Sign in

Gabriela Zanfir-Fortuna

@gzf.bsky.social
3K followers 414 following 483 posts

Data Protection Geek. Co-author of the big GDPR OUP Commentary🇷🇴🇪🇺🇺🇸 US-based, former Brussels bubbler. Writes about data protection law and policy, AI governance through a Global lens (& sometimes democracy) Strictly personal views. www.pdpecho.com.

PostsRepliesMedia
Gabriela Zanfir-Fortuna @gzf.bsky.social · 27/09/2026
A scathing portrait of the inability of governments to act and enact policies to meaningfully govern AI safety, by Cecilia Kang and Adam Satariano in today's New York Times (gift link). The authors write about "a global policy vacuum as AI models rapidly advance" (…) www.nytimes.com/2026/09/27/t...
nytimes.com
As A.I. Accelerates, Governments Are Increasingly Being Left Behind (Gift Article)
The gap between technology and policymaking has gotten wider than ever with artificial intelligence, leaving a global policy vacuum as A.I. models rapidly advance.
112
Gabriela Zanfir-Fortuna @gzf.bsky.social · 26/09/2026
Cleaning old office stuff and I stumbled upon these, from the time I was working on the 1st edition of the OUP GDPR Commentary back in 2019 (?). So much work, effort and stress… It was eventually done. I had forgotten about how difficult it was. And, why, in the end, all that effort 🤷‍♀️
151
Gabriela Zanfir-Fortuna @gzf.bsky.social · 26/09/2026
The plot thickens. Perhaps it’s a good time to double check and toggle those opt-outs. Even the memory function “on” looks a bit unnecessary at this time 🫢 www.axios.com/2026/09/25/o...
axios.com
OpenAI agents posted user images online, disclose dozens of third party incidents
Over 50 leaked images from ChatGPT users appeared online, the company disclosed.
053
Gabriela Zanfir-Fortuna @gzf.bsky.social · 22/09/2026
I understand the "pacing" plea in AI development as technically meaning "festina lente", the first Latin expression I learned in secondary school, and, frankly, the only one that stayed with me for so long because it had such a curious meaning. The Romans were sage, indeed! #pacing
121
Gabriela Zanfir-Fortuna @gzf.bsky.social · 20/09/2026
Gently launching into the world my personal Substack, Ai Carte - I explain here why “Ai Carte” aicarte.substack.com/p/why-ai-car... and here you can find a first post about a book, “The Bookshop Woman”, by Nanako Hanada aicarte.substack.com/p/the-booksh... I missed writing for the pleasure of it.
aicarte.substack.com
Why “Ai Carte”?
Reading is the strongest form of resistance I can think of against AI’s takeover of minds. And writing about what you read might just meaningfully entrench this resistance form.
030
Gabriela Zanfir-Fortuna @gzf.bsky.social · 16/09/2026
To a certain extent, the AI alignment problem is what a purpose limitation principle would solve in data protection law 🤔
141
Gabriela Zanfir-Fortuna @gzf.bsky.social · 16/09/2026
Maybe this is how Canada will finally get GDPR-grade data protection law 👀 😅 www.npr.org/2026/09/16/n...
npr.org
EU's Ursula von der Leyen says she wants Canada to become an associate member
European Commission President Ursula von der Leyen on Wednesday proposed making Canada the European Union's first associate member, a striking overture as U.S. President Donald Trump's tariffs drive O...
020
Gabriela Zanfir-Fortuna @gzf.bsky.social · 08/09/2026
The same day the OECD publishes alarming PISA test results for kids around the world steeply declining in cognitive tests, OpenAI announces this feat. Is it Poe poetry? Coincidence? Tragicomedy? It’s something for sure. openai.com/index/navier...
openai.com
On the Navier–Stokes Millennium Prize Problem
We’re sharing an AI-generated solution to the Navier–Stokes Millennium Prize Problem, including a writeup and a formal proof in Lean.
