The Signature That Doesn't Mean Yes
Maryland became the first US state to ban AI surveillance pricing in grocery stores in May 2026. The Federal Trade Commission sanctioned Cox Media Group in the same period for representing that its AI could target consumers by listening through device microphones - and explicitly rejected Terms and Conditions as a valid consent mechanism for the practice. The European Commission proposed, also in the same period, that personal data used to train AI models could be processed under legitimate interest, provided individuals received an unconditional right to opt out.
Three regulatory responses. Three jurisdictions. The same underlying architecture.
That architecture is: protect people by giving them a right, and let them exercise it.
Maryland concluded this doesn't work and banned the practice instead. The FTC concluded that T&Cs don't constitute meaningful consent and ordered changes. The Commission concluded that the right solution is a new right - the right to opt out - and proposed no mechanism to make exercise of that right feasible.
This is worth examining carefully, because the Commission's approach is not an outlier. It is the default posture of data protection regulation as applied to AI: constrain what is done to people by giving people rights over it, rather than by limiting what can be done. The interesting regulatory question of 2026 is whether this posture is working. Maryland and the FTC are beginning to answer.
What Surveillance Pricing Actually Is
The distinction between surveillance pricing and dynamic pricing matters legally and it is not always drawn correctly.
Dynamic pricing adjusts prices based on aggregate demand signals. Flights cost more in August because many people want to fly in August. The signal is market-wide; the price reflects conditions external to the individual buyer. The individual buyer is not the subject of the pricing decision. They are a member of a market.
Surveillance pricing adjusts prices based on individual consumer signals. This person, at this moment, with this inferred income level, these spending patterns, this location history, and this behavioural profile, will pay up to this amount. The signal is the individual; the price reflects what can be extracted from them specifically. The individual buyer is not a participant in a market. They are the object of an extraction.
Under GDPR Article 4(4), what surveillance pricing requires is profiling: "automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's economic situation". Profiling for pricing decisions in essential goods categories - groceries, utilities, insurance - produces effects that GDPR Article 22 characterises as "legally or similarly significant". The legal framework covers this.
The coverage becomes more uncomfortable when the consumer being profiled is not a rational economic actor with stable preferences and full information, but a person under stress. The AXA Mind Health Report, published this year, found that more than six in ten people now turn to AI systems for psychological support. An AI application that profiles users' emotional states and financial anxieties - inferred from conversation history, usage patterns, and behavioural signals - and uses that profile to determine what to offer them, and at what price, is conducting surveillance pricing on people who came for support. Article 22 was drafted with credit decisions in mind. The drafters did not anticipate applications operating in cognitive real estate - interfaces designed to produce engagement, not understanding - that could identify a depressive episode and surface a subscription upgrade in the same interaction.
Maryland banned the grocery store version. No registry, no opt-out portal, no transparency dashboard. Just a prohibition.
The FTC's Doctrinal Move
The Cox Media Group enforcement action is worth reading closely, because the FTC did something that EU regulators have approached more slowly.
The company had represented that its AI could target advertising based on ambient audio captured through consumers' device microphones. The FTC found that these representations were false - that the claimed capability did not work as described. The Commission might have stopped there, with a straightforward misrepresentation finding.
It did not.
The FTC explicitly rejected Terms and Conditions as a valid consent mechanism for the practices in question, regardless of whether the T&Cs had accurately described them. The ruling is clear: broad consent provisions in commercial agreements do not constitute meaningful authorisation for AI data practices that consumers cannot understand, anticipate, or practically control.
US consumer protection law and EU data protection law operate through entirely different frameworks. They have arrived at the same conclusion. The EDPB has established through successive opinions that GDPR consent must be specific, informed, freely given, and not bundled with other terms. The FTC reached the same destination through the more direct route of finding that a company cannot consent someone to something that, if fully understood, they would not agree to.
The consequence for practitioners advising AI-driven business models is the same regardless of jurisdiction: broad T&C consent for AI personalisation, profiling, and pricing is not a durable legal strategy. Regulatory tolerance for this approach is declining simultaneously in both systems. The pathways are different; the direction is the same.
The Commission's Opt-Out
The Digital Omnibus proposal currently before the European legislature would amend GDPR to allow AI providers to rely on legitimate interest for personal data used in AI training - provided they give individuals an unconditional right to opt out. The EDPB and the European Data Protection Supervisor responded with a joint critical opinion in January 2026. The criticism is technically correct and misses the deeper point.
The opt-out mechanism requires individuals to register their objection to the processing of their personal data for AI training purposes. To exercise this right effectively, they would need to know which AI providers are training on their data, how to contact those providers, what specific data is involved, and how to submit an objection that the provider is legally obliged to honour.
