Navigating the New Regulatory Frontier of Artificial Intelligence, Emerging Technologies, and Privacy
John H. Fisher | Compliance Lawyer | July 2026
Introduction – Artificial Intelligence, Emerging Technologies, and Privacy

Every major artificial intelligence deployment in the modern enterprise processes personal data. A hiring algorithm ingests resumes, work histories, and demographic proxies. A customer service chatbot captures names, account details, behavioral cues, and conversational content. A fraud detection model analyzes transaction records, device fingerprints, and location histories. A recommendation engine builds longitudinal behavioral profiles aggregating thousands of micro-data points per user. In each instance, the AI system and the privacy compliance obligation are not merely adjacent concerns — they are inseparable. AI and privacy law are not parallel regulatory tracks. They are deeply intersecting, and increasingly, codified as a unified regulatory field.
For legal counsel, compliance officers, and senior executives at small to mid-size companies with international operations, 2024 through 2026 has constituted a dual regulatory moment of historic significance. The European Union’s Artificial Intelligence Act, Regulation (EU) 2024/1689 — the world’s first comprehensive, horizontal AI law — entered into force on August 1, 2024. Its prohibition on certain AI practices has been enforceable since February 2, 2025, with high-risk AI obligations for most Annex III systems phasing in through August 2027 following the Digital Omnibus amendment’s twelve-month extension of the original 2026 deadline. Simultaneously, the General Data Protection Regulation has governed algorithmic processing of personal data since 2018: Articles 22, 35, and 5 of the GDPR already impose substantive obligations on automated decision-making, profiling, data impact assessments, and data minimization as applied to AI systems. These two legal frameworks do not conflict — they compound.
For the typical SMB operating in this environment, the compliance challenge is three-dimensional. First, if the company processes EU personal data, GDPR governs all AI-based processing of that data. Second, if the company deploys AI systems used in the EU — whether as a developer, deployer, importer, or distributor — the EU AI Act applies regardless of the company’s physical location. Third, a rapidly expanding body of U.S. state and federal frameworks — including the Colorado AI Act (SB 205, effective February 2026), the New York City Local Law 144 on automated employment decision tools, EEOC algorithmic guidance, and FTC enforcement authority — creates domestic obligations that run in parallel. Compounding all of this: SMBs that procure AI tools from third-party vendors inherit embedded compliance obligations through those vendor relationships.
This chapter proceeds as follows. Section 7.1 maps the architecture and risk tiers of the EU AI Act, the obligations each tier imposes, and the penalty exposure that attaches. Section 7.2 examines the existing GDPR framework for algorithmic processing — the law that applies today. Section 7.3 addresses biometric data, the single highest-risk AI data category at the intersection of GDPR Article 9, the AI Act’s Article 5 prohibitions, and U.S. state biometric privacy statutes. Section 7.4 turns to generative AI in the enterprise — the deployment context most immediately relevant to most SMBs in 2025 and 2026. Section 7.5 surveys the emerging U.S. AI governance patchwork. Section 7.6 provides a seven-step practical AI compliance program. Section 7.7 addresses emerging technologies beyond AI — IoT, location data, and neural data — that carry their own escalating regulatory obligations. The chapter concludes with a Practitioner’s Checklist of twelve action items.
Read more in Creating a Data Protection Program – A Guide for Small to Mid-Size Businesses