How organisations stay in control of the systems they ship.
Plain-language notes on the European rules and timelines.
Where GDPR and AI actually overlap: legal basis, DPIAs, transfers.
Live and upcoming AI and data deadlines in one place.
How UK regulators approach AI without a single statute.
State AI laws in the US, and China's filing and labelling rules.
Finding the real inefficiency before picking a tool.
AI governance
A procurement list you can actually use. Data handling, training-on-your-data, sub-processors, audit rights, and model-change notifications: the clauses that decide whether a vendor is safe to put on a live path.
Start with a list. Most governance programmes stall because nobody has an honest register of what is already in use, including the vendor copilots people forget to mention. The sheet below is the one we use in an audit. Copy it.
Oversight that cannot be performed on a Tuesday afternoon is not oversight. The reusable pattern is: the system flags, a named person confirms, the refusal path is normal, and the decision is recorded. That pattern now sits under EU, UK and GDPR legal hooks, and it is how we built Vista.
EU AI Act
Annex III is a use-case list, not a model list. Most Lathestone clients who over-classify do it because the tool is 'AI'; most who under-classify miss internal HR and customer-decision systems. Article 6(3) exemptions exist. They are narrow, and profiling is not one of them.
As of 13 August 2026, Regulation (EU) 2026/1744 has moved Annex III high-risk duties to 2 December 2027 and Annex I product-safety high-risk duties to 2 August 2028. Article 5 prohibitions, GPAI Chapter V, and Article 50 transparency are not part of that deferral.
If you did not train and place the model on the market, you are probably a deployer, not a GPAI provider, and Chapter V is not your chapter. Providers have been on the clock since 2 August 2025: transparency, copyright policy, a training-content summary, and extra duties above 10^25 FLOPs.
EU data & privacy
The GDPR is stable. What keeps moving is how the EDPB applies it to models. The overlap that matters in practice is three points: a legal basis for training and inference, purpose limitation when you reuse customer data for a new AI feature, and when an AI system triggers a DPIA.
In the EU, Article 22 GDPR still restricts solely automated decisions with legal or similarly significant effects, with a right to human intervention. ‘Meaningful’ involvement is a person who can change the outcome. A click is not enough. The UK has replaced Article 22 with Articles 22A–22D; that regime is a separate page.
The common case is a UK or EU operator sending personal data to a US-hosted model or SaaS tool. Adequacy (including the EU-US Data Privacy Framework and the UK Extension) is the first gate; if it does not cover that vendor, you need 2021 SCCs and/or the UK IDTA or Addendum, plus a transfer risk assessment.
Regulation calendar
UK AI
Section 80 of the Data (Use and Access) Act 2025 replaced UK GDPR Article 22 with Articles 22A–22D from 5 February 2026. The old default was prohibition-plus-exceptions. The new default for most significant automated decisions is permission-plus-safeguards. Special-category decisions stay tighter.
As of 13 August 2026 the ICO is under a statutory duty to prepare a code of practice on AI and automated decision-making (SI 2026/425, in force 12 May 2026). The code itself has not been published. Separate ADM guidance was consulted on until 29 May 2026; the ICO currently lists the final version as due in winter 2026.
As of 13 August 2026 there is no UK AI Act and no government AI bill before Parliament. Enforcement sits with existing regulators: ICO, CMA, FCA, MHRA, Ofcom, under existing law. A statutory ICO code on AI and ADM is required; the code itself is not yet in force.
US & China
Public generative AI services in China need a CAC security assessment and algorithm filing before launch. Labelling of AI-generated content has been mandatory under the March 2025 Identification Measures and GB 45438-2025 since 1 September 2025. Selling into China is not the same as training or deploying a model there.
There is no federal AI Act. As of 13 August 2026 the live picture is a state patchwork, led by Colorado’s rewrite (SB 26-189, mostly effective 1 January 2027) and California’s AI Transparency Act (SB 942 / BPC Chapter 25, operative 2 August 2026). Treat every other state’s column as volatile.
Workflow
A rule, a model, and a person are three different tools. Use a rule when the path is stable and the answer is known. Use a model when the input varies and a person will still confirm. Leave it with a person when the volume is low, the judgement is high, or the failure is expensive.
Twelve questions that surface the real inefficiency before anyone picks a tool, a model, or a rewrite. This is the framework we walk in an audit, published in full. If you cannot answer question 11, you are not ready to choose.
The guides above are for everyone. Our standards are how Lathestone behaves on client work and on our own products.
See our standards