# Data Governance for AI — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/data-governance-ai
> Sources are cited per item. Verify against the official texts before relying on them.

The AI Act's section on 'Data and data governance' requires specific provisions for managing training data, validation data, and test data in AI systems. This concept is distinct from general data protection and deserves its own topic to capture AI-specific data governance requirements including data quality, documentation, and management practices.

## Overview

## Legal Framework

Article 10 of the AI Act establishes the data governance obligations applicable to providers of high-risk AI systems. These requirements are distinct from — though overlapping with — the data protection regime under the GDPR. Article 10 targets the integrity and quality of training, validation, and testing datasets used to develop AI models, not the lawfulness of processing personal data per se.

Under Article 10(1), datasets used for training, validation, and testing must be subject to appropriate data governance and management practices. Article 10(2) specifies that these practices must encompass design choices, data collection processes, data preparation operations — including formulation of assumptions, assessment of data relevance, representativeness, and freedom from errors — as well as the formulation of assumptions and methodology for identifying and mitigating biases. Article 10(3) requires that training, validation, and testing datasets be relevant, sufficiently representative, and, to the best extent possible, free of errors, taking into account the intended purpose of the system. Article 10(4) permits the processing of special categories of personal data under GDPR Article 9 strictly for the purpose of detecting and correcting bias, subject to stringent safeguards including functional separation, restricted access, and deletion once bias correction is complete. Article 10(5) exempts providers of systems that are high-risk solely under Article 6(1)(b) from the dataset quality requirements in paragraphs 2 and 3. Article 10(6) requires providers to document data governance practices in the technical documentation required under Article 11 and Annex IV.

Recital 27 situates these obligations within the broader framework of trustworthy AI principles, including privacy and data governance as identified by the AI HLEG ethics guidelines.

## Key Developments

The AI Act entered into force on 1 August 2024, with Article 10 applicable from 2 August 2026 for most high-risk systems. No enforcement decisions have yet been issued under the AI Act's data governance provisions, as the compliance deadline has not passed. However, the GDPR enforcement landscape provides instructive parallels. The Court of Justice's ruling in *Schufa* (C-634/21) established that automated decision-making producing legal effects triggers Article 22 GDPR scrutiny, which intersects with AI Act obligations when high-risk systems process personal data. The Italian Garante's 2023 restriction on OpenAI's processing of personal data for model training underscored that lawful basis, transparency, and data minimisation remain prerequisites even where AI Act data governance requirements apply separately.

## Practical Guidance

- Implement a documented data governance framework covering the full dataset lifecycle — collection, preparation, validation, and testing — with explicit methodology for bias identification and mitigation, as required by Article 10(2).
- Conduct and record representativeness assessments for each dataset, demonstrating that the data adequately reflects the intended deployment context and population, per Article 10(3).
- Where special category data under GDPR Article 9 must be processed for bias detection, establish strict access controls, functional separation from other processing, and deletion protocols triggered upon completion of bias correction, as mandated by Article 10(4).
- Maintain technical documentation in accordance with Annex IV that traces data provenance, collection criteria, preparation steps, and quality assurance measures — this documentation will be the primary evidence of compliance during conformity assessment.
- For systems classified as high-risk solely under Article 6(1)(b), confirm whether the Article 10(5) exemption applies, but still document data sources and preparation methods to meet broader transparency obligations under Article 13.

## Legislation (full text of key provisions)

### Data and data governance

*Source: AI Act, aiact-art-10-en, 2024-06-12 — https://overview.legal/posts/92127*

### Recital 107 — transparency training data summary

*Source: AI Act, aiact-rec-107-en, 2024-06-12 — https://overview.legal/posts/93896*

In order to increase transparency on the data that is used in the pre-training and training of general-purpose AI models, including text and data protected by copyright law, it is adequate that providers of such models draw up and make publicly available a sufficiently detailed summary of the content used for training the general-purpose AI model. While taking into due account the need to protect trade secrets and confidential business information, this summary should be generally comprehensive in its scope instead of technically detailed to facilitate parties with legitimate interests, including copyright holders, to exercise and enforce their rights under Union law, for example by listing the main data collections or sets that went into training the model, such as large private or public databases or data archives, and by providing a narrative explanation about other data sources used. It is appropriate for the AI Office to provide a template for the summary, which should be simple, effective, and allow the provider to provide the required summary in narrative form.

