Did you know that the biggest challenge with AI may not be using it, but knowing where the responsibility lies when something goes wrong?
AI is changing how organisations collect, process and use information. It is also introducing new risks that privacy teams, business leaders and employees cannot afford to overlook. So, does privacy still matter when AI is moving so quickly?
We put that question to Katrina Destrée, a senior privacy and sustainability professional and responsible AI and privacy consultant with extensive international experience. Her take was clear on the matter!
“Privacy remains highly relevant. The challenge is learning how to stay compliant without slowing responsible innovation.”
In her recent Grow Skills Store webinar, “Privacy in the Era of AI,” Katrina explored how organisations can approach AI without losing sight of privacy, security and accountability. She talked about everything from privacy and AI principles to emerging risks, regulatory expectations, AI standards and the role of human judgement in responsible innovation.
But what do these ideas mean for organisations putting AI into practice? Most importantly, how can privacy and compliance support innovation rather than hold it back?
Does Privacy Still Matter in the Age of AI?
Yes, privacy still matters in the age of AI. If anything, the growing use of AI gives organisations more situations in which they need to think carefully about how personal data is collected, used, and processed. Katrina made a similar point during the webinar when she said:
“GDPR established important foundations around personal data and accountability, but the way organisations use data continues to evolve.”
We agree! Privacy still matters in the age of AI, and organisations need to take those existing responsibilities into account as AI changes the way they handle information. AI can introduce new ways of collecting, analysing, sharing and acting on personal data. However, it can also change who or what has access to that information and how decisions are made.
That means the introduction of AI can change the privacy considerations around an existing process. For example, organisations may need to reassess:
|
AI use may affect |
What you need to consider |
|
Privacy |
How personal data is collected, used and processed |
|
Employment |
Whether AI-supported decisions affect employees or employment obligations |
|
Consumer protection |
Whether AI changes how customers are treated or decisions are made about them |
|
Intellectual property |
How protected information, content or other intellectual property is used |
|
Competition |
Whether AI-supported practices create competition concerns |
The important thing to note here is that privacy cannot be treated as a one-time compliance exercise. When an organisation introduces AI into an existing process, it needs to assess
- What has changed
- Which responsibilities may be affected
- Whether its existing safeguards and practices are still appropriate
This is also why AI privacy compliance needs to happen alongside AI adoption, rather than after it. You should be assessing the impact of an AI use case before introducing it, not waiting until a problem reveals that something was overlooked.
You Should Use OECD Privacy and AI Principles to Make Better Decisions
Rules and compliance requirements may not always give you an easy answer when AI changes how your organisation collects, processes, or uses information. This is where the OECD privacy principles and OECD AI principles can help.
They give organisations a practical basis for thinking through AI use cases and deciding whether a proposed approach is responsible. They can also provide useful direction when organisations are considering AI privacy and responsible data use.
Katrina highlighted both sets of principles during the webinar. She explained that organisations can use them to evaluate AI use cases, understand whether a proposed approach aligns with responsible practices, and establish principles that fit their own organisation.
She also suggested keeping those internal principles simple. You do not need to create a long list that employees have to memorise. Instead, organisations could establish three to five clear principles that people can remember and use as a mental checklist when evaluating AI use cases.
We agree with this approach and believe that the value of principles is not simply in knowing what they say. It is in using them to guide decisions when your organisation is faced with a new or unfamiliar AI use case. For example, your team could use the following questions to put that principle-based approach into practice:
|
Question to ask |
What it helps you assess |
|
Why are we processing this data? |
Whether there is a clear purpose for the proposed use |
|
How will the data be processed? |
Whether the processing is appropriate and responsible |
|
What impact could the AI use have? |
Potential effects on people, the organisation and wider society |
|
Does the use align with our principles? |
Whether the proposed use fits your organisation’s approach to responsible AI |
|
Is anything in conflict with those principles? |
Whether the use case needs further review or reconsideration |
|
Who is responsible for the decision? |
Whether ownership and accountability are clearly established |
These questions help teams move from knowing the principles to applying them. They also give organisations a practical way to consider data protection in AI, particularly when a new use case changes how information is collected, processed or used.
