Skip to main content
AI Governance Without a Rulebook: What Happens When Compliance Lags Behind DeploymentPrivacy Governance & Design
4 min readFor Legal & Compliance Teams

AI Governance Without a Rulebook: What Happens When Compliance Lags Behind Deployment

The Compliance Challenge

Organizations are deploying AI systems without waiting for regulatory clarity, creating a gap between technical capability and compliance infrastructure. This has led to teams processing personal data through AI tools without documented lawful bases, risk assessments, or appropriate technical and organizational measures tailored to automated decision-making.

This isn't an isolated incident. It's a widespread pattern as AI becomes embedded in business operations while data protection frameworks struggle to catch up. The compliance debt is now coming due.

Timeline of Events

2018-2022: GDPR Article 22 existed on paper, but most controllers treated automated decision-making as a distant edge case. AI deployment accelerated anyway.

2023-2025: Supervisory authorities began issuing sector-specific guidance. Organizations realized their existing privacy impact assessments didn't account for model training on personal data, algorithmic bias, or the transparency obligations unique to AI systems.

2026: Regulatory developments crystallized around risk-based approaches and sector-specific rules. Teams that moved fast without building compliance infrastructure now face retrofit costs and enforcement exposure.

Missing Controls and Failures

No documented compatibility assessment for AI training data. Controllers repurposed personal data collected under one purpose (customer service records, HR files) to train AI models without documenting whether that secondary use was compatible with the original purpose. Article 6(4) requires this analysis before you expand processing scope.

Missing or inadequate Article 22 safeguards. When your AI system produces decisions that significantly affect individuals, you need documented human review processes, clear logic disclosure, and contestation mechanisms. Most teams built the model first and thought about these requirements later.

Failure to update processor agreements. Your standard data processing agreement probably doesn't cover model training, algorithmic auditing rights, or restrictions on using personal data to improve the processor's own AI capabilities. If your processor is doing any of those things, you're operating without contractual coverage.

No risk-based governance framework. Organizations treated all AI deployments the same way, whether the system was recommending product features or making hiring decisions. Risk-based approaches require different controls for different impact levels. Without that classification system, you can't demonstrate proportionate safeguards.

Transparency obligations ignored. Articles 13 and 14 require you to tell data subjects about automated decision-making, including meaningful information about the logic involved. Generic privacy notices that say "we may use AI to improve our services" don't meet this standard when the AI is making consequential decisions about individuals.

Regulatory Requirements

Article 6(4) compatibility: Before you use personal data for AI training that wasn't part of your original collection purpose, document the compatibility factors: the link between original and new purposes, the context of collection, the nature of the data, possible consequences, and existing safeguards.

Article 22 protections: When automated processing produces legal or similarly significant effects, you must implement the right to human intervention, the right to express a point of view, and the right to contest the decision. Document how a human reviewer can meaningfully override the AI's output.

Article 35 data protection impact assessments (DPIAs): AI systems that involve systematic monitoring, automated decision-making with legal effects, or large-scale processing of special category data trigger mandatory DPIAs. These assessments must be specific to the AI use case, not generic privacy reviews.

Article 28 processor requirements: Your processor agreements must specify what the processor can and cannot do with personal data during AI operations. Include audit rights that let you verify the processor isn't using your data to train models for other clients.

Risk-based governance: The GDPR requires appropriate technical and organizational measures proportionate to the risk. That means high-risk AI systems need stronger controls than low-risk automation.

Action Items for Your Team

Map your AI inventory to GDPR obligations. List every system that processes personal data through AI or machine learning. For each one, document the lawful basis, whether Article 22 applies, and whether you've completed a DPIA. If you can't answer these questions for a system already in production, that's your compliance gap.

Build a risk classification system. Not all AI deployments carry the same data protection risk. Create clear criteria for categorizing systems as high, medium, or low risk based on the nature of personal data processed, the degree of automation in decision-making, and potential impact on individuals. Apply proportionate controls to each category.

Update your processor due diligence. Before you sign with an AI processor, confirm they can support your Article 28 obligations. Get explicit contractual commitments that your personal data won't be used to train models for other customers. Verify they can provide audit evidence of these restrictions.

Document your Article 6(4) analysis before expanding AI use. If you're considering training a model on personal data collected for a different purpose, complete the compatibility assessment first. If the purposes aren't compatible, you need fresh consent or a new lawful basis. Don't assume legitimate interests will cover it.

Design human review that actually works. Article 22 doesn't just require a human in the loop; it requires meaningful human intervention. That means your reviewer needs access to the factors the AI considered, the ability to override the decision with documented reasoning, and enough time to actually evaluate the case. A rubber-stamp review process won't survive supervisory authority scrutiny.

Rewrite your transparency language for AI systems. If your AI makes decisions about individuals, your privacy notice must explain the logic involved in terms a reasonable person can understand. "We use machine learning algorithms" isn't sufficient. Describe what the system evaluates and how it reaches decisions.

The regulatory landscape for AI is still taking shape, but the GDPR's core obligations already apply. You don't need to wait for sector-specific AI rules to get your compliance infrastructure in place. Start with the controls the regulation already requires.

You Might Also Like