Europe Moves to Reassess the Legal Floor Under Transatlantic AI Data Flows
Europe's data regulators have asked the European Commission to reassess the EU-US Data Privacy Framework after a US Supreme Court ruling stripped the FTC independence it rests on, leaving firms that run European data through US-controlled AI infrastructure on visibly less stable legal ground.

Europe's data protection regulators have formally asked the European Commission to reassess the EU-US Data Privacy Framework, the adequacy arrangement that underwrites the lawful flow of European personal data to American cloud and AI providers. The trigger is a US Supreme Court ruling that dismantled the independence guarantees on which that arrangement was built, and the strategic consequence is that every organisation running European data through US-controlled AI infrastructure now carries a legal dependency that is visibly less stable than it was a month ago.
A Ruling in Washington, a Letter From Brussels
On June 29, 2026, the US Supreme Court decided Trump v. Slaughter, overruling the 1935 Humphrey's Executor precedent and holding that the President may remove Federal Trade Commission commissioners at will. The case arose from President Trump's dismissal of Commissioner Rebecca Kelly Slaughter, which was not based on the narrow grounds of inefficiency, neglect of duty, or malfeasance that the Data Privacy Framework's underlying commitments assumed.
On July 31, the European Data Protection Board responded. In a letter to the European Commission, signed under Chair Anu Talus, the Board asked the Commission to closely examine whether the ruling affects the continued validity of the EU-US Data Privacy Framework. The Board's reasoning is structural: the existence and effective operation of independent supervisory authorities in a third country is a key factor in any adequacy assessment, and the FTC is the primary enforcement authority behind the Framework's commercial commitments. The letter became the subject of wide coverage between August 3 and August 5, including analyses from IAPP and Hunton Andrews Kurth.
The Framework remains valid today. It falls only if the Commission amends or withdraws it, or if the Court of Justice of the European Union strikes it down. Privacy advocate Max Schrems, who felled the two previous transatlantic arrangements, has said publicly that in his view the deal is already done and that a legal challenge is in preparation; that assessment is his own position, not an established fact. Others, including former FTC official Maneesha Mithal, argue the agency's privacy enforcement practice continues regardless of the removal doctrine.
Adequacy Was Always a Bet on American Institutions
The Data Privacy Framework is not a technical mechanism; it is a political judgment that US institutions provide essentially equivalent protection for European personal data. That judgment rested on two pillars: an intelligence oversight apparatus created by executive order, and independent regulatory enforcement led by the FTC. Trump v. Slaughter weakens the second pillar as a matter of constitutional law, not merely of administration policy. An enforcement authority whose commissioners serve at presidential pleasure is, in the EDPB's framing, a different institution from the one the Commission assessed in 2023.
This matters far beyond adtech and e-commerce. The Framework, together with standard contractual clauses that lean on the same adequacy reasoning, is the legal substrate for European use of US-based AI services: model APIs, AI-enabled SaaS, cloud-hosted training and inference pipelines that touch personal data. The pattern is also familiar. Safe Harbor fell in 2015, Privacy Shield fell in 2020, and each collapse arrived through litigation that took years to mature while businesses continued to build on the arrangement. Organisations that treated adequacy as permanent infrastructure absorbed the disruption; organisations that treated it as a revocable licence adapted faster.
The Case for Controlling Your Own Inference Just Got Stronger
For decision-makers, the practical question is not whether the Framework survives this specific review. It is what the recurring fragility of transatlantic adequacy means for architecture. Three consequences follow.
First, dependency mapping becomes urgent work rather than compliance hygiene. Organisations should know precisely which AI workloads move European personal data to US-controlled infrastructure, under which legal instrument, and what the fallback is if that instrument weakens: standard contractual clauses with genuine supplementary measures, EU-region processing with contractual data residency, or removal of personal data from the workload entirely.
Second, the strategic value of local and private inference rises. Models run on infrastructure the organisation controls, whether self-hosted open-weight models or EU-jurisdiction sovereign cloud offerings, are insulated from adequacy volatility by design. What was often justified as a confidentiality or lock-in play now carries a further advantage: legal continuity that does not depend on the outcome of litigation in Luxembourg or doctrine in Washington.
Third, there is genuine upside for the European supply side. Every episode of transfer uncertainty has accelerated demand for EU-based processing, and vendors of sovereign cloud, open-source model stacks, and residency-guaranteed AI services now have a stronger commercial argument than at any point since Schrems II. For US providers, the opportunity is symmetrical: those that can offer credible EU-boundary deployments, with keys, logs, and inference kept inside European jurisdiction, will be better positioned than those selling adequacy-dependent architectures.
Treat Adequacy as a Variable, Not a Constant
The Data Privacy Framework has not fallen, and it may yet survive this review intact. But the EDPB has now put on record that the institutional ground beneath it has shifted, and the history of transatlantic data arrangements argues against complacency. Organisations that architect their AI systems so that data location and model control are decisions they own, rather than outcomes they inherit from a treaty-like arrangement, will be indifferent to how this review ends. That indifference is what sovereignty buys.
Sources: EDPB letter to the European Commission on Trump v. Slaughter, July 31, 2026 (primary source): https://www.edpb.europa.eu/documents/edpb-correspondence/edpb-letter-to-the-european-commission-on-us-supreme-court-judgment_en; US Supreme Court opinion, Trump v. Slaughter, No. 25-332, June 29, 2026: https://www.supremecourt.gov/opinions/25pdf/25-332_qn12.pdf; IAPP coverage, August 3, 2026: https://iapp.org/news/a/edpb-requests-review-of-eu-us-data-privacy-framework-following-trump-v-slaughter; Hunton Andrews Kurth analysis, August 5, 2026: https://www.hunton.com/privacy-and-cybersecurity-law-blog/edpb-calls-for-review-of-eu-u-s-data-privacy-framework-after-u-s-supreme-court-decision-on-ftc-independence
Source: European Data Protection Board