No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Compliance

EU AI Act Elevates Responsible Standards, Outpacing GDPR

Rigid guidelines to impact deployment and innovation of AI on a global scale

by Karen Schuler
August 14, 2024
in Compliance, Opinion
eu flag behind security cameras

Due to its touchpoints on fundamental rights, safety and consumer protection — and its global reach — the EU AI Act has the potential for a broader impact on AI governance than the GDPR, argues BDO’s Karen Schuler.

The EU AI Act, which went into effect earlier this month, will likely spur more legislation. GDPR, for example, has become the global standard for privacy, affecting organizations beyond Europe as they look for guidance around data practices. The California Consumer Privacy Act (CCPA) is recognized as one of the most impactful data privacy laws in the U.S., with aspects similar to GDPR, such as consumers’ rights to be aware of the personal data being collected about them, to access that data and to request its deletion. Data protection laws in Brazil, Japan and Canada (among others) have been created and even amended to mirror GDPR’s guidance.

In a similar fashion, the EU AI Act will likely serve as the starting point for future legislation beyond Europe. As AI continues to gain momentum and more cross-industry applications, leaders around the world will be prompted to implement guardrails around its usage and development. The U.S. has agreed to cooperate with the EU on AI initiatives, and the federal government has already published a blueprint for an AI Bill of Rights, a sector-agnostic framework outlining five principles and associated practices to guide the design, use and deployment of AI systems. This marks the first step toward a clear and consistent federal framework regulating AI, which has the potential to drive a common understanding and alignment across the country, encouraging confidence in the future of AI usage and development.

Rigorous standards promise major impact

While the GDPR protects individuals’ data, the EU AI Act regulates AI systems. The GDPR applies to personal data processing — regardless of whether it involves AI — and the EU AI Act applies to AI systems that pose a risk to fundamental rights, safety or consumer protection. Instead of creating new rights for individuals, the EU AI Act focuses on the responsibilities of AI providers and users.  

The GDPR establishes broad principles like lawfulness, fairness and security. By contrast, the EU AI Act is much more granular, establishing specific technical requirements in domains such as data quality, human oversight, accuracy, transparency and accountability. The EU AI Act also introduces a risk-based approach with different requirements and prohibitions based on the potential harm of the AI system. Organizations must conduct conformity assessments for high-risk systems. This classification guide sets a global standard for the development and use of AI — laying the groundwork for a similar if not larger potential impact than the GDPR.

long road to futuristic city in abstract style
Compliance

The Long and Winding Road to Custom-AI Compliance

by Peter K. Jackson
July 31, 2024

Peter K. Jackson, a counsel in Greenberg Glusker’s intellectual property group, tells a hypothetical story about creating (or buying?) a responsible, useful and risk-aware AI tool.

Read moreDetails

The EU AI Act will propel compliance and innovation

Regulators intend the EU AI Act to inspire innovation. By promoting the safe development and application of AI technology, they seek to encourage confidence, optimism and investment in AI research. The EU AI Act is also slated to spur development in environmental protections, diversity and advancing public engagement with AI. However, the new regulations may constrain innovation in areas where certain types of AI applications are already restricted, such as biometric identification, social scoring and subliminal manipulation.

For example, in November 2023, Spain published guidelines on processing biometric data, which officials there view as a high-risk activity. The rules require companies to conduct privacy impact assessments (PIAs), implement data protection by design and conduct thorough assessments as to whether the risk of using the biometric system is warranted. As a result, certain companies in Spain have taken steps to eliminate the use of biometric systems and revert to the use of radio frequency identification (RFID) systems instead.

Certain sectors, like education and healthcare, may find themselves at a disadvantage due to the sensitive nature of the data they process. Across the board, the organizations will likely face increased compliance costs and administrative overhead, driven by the enhanced accountability required by the EU AI Act.

Navigating a transforming AI landscape

The EU AI Act’s comprehensive requirements mean companies must invest time and resources to achieve and maintain compliance. There are several steps a company can take to begin their compliance journey:

  • Test AI systems to ensure they are only trained on data that is relevant, representative, free of biases and errors and complete.
  • Establish transparent and verifiable data processing methods with meaningful explanations and justifications for the AI system’s decisions or outcomes.
  • Promptly report errors, biases or inaccuracies to regulators and data subjects.
  • Implement security measures like access and confidentiality controls to limit unauthorized access, use and disclosure.
  • Mandate employee education and training on responsible AI use and how to protect consumer privacy.

In addition to these steps, companies need to account for the EU AI Act’s lesser-known requirements. For example, companies must collect and analyze data on the system’s performance, safety and post-market impact. They must also report serious incidents or malfunctions to authorities in the country where the issue occurred. Without effective post-market monitoring, companies may overlook issues in their AI systems, potentially leading to ongoing noncompliance with the EU AI Act which could result in hefty fines and legal penalties.

Companies can easily slip into noncompliance. In fact, 74% of European data protection professionals said in a survey that authorities would find relevant violations of GDPR within the average company. The continuous oversight and quality control mandated by the EU AI Act — which includes regular check-ups on AI systems and practices to ensure ongoing compliance — will require significant costs and resources that may not be proportionate to the risks posed by the company’s use of AI.


Tags: Artificial Intelligence (AI)GDPR
Previous Post

Understanding Canada’s Forced Labor Law

Next Post

Landmark EU AI Act Takes Effect; Here’s What You Need to Know

Karen Schuler

Karen Schuler

Karen Schuler is a BDO principal who leads the U.S. and global privacy & data protection business line. Over the past 30 years, she built and managed organizations that offer investigations and data protection services and products. Karen has testified in deposition, arbitration and federal, state and local courts throughout the U.S. and assists her clients with negotiating privacy and data protection fines. She currently serves as the data protection officer for Global 100 and high-profile global organizations across several industries.

Related Posts

surrealist businessmen on platforms doing tug of war

Regulation vs. Innovation: The Tug-of-War Defining Finance’s Future

by Alex Tsepaev
June 6, 2025

AI compliance creates a global patchwork where EU fines reach €35 million while the US encourages growth — leaving financial...

Ethiciti AI Transforming Online Compliance Training

How AI is Transforming Online Compliance Training

by Corporate Compliance Insights
June 3, 2025

Is your compliance training keeping up with AI innovation? Whitepaper How AI is Transforming Online Compliance Training What's in this...

GAN Integrity TPRM & AI

Where TPRM Meets AI: Balancing Risk & Reward

by Corporate Compliance Insights
May 13, 2025

Is your organization prepared for the dual challenges of AI in third-party risk management? Whitepaper Where TPRM Meets AI: Balancing...

tracking prices

Pricing Algorithms Raise New Antitrust Concerns

by FTI Consulting
May 13, 2025

Interdisciplinary frameworks can help manage legal, privacy and consumer protection risks

Next Post
eu flag on wooden bench

Landmark EU AI Act Takes Effect; Here’s What You Need to Know

No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2025 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
No Result
View All Result
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe

© 2025 Corporate Compliance Insights