When I heard about the AI Act, I had a moment of panic — not because of having to comply with it, but because I remember what happened when GDPR rolled out. The emails. The updates. The “changes to how we communicate”.
My inbox didn’t recover for months.
When GDPR rolled out, the main focus of most companies with an online presence was compliance. They saw the €20M-or-4%-of-global-turnover fine threat and said “nope”. They got their ducks in a row and figured it out. They pointed to their CRM, their email marketing provider, their POS, their ERP — anywhere customer data lives — slapped a “GDPR compliant” sticker on it, and showed that to anyone and everyone.
I figure the same sort of situation will probably happen with AI Act compliance. Ticking a box without proper governance or team-wide understanding behind it.
GDPR was never treated as a team sport — but AI Act compliance will have to be#
One part of the regulation was to make sure each company had a data compliance officer — someone who, at the end of the day, would be able to be held accountable if there was a GDPR breach. That isn’t the “full” set of their responsibilities, but that’s what it felt like, in essence.
This was fine when the tech we were using was straightforward. You had places your client data lived, you had a record of who accessed it and how, you had a way to delete it, and a way to prove you deleted it. Then, for some reason, we started telling everyone to experiment with AI and didn’t train THOSE people in GDPR first.
That’s why I think, for AI Act compliance, you will also have to start getting your team on board with GDPR and the reasons behind the regulations.
If I could guess how many GDPR violations there have been since the start of the AI wave, I’d say it’s an order of magnitude more than the enforcement tracker documents. And I know this because I have had to push back on sales leads who have wanted me to dump client information into an AI black box for their own goals, including pressuring me to set up voice recording without consent, among other nightmarish situations for someone like me who spends a lot of time thinking about privacy.
One of the major problems is that these team members don’t understand how GDPR works, how technology works, or why we need to protect these values. They are being pressured to reach higher and higher sales targets, and are willing to do anything to meet them. AI seems like a really quick means to an end.
AI is a lot more “mysterious” than other technology platforms, so people are confused about what they need to do to comply#
With other tech platforms, you have a clear idea of how it works. You might not be able to see the code exactly, but you have an understanding that when you press button Y, X happens.
With AI (chat, coding, or any non-linear workflow), every time you prompt — even on the same account, even with the exact same words — you will get a different outcome. Not just in the response, but in the way the response is found. The AI will call different tools, and even access different documents on your computer.
There are ways to lock this down — you can set in the settings exactly what Claude Code can access, for example — but even that’s not a guarantee (Grok, for example, has recently been found to not behave as expected when given strict instructions).
As a developer, I’m constantly looking for ways to ensure I’m using these tools safely. This includes building my own private AI harness on an EU-sovereign rented GPU, with an open weight/open source (they are different, read more here) model that I spin up as needed and tear down when done. I will move to on-prem as soon as possible.
But if you’re not a tech person, or not as deeply (and frankly, problematically) obsessed with AI as I am, those words might read as gibberish to you. You’re not using AI the way someone like me is. That’s fine, but it’s a problem we need to solve.
What companies need to put in place for EU AI Act and GDPR compliance in their AI use#
So here’s the bread and butter of this post.
1. Have a company-wide discussion and training on data privacy and AI transparency#
You need to make it real, and emotional. You need to share concrete examples of how AI is being used to hurt people. You need your team to understand the risks of compromising other peoples’ data, and how it can happen unintentionally. They also need to understand how AI is increasingly being implicated in surveillance by states that are known to breach personal privacy for unfounded reasons, and that sharing data with tech companies in other countries can put that data at risk.
You also need to make sure they understand why using AI for everything — and especially not disclosing it — can make customers lose trust in your brand.
Obviously, disclosure of AI systems that interact with customers is becoming a non-negotiable under the EU AI Act. This includes:
- Chatbots
- Assistants
- Voice bots
Even if you disclose, you’re still liable for issues — for example, if an e-commerce bot recommends the wrong product and harms the user.
Finally, in my opinion, you need this done as both formal training (for compliance) and unstructured “watercooler” conversation (for enforcing it in the culture). And there are plenty of other places where you’re not “required” to disclose, that you still should.
2. Enforce DPA-only contracts for AI tools#
A lot of people don’t realize that if you’re not on an enterprise account or using an API to access your model — if you’re just on the consumer-grade subscription (yes, even the €200-a-month Claude Pro Max plan at 20x tokens) — then you’re not protected, legally, for any data you or your team accidentally share with an AI assistant.
If you are using an enterprise-level account, you need to ensure that you’ve either signed the DPA, or that it’s “accepted” by default. Mistral, for example, has a DPA automatically included in its commercial terms. Other companies, like OpenAI, require you to fill out a form.
Some ways to fix this:
- If truly necessary, move to an enterprise account for chat (so you’ll likely be enforcing that everyone uses one platform rather than having their own AI of choice) and make sure you have a DPA in place.
- Integrate AI models via API into your existing tools, like your CRM, and set up intelligent workflows to surface insights and help draft contracts, manage sales pipelines, and so on from a single place. Then you’re not playing the copy-paste game, and you have a record of your data orchestration.
- Use a local/self-hosted/on-prem model where you can set it up in a way that has an audit log. You become the data processor.
3. Create true transparency around your use of AI#
Personally, I created a page that I’ve tucked into my legal pages.
Even though I don’t use AI to create realistic images (or any images), and the only AI-generated text I use is for my site’s pages (which I heavily review) and never on my blog posts (so if this reads as slop to you, I’ll have you know, it’s artisanal hand-typed slop), I still want people to know where AI touched my business and my output. It just doesn’t feel right otherwise.
This will help you meet certain obligations, but it will also help you examine where you may be over-relying on AI. Is your whole business AI at this point? There may be a reason why people don’t feel connected to your brand. It might be worth looking at where you can use AI for efficiency in internal procedures, and adding a human element back to your customer-facing touchpoints.
The uphill battle ahead#
People don’t trust AI for some of the reasons I’ve shared in this post, and for many others we’ve gotten into in previous posts. I’ll continue to dissect all of this ongoing.
But AI can be so many things. I see it as a way for a young person with a good idea to become an entrepreneur, for someone with ADHD to have a better reminder system, or for people who don’t like working on computers to be able to spend more time face-to-face while an agent handles tasks in the background.
There are people already living this dream, but there are also people having their lives absolutely ruined by it. At some point, we will have to decide if the benefits outweigh the risks. While there are many criticisms of the EU AI Act, I do appreciate that someone is trying to find a way to protect individuals while still allowing us to see what we can do with this technology that’s actually going to change the world.
If you’d like help getting your team AI-ready without cutting corners on privacy, get in touch.