For personal data published online - social media profiles, forum posts, professional histories, public statements - the practical exercise of this right requires an infrastructure that does not exist: a registry of AI training data sources, a standard mechanism for registering objections, and a technically reliable process for removing data from training pipelines that have already been run. The EDPB's criticism focuses on the second and third of these. The first - that the population of AI providers using any given person's data is effectively unknown to that person - is the structural constraint that makes the others moot.
The EDPB is right that the opt-out mechanism as proposed doesn't work. What the criticism does not quite say directly is why: the opt-out imports the same architecture as the T&C consent mechanism that the FTC has just rejected. Both approaches protect people by giving them a right, in a context where the exercise of that right requires information and infrastructure they do not have. The T&C says "you agreed to this." The opt-out says "you could have objected to this." In both cases, the practical position of the data subject is the same: they did not understand what was happening, they had no viable mechanism to affect it, and the legal form of protection was real while its substance was not.
The Commission is not acting in bad faith. It is applying the default framework. The default framework is consent, or consent-adjacent constructs like legitimate interest with an opt-out. This framework has served EU data protection law reasonably well for interactions it was designed for. It is straining under the weight of AI training at scale.
The Council Removes the Provision. The Practice Remains.
In April 2026 the Council of the European Union moved to remove the legitimate interest provision for AI training from the Digital Omnibus entirely.
This requires a moment of careful attention, because the institutional logic is quite exquisite.
The Commission proposed that AI providers could use legitimate interest, provided they offered an opt-out. The EDPB said the opt-out didn't work. The Council's response was not to fix the opt-out, and not to ban the practice. It was to remove the codification on the grounds that it was unnecessary - because the EDPB's own December 2024 opinion already permits legitimate interest for AI training under existing GDPR provisions, provided certain conditions are met.
The result: the practice continues. The legal basis is the same as before the proposal. The opt-out that nobody could exercise has been replaced by the absence of a framework - which produces the same practical outcome for data subjects, with the additional disadvantage that the conditions under which legitimate interest applies are now less explicit, not more.
The Clause - the one that protects data subjects by giving them rights they cannot exercise - has performed a complete rotation. The Commission offered a right. The EDPB said the right was insufficient. The Council agreed - and removed the right. The data subject's position has not changed. The institutional machinery has consumed considerable energy arriving precisely where it started.
This is not dysfunction. This is the system working as designed: a regulatory gift that benefits those who can navigate ambiguity and disadvantages those who cannot. The ambiguity has been preserved. The gift has been delivered.
The Architecture of Fictional Consent
Maryland and the FTC are not making the same regulatory choice. Maryland banned a practice; the FTC imposed a consent-based remedy. But read together, the US regulatory landscape in this period is moving toward a recognition that some AI data practices are not problems of consent quality - that no improvement to transparency requirements, disclosure specificity, or opt-out mechanisms will produce consent that is meaningful, because the conditions for meaningful consent do not obtain.
The conditions are not complicated: the consenting party understands what they are consenting to; they have a genuine alternative to not consenting; and they can exercise rights over what happens after. In commercial AI contexts - where the data practices are technically complex, the commercial pressure to accept is significant, and the rights exercisable after the fact require infrastructure that does not exist - none of these conditions hold reliably for most people in most transactions.
GDPR's response to the observation that consent conditions don't hold has generally been to strengthen the consent framework: better transparency, clearer disclosure, stronger requirements for specificity. These improvements are not worthless. They have made some consent mechanisms more meaningful in some contexts. They have not solved the structural problem, because the structural problem is not that consent forms are poorly written. The structural problem is that consent in commercial AI contexts is largely a mechanism for transferring legal responsibility from companies to consumers in transactions where consumers lack the information, infrastructure, and practical capacity to exercise what they have accepted.
The Article 29 Working Party wrote in 2018 that consent should not be "a ticket to unlimited processing." The EDPB has said this repeatedly in different formulations since. The Commission's Digital Omnibus opt-out proposal is, in effect, a ticket to unlimited AI training, with a stub attached.
The stub says: you can opt out. Provided you know who to call. The Council has since removed the stub. The door remains locked; the sign has been taken down.
Regulators are catching up. Maryland and the FTC are ahead. The Commission proposed. The EDPB criticised. The Council removed. The data subject's position has not changed at any point during this sequence.
This is what the catching-up looks like, from the inside: the same logic running into the same wall, in slightly different rooms, at slightly different times, with slightly different drafters who each believe they have improved on the previous attempt. Occasionally the wall runs into itself.
The wall has not moved.