Data, AI and Trust: What Businesses Should Watch in 2026 and Beyond

Data, AI and Trust: What Businesses Should Watch in 2026 and Beyond

Data protection is no longer something businesses can address through a privacy notice, cookie banner and consent form alone.

As AI becomes part of everyday business operations, organizations are increasingly expected to explain where their data came from, why they are allowed to use it, how it is protected and how technology-supported decisions are made.

For market research, these questions are especially important. Data may move between clients, panel providers, research platforms and technology partners before it becomes a final insight. Each step adds another responsibility - and another point at which trust can be strengthened or lost.

Jurgita Sakalauskienė, General Counsel at Syno International

“AI does not make familiar data protection duties disappear. It adds another layer of questions that organizations must be ready to answer,” says Jurgita Sakalauskienė, General Counsel at Syno International.

The GDPR and the AI Act need to be considered together

The EU AI Act became generally applicable on 2 August 2026, although some requirements are still being introduced in stages. Following the AI Omnibus amendments, rules for systems used in certain high-risk areas will apply from 2 December 2027, while rules for high-risk systems built into regulated products will apply from 2 August 2028.

However, the AI Act does not replace the GDPR. A system may fall outside the AI Act’s high-risk categories and still raise questions under data protection law. These may concern the lawful basis for processing, transparency, data minimization, security, profiling or individuals’ rights.

This means that deciding whether an AI tool can be used should involve more than checking its risk category. Businesses also need to understand:

  • What data the tool receives
  • Where that data originated
  • What the tool may infer from it
  • Whether the output can be understood, reviewed and challenged
First-party data is valuable, but it is not automatic permission

As access to third-party data becomes more restricted, businesses are paying more attention to data collected directly from customers, users and research participants. First-party data can offer better visibility into how information was collected and may also improve its relevance and quality.

But “first-party” describes the source of the data. It is not, by itself, a lawful basis under the GDPR.

A direct relationship with an individual does not automatically allow an organization to reuse their data for AI training, additional profiling or an unrelated analytical purpose. The new use still needs to be lawful, transparent and compatible with the purpose for which the information was originally collected.

The European Data Protection Board has also made clear that the use of personal data in AI models needs to be assessed case by case. Legitimate interest may be available in some situations, but only when the relevant legal conditions are met and properly documented.

Data provenance matters

It is becoming harder to rely on broad statements that a dataset is “compliant.” Organizations should be able to look behind that label and understand:

  • How the data was collected
  • What people were told at the time
  • Which lawful basis applies
  • Whether sensitive information could be revealed or inferred
  • Whether the data can be linked back to an individual

The same caution applies to publicly available information. Being able to access data online does not automatically mean it can be collected and reused without data protection considerations.

Anonymization also deserves careful attention. Removing names or replacing them with identifiers does not necessarily make a dataset anonymous. If a person can still be identified, singled out or connected to other information using reasonably likely means, the data may still be personal data.

This is particularly relevant in longitudinal research, small audience segments and datasets that combine demographic and behavioral attributes.

Security now includes the AI supply chain

AI creates new questions about where business and research data goes after it is entered into a tool.

Before employees upload documents, datasets or prompts, an organization may need to establish whether that information is retained, used to train the provider’s models, shared with subprocesses or transferred outside the European Economic Area.

Security is therefore not only about preventing unauthorized access. It also includes controlling what information is intentionally shared with external technologies and setting clear rules for how AI services may be used.

The allocation of responsibilities matters too. In market research, a client, research agency, panel provider and technology platform may act as controllers, joint controllers or processors, depending on the actual processing activities. Those roles should reflect what each party really does, rather than simply the terminology used in a contract.

Evidence will matter more than broad assurances

Looking forward to 2027, we expect regulators, clients and business partners to ask for more evidence behind compliance claims.

Organizations should be prepared to show how they assess AI tools and data suppliers, document risks, set retention periods and maintain meaningful human oversight. They should also be able to explain who is responsible when several parties are involved in collecting, processing or analyzing the same data.

“Saying that data or an AI tool is compliant will increasingly be only the beginning of the conversation,” Jurgita explains. “Businesses will need to show what they checked, what they documented and which safeguards they put in place.”

For us at Syno, this is closely connected to research quality. Reliable insights depend not only on the amount of data available, but also on whether its origin is understood, its use is justified and the people behind it are treated responsibly.

stats syno international matomo showing the data of syno international company