Data Governance for AI
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.The AI Act's section on 'Data and data governance' requires specific provisions for managing training data, validation data, and test data in AI systems. This concept is distinct from general data protection and deserves its own topic to capture AI-specific data governance requirements including data quality, documentation, and management practices.
Overview
16 sources · Jul 23, 2026Legal Framework
Article 10 of the AI Act establishes the data governance obligations applicable to providers of high-risk AI systems. These requirements are distinct from — though overlapping with — the data protection regime under the GDPR. Article 10 targets the integrity and quality of training, validation, and testing datasets used to develop AI models, not the lawfulness of processing personal data per se.
Under Article 10(1), datasets used for training, validation, and testing must be subject to appropriate data governance and management practices. Article 10(2) specifies that these practices must encompass design choices, data collection processes, data preparation operations — including formulation of assumptions, assessment of data relevance, representativeness, and freedom from errors — as well as the formulation of assumptions and methodology for identifying and mitigating biases. Article 10(3) requires that training, validation, and testing datasets be relevant, sufficiently representative, and, to the best extent possible, free of errors, taking into account the intended purpose of the system. Article 10(4) permits the processing of special categories of personal data under GDPR Article 9 strictly for the purpose of detecting and correcting bias, subject to stringent safeguards including functional separation, restricted access, and deletion once bias correction is complete. Article 10(5) exempts providers of systems that are high-risk solely under Article 6(1)(b) from the dataset quality requirements in paragraphs 2 and 3. Article 10(6) requires providers to document data governance practices in the technical documentation required under Article 11 and Annex IV.
Recital 27 situates these obligations within the broader framework of trustworthy AI principles, including privacy and data governance as identified by the AI HLEG ethics guidelines.
Key Developments
The AI Act entered into force on 1 August 2024, with Article 10 applicable from 2 August 2026 for most high-risk systems. No enforcement decisions have yet been issued under the AI Act's data governance provisions, as the compliance deadline has not passed. However, the GDPR enforcement landscape provides instructive parallels. The Court of Justice's ruling in Schufa (C-634/21) established that automated decision-making producing legal effects triggers Article 22 GDPR scrutiny, which intersects with AI Act obligations when high-risk systems process personal data. The Italian Garante's 2023 restriction on OpenAI's processing of personal data for model training underscored that lawful basis, transparency, and data minimisation remain prerequisites even where AI Act data governance requirements apply separately.
Practical Guidance
- Implement a documented data governance framework covering the full dataset lifecycle — collection, preparation, validation, and testing — with explicit methodology for bias identification and mitigation, as required by Article 10(2).
- Conduct and record representativeness assessments for each dataset, demonstrating that the data adequately reflects the intended deployment context and population, per Article 10(3).
- Where special category data under GDPR Article 9 must be processed for bias detection, establish strict access controls, functional separation from other processing, and deletion protocols triggered upon completion of bias correction, as mandated by Article 10(4).
- Maintain technical documentation in accordance with Annex IV that traces data provenance, collection criteria, preparation steps, and quality assurance measures — this documentation will be the primary evidence of compliance during conformity assessment.
- For systems classified as high-risk solely under Article 6(1)(b), confirm whether the Article 10(5) exemption applies, but still document data sources and preparation methods to meet broader transparency obligations under Article 13.