07-10-2025 - As AI becomes a central focus for organisations under the EU Artificial Intelligence Act (“AI Act”), many organisations are rethinking their compliance strategies. Yet the foundations of privacy law remain firmly in place. With increasing enforcement across Europe and global developments around the world, building a compliance programme that integrates both AI and privacy obligations is critical. This blog will explore the risks of neglecting foundational privacy duties and offer practical insights on creating a comprehensive compliance framework that supports innovation and business progress while maintaining regulatory compliance.
Setting the stage: AI versus privacy and a multi-jurisdictional perspective
The past year has been mostly defined by one theme in compliance conversations: AI. With the world’s first comprehensive AI legislation, the AI Act, set to apply in stages and become fully enforceable by summer 2026, its scale and novelty has unsurprisingly captured the attention of boardrooms, compliance teams, and regulators alike. Yet, while organisations scramble to map their AI strategies and prepare for their obligations under the AI Act, there is a slowly creeping risk to lose sight of the broader compliance landscape. Robust AI regulation may be new, but organisations must not neglect their already firmly established privacy obligations. In fact, these obligations continue to expand worldwide, and enforcement is very much active.
Despite potential upcoming shake-ups, the EU General Data Protection Regulation (“GDPR”) remains the backbone of privacy compliance, continuing to enforce principles of lawful personal data processing, transparency, accountability, protection of individual rights, and rules for international transfers. At the same time, international developments are reshaping cross-border compliance: from Brazil's and China’s new rules on cross-border data transfers, to the continuously evolving privacy frameworks of other jurisdictions including India, Singapore, South Africa and an increasing number of US states. The result is a patchwork of both overlapping and differing requirements that global organisations must manage.
This reflection comes on the heels of Considerati’s recent GROWING TRUST – Privacy & AI Compliance across Frontiers conference. Across panels, keynotes, and workshops, a recurring theme emerged: organisations cannot afford to treat AI and privacy as separate silos. Instead, success depends on building comprehensive compliance programmes that integrate both.
The intersection of AI and privacy
AI and privacy are not mutually exclusive. AI systems process vast amounts of data, often including personal data, which means they sit squarely within the scope of existing privacy laws. EU’s privacy watchdog, the European Data Protection Board (EDPB) emphasised last year that providers and deployers of AI models must still respect the GDPR’s principles, including lawful basis, data minimisation, and the rights of individuals.
This alignment means that compliance programmes cannot treat the AI Act in isolation. Meeting its requirements will depend on already having strong privacy governance in place. For example, conducting data protection impact assessments and ensuring vendor oversight are just some prerequisites for responsibly deploying AI.
The risks of forgetting the fundamentals
Neglecting privacy while focusing exclusively on AI governance is more than a theoretical concern. Earlier this year the Garante, Italy’s supervisory authority, fined the US company managing the chatbot Replika €5 million for failing to comply with GDPR obligations including lawful processing, transparency, and age verification. Similarly, last year the Dutch Data Protection Authority imposed a €30.5 million fine on a US AI company for creating an unauthorised biometric database of scraped images, in breach of GDPR provisions on sensitive data. These cases demonstrate that regulators remain focused on privacy compliance, even where AI is involved. Treating AI compliance as a substitute for privacy compliance may thus become a costly mistake.
The case for comprehensive compliance
The AI Act adds a new layer of regulation, but it does not replace existing obligations. Organisations that focus narrowly on AI risk leaving themselves exposed on the fundamental privacy requirements. As the enforcement cases illustrate, AI is not treated in isolation from privacy; both frameworks are interconnected. A sustainable strategy is therefore to build a comprehensive compliance programme that unites privacy and AI, aligning global obligations under one framework. That means maintaining records of processing activities, implementing privacy by design, safeguarding cross-border transfers and respecting data subject rights, while also conducting risk assessments, documenting AI system design and meeting AI Act transparency requirements. This integrated approach does more than avoid penalties; it enables access to new markets, supports innovation, and strengthens trust with customers and regulators alike.
Looking ahead
The AI Act will undoubtedly shape compliance priorities in the coming years. But it should not come at the expense of ongoing privacy obligations that are already enforceable across many jurisdictions. Privacy law provides the foundation on which AI governance should stand. Organisations that succeed in balancing both investing in AI readiness while ensuring that privacy obligations remain front and centre will be best suited for what is to come.
Considerati will continue to monitor the global developments in privacy and AI. If you have questions or need help on optimising your compliance programme to manage both privacy and AI obligations, do not hesitate to connect with us.
Recente blogs
18-07-2025 – The European Data Protection Board (EDPB) and European Data Protection Supervisor (EDPS) recently issued a Joint Opinion on the European Commission’s…