AI and Data Protection: GDPR, UK GDPR and US State Law Are Not One Rulebook

Three regimes, one AI tool, and guidance that contradicts itself across borders. What the ICO, the EDPB and the state regulators actually say — including the Colorado law that was repealed and rewritten in May 2026, which a good deal of published advice has not caught up with.

Short answer

Do not write one AI privacy policy for three regimes. In the EU the model itself may carry personal data and anonymity has to be demonstrated. In the UK the wording looks the same but the ICO says EU guidance is not binding, and a DPIA is the default for AI rather than the exception. In the US the rules are state law and they are moving fast — Colorado repealed and rewrote its AI statute in May 2026. The practices overlap almost entirely; the legal claims do not.

This summarizes published guidance and legislation as at 10 August 2026. It is not legal advice, and privacy law is moving faster than a good deal of the content written about it.

Three rulebooks, not one

The convenient assumption is that data protection is one discipline with regional accents. It was nearly true when the UK left the EU with an identical statute and the US had no AI-specific law at all. It is not true now, and the divergence has arrived in the exact place AI touches: automated decisions, training data, and what you must be able to explain.

What follows is organized by regime, because organizing it by theme is what produces the policy that is confidently wrong in two jurisdictions at once.

EU: the model itself may be personal data

The document that reset this discussion is the European Data Protection Board’s opinion on AI models, adopted on 18 December 2024. Three findings matter commercially.

  • Anonymity is not a status you declare. Whether a model is anonymous is assessed case by case, and for it to qualify it should be very unlikely both to directly or indirectly identify the individuals whose data created it, and to extract that personal data from the model through queries. A fine-tuned model trained on your CRM is not automatically outside the GDPR.
  • Legitimate interest can work, but it is tested. The three-step test applies. The EDPB gives conversational agents and cybersecurity as examples that can rely on it — “but only if the processing is shown to be strictly necessary and the balancing of rights is respected”.
  • Unlawful training data contaminates deployment. Where a model was developed with unlawfully processed personal data, that “could have an impact on the lawfulness of its deployment, unless the model has been duly anonymised”. This is the sentence that makes vendor provenance a live commercial question rather than a procurement formality.

Sitting alongside this, the EU AI Act adds obligations of a different kind — transparency, and for some systems a high-risk regime. The two do not substitute for each other, and the AI Act timeline changed in July 2026: what actually applies now, for companies outside the EU.

UK: same words, different regime

The UK GDPR reads almost identically to its EU counterpart, which is exactly why it is misread. The ICO states the position without ambiguity: EDPB guidelines “are no longer directly relevant to the UK regime and are not binding under the UK regime”, while remaining potentially helpful.

On the operational question that comes up first — do we need a data protection impact assessment — the ICO’s AI guidance is direct: “In the vast majority of cases, the use of AI will involve a type of processing likely to result in a high risk to individuals’ rights and freedoms, and will therefore trigger the legal requirement for you to undertake a DPIA. You will need to make this assessment on a case by case basis.”

Read the top of that ICO page before you rely on the rest of it: “Due to changes made by the Data (Use and Access) Act, this guidance is under review and may be subject to change.” A regulator telling you its own guidance is mid-revision is a reason to date-stamp your compliance notes, not a reason to wait.

One practical consequence for buyers: where you procure an AI system rather than build it, the ICO expects the evaluation to happen at procurement rather than afterwards, and expects you to specify your requirements at that stage. That is a contract question as much as a privacy one — the same territory as what belongs in an agency agreement before work starts.

US: state by state, and moving

There is no federal AI privacy statute. What exists is a growing set of state regimes, each with its own vocabulary, and the published commentary ages badly. Verified against the primary sources on 10 August 2026.