That becomes particularly useful when your organisation encounters a situation that existing policies do not address directly. A new AI tool, a new way of processing information, or a new vendor relationship may not fit neatly into an existing checklist. Clear internal principles give your team a consistent basis for deciding which of these needs closer attention.
They also make accountability more practical. The organisation approving an AI use case should be able to explain why it approved that use, what risks and responsibilities it considered, and how the decision aligned with its principles. This creates a clearer connection between AI privacy compliance and the decisions people make every day. The takeaway is simple!
OECD privacy and AI principles should not simply sit in a policy document. Your organisation should use them as a practical guide when deciding whether and how to use AI.
Innovation Needs Guardrails, Not Fewer Rules
It is easy to assume that privacy and compliance naturally slow innovation. However, that was not the message of the webinar. Responsible governance does not have to prevent organisations from exploring what AI can do.
Katrina acknowledged the importance of innovation and discussed applications such as smart cities, public safety, usage prediction and pattern detection. These technologies can create valuable opportunities, support economic growth and improve people’s lives. At the same time, an AI system being described as “innovative” does not automatically make its use responsible.
A system developed for one purpose could potentially be used for another. That secondary use may create risks or consequences that were not considered when the system was originally designed. This is why organisations need to think about the potential impact of an AI use case before deployment and consider how it could be used across its wider value chain.
We believe this is where governance can play a different role. It does not have to put unnecessary limits on innovation. Instead, it can give teams enough guidance to understand where an AI use case is appropriate, where it needs further assessment, and where the proposed approach may need to be reconsidered.
Clear principles and practical guardrails can help create that balance. They give teams a basis for making decisions without requiring every new AI use case to be treated as a reason to stop or delay innovation.
The goal of this approach is not to choose between compliance and innovation. It is to help organisations make better decisions about how they innovate with AI.
Agentic AI Makes Those Guardrails Even More Important
Agentic AI can take actions, make decisions within defined parameters, and interact with systems without someone directing every individual step. That makes the need for clear guardrails even more important as organisations move from using AI to allowing AI systems to act on their behalf.
Katrina used a simple comparison during the webinar. Think about onboarding a new employee. You would not give a new employee unrestricted access to every system and every piece of information on their first day. You would first consider what they need to access, what they are responsible for, and what limits should apply.
The same thinking should apply to AI agents. An organisation needs to consider the following before allowing an agent to act on its behalf:
- What the agent can access
- What actions it can perform
- Which information it can use
- When access should begin
- When access should end
- What guardrails should apply
- Who remains accountable
This is where access management becomes part of responsible AI governance. An AI agent may be capable of performing tasks independently, but that does not mean the organisation can hand responsibility over to the technology.
We also believe organisations should approach agentic AI in the same way they should approach other AI innovation. You need to understand what the technology enables, identify the risks it introduces, and establish appropriate boundaries before giving it greater autonomy.
The more autonomy an AI system has, the clearer the organisation’s boundaries and accountability need to be.
AI Risk Does Not Stop With Your Organisation
AI systems often involve suppliers, vendors, developers, enterprises and users. Each of these parties potentially influences how an AI system is developed, deployed or used. That’s exactly why Katrina highlighted the importance of considering this entire AI value chain when assessing AI risks.
Doing so matters because strong internal controls do not necessarily address risks introduced by another organisation. Your organisation may rely on a vendor to provide an AI system, a supplier to process data, or another party to support its deployment. If you assess only your own systems, you may overlook risks that arise elsewhere. That’s why your organisation should always consider the following when assessing an AI use case:
- Where the data goes
- Who has access to it
- How the AI system is being used
- Which organisations are involved
- Who is responsible for different parts of the process
This wider view is important for AI privacy compliance and effective data protection in AI, particularly when personal information moves between organisations.
- Stakeholder Engagement Matters
Looking across the value chain also means involving the people who understand different parts of the AI use case. Your internal privacy teams may identify concerns about personal data, while security teams may highlight access or system risks. Business teams may focus on the intended outcome, and employees or other users may identify practical concerns that are not obvious during the planning stage.
Bringing these perspectives together before an AI system is deployed gives the organisation a better opportunity to identify concerns, understand priorities and address issues early.
