Europe’s AI Act and GDPR Set Rules US Voluntary Frameworks Cannot Match

Europe's AI Data Privacy Rulebook vs. America's Emerging Risk-Based Path
Key Takeaways

  • The EU AI Act’s Article 10 imposes legally binding data governance requirements on high-risk AI systems, including bias examination and documented data provenance, with full compliance due by December 2027.
  • The US has no federal AI statute equivalent to GDPR or the EU AI Act; instead, the NIST AI Risk Management Framework offers voluntary guidance, leaving enforcement to the FTC and a patchwork of state privacy laws.

Multinationals building AI across both the EU and US markets now face a compliance decision with no clean middle ground. Europe’s AI Act Article 10 mandates documented bias examination, data provenance records and quality assessments before training begins, with full enforcement from December 2027. The US offers voluntary frameworks and fragmented state law. The gap between those two positions is substantial, and it is widening.

Europe’s Rights-First Data Model

GDPR which has applied to machine learning systems processing EU residents’ personal data since May 2018sets the floor: lawful basis for processing, data minimisation, purpose limitation and the right to erasure. France’s CNIL previously fined Clearview AI for web crawling practices that breached Article 6 lawful basis obligations when building its facial recognition model.

Data minimisation means identifying the minimum useful data to achieve model objectives rather than collecting at scale. A ride-hailing company that removed age and full location trails from its pricing model, retaining only aggregated travel zones, reportedly found its model accuracy unchanged while its compliance exposure fell. That kind of documented audit is now what regulators expect.

The EU AI Act enacted in 2024, builds on GDPR with AI-specific obligations for systems operating in high-risk domains: biometric identification, critical infrastructure, employment and law enforcement. Article 10 covers data collection and origin, preparation processes including annotation and cleaning, bias examination and the identification of data gaps. Providers must ensure datasets are relevant, sufficiently representative and, to the extent possible, free of errors. Documentation of how datasets are sourced, quality-assessed and evaluated for bias is mandatory.

Providers of General Purpose AI models face an additional disclosure requirement: a sufficiently detailed summary of training content, including copyrighted material, submitted using a template from the AI Office. High-risk providers have until December 2027 to comply with the full suite of requirements.

The right to erasure remains the hardest technical problem. Once personal data is embedded in a model’s weights, isolating and removing its influence without retraining from scratch is genuinely difficult. The European Data Protection Board has acknowledged this, noting limited understanding of how individual data points affect model behaviour and the stochastic nature of training itself.

The US: Voluntary Guidance, Reactive Enforcement

The US has no federal data privacy law comparable to GDPR and no comprehensive federal AI statute. What exists is the NIST AI Risk Management Framework, released in January 2023, which provides voluntary guidance organised around four functions: Govern, Map, Measure and Manage. It is widely cited in procurement and compliance documentation, but carries no legal force.

For AI training data specifically, the NIST AI RMF encourages privacy-enhanced design, data handling controls and bias management as components of broader risk mitigation. Enterprises adopting it typically begin by inventorying AI systems, models, datasets and APIs before establishing governance structures through the Govern function. How rigorously that happens in practice varies considerably. A direct comparison of the EU AI Act and the NIST RMF makes the gap between prescriptive legal obligation and voluntary best-practice guidance concrete.

State-level privacy laws add specific data handling requirements, consent rules and transparency obligations, some of which name AI and automated decision-making directly. Unlike European law, most US state statutes permit use of publicly available data for model training with minimal restriction. That flexibility has not shielded companies from litigation: OpenAI Microsoft and Google have all faced legal challenges over data scraping practices for AI training.

The Federal Trade Commission is the closest thing the US has to a unified AI data enforcement authority. It has used existing consumer protection and anti-discrimination powers to require companies that unlawfully obtained consumer data to delete AI models built on it. Data misuse in AI training is an FTC enforcement priority, even without a dedicated federal statute.

Where the Systems Diverge

Europe’s framework is rooted in individual fundamental rights and sets prescriptive, legally binding obligations. The US model, as reflected in the NIST AI RMF, prioritises flexibility and private-sector accountability, with enforcement arriving after the fact through consumer protection law rather than front-loaded regulatory requirements.

On training data specifically, GDPR demands explicit lawful bases, data minimisation and data subject rights. The EU AI Act adds documented bias assessment, quality controls and provenance records as legal requirements for high-risk systems. The cumulative compliance burden requires deep scrutiny of data origins, consent mechanisms and ongoing documentation at every stage of the model lifecycle.

The US permits more latitude, particularly around publicly available data, and relies on internal risk management rather than regulatory prescription. That flexibility carries its own risk: FTC enforcement actions and class-action litigation have shown that the absence of a prescriptive framework does not mean the absence of liability.

What Multinationals Should Do Now

A training data strategy designed for US requirements alone will not satisfy Article 10. Legal and compliance practitioners advising multinationals have consistently recommended aligning to the stricter standard globally, treating EU requirements as the baseline rather than a regional carve-out.

Article 10 calls for documented data collection processes, quality assessments, bias evaluations and purpose limitation applied before training begins. The Act also requires providers to build mechanisms for individuals to exercise data rights, including deletion where feasible. The European Data Protection Board has noted that differential privacy, federated learning and machine unlearning are relevant to the erasure problem, though none constitutes a complete solution.

Both the FTC and European data protection authorities have demonstrated willingness to act on training data governance failures. Our AI Policy coverage follows how these rules land in practice.

Jordan Mills
Jordan Mills

Jordan covers AI policy, regulation, and ethics across global markets. With a focus on governance frameworks and compliance, Jordan tracks the regulatory forces shaping the AI industry.

📰 Journalists welcome — cite Auton AI News with attribution. Press & Media → | press@autonainews.com