### Recital 67 — high-quality data governance for AI

*Source: AI Act, aiact-rec-67-en, 2024-06-12 — https://overview.legal/posts/93816*

High-quality data and access to high-quality data plays a vital role in providing structure and in ensuring the performance of many AI systems, especially when techniques involving the training of models are used, with a view to ensure that the high-risk AI system performs as intended and safely and it does not become a source of discrimination prohibited by Union law. High-quality data sets for training, validation and testing require the implementation of appropriate data governance and management practices. Data sets for training, validation and testing, including the labels, should be relevant, sufficiently representative, and to the best extent possible free of errors and complete in view of the intended purpose of the system. In order to facilitate compliance with Union data protection law, such as Regulation (EU) 2016/679, data governance and management practices should include, in the case of personal data, transparency about the original purpose of the data collection. The data sets should also have the appropriate statistical properties, including as regards the persons or groups of persons in relation to whom the high-risk AI system is intended to be used, with specific attention to the mitigation of possible biases in the data sets, that are likely to affect the health and safety of persons, have a negative impact on fundamental rights or lead to discrimination prohibited under Union law, especially where data outputs influence inputs for future operations (feedback loops). Biases can for example be inherent in underlying data sets, especially when historical data is being used, or generated when the systems are implemented in real world settings. Results provided by AI systems could be influenced by such inherent biases that are inclined to gradually increase and thereby perpetuate and amplify existing discrimination, in particular for persons belonging to certain vulnerable groups, including racial or ethnic groups. The requirement for the data sets to be to the best extent possible complete and free of errors should not affect the use of privacy-preserving techniques in the context of the development and testing of AI systems. In particular, data sets should take into account, to the extent required by their intended purpose, the features, characteristics or elements that are particular to the specific geographical, contextual, behavioural or functional setting which the AI system is intended to be used. The requirements related to data governance can be complied with by having recourse to third parties that offer certified compliance services including verification of data governance, data set integrity, and data training, validation and testing practices, as far as compliance with the data requirements of this Regulation are ensured.

### Recital 109 — proportionate compliance for general-purpose AI providers

*Source: AI Act, aiact-rec-109-en, 2024-06-12 — https://overview.legal/posts/93900*

Compliance with the obligations applicable to the providers of general-purpose AI models should be commensurate and proportionate to the type of model provider, excluding the need for compliance for persons who develop or use models for non-professional or scientific research purposes, who should nevertheless be encouraged to voluntarily comply with these requirements. Without prejudice to Union copyright law, compliance with those obligations should take due account of the size of the provider and allow simplified ways of compliance for SMEs, including start-ups, that should not represent an excessive cost and not discourage the use of such models. In the case of a modification or fine-tuning of a model, the obligations for providers of general-purpose AI models should be limited to that modification or fine-tuning, for example by complementing the already existing technical documentation with information on the modifications, including new training data sources, as a means to comply with the value chain obligations provided in this Regulation.

### Recital 27 — ethics guidelines for trustworthy AI

*Source: AI Act, aiact-rec-27-en, 2024-06-12 — https://overview.legal/posts/93736*

While the risk-based approach is the basis for a proportionate and effective set of binding rules, it is important to recall the 2019 Ethics guidelines for trustworthy AI developed by the independent AI HLEG appointed by the Commission. In those guidelines, the AI HLEG developed seven non-binding ethical principles for AI which are intended to help ensure that AI is trustworthy and ethically sound. The seven principles include human agency and oversight; technical robustness and safety; privacy and data governance; transparency; diversity, non-discrimination and fairness; societal and environmental well-being and accountability. Without prejudice to the legally binding requirements of this Regulation and any other applicable Union law, those guidelines contribute to the design of coherent, trustworthy and human-centric AI, in line with the Charter and with the values on which the Union is founded. According to the guidelines of the AI HLEG, human agency and oversight means that AI systems are developed and used as a tool that serves people, respects human dignity and personal autonomy, and that is functioning in a way that can be appropriately controlled and overseen by humans. Technical robustness and safety means that AI systems are developed and used in a way that allows robustness in the case of problems and resilience against attempts to alter the use or performance of the AI system so as to allow unlawful use by third parties, and minimise unintended harm. Privacy and data governance means that AI systems are developed and used in accordance with privacy and data protection rules, while processing data that meets high standards in terms of quality and integrity. Transparency means that AI systems are developed and used in a way that allows appropriate traceability and explainability, while making humans aware that they communicate or interact with an AI system, as well as duly informing deployers of the capabilities and limitations of that AI system and affected persons about their rights. Diversity, non-discrimination and fairness means that AI systems are developed and used in a way that includes diverse actors and promotes equal access, gender equality and cultural diversity, while avoiding discriminatory impacts and unfair biases that are prohibited by Union or national law. Social and environmental well-being means that AI systems are developed and used in a sustainable and environmentally friendly manner as well as in a way to benefit all human beings, while monitoring and assessing the long-term impacts on the individual, society and democracy. The application of those principles should be translated, when possible, in the design and use of AI models. They should in any case serve as a basis for the drafting of codes of conduct under this Regulation. All stakeholders, including industry, academia, civil society and standardisation organisations, are encouraged to take into account, as appropriate, the ethical principles for the development of voluntary best practices and standards.

