


























Carlo Salizzo moved to Ireland to be at the heart of European tech law as it was being drafted. A decade on, he’s exactly where he wanted to be.
A New Zealander who has called Ireland home for close to a decade, Carlo Salizzo came here with a clear purpose – to be at the centre of European technology law as it was being written. His timing, he says, was fairly fortuitous.
“The move to Ireland was basically in order to get involved in the really interesting, exciting, cutting-edge technology law work that happens in Dublin and in Ireland,” he says. “I was, I suppose, fortunate in my timing, in that as I was arriving, it was the gearing-up period to the GDPR, and I had the opportunity to work with people who were getting to grips with this massive, world-changing legislation.”
The comparison between his home country and his adopted one is one Salizzo draws readily. “I joke that if you took Ireland and put it in the middle of the Atlantic, away from the EU and the UK, you’d have New Zealand,” he tells me. “Both are small, open, English-speaking economies with outsized global ambition. The difference, of course, is that Ireland sits at the intersection of European regulation and a technology sector of genuine international scale.”
Since arriving in Ireland, Salizzo has worked with some of the biggest companies in the world, navigating an ever-expanding landscape of European digital law. The past five years at Dentons Ireland have been a particular success story, he says. The technology and digital regulation team has grown under “the watchful eye, stewardship and energy” of managing partner Eavan Saunders, he says.
“We’ve really worked on putting together the best possible team, drawing in lawyers with international experience and really deep Irish market knowledge to establish a team that’s made up of stars in every area.” And technology and digital regulation is just the latest area, with his colleagues including David Kirton and Julian Michael.
“A lot of the clients we work with are managing a European operation, or a European legal team, or even broader, an EMEA legal team,” he says. “Part of delivering really high-quality, cutting-edge advice is having an understanding of what’s going on across the island, the UK, Europe, even the Middle East, Africa and further afield. And so being able to bring that Irish knowledge and tap into the Dentons engine, the Dentons firm is just so powerful.”
Ask Salizzo what is defining 2026 from a digital regulation perspective and the answer comes in three clear chapters: artificial intelligence, cybersecurity and online safety. Privacy, he notes, has not gone away – but it has become so interwoven with everything else that it is now the baseline rather than the headline.
“Everybody wants to know what’s happening with AI. Everybody wants to know how the new legislation will work, but also how your existing legal concepts – like intellectual property or contract law – need to adapt, or will impact on your artificial intelligence roll-out,” he says. Alongside that, cyber resilience has moved firmly up the boardroom agenda, and online safety – driven in the EU by the Digital Services Act – is increasingly in the public eye.
On AI, Salizzo is quick to correct what he regards as a persistent misconception. The EU AI Act, he says, is emphatically not GDPR 2.0.
“With the EU AI Act, one of the very common misconceptions in the early days is that it is a privacy law, or that it is a kind of GDPR II. It absolutely is not,” he says. “What it resembles is far closer to a product safety or product liability piece of legislation.”
The obligations, he explains, fall primarily on the providers putting AI tools on the market. Businesses that are not selling AI as a core offering will find their compliance burden considerably lighter – particularly if they fall outside the prohibited and high-risk activity categories set out in the act.
“Quite often, with a few appropriate policies, we can help them navigate that quite simply,” he says. For those that are building and selling AI products, however, the certification requirements represent genuinely new territory for software organisations. “Having to conduct these certification exercises, ensuring that you have the CE mark and ensuring that you have the appropriate documentation in place – it’s not something that will be familiar for a lot of software organisations.”
The murkier terrain, he suggests, is what might be called the shadow AI problem – the gap between official policy and actual behaviour inside organisations.
“If people aren’t saying they’re using AI, they’re still using AI, but they may be doing so in a way that’s not consistent with the business’s policies, or may not be doing so in a way that’s going to protect intellectual property,” he says. And when it comes to cybersecurity, the implications run deeper still. “AI acts as a force multiplier for all of this. If you’re concerned about cybersecurity, then you have to look at the fact that your bad actors, your adversaries, are now empowered to be many, many times more efficient at what they’re trying to do.”
The corollary, he is clear, is that businesses must match that pace. “The game is trying to make sure that you’re deploying AI in a way where you are outpacing those inputs – whether they’re complaints, plaintiffs, new legislation, new regulations, investigations.”
The cyber threat is one Salizzo takes seriously – and Ireland’s own recent history makes it hard to look away. “The HSE data breach a few years ago is never far from the mind,” he says. Repeated attacks on national health infrastructure and other parts of the economy have made cyber resilience a lived reality here, not just a compliance exercise.
At Dentons, the offering is built around preparedness as much as response: policies stress-tested before the incident, threats known in advance, tabletop exercises run while the systems are still working. “You can never predict when the incident is going to happen or when the attack will come,” he says. “Part of the offering that we’ve built here at Dentons is the ability to manage that and, more importantly, helping our clients be prepared for when it does happen, so that we can mitigate and avoid the worst of the impact.”
On EU Inc – the proposal for a simplified pan-European company structure that has sparked considerable discussion in the start-up and venture capital world – Salizzo is measured but positive. “It certainly seems to be a positive step in the right direction. The challenge is going to be making it work, as it always is,” he says. He flags the potential significance of a unified insolvency procedure, possibly comparable to Chapter 11 in the US, for early-stage investors seeking certainty. But he adds a nuance worth noting for Irish companies: the Irish limited company, with its common law familiarity and English-language operating environment, retains its own considerable appeal. “It may be the case that an Irish limited company continues to be the appropriate way to do that, with other outposts across Europe.”
On GDPR simplification, currently moving through the European legislative process, Salizzo is similarly measured. The proposed changes are modest, he says, but some are genuinely meaningful. “It’s welcome to see things like calibration of when the right of access is, in fact, excessive,” he says. “It’s very, very welcome to see a single point of entry for breach reporting across the various European legislation that all require you to notify incidents. We’d very much like to see very practical and commercial changes like that brought into European law.”
Then there is the question closest to home: how AI is reshaping the legal sector itself. Here, Salizzo is candid and enthusiastic in equal measure. “We were very, very early to deploying AI. We have a tool called Fleet AI, which has been developed, built on top of ChatGPT, and that is very much a big part of how we do business now,” he says. Beyond large language models, Dentons’ innovation team is deploying a dozen different technologies to deliver legal services, he says – drawing on the resources of a global firm to stay at the cutting edge.
“I’m really excited to see what happens, and very excited, frankly, for our team – which has been built with this in mind – to really innovate and lead from the front in terms of providing the best service to our clients in the most secure and technologically empowered way.”
Looking ahead to the rest of 2026, Salizzo is hopeful that Ireland will pass its long-awaited cybersecurity bill this year. The Irish Presidency of the Council of the EU means a busy calendar for the Government, he acknowledges. And in October, Dentons is helping to anchor a month of European AI innovation and an AI summit in Dublin, drawing colleagues and conversations from across the continent.
“It’s actually going to be a very exciting year,” he says, “after a series of very exciting years. From a digital regulation perspective, it’s a real privilege to be able to work with some of the clients that we get to work with here.”
On the larger question – whether the law can truly keep pace with technology – Salizzo has a characteristically clear view. “The law is there and the technology is coming, and the law will adapt to it over time.” It is not the answer of someone who fears disruption. Rather it is the answer of someone who has already decided which side of it he wants to be on.
Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。