141
Gabriela Zanfir-Fortuna @gzf.bsky.social · 07/08/2026
The new EU Cloud and AI Development Act (CADA) proposal marks a genuine shift in the way the bloc regulates AI, as it codifies the “AI first” principle & it is as much an “AI promotion and enabling”-type of legislation as it is a cloud sovereignty one. My in depth analysis: fpf.org/blog/cada-an...
fpf.org
CADA: An (E)U-turn on AI regulation
The new EU Cloud and AI Development Act (CADA) proposal marks a genuine shift in the way the bloc regulates AI, as it codifies the “AI first” principle, and it is as much an “AI promotion and enabling...
032
Reposted by Gabriela Zanfir-Fortuna
TJ McIntyre @tjmcintyre.com · 16/06/2026
Thanks! Paras 110-113 are very interesting in that 'knowledge' and 'control' of content are disaggregated, and providers don't merely lose the hosting immunity if they algorithmically choose content - they also lose the benefit of the prohibition on general monitoring.
152
Reposted by Gabriela Zanfir-Fortuna
TJ McIntyre @tjmcintyre.com · 16/06/2026
Liability is a function of the underlying law so it will differ between defamation, hate speech, harassment, data protection, copyright infringement, etc. This is significant in that it takes away an EU-wide shield, and exposes providers to liability under different domestic laws.
1125
Gabriela Zanfir-Fortuna @gzf.bsky.social · 16/06/2026
I'm curious how this reads together with Russmedia 👀
130
Reposted by Gabriela Zanfir-Fortuna
Lukasz Olejnik @lukaszolejnik.bsky.social · 26/04/2026
A European Commission proposal could create one of Europe’s largest privacy and national-security risks in decades. techletters.substack.com/p/the-europe...
blog.lukaszolejnik.com
The European Commission is turning Google Search into a privacy and national-security risk
The European Commission is preparing to compel Google to stream search data to third-party companies through an automated API. It is doing this under the Digital Markets Act, a regulation with a sound...
11712
Gabriela Zanfir-Fortuna @gzf.bsky.social · 19/04/2026
Data protection law does not define responsibilities for users’ data, but for individuals’ fundamental rights and how they are impacted through the processing of their data. A fundamental difference that creates a sequence of wrong interpretations of data protection law.
1102
Reposted by Gabriela Zanfir-Fortuna
Future of Privacy Forum @futureofprivacy.bsky.social · 17/04/2026
Join FPF CEO @julespolonetsky.bsky.social polonetsky.bsky.social and FPF VP for Global Privacy @gzf.bsky.social for a LinkedIn Live discussion marking 10 years of the adoption of the GDPR. 🗓️ Today, Friday April 17th at 12 noon ET 🔗Sign-up here: linkedin.com/events/74498...
042
Reposted by Gabriela Zanfir-Fortuna
Emanuel Maiberg @emanuelmaiberg.bsky.social · 26/03/2026
after much deliberation and giving AI the benefit of the doubt, Wikipedia editors have had enough of AI slop. New policy bans LLM generated content, periodt www.404media.co/wikipedia-ba...
404media.co
Wikipedia Bans AI-Generated Content
“In recent months, more and more administrative reports centered on LLM-related issues, and editors were being overwhelmed.”
10982832298
Gabriela Zanfir-Fortuna @gzf.bsky.social · 17/03/2026
This is why tech neutral rules like the GDPR (which, by the way, fully applies to AI agents whenever they touch personal data) are generally a better idea 💡
072
Gabriela Zanfir-Fortuna @gzf.bsky.social · 09/03/2026
With everything happening in the world today, these are the top 3 news I got on X when I opened it 👀 And I have almost zero interest in American sport (I guess this is also what happens when the algorithm forgets you due to inactivity 🤖)
110
Reposted by Gabriela Zanfir-Fortuna
Future of Privacy Forum @futureofprivacy.bsky.social · 03/03/2026
2026 is a "perfect storm" for global privacy, says FPF VP of Global Privacy, @gzf.bsky.social. Her latest blog breaks down how three converging forces will shape global data protection and privacy. Read more below. fpf.org/blog/2026-a-...
fpf.org
2026: A Year at the Crossroads for Global Data Protection and Privacy
Three forces are reshaping global data protection in 2026: GDPR’s reopening, rapid AI development, and expanding digital regulation amid geopolitics.
