The AI landscape doesn't move in one direction — it lurches. Some techniques leap from experiment to table stakes in a single quarter; others stall against regulatory walls, technical ceilings, or organisational inertia that no amount of hype can dislodge. Knowing which is which is the hard part. The State of Play cuts through the noise with a rigorously maintained index of AI techniques across every major business domain — classified by maturity, evidenced by real-world adoption, and updated daily so you always know where you stand relative to the field. Stop guessing. Start knowing.
A daily newsletter distilling the past two weeks of movement in a domain or two — delivered to your inbox while the index updates in the background.
Each dot marks the weighted maturity of practices within a domain — hover for a brief summary, click for more detail
AI that automates GDPR, CCPA, and other data protection compliance tasks including DPIA, consent management, and breach response. Includes data subject request processing and privacy impact assessment; distinct from data anonymisation which applies technical privacy controls rather than managing compliance processes.
Privacy compliance automation has a proven ecosystem, quantified ROI, and analyst-validated tooling — yet the practice's defining tension is that most organisations still aren't using it effectively. Platforms can now automate data subject requests, consent orchestration, privacy impact assessments, and breach response workflows across GDPR, CCPA, and a growing patchwork of global regulations. The business case is settled: documented outcomes include 90% reductions in DSR cycle times and six-figure annual cost savings. But only 28% of organisations achieve GDPR compliance and 11% meet CCPA/CPRA requirements, while over 80% of compliance professionals still rely primarily on manual processes. Regulatory enforcement has intensified sharply in Q2 2026, with regulators now verifying operational compliance (not just notice presence) — a shift evidenced by enforcement actions targeting specific technical failures in consent systems (GPC signal handling, opt-out effectiveness, audit trails). The bottleneck is no longer vendor capability. It is organisational readiness — the process discipline, integration work, and change management required to operationalise what these platforms offer. This makes privacy compliance automation a rollout challenge, not a proof-of-concept one.
OneTrust remains the category leader, recognized by Gartner as a Visionary in the 2026 inaugural AI Governance Platforms Magic Quadrant, while competitors like TrustArc, DataGrail, and Ketch carve out niches — often by absorbing customers frustrated with OneTrust's implementation costs (3-6 month deployments, $100K+ consulting fees) and aggressive renewal pricing. The vendor ecosystem is mature and competitive, with OneTrust's Winter 2026 release introducing AI-powered agents for automated review and governance workflows, and newer platforms emphasizing cloud-native automation (80% DSAR processing <24hr vs. legacy 3-5 days). TrustArc's ROI data documents DSR processing costs dropping from $1,200 to $150-225 per request and cycle times compressing from 35-40 days to 4-5 days. Real-world deployment evidence: 344 verified UK firms running TrustArc (Firmbase, June 2026), concentrated in mid-market (median £472.8K turnover) and sectors with high regulatory overhead (49.7% wealth management, 13.1% SaaS). These are compelling numbers, but they describe what is possible, not what is typical.
The gap between platform capability and field reality remains stark. ISACA's June 2026 survey of 1,800+ privacy practitioners reveals the structural adoption barrier: median privacy team size contracted 37.5% in one year (8 to 5 employees), only 13% currently deploy AI tools (38% plan within 12 months), and 50% anticipate budget cuts despite 56% board prioritization. Over 80% still rely primarily on manual processes despite available tooling, and 73.5% have faced enforcement consequences. Enforcement intensity has accelerated: EUR 7.1 billion in cumulative GDPR fines since May 2018, with EUR 1.2 billion issued in 2025 alone and 22% YoY increase in breach notifications. Yet critical deployment failures persist post-platform-adoption: independent auditor assessment (June 2026) documents five recurring OneTrust failure modes—cookie inventory gaps, tag stack bypasses, geolocation misconfiguration, insufficient testing, and ongoing maintenance decay—revealing that compliance automation platforms address the technical layer but cannot mandate the operational discipline, governance oversight, and change management required for real effectiveness. Named enforcement cases highlight this gap: Disney's $2.75M CCPA fine (incomplete GPC signal handling), Healthline Media $1.55M (consent mechanism misconfiguration), Tractor Supply $1.35M (failure to recognize GPC signals)—all companies with deployed CMPs but failed technical execution. Regulatory scope is also expanding: AI governance now intersects privacy compliance, with DPIAs shifting from point-in-time review to continuous re-evaluation (EDPB March 2026 standardized template, mandating automation by June 2026). The French CNIL and EU EDPS have issued official guidance mandating DPIAs for AI systems as a gating control in development pipelines. The market is projected to reach $6.7 billion by 2033, but growth depends less on new features than on closing the organisational readiness gap. Adoption acceleration is measured: organizations with 6+ integrated automation initiatives score 75% maturity versus 18% for fragmented programs—a 4X gap driven by integration discipline and change management, not vendor capability alone. Cost pressure accelerates adoption: DataGrail reports DSR volumes increasing for the fifth consecutive year, with manual DSAR management costing ~$1.5 million annually for mid-sized companies. Third-party risk is doubling (now 30% of breaches, up from 15%), driving shift from annual vendor questionnaires to continuous vendor monitoring. However, deployment of AI itself creates new compliance barriers: Aithos research shows frontier AI models fail GDPR and EU AI Act compliance tests at 46-93% rates, revealing that specialized compliance automation tools with mandatory human oversight remain essential for responsible AI deployment.
— TrustArc benchmark analysis: integrated programs (11 automation initiatives) score 85% Global Privacy Index vs 18% for fragmented approaches; 90% of organizations expanding privacy budgets due to AI; quantifies ROI multiplier from reusable evidence infrastructure.
— Critical assessment documenting adoption barriers in market leader: pricing volatility (10–30× increases on renewal), 8-month deployment timelines, 20–40 person team requirements, architectural mismatch for mid-market/SMB organizations despite platform maturity.
— Cyera DSR platform deployment evidence: 450K+ DSRs fulfilled with 98% time reduction (9 hours to 8 minutes per request), 10× return on investment; demonstrates enterprise-scale automation of labor-intensive compliance workflows.
— Quantified enforcement escalation driving automation adoption: €1.27B GDPR fines in 2025 (+60% YoY), CCPA $16M YTD 2026, 20 US state laws in effect, California DROP platform operational Aug 1 with 45-day deletion compliance requirement.
— Real market adoption signal from Vendr transaction tracking: 47 TrustArc purchases, median $15,120/yr ($8,000–$44,000 range), implementation $10,000–$50,000; demonstrates enterprise-scale contracting breadth for full-suite privacy automation platforms.
— Documented OneTrust implementation failure: banner deployed but consent enforcement broken (182→186 trackers post-opt-out), revealing gap between automation platform deployment and actual technical compliance in production environments.
— Multi-vendor integration patterns documented across OneTrust, BigID, TrustArc, Securiti for AI-assisted DSR automation (intake triage, data discovery, response drafting, deletion orchestration, fraud scoring) showing ecosystem maturity in vendor-agnostic automation workflows.
— Named customers (Pilatus Aircraft, AXA, Openmedical) achieved 60% cost reduction vs. OneTrust, ROPA recertification reduced 3 weeks to 2 days, 200+ hours saved on ISO 27001 certification.