Regulation of Artificial Intelligence Bill 2026: Committee Stage (Resumed) and Remaining Stages Seanad Éireann — 2026-07-15 ============================================================ Alice-Mary Higgins (IND), National University of Ireland I move amendment No. 49: In page 33, line 29, after “purposes” to insert “other than the personal data of a child,”. Amendments Nos. 49 to 53, inclusive, seek to ensure that the personal data of a child shall not be collected for the purposes of developing, training and testing AI systems in a sandbox. Article 59 does allow for the training of AI systems in a sandbox, however, paragraph 3 of Article 59 also allows for member states to develop national law which excludes the processing of certain kinds of personal data. Those are choices that can be made at a national level. Our amendments seek to utilise this discretionary power to prevent the personal data of children from being used to develop AI systems in a sandbox. That is a very minimal piece. There has been a strong focus on the question of access to the Internet for children and all of that. We had that debate in 2017 and 2018 when the Data Protection Act was going through. This is an important point. At the time the Data Protection Act was going through, Senator Ruane and I put forward a new section, which, rather than focusing on the child and the child's access to the Internet, focused on the practices of the companies that operate on the Internet. We put forward an amendment at that time explicitly stating that the personal data of children should not be available to those companies for use for commercial purposes. That is basic. Here is the thing: that amendment passed. It went into the Bill. It was a part of the Bill but that section was never commenced. That is why I sometimes take it with a grain of salt when I hear people saying it is terrible where children and companies are concerned and the fact, for example, that Grok is available to children. It is not just the availability. We made this point back then, almost a decade ago. It is not solely about children accessing these services. It is the idea that children's data is used for commercial purposes. The specific requirement was that children's data could not be used commercially for micro-targeting and the development of profiles. We were told at the time there was not a definition of "micro-targeting", or some other excuse was given for non-commencement. I urge the Minister to revisit that issue. There is a cross-party mandate from the Oireachtas. The Seanad agreed and voted with us on that amendment. Government Members voted with us on it. There is not a monopoly on caring about that issue. It went into the Act but was not commenced for technical reasons, etc. Nothing happened then for years and years. There is now a high-profile thing about under 16-year-olds going on the Internet but the real problem is that companies are commercially using children's information. They create products. You can buy advertising that is targeted at children. You can sandbox products that are designed to commercially target children or use children's data in a commercial way. That is the problem. The business models of tech companies are based on the exploitation of children's data. That is the bigger problem. It is not whether children can access the hellish room where all the horrible stuff is happening. It is that there is a hellish room where horrible stuff is happening. That is the other fundamental problem. Part of the things happening in that room are based on the commercial exploitation of children's data, the building of profiles and the kinds of algorithms that target it. They should have been part of Commissioner McGrath's measures but were not sufficiently included in terms of tackling the issues of algorithms. We now have another shot. We have another area. We have another sandbox. This is why I was concerned about the transparency in the register. When you create these boxes, there is concern around what is happening in them. The Minister has the opportunity and the right under the regulation to explicitly exclude children's data from what is going to be happening in the sandbox. This is to be strongly considered. I will speak the rest of our amendments in this section. They seek to use the discretion to prevent the data of children being used to develop AI systems, including commercial AI systems, in a sandbox. It is the same thing we have been looking for since 2018 but now the dangers are even more acute. Amendment No. 51 relates to the processing of repurposed personal data for the development, training and testing of certain AI systems in a sandbox environment. On personal data being given for a particular purpose, going back to that issue under the GDPR, you own your data. This new dilution, which we know is in the AI omnibus Act, makes a carve-out for AI training as a reason that personal data can be used. That should be hugely opposed. Personal data that was given for one reason can just be grabbed up and sucked up and used for the testing of certain AI systems in the sandbox environment. The AI regulatory sandboxes are controlled environments where developers and researchers test new AI systems under the direct supervision of the regulatory authorities. The Bill empowers the new AI office to establish the regulatory sandboxes in which new technologies can be tested in real-world scenarios. They are subject to oversight. The idea is that we are going to ensure the technologies comply with legal fundamental rights and ethical standards. The GDPR generally prohibits the use of personal data for a new, secondary purpose, unless that purpose is compatible with the original reason for collection. However, the AI Act is allowing, and we know the AI omnibus Act continues this, the repurposing of personal data in controlled regulatory requirements, subject to certain safeguards. In this context, the