042
Gabriela Zanfir-Fortuna @gzf.bsky.social · 28/02/2026
Here’s a conundrum for you: fit the two red lines Anthropic didn’t want to forgo into the EU AI Act’s red lines under Article 5. 🦗 🦗 🦗 First thing: military use, out of scope. But even as dual use technology: 🦗 🦗 🦗 Should egregious red lines not be spelled out? Or is it an oversight?
122
Reposted by Gabriela Zanfir-Fortuna
Ramsha Jahangir @ramshajahangir.bsky.social · 26/02/2026
Privacy regulators from four continents have aligned around a clear position that AI-generated sexualized deepfakes are a data protection violation. For Grok, already under investigation in multiple jurisdictions, that alignment increases the likelihood of sustained and parallel regulatory action.
techpolicy.press
Privacy Regulators in 61 Countries Back Enforcement Against AI Deepfakes
Regulators remind platforms that creation of non-consensual intimate imagery can constitute a criminal offence in many jurisdictions, reports Ramsha Jahangir.
23523
Gabriela Zanfir-Fortuna @gzf.bsky.social · 20/02/2026
This week, we launched a blog series exploring the "Red lines" drawn by the AI Act, a year after they became applicable. Among our takeaways, we noted that the Act does not prohibit technology per se, but uses or practices of technology that pose unacceptable risk.1🧵 LINK: fpf.org/blog/red-lin...
132
Gabriela Zanfir-Fortuna @gzf.bsky.social · 19/02/2026
My magazines this week 🫠 * But since I’m deep into these conversations at my job, at least they remind me the job is kind of relevant? 🤷‍♀️ 🧐
040
Reposted by Gabriela Zanfir-Fortuna
Stephan Geering @stephangeering.bsky.social · 19/02/2026
Amazing resource Cc @gzf.bsky.social
131
Reposted by Gabriela Zanfir-Fortuna
Justin Hendrix @justinhendrix.bsky.social · 14/02/2026
Next week’s India AI Impact Summit is framed around “democratizing AI.” But as India expands AI-driven surveillance, predictive policing, and welfare automation, minorities and marginalized communities are bearing the costs, writes Tavishi.
techpolicy.press
India’s Global AI Pitch Masks A Troubling Reality At Home
Without regulatory oversight and guardrails, AI in India will continue to function less as a public good and more as a tool of oppression, writes Tavishi.
24833
Gabriela Zanfir-Fortuna @gzf.bsky.social · 15/02/2026
All events of the #AIImpactSummit in New Delhi will be live-streamed throughout next week and you can watch them here: m.youtube.com/@indiaai India certainly wins at accessibility and inclusiveness. 👀 Is this what a touch of the Global Majority looks like on AI Governance? 🤞
m.youtube.com
IndiaAI
IndiaAI Mission, an initiative by MeitY, is building a robust, inclusive AI ecosystem through democratized compute, high-quality data, talent, R&D, startup support, industry collaboration & ethical AI...
011
Reposted by Gabriela Zanfir-Fortuna
Masters of Privacy @mastersofprivacy.bsky.social · 14/02/2026
[EN] @gzf.bsky.social joined us last week to discuss proposed changes to the EU legal framework for #AI and digital services open.substack.com/pub/masterso... #GDPR #AIAct
open.substack.com
Gabriela Zanfir-Fortuna: GDPR changes, AI Act hangover, Russmedia
Listen now | The Digital Omnibus in its context, birth defects of the AI Act, South Korea, Russmedia
011
Gabriela Zanfir-Fortuna @gzf.bsky.social · 14/02/2026
This is how important the Chief Privacy Officer job is. www.nytimes.com/2026/02/13/t...
nytimes.com
Homeland Security Wants Social Media Sites to Expose Anti-ICE Accounts
002
Reposted by Gabriela Zanfir-Fortuna
Tech Policy Press @techpolicypress.bsky.social · 13/02/2026
The most important question about AI isn't determining whether the machine thinks — it's whether interacting with it displaces the conditions under which we think, writes Eryk Salvaggio.
buff.ly
The Illusion of AGI, or What Language Models Can Do Without Thought
It is not simple stubbornness that LLMs are not “intelligent,” much less a form of “general” intelligence, writes Eryk Salvaggio.
