14 min read

AI systems create privacy risk in ways most policies weren't written to cover: the sheer volume of data they train on, the inferences they draw from it, and the speed at which regulators are still figuring out how to govern them. Over the past two years, lawmakers on both sides of the Atlantic have tried to catch up. What 2026 has shown, repeatedly, is that the specific rules keep moving even as the underlying privacy risks stay the same.
That's the problem with an AI governance framework written to the letter of one law. Colorado rewrote its comprehensive AI statute months before it took effect. The EU pushed back its own high-risk deadline by 16 months. A framework tied to either one of those laws as they stood in January needed a rewrite by summer. What holds up, regardless of which rule is in effect this quarter, is a system that can actually show how it handles data, not a document that describes how it's supposed to.
The EU AI Act is the clearest example of how much this space has moved. Its Digital Omnibus amendment, adopted in June 2026 and in force since late July, pushed the compliance deadline for high-risk systems, the category covering employment, credit, education, and biometric use cases, from August 2026 to December 2, 2027. AI embedded in regulated products gets until August 2028.
Not everything moved, though. Article 50's transparency requirements, disclosing to users that they're interacting with AI and labeling AI-generated content, took effect on schedule on August 2, 2026, and are already enforceable. General-purpose AI provider obligations have applied since August 2025. The Act's outright prohibitions, covering manipulative and exploitative AI practices, have been in force since February 2025, and a new prohibition on AI-generated non-consensual intimate imagery joins them this December.
Colorado tells a similar story domestically. Its original AI Act would have imposed risk management programs and impact assessments on any company using AI in employment, housing, credit, or health decisions. After a federal court paused enforcement and the legislature ran out of time to negotiate a fix, Colorado repealed it and passed a narrower disclosure law in its place, now set to take effect January 1, 2027 instead of the original date. The GDPR and the CCPA still apply to AI systems that process personal data underneath all of this, and neither has gone anywhere.
The compliance bar keeps relocating rather than dropping, and a policy anchored to a single deadline or a single law's original text is exactly the kind of thing that goes stale first.
Regulators are reacting to real harms, not hypothetical ones. AI's ability to profile people at scale creates at least four distinct categories of risk: exposure of information someone never directly disclosed, inference of sensitive traits like health status or political views from unrelated data, discrimination against groups identified through pattern-matching rather than individual judgment, and manipulation of behavior without a person's knowledge or consent.
Two well-known cases illustrate how this plays out. Cambridge Analytica built psychological profiles from a personality quiz and used them to target political advertising, all from data most of the 87 million people involved never knowingly handed over for that purpose. Strava's public activity heatmap, built to celebrate its users' athletic routes, ended up revealing the locations of military bases because the platform's default sharing settings didn't distinguish a morning jog from a patrol route.
Neither company set out to cause harm. Both had a privacy policy. Neither policy anticipated what their own systems would eventually be capable of inferring or exposing.
Privacy by design, building data protection into a system from the start rather than bolting it on afterward, is the starting point regulators now expect. In practice, that means minimizing what data an AI system collects in the first place, restricting who and what can access it, and giving users real transparency and control over how their information is used.
A newer set of tools go further, letting AI systems work with data while limiting what any single output can reveal about a given person:
These techniques matter because they change what an audit can verify. A privacy policy is a claim. A system built with data minimization, access controls, and privacy-preserving computation produces evidence: what data was touched, what was withheld, and what a specific output could and couldn't have revealed. Transcend's AI governance capabilities are built around that same distinction, enforcing data-use restrictions inside the systems that train and run AI models rather than leaving them as a policy sitting next to the pipeline.
The operational side of governance is where most organizations still lean on documentation instead of enforcement. An AI governance framework that can withstand a regulator's questions needs a few things a policy document alone can't provide:
Get the RACI Framework for AI Governance to assign accountability across your AI systems before a regulator asks who owns it.
Get the RACI frameworkEvery item on that list produces something checkable. That's the difference between a responsible AI framework that reads well in a board deck and one that would hold up if a regulator, or an internal audit, went looking for proof.
See how Privacy, Legal, and Risk teams operationalize AI governance at Transcend for Privacy, Legal & Risk
See the solutionThe pattern across the EU AI Act and Colorado's rewrite is consistent: regulators kept the substance and moved the dates, twice in Colorado's case within a single year. Any organization that spent 2026 building compliance around a specific deadline has already had to rebuild it once.
The organizations that won't have to rebuild it again are the ones that treated AI compliance as an engineering problem from the start: data minimization, access controls, privacy-preserving computation, and assigned accountability, all producing evidence a regulator can actually check. That infrastructure holds up no matter which law's calendar changes next.
Talk to us about enforcing AI governance across your systems
Reach out