Katrina connected this to the importance of building bridges with stakeholders. We believe this is particularly relevant to AI privacy because responsible AI cannot be managed effectively by one team working in isolation. The organisation needs people across the relevant functions, as well as external parties where appropriate, to understand their role in managing the risks associated with an AI use case.
- Use Risk Frameworks to Structure Decisions
Stakeholder input can help identify different concerns, but organisations also need a consistent way to assess and manage those risks. Katrina discussed the NIST AI Risk Management Framework as one approach that can help organisations build a stronger risk-management culture. The framework encourages organisations to:
- Understand the context of the AI use case
- Identify and analyse risks
- Track and prioritise those risks
- Determine what action is appropriate
- Continue monitoring risks as circumstances change
Such an approach helps move risk management beyond simply identifying a problem and recording it.
But note that not every risk can and would necessarily be eliminated. Some may remain as residual risks after appropriate controls have been considered. What matters is that the organisation understands those risks, makes an informed decision about how to manage them, and continues to review whether further action is needed.
Where Should Your Organisation Start With AI Privacy Compliance?
Start with where you are and what you are processing. This is the foundation of effective AI privacy compliance because your organisation first needs to understand:
- What data it processes
- Why it processes it
- Where that processing happens
- Which responsibilities apply
This was Katrina’s practical advice during the webinar, and we agree with this approach. Organisations do not need to have everything perfect before they begin. A useful starting point is:
- Identify your jurisdiction: Understand which laws apply based on where you operate and the markets you serve.
- Understand your processing: Identify what personal data you process and what you use it for.
- Understand where processing happens: Consider your systems, suppliers, vendors, and wider AI value chain.
- Identify applicable obligations: Look at privacy, AI and other relevant legal and business requirements.
- Use standards and principles to structure your approach: Select frameworks and standards that fit your organisation and its risks.
- Demonstrate accountability: Document what you are doing, why you are doing it and what steps you are taking to manage your responsibilities.
Katrina also talked about the importance of recognising what you process, understanding your obligations and beginning to take steps towards compliance. She used GDPR as an example of how understanding your current position and taking steps towards compliance can provide a meaningful starting point.
From our perspective, organisations do not need to have everything perfect before they begin. We believe taking those initial steps can help demonstrate intent, responsibility and accountability.
How ISO 27701 and AI Standards Can Support Governance
ISO 27701 and ISO/IEC 42001 can help organisations structure their approach to privacy and AI governance. They provide recognised frameworks that can help organisations establish clearer processes, responsibilities and management practices around privacy and AI.
Katrina also highlighted ISO 27701 and ISO/IEC 42001 during the webinar and mentioned:
|
Standard |
Role |
|
ISO 27701 |
Supports privacy information management |
|
ISO/IEC 42001 |
Provides a framework for AI management |
We believe these standards can provide useful structure, particularly when organisations are considering AI privacy, ISO 27701 and AI governance together. However, they should not become checklists that organisations follow without considering their specific circumstances. Their value is strongest when organisations use them alongside principles, risk frameworks and human judgement. Each provides a different way to support responsible decision-making.
The question, therefore, is not simply “Which standard do we need?” It is how the right standards can help your organisation make more consistent and responsible decisions about AI use.
AI Privacy Compliance Requires Continuous Learning
AI privacy compliance cannot remain static when AI technologies, regulations and risks continue to evolve. Organisations need to keep learning so their people can make informed decisions as those changes occur.
Katrina also emphasised the importance of AI literacy and ongoing learning throughout the webinar. This applies across the organisation. Employees need to understand responsible AI use, while leaders and specialist teams need to keep up with changing risks, regulations, standards and governance expectations.
At Grow Skills Store, we believe learning should lead to better decisions, not simply greater knowledge. That is why our training helps organisations build practical capabilities across areas such as AI governance, data protection, cybersecurity and compliance. Courses such as AI Governance Training, GDPR Training and AI Literacy Training can help teams develop the knowledge they need to use AI responsibly.
Ultimately, AI privacy compliance is not just about having policies in place. It is about giving people the knowledge to apply them and the confidence to make responsible decisions.