How to build effective AI governance structures on top of your existing GDPR framework

Very good piece by Kristin Johnston on aigovernance and in particular how to start the process. One recommendation – building AI governance on top of existing privacy processes – is very relevant but you have to be careful about how you implement it.

The key challenge is making sure it can be sufficiently distinct as well from a data protection compliance framework, so that people within the organisation remember that the AI governance framework (just like a broader datagovernance framework) needs to be observed also when the project has nothing to do with personaldata.

This has practical implications in my experience – for instance when it comes to choosing where the policies are made available (best not through a “privacy portal”) and which tools are used (if you use a tool for data protection compliance and it is clearly labelled in that way, repurposing it internally for AI-related processes can mislead users into thinking this is only relevant to the extent that you process personal data).

As Kristin also points out in her piece, there are many issues to be taken into account in the context of AI governance – and rules regarding personal data are just one of them (next to intellectual property, liability, fairness and non-discrimination, etc.).

🫖

Did this analysis get you thinking? Reach out!

DataLaws.net is entirely open-access, and instead of getting your data in exchange for this content, how about another trade? If this commentary saved you research time or sparked an idea, feel free to invite me over for tea, chai or a hot chocolate next time you are around Brussels or Antwerp - or invite me over to your offices for a chat!

Get in touch ↗   Let's connect on LinkedIn ↗