Key Takeaways

Organizations that:

  1. Integrate appropriate AI governance into privacy efforts,
  2. Build foundational compliance processes now, and
  3. Assess current AI use cases before regulators ask about them,

will be better positioned to manage risk, comply with emerging regulations, and avoid having a compliance gap discovered by regulators, customers, or plaintiffs’ attorneys.

Why AI Governance Should Start with Privacy

The availability and use of generative artificial intelligence, or AI, tools is increasingly ubiquitous, particularly in the workplace. In response, lawmakers are sprinting to enact AI-focused regulations to keep up with the rapidly evolving technology.

For governance, risk, and compliance professionals watching AI regulations evolve, there is a good chance they’re experiencing a feeling of déjà vu, and rightly so. The core obligations emerging in state AI statutes, the EU AI Act, and sector-specific AI guidance are not new legal concepts. Rather, they are the same foundational principles that have anchored privacy law for the better part of a decade, i.e., transparency and control.

The practical implications for businesses leveraging AI tools should feel familiar in that the business needs to know what data it’s processing, understand why it’s processing it, be able to explain such processing to individuals affected by it, and give them a meaningful way to object or opt out.

The parallels between Privacy and AI regulations extend to compliance programs and underlying processes. For example, regulations or standards requiring impact assessments before deploying certain AI systems will involve steps familiar to anyone who has built a Data Protection Impact Assessment program under CPRA or GDPR: identify the data involved, assess the risk of harm, document mitigation steps, and be ready to show the work.

Similarly, transparency obligations applicable to certain uses of AI-powered automated decision-making technologies echo or, in some cases, are even an expansion of similar requirements under existing privacy laws. While examples abound, the throughline is consistent: transparency about what’s happening, and some mechanism of individual control over it.

Unfortunately, similarity does not always equate to efficiency. Currently, there is no single federal AI standard to design around, just as there has never been one for privacy. Compliance teams that have spent the last several years building out their operations for compliance with a patchwork of distinct state privacy laws – i.e., varying thresholds, notice requirements, or individual rights depending on which states their customers or employees sit in – will easily recognize the same pattern taking shape around AI. A multitude of states, including Colorado, California, Illinois, New York, Oregon, Virginia, Washington, Utah, and Texas, among others, have passed or are moving toward passing standalone AI legislation, or are layering AI-specific obligations onto their existing privacy frameworks. And similar to the evolution of privacy laws, state legislatures are moving on different timelines and with different triggers and definitions for what constitutes “high-risk” or “consequential” AI use.

The challenges presented by evolving AI compliance obligations also present an opportunity, especially for companies that may not have finished building out their privacy compliance program. This is not an uncommon position considering the state privacy law patchwork arrived quickly, enforcement felt distant, and other priorities crowded it out.

AI compliance changes that calculus, because the risk feels more immediate and more visible to leadership. A hallucinated output, a biased hiring algorithm, or a customer-facing chatbot making an unauthorized commitment is the kind of incident that reaches the board in a way a stale privacy notice rarely does. That visibility is useful. Standing up an AI governance function is, in practice, an opportunity to build the underlying data inventory, vendor risk process, and impact assessment template that a privacy program needs anyway. Companies that recognize this can close two compliance gaps with one build, rather than treating AI governance as a distinct initiative competing for limited resources.

None of this means AI governance is trivial or that compliance teams can simply relabel old work product. Model drift, hallucination, disparate impact in automated decision making, and IP questions around training data and outputs don’t have clean privacy-law analogs, and the state AI patchwork is still young enough that definitions and thresholds are shifting under everyone’s feet. But the foundational underpinnings of transparency and control that a privacy compliance program rests upon are largely the same. Building AI governance on top of privacy, rather than beside it, is more cost-effective and defensible if ever scrutinized.

If the organization is standing up AI governance separately from privacy compliance, or if last year’s privacy project never quite got finished, that’s usually a sign worth a conversation before it becomes a gap someone else finds first.

This article summarizes aspects of the law and does not constitute legal advice. For legal advice with regard to your situation, you should contact an attorney.

Sign up

Ideas & Insights