A model that ranks inbound leads and routes the top decile to a rep while the rest go to a nurture sequence is making a decision with a real effect on that person. The Omnibus treats that as in scope, regardless of whether a human technically pressed send.

What that means in practice:

That last point is the one most teams skip. A scoring model that auto-enrolls prospects into a sequence without a human review is now a compliance problem, not just a quality problem. The practical fix is to separate scoring from action: let the model rank and explain, but require a person to authorize outreach. That preserves the efficiency gain while creating the audit trail the regulation expects.

The €550M AliExpress fine is about data governance, not e-commerce

The headline number gets attention. The reason behind it matters more for B2B sellers.

The fine centred on how AliExpress handled user data across jurisdictions, including how it transferred and processed information without adequate safeguards. That's the same category of risk you take on when you buy a prospect list from a vendor who won't tell you where the data came from.

What makes the ruling instructive is the enforcement logic. Regulators did not stop at the point of collection. They traced how data moved between entities, which legal basis justified each transfer, and whether the safeguards attached to that basis actually held up in practice. The failure was cumulative — a chain of small gaps that, taken together, amounted to an ungoverned data pipeline. For a small sales team, the lesson is structural rather than financial. You will never face a €550M penalty, but you can face the same audit question: can you reconstruct where each contact record originated, who authorised its use, and what happened to it between acquisition and outreach?

We covered this in July 2026's compliance records — your prospect list is now a liability if you can't trace its provenance. The AliExpress ruling reinforces that. Regulators are looking at the full data chain, not just the final email.

If you're buying lists, ask the vendor three questions:

If they can't answer all three, you're carrying their risk. The practical alternative is to build lists from first-party signals — your own site behaviour, inbound replies, and consented interactions — where the provenance is self-evident because you generated it. That approach scales more slowly, but it survives scrutiny, and scrutiny is now the default operating condition.

The UK upheld the TikTok fine, which signals aggressive enforcement

The £12.7 million fine against TikTok was upheld on appeal in July. The case involved how the platform handled children's data, but the precedent is broader: UK regulators will defend their fines through the appeals process.

For outbound teams, this matters because it removes the "we'll fight it and win" assumption. The ICO and its EU counterparts are building a track record of enforcement that survives legal challenge. That changes the calculus on compliance shortcuts.

The appeals process itself is where this gets expensive. A fine that survives review isn't just a cost — it's a validated methodology. When a regulator's interpretation of the law holds up in tribunal, that same reasoning becomes the template for the next hundred cases. TikTok's loss gives the ICO a citable precedent for how it defines consent, age verification, and data minimisation in practice. Those definitions then flow downhill to every smaller company operating in the same jurisdiction.

There's also a timing dimension worth noting. Appeals take months or years, during which the underlying compliance obligation doesn't pause. Companies that treat a fine as a negotiable line item are effectively running their operations under a legal cloud, with the added risk that the eventual ruling applies retroactively to conduct that continued in the meantime.

We've seen this pattern before with GDPR enforcement hitting €5.88 billion. The fines accumulate, the appeals fail, and the cost of getting it wrong keeps climbing.

For founders running outbound at scale, the practical takeaway is that "we'll deal with it if it comes up" is no longer a defensible posture. The enforcement infrastructure is mature, the case law is thickening, and the regulators have demonstrated they'll spend years defending their position. Compliance isn't a cost centre you can defer — it's a precondition for operating in these markets at all.

What this means for cross-border B2B outbound

If you're selling into the EU or UK from outside, you're now operating under three overlapping regimes: GDPR, the AI Omnibus, and whatever local enforcement looks like in your target market. That's not a reason to stop. It's a reason to tighten your process.

The overlap matters more than any single rule. A prospect record can be lawful under GDPR's legitimate-interest basis and still fail the AI Omnibus test if an automated system scored or segmented that person without adequate disclosure. Likewise, a compliant AI workflow doesn't protect you if the underlying contact data was sourced without a defensible legal basis. Regulators increasingly look at the chain, not the individual link.

The teams we see doing this well have three things in common:

They know their data sources. Every prospect record has a traceable origin. No mystery lists, no scraped data with no paper trail.

They keep a human in the loop. No automated sends, no auto-enrollment based on a score. Someone reviews before anything goes out.

They document their logic. If a regulator asks why a prospect was contacted, they can point to a specific reason, not a black-box model.

What separates these teams isn't budget or legal counsel. It's that they treat compliance as a design constraint rather than a cleanup task. They map data flows before they build sequences, they log the reasoning behind each outreach decision, and they can reconstruct that reasoning months later if asked. That discipline also happens to make their outbound sharper: cleaner lists, better targeting, fewer wasted sends.

None of this is glamorous. It's the unsexy work that keeps you out of the enforcement headlines.

What we'd do next

Audit your prospect sources this week. If you can't trace where a list came from, stop using it. Then check your scoring model — if it auto-enrolls prospects without human review, add a manual step. The legislation is only getting tighter, and the fines are only getting larger.

That audit should be more than a one-time cleanup. Build it into a recurring review: a monthly pass over every source you pull from, with a note on where each list originated, what consent or lawful basis you're relying on, and when it was last verified. Sources that can't answer those questions should be retired, not grandfathered in. The same logic applies to your scoring model. A model that silently enrolls prospects into sequences is the easiest place for a compliance failure to hide, because no one sees the decision being made. Adding a human checkpoint isn't just a safeguard — it's a record. When someone reviews and approves an enrollment, you have a defensible account of why that contact was approached.

It's also worth separating the two risks regulators keep treating as one. Data provenance is about where the contact came from and whether you had a basis to hold it. Automated decisioning is about what your system does with that contact once it's in. A clean source doesn't excuse an unchecked model, and a careful model doesn't fix a list of unknown origin. Audit both, and document both.

If you want a tool that keeps a human in the loop by default, give MiraReach a try. We built it so nothing sends without you pressing the button.

— Mira

Share on X Share on LinkedIn
Until next time — keep sending emails that are worth reading.
M
Mira
Head of Content at MiraReach
★ The Solopreneur Playbook · Free

Find 50 customers in 12 minutes.

Five customer-discovery prompts. Eight cold-email templates that hit 8% reply rate. The honest math: manual = 4 hours, MiraReach = 12 minutes.

Read the playbook →