Bill proposes that personal data gathered for other purposes may be processed to support the development, training or testing of AI systems. Our amendment seeks to introduce an additional privacy safeguard that will require that any repurposed personal data being processed in sandbox conditions must first be anonymised so it can no longer be linked to an identifiable individual. We know that data is considered anonymised when the data subject cannot be identified or is not identifiable having regard to all methods reasonably likely to be used by the data controller or other persons to identify the data subject directly or indirectly. This applies to direct or indirect identification. Carried out effectively, such anonymisation can assist in the privacy rights of individual data subjects. We must bear in mind that we also have our constitutional imperative on privacy here in Ireland. The anonymisation can allow the data controllers to achieve the balance between the right to privacy and other interests. This is an additional safeguard, but to be frank, it is a minimum safeguard because the core of the GDPR is not just your right to privacy. It is not a privacy piece. It is about your right to ownership of your data and your right to decide what it gets used for and does not get used for. There is often a misnomer when people talk about data protection. They say that the data is anonymised. The anonymity is an essential, and should be a safeguard in these sandboxes. That is a core consideration. You should not be able to recognise anyone from their data. As I say, there is a constitutional imperative, leaving aside anything else. The other piece is that we should be with the spirit of the GDPR, which was a high watermark for Europe. We hear about innovation and competitiveness. The GDPR was one of the great fosterings of innovation. It is what forces good innovation so that the products and technologies fit with society's needs and rights. That is good innovation. It is not just about money maximising. That is not the only form of innovation. It is also about making things better. That is why strong regulations, such as the GDPR, fostered areas where if we were genuinely competitive and Europe was genuinely looking to be competitive - I am going to sidetrack for one moment on the competitiveness we hear about - we would be looking to have those high standards to set the benchmark for all the technologies that are operating within Europe, which is a huge market, so that then companies within Europe that meet those high standards will have a competitive advantage. I sometimes hear about the competitiveness agenda and then I see the Commissioners going into rooms with Exxon Mobil, Microsoft and all the rest. If it is about European competitiveness, why are they letting giant US tech companies and commercial entities set the agenda and get you to lower the bar so they have more access to European markets and European companies, which invest and do the work of trying to do good technology , are at a disadvantage? That is a side point on competitiveness. There is a question of privacy. That is the basic that we are looking for here. When people's data is being repurposed, they should be informed of that and should be given a right to object. That is a stronger reading of the GDPR for which we have not even pushed in this amendment. I am just pointing out that is my view. Amendment No. 52 imposes an obligation on the AI office to consult with the Data Protection Commissioner before an AI regulatory sandbox is established, insofar as the sandbox involves issues related to personal data. This encourages early engagement on privacy and data protection matters, as opposed to addressing these issues only after the sandbox is operational and data has been repurposed and processed. We need to consult beforehand, not just after we have scraped the data and are already using it. As drafted, the Bill empowers the Data Protection Commissioner in a supervisory capacity after the sandbox is operational. While I welcome the supervisory role for the commissioner, it should be there before the fact. The data impact assessment and all of that piece should be beforehand. The role of the Data Protection Commissioner should come in before the data is taken and processing has begun. The amendment would ensure privacy and data protection safeguards would be built into regulatory sandboxes at the development process, preventing privacy risks and rights risks being overlooked in the design stages. That would help build public confidence in what the Government is trying to do with sandboxes, that AI innovation and so forth. Amendment No. 54 seeks to ensure any personal data lawfully collected for other purposes that is used in the training of an AI system would be subject to a data protection impact assessment, as I mentioned. The Minister of State has stated that the purpose of the Bill is to put in place governance structures necessary to implementing the AI Act. Amendment No. 54 seeks to ensure there is an appropriate governance structure. It is in line with what the AI Act has called for, namely effective mechanisms to identify if there are high risks to the rights and freedoms of data subjects. Doing the data impact assessment beforehand is what allows us to comply with the AI Act and the requirement to identify risks. We do not want to identify risks after the fact. The data protection impact assessment is the mechanism we have for that. These are good faith amendments to ensure the sandbox delivers what it is hoped it will deliver. --- Source: Houses of the Oireachtas. Licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). The Official Report is revised after first publication; the fetch timestamp below identifies the version quoted. Record URI: https://data.oireachtas.ie/akn/ie/debateRecord/seanad/2026-07-15/debate/main Retrieved: 2026-08-27T06:52:16+00:00 Sitting date: 2026-07-15