
Artificial intelligence (AI)-driven genomic research challenges prevailing consent frameworks by enabling iterative data reuse, cumulative inference, and intergenerational risk that static, one-off consent cannot adequately address. This article applies the Social Construction of Technology (SCOT) and the principle of Respect for Persons (PRP), interpreted through relational autonomy, to examine how regulatory categories such as broad consent, minimal risk, and compatible purpose are socially constructed, institutionally stabilised, and ethically consequential. In this context, consent rules operate not merely as mechanisms of authorisation but as governance tools that allocate responsibility, shape expectations, and determine the legitimacy of downstream data use over time. Through a comparative analysis of the EU General Data Protection Regulation (GDPR) and the U.S. Common Rule (U.S.C.R.), the article demonstrates how categorical exemptions and procedural consent under the U.S.C.R. fail to ensure sustained participant protection in genomic AI, while the GDPR embeds consent within a cumulative legality architecture grounded in Articles 5, 6(4), 9, and 89(1), with Recital 33 guiding interpretation. The article argues that dynamic consent does not constitute an independent lawful basis under the GDPR but may offer a doctrinally compatible and ethically robust governance mechanism capable of operationalising existing GDPR obligations. It may do so by enabling iterative engagement, granular permissions, and accountability across evolving research contexts, particularly in dual-regulation environments such as Qatar, where GDPR-style frameworks coexist with U.S.C.R. requirements.
dynamic consent; relational autonomy; genomic AI; GDPR Article 9; Recital 33; Social Construction of Technology (SCOT); Respect for Persons; Common Rule; exemption frameworks; data ethics