1228
Reposted by Gabriela Zanfir-Fortuna
Gabriela Zanfir-Fortuna @gzf.bsky.social · 13/02/2026
Casey - have you come across Joseph Weizenbaum’s Computer Power and Human Reason? He is the creator of the first chatbot, Eliza, at MIT in the 60s. He pulled the plug in horror after seeing the deep paychological impact of talking to the bot on his team 🙃
011
Gabriela Zanfir-Fortuna @gzf.bsky.social · 12/02/2026
The thing about Laura Codruta Kovesi is that she weeds out corruption like no one else I’ve ever seen in my life. Her EPPO is also behind the Le Pen trial, the EEAS/College of Europe muddy case and now this: www.lalibre.be/internationa...
lalibre.be
La Commission européenne et la SFPIM perquisitionnées suite à une vente de biens immobiliers à l'État belge
L'enquête porterait sur des irrégularités constatées dans la vente de bâtiments acquis par la Société fédérale de portefeuille et d'investissement...
130
Gabriela Zanfir-Fortuna @gzf.bsky.social · 10/02/2026
Esta americana quere agradecer a Marimar, Maria la Del Barrio, Corazon Salvaje, Cafe con Aroma de Mujer y todas las telenovelas which ella watched en Rumania cuando era una nena y thanks to which ella ahora comprende so much Espanol 💃 Gracias, gracias, gracias ☺️
000
Reposted by Gabriela Zanfir-Fortuna
Luiza Jarovsky, PhD @luizajarovsky.bsky.social · 10/02/2026
There seem to be millions of people who believe that if they ask an AI chatbot to "brainstorm" about a topic and then ask it to write a "first draft," it will still be a human-made work if they edit it. I'm sorry, but it won't.
031
Gabriela Zanfir-Fortuna @gzf.bsky.social · 09/02/2026
I've been thinking a lot lately about being human, about what is unique in the way we absorb the world and we are in the world, which is beyond computability. 1/2 Detroit Institute of Arts, Contemporary Anishinaabe Art exhibition (Norval Morriseau, “Bear, Fish, Bird - Interdependence”)
160
Reposted by Gabriela Zanfir-Fortuna
The AI Capitalist @theaicapitalist.bsky.social · 08/02/2026
This feels less like a privacy perfect storm and more like an infrastructure reckoning. Once AI workloads and cross-border data flows collide with GDPR reform, control of compute and models becomes the real pressure point. Data localization isn’t just regulatory anymore—it’s strategic.
011
Reposted by Gabriela Zanfir-Fortuna
Casey Newton @caseynewton.bsky.social · 06/02/2026
Last week @ellamarkianos.bsky.social pitched me on the idea of trying to replace herself with a bot. Ella is irreplaceable, but her piece on building "Claudella" is sharp, funny and moving www.platformer.news/journalism-j...
I’ve had many conversations with my fellow AI reporters about what moats we might have against the advancement of AI automation. Chief among them are developing relationships with human sources, reporting on scenes in person, and getting scoops that people wouldn’t entrust an AI with.

But the things I love most about AI reporting are having an excuse to read really long computer science papers and then writing about them. I worry that if AI becomes a great writer and research assistant, AI journalism will mostly become about networking.
1334
Reposted by Gabriela Zanfir-Fortuna
Future of Privacy Forum @futureofprivacy.bsky.social · 05/02/2026
The U.S. privacy landscape has transitioned from a period of legislative expansion to one of regulatory maturation. Our latest retrospective highlights four key trends in privacy law enforcement in 2025. Read more. fpf.org/blog/fpf-ret...
fpf.org
FPF Retrospective: U.S. Privacy Enforcement in 2025
The U.S. privacy law landscape continues to mature as new laws go into effect, cure periods expire, and regulators interpret the law through enforcement actions and guidance. State attorneys general a...