US state AI and automated-decision rules in force
StateInstrumentStatus and datesWhat it turns on
CaliforniaCPPA regulations on ADMT, risk assessments and cybersecurity auditsAdopted 24 July 2025, effective 1 January 2026, rulemaking complete“Significant decisions” — including employment or independent contracting opportunities or compensation, lending, housing, insurance, education, healthcare and essential goods
ColoradoSB26-189, which repeals and reenacts SB24-205Signed May 2026; the Attorney General states the law and its provisions go into effect 1 January 2027“Automated decision-making technology” used in “consequential decisions”
ColoradoHB26-1263, Chatbot Safety ActSigned 1 July 2026, effective 1 January 2027Conversational AI. Includes a duty on chatbot operators to disclose that users are interacting with AI and not humans
TexasTRAIGAEffective 1 January 2026Intent. Prohibitions require intent, and “a disparate impact alone is not sufficient to demonstrate an intent to discriminate”

Colorado deserves a paragraph of its own, because it is where stale advice concentrates. The law everyone cites — SB24-205, with its much-repeated deadline — was repealed and reenacted by SB26-189, signed in May 2026. On timing, take it from the office that will enforce it: the Colorado Attorney General states that “this new law and its provisions go into effect January 1, 2027”. Nothing under it bites today.

What lands on that date is worth preparing for. The replacement defines automated decision-making technology broadly, covers consequential decisions about education, employment, housing, financial or lending services, insurance, health care and essential government services, and requires deployers to give clear and conspicuous notice at the point of interaction. After an adverse outcome, a consumer must receive a plain language description of the technology’s role within 30 days, and may request meaningful human review. Developers must supply deployers with technical documentation from 1 January 2027, and both sides must retain compliance records for at least three years. Enforcement is by the attorney general under the Colorado Consumer Protection Act, with a 60-day notice and cure period before 1 January 2030, and there is no new private right of action.

Arriving on the same date, and less discussed: Colorado’s Chatbot Safety Act, HB26-1263, signed on 1 July 2026. Among other things it requires chatbot operators to disclose that users are interacting with AI and not humans. That is a genuine bot-disclosure duty on private operators in a US state — which is exactly what Texas is wrongly assumed to have imposed.

Texas is the one LYVIA most often sees described inaccurately. Under TRAIGA, effective 1 January 2026, the obligation to disclose that a consumer is interacting with an AI system applies to a governmental agency, with a separate disclosure duty where AI is used in relation to health care services or treatment. Private businesses are not given a general bot-disclosure duty by that statute. What does bind everyone is the prohibitions — behavioral manipulation toward self-harm or crime, social scoring by government, certain biometric capture, and discrimination — and the discrimination prohibition is drafted around intent.

What actually overlaps

The good news is that the underlying work is largely common. Doing these five things well puts you in a defensible position under all three regimes, even though you will describe them differently in each.

One practice, three legal descriptions
What you doWhy it counts, per regime
Keep an inventory of AI systems and the data each touchesThe precondition for a DPIA in the UK, a risk assessment in California, and any Article 30 record in the EU. Without it, every other answer is a guess.
Document the assessment before you switch the system onICO expects it at procurement; California requires risk assessments before initiating the processing; Colorado will require compliance records retained for at least three years from 1 January 2027.
Keep a human able to overturn a consequential decisionFrom 1 January 2027 Colorado will grant a right to request meaningful human review after an adverse outcome; the EU regime treats solely automated decisions with legal effects as a distinct category.
Be able to explain a specific decision in plain languageColorado will require a plain language description within 30 days of an adverse outcome, from 1 January 2027. The others expect explainability without prescribing the format.
Know where your vendor’s training data came fromThe EDPB position on unlawfully processed training data makes this a question about your own lawfulness, not only theirs.

The vendor question nobody asks

Procurement conversations about AI tools cover uptime, price, and integrations. In LYVIA’s experience they rarely cover the two questions that determine your exposure: what happens to data you send, and what the model was trained on.

The first is usually answerable from documentation — whether inputs are retained, whether they are used for training, where they are processed, and how long they persist. The second is often not answerable at all, and a supplier who cannot say anything about provenance has handed you a risk you cannot assess. That is not automatically a reason to walk away. It is a reason to write down that you asked, what you were told, and what you decided — which is precisely what a regulator will look for later.

Retrieval-based setups change this calculus, because your documents stay yours and are consulted at answer time rather than absorbed into weights: how retrieval over company documents works. The hosting choices behind it are covered in our guide to AI infrastructure.

