Retour au blog
Compliance & Regulation

AI Governance and Privacy: Overlapping Requirements in the EU and US

Rachel Torres, Privacy CounselAugust 14, 202616 min de lecture
AI GovernanceEUUSLegal
AI Governance and Privacy: Overlapping Requirements in the EU and US
# AI Governance and Privacy: Overlapping Requirements in the EU and US **Date:** August 14, 2026 **Author:** Rachel Torres, Privacy Counsel **Category:** Compliance & Regulation **Reading Time:** 16 min --- August 2026 marks a pivotal moment in digital regulation. The EU AI Act is fully applicable, and in the US, the Colorado AI Act and extensive new California regulations are reshaping how companies build and deploy algorithms. If you are a global business, you are likely staring at two different compliance checklists. One for Brussels, one for Washington. The good news? There is significant overlap. The bad news? The details matter. ## The Convergence: Risk-Based Approaches Both the EU and US frameworks have adopted a "Risk-Based" approach. They don't regulate *all* AI; they regulate AI that matters. * **High Risk (EU) / Consequential Decisions (US):** Both regions focus on AI that affects: * Employment (Hiring/Firing). * Housing / Lending. * Healthcare. * Legal / Criminal Justice. ## The Divergence: Fundamental Rights vs. Consumer Protection ### EU: The "Fundamental Rights" Model The EU AI Act requires a **Fundamental Rights Impact Assessment (FRIA)** for deployers of high-risk systems. You must ask: "Does this AI violate the right to non-discrimination? The right to a fair trial?" ### US: The "Consumer Harm" Model US laws (like Colorado's SB 205) require a **Data Protection Assessment (DPA)** focused on "reasonably foreseeable risks of algorithmic discrimination." The language is narrower, focusing on specific protected classes (race, gender, age) rather than broad human rights. ## Friction Points: Automated Decision Making (ADM) ### The "Opt-Out" Right * **GDPR/AI Act:** Users have a right *not* to be subject to ADM (with exceptions). It's a "No" by default unless you have a legal basis. * **US State Laws:** Users have a right to *Opt-Out* of profiling. You can do it until they say stop. **Compliance Strategy:** Build an "Opt-Out" switch into your user profile settings that works globally. If a user clicks it, downgrade them to a rules-based system or human review workflow. It is easier to maintain one standard than to geo-gate this feature. ## Friction Points: Explainability * **EU:** You must provide "meaningful information about the logic involved." * **US:** You must provide a "plain language explanation" of how the decision was made. **The Challenge:** Deep Learning models (Neural Networks) are "black boxes." Even the engineers often don't know exactly *why* the model made a specific prediction. **The Solution:** You must invest in **Explainable AI (XAI)** tools (like SHAP values) that can approximate the reason (e.g., "The loan was denied because 'Debt-to-Income Ratio' contributed -40% to the score"). ## A Unified Governance Framework for 2026 We recommend against building separate compliance teams. Build a unified **"Algorithmic Governance Council"** that includes: 1. **Legal:** interpreting the laws. 2. **Data Science:** validating the models. 3. **Ethics/Diversity:** reviewing for bias. **The Golden Rule:** If you can't explain it, don't deploy it. Whether it's a regulator in Berlin or a judge in San Francisco, "the algorithm did it" is no longer a valid defense.
R

Rachel Torres, Privacy Counsel

Rédacteur chez GetCookies, spécialisé dans la conformité en matière de confidentialité, la gestion du consentement et l'optimisation du marketing numérique.

Prêt à simplifier le consentement cookies ?

GetCookies rend la conformité RGPD, CCPA et mondiale sans effort. Commencez aujourd'hui.