033
Reposted by Gabriela Zanfir-Fortuna
heather bussing @heatherbussing.bsky.social · 02/02/2026
breathe
A narrow road through the redwoods
26110
Reposted by Gabriela Zanfir-Fortuna
Stephan Geering @stephangeering.bsky.social · 01/02/2026
... increased data sharing within complex AI agent models / tools and - for a lack of better word - "social medialisation" of chatbots with detailed profiles of users, using this for ads and the related pressure to keep users online for longer.
011
Reposted by Gabriela Zanfir-Fortuna
Stephan Geering @stephangeering.bsky.social · 01/02/2026
Only managed to read this now. Great piece. I particularly like the description of how rapidly the EU policy on re-opening GDPR changed. On LLMs, I always thought that models contain personal data. I think the big issues going forward will indeed be personalisation (increasing context windows), ...
121
Reposted by Gabriela Zanfir-Fortuna
Stephan Geering @stephangeering.bsky.social · 01/02/2026
Fascinating blog article that highlights how quickly EU data protection policy changed in 2025, how the rapid AI developments create data protection challenges, and how geopolitics plays into all of it.
072
Gabriela Zanfir-Fortuna @gzf.bsky.social · 30/01/2026
“AI models” as the new “data”? Maybe 👀 Here’s an overview of why I think Data Protection is at an inflection point. Bonus: everything in the text comes from a complicated human mind, from iteration to writing. 🫣 Very rare thing these days. #Privacy #GlobalPrivacy #AIModels fpf.org/blog/2026-a-...
fpf.org
2026: A Year at the Crossroads for Global Data Protection and Privacy
Three forces are reshaping global data protection in 2026: GDPR’s reopening, rapid AI development, and expanding digital regulation amid geopolitics.
272
Reposted by Gabriela Zanfir-Fortuna
Future of Privacy Forum @futureofprivacy.bsky.social · 28/01/2026
Happy #DataPrivacyDay! This year, we’re celebrating this important day in data protection history by highlighting some key privacy tips for how to keep your personal data safe when interacting with generative AI. We partnered with Snap Inc. to create a privacy-themed Lens. fpf.org/blog/6-priva...
fpf.org
6 Privacy Tips for the Generative AI Era
Data Privacy Day, or Data Protection Day in Europe, is recognized annually on January 28 to mark the anniversary of Convention 108, the first binding international treaty to protect personal data. The...
032
Reposted by Gabriela Zanfir-Fortuna
Darth Putin @darthputinkgb.bsky.social · 26/01/2026
We have been using a platform that is banned in Russia to say that free speech is banned in the EU on the platform we banned.
10813231
Gabriela Zanfir-Fortuna @gzf.bsky.social · 09/01/2026
Now marry Russmedia with the Grok CSAM thing. What do you get? 🤭 #GDPR
281
Reposted by Gabriela Zanfir-Fortuna
evacide @evacide.bsky.social · 02/01/2026
If you are a resident of California, the state now has a portal where you can demand deletion of your personal data from 500+ registered data brokers with a single request form, for free. consumer.drop.privacy.ca.gov
consumer.drop.privacy.ca.gov
274116475134
Reposted by Gabriela Zanfir-Fortuna
The Economist @economist.com · 01/01/2026
Would you like to join The Economist’s business desk, covering the most important American companies? We’re looking for a US business writer. Find out more and apply here
econ.st
Wanted: a new business writer
An opportunity to join the staff of The Economist
256
Gabriela Zanfir-Fortuna @gzf.bsky.social · 31/12/2025
Look what the postman delivered last day of the year ♥️ 📚 One of my biggest wishes for 2026: the time and peace of mind to read for the pleasure of reading. Happy New Year, friends! May it bring at least some of the things you are most wishing for 🎉
050
Reposted by Gabriela Zanfir-Fortuna
Victoria McIntosh @vmcntosh.bsky.social · 24/12/2025
The Office of the Information and Privacy Commissioner of Canada’s website shows they’re already getting organized for Privacy Week 2026, and honestly, respect that hustle.
082
Gabriela Zanfir-Fortuna @gzf.bsky.social · 21/12/2025
💜 the gdpr
020