What to do this quarter

  • Write the inventory first. Every system, what personal data it sees, who its outputs affect, and in which jurisdictions those people are. Everything else depends on this and nothing else can be done without it.
  • Separate consequential from convenient. A tool that drafts an email and a tool that screens an application sit in different legal worlds. Mark which of yours touch employment, credit, housing, insurance, education or healthcare.
  • Run the DPIA for anything on that list. The ICO’s default is that AI triggers it; treat an exception as a documented decision rather than a silence.
  • Fix the notice at the point of interaction where a consequential decision is involved, and build the route to a human who can actually reverse it. Both regimes that moved most recently ask for exactly this, Colorado from 1 January 2027.
  • Re-check your sources every quarter, and date every note. One of the three regimes in this article was rewritten three months ago. Guidance you wrote in 2025 is not wrong because you were careless; it is wrong because the law moved.

The security side of the same conversation — access, leakage, and what employees paste into chat windows — is in AI and cybersecurity for small business. Where the consequential decision is a hiring decision, the duties are set out in AI in hiring: what the law actually requires, and the wider automation context in our guide to AI automation for small business.

Frequently asked questions

Do we need a DPIA before using an AI tool on customer data?

Under the UK GDPR, usually yes. The ICO puts it plainly: "In the vast majority of cases, the use of AI will involve a type of processing likely to result in a high risk to individuals' rights and freedoms, and will therefore trigger the legal requirement for you to undertake a DPIA." It also says the assessment must be made case by case, so the answer is a documented decision rather than an assumption in either direction.

Is an AI model itself personal data?

Sometimes, which is the uncomfortable part. The EDPB's December 2024 opinion says anonymity must be assessed case by case, and that for a model to be anonymous it should be very unlikely both to identify individuals whose data was used to create it and to extract that personal data from the model through queries. A model trained on your customer records is not automatically anonymous just because it no longer holds a database.

Does UK GDPR guidance follow EU guidance?

Not automatically, and the ICO says so directly: EDPB guidelines "are no longer directly relevant to the UK regime and are not binding under the UK regime", though they may still be helpful. Treating the two as one rulebook is the most common structural error LYVIA sees in the policies it reviews — an observation from its own engagements, not a survey.

What changed in Colorado?

Almost everything, and recently. Senate Bill 24-205 — the law most published guidance still refers to, including its much-quoted deadline — was repealed and reenacted by SB26-189, signed in May 2026. The Attorney General's office, which enforces it, states that "this new law and its provisions go into effect January 1, 2027". So the practical answer for right now is that Colorado has a new statute, nothing under it is yet enforceable, and you have until the start of 2027 to be ready for it.

Does the Texas AI law require us to tell customers they are talking to a bot?

Not if you are an ordinary private business. Under TRAIGA, effective 1 January 2026, the disclosure duty for AI systems intended to interact with consumers falls on governmental agencies, with a separate duty on providers of health care services or treatment. It is regularly described, inaccurately, as a general business obligation. What TRAIGA does apply to everyone is a set of intent-based prohibitions.

Can we write one AI privacy policy for all three regimes?

You can write one set of practices, but not one set of claims. Much of the underlying work — knowing what data goes into which system, documenting the assessment, keeping a human in the loop on consequential decisions, being able to explain a decision — satisfies all three. What does not transfer is the legal characterization: the basis you rely on, the notices you give, and the rights you must honour differ, and copying EU wording into a US notice creates promises you may not have intended to make.

If you are deploying AI across UK, EU and US customers and want to know which of your systems actually attract obligations, the inventory is the first hour well spent. Book a call.

LYVIA

LYVIA Team

AI automation and SEO/GEO visibility

LYVIA builds custom AI tools for companies of 10 to 100 people, and gets them found on Google and inside AI answers.

Free offer

Get your free AI audit
in 30 minutes

A LYVIA expert reviews your workflows, pinpoints the 3 highest-ROI AI opportunities, and hands you a concrete roadmap. No commitment, no jargon.

  • Full diagnostic of your business processes
  • Automatable quick wins, identified
  • A personalized roadmap you keep
Book my free audit

30 min · Free · No commitment