### Recital 69 — privacy and data protection lifecycle

*Source: AI Act, aiact-rec-69-en, 2024-06-12 — https://overview.legal/posts/93820*

The right to privacy and to protection of personal data must be guaranteed throughout the entire lifecycle of the AI system. In this regard, the principles of data minimisation and data protection by design and by default, as set out in Union data protection law, are applicable when personal data are processed. Measures taken by providers to ensure compliance with those principles may include not only anonymisation and encryption, but also the use of technology that permits algorithms to be brought to the data and allows training of AI systems without the transmission between parties or copying of the raw or structured data themselves, without prejudice to the requirements on data governance provided for in this Regulation.

### Recital 122 — high-risk AI compliance presumption

*Source: AI Act, aiact-rec-122-en, 2024-06-12 — https://overview.legal/posts/93926*

It is appropriate that, without prejudice to the use of harmonised standards and common specifications, providers of a high-risk AI system that has been trained and tested on data reflecting the specific geographical, behavioural, contextual or functional setting within which the AI system is intended to be used, should be presumed to comply with the relevant measure provided for under the requirement on data governance set out in this Regulation. Without prejudice to the requirements related to robustness and accuracy set out in this Regulation, in accordance with Article 54(3) of Regulation (EU) 2019/881, high-risk AI systems that have been certified or for which a statement of conformity has been issued under a cybersecurity scheme pursuant to that Regulation and the references of which have been published in the Official Journal of the European Union should be presumed to comply with the cybersecurity requirement of this Regulation in so far as the cybersecurity certificate or statement of conformity or parts thereof cover the cybersecurity requirement of this Regulation. This remains without prejudice to the voluntary nature of that cybersecurity scheme.

### Recital 108 — AI Office copyright compliance monitoring

*Source: AI Act, aiact-rec-108-en, 2024-06-12 — https://overview.legal/posts/93898*

With regard to the obligations imposed on providers of general-purpose AI models to put in place a policy to comply with Union copyright law and make publicly available a summary of the content used for the training, the AI Office should monitor whether the provider has fulfilled those obligations without verifying or proceeding to a work-by-work assessment of the training data in terms of copyright compliance. This Regulation does not affect the enforcement of copyright rules as provided for under Union law.

### Recital 76 — AI system cybersecurity protection measures

*Source: AI Act, aiact-rec-76-en, 2024-06-12 — https://overview.legal/posts/93834*

Cybersecurity plays a crucial role in ensuring that AI systems are resilient against attempts to alter their use, behaviour, performance or compromise their security properties by malicious third parties exploiting the system’s vulnerabilities. Cyberattacks against AI systems can leverage AI specific assets, such as training data sets (e.g. data poisoning) or trained models (e.g. adversarial attacks or membership inference), or exploit vulnerabilities in the AI system’s digital assets or the underlying ICT infrastructure. To ensure a level of cybersecurity appropriate to the risks, suitable measures, such as security controls, should therefore be taken by the providers of high-risk AI systems, also taking into account as appropriate the underlying ICT infrastructure.

### Recital 111 — systemic risk classification methodology for general-purpose AI models

*Source: AI Act, aiact-rec-111-en, 2024-06-12 — https://overview.legal/posts/93904*

It is appropriate to establish a methodology for the classification of general-purpose AI models as general-purpose AI model with systemic risks. Since systemic risks result from particularly high capabilities, a general-purpose AI model should be considered to present systemic risks if it has high-impact capabilities, evaluated on the basis of appropriate technical tools and methodologies, or significant impact on the internal market due to its reach. High-impact capabilities in general-purpose AI models means capabilities that match or exceed the capabilities recorded in the most advanced general-purpose AI models. The full range of capabilities in a model could be better understood after its placing on the market or when deployers interact with the model. According to the state of the art at the time of entry into force of this Regulation, the cumulative amount of computation used for the training of the general-purpose AI model measured in floating point operations is one of the relevant approximations for model capabilities. The cumulative amount of computation used for training includes the computation used across the activities and methods that are intended to enhance the capabilities of the model prior to deployment, such as pre-training, synthetic data generation and fine-tuning. Therefore, an initial threshold of floating point operations should be set, which, if met by a general-purpose AI model, leads to a presumption that the model is a general-purpose AI model with systemic risks. This threshold should be adjusted over time to reflect technological and industrial changes, such as algorithmic improvements or increased hardware efficiency, and should be supplemented with benchmarks and indicators for model capability. To inform this, the AI Office should engage with the scientific community, industry, civil society and other experts. Thresholds, as well as tools and benchmarks for the assessment of high-impact capabilities, should be strong predictors of generality, its capabilities and associated systemic risk of general-purpose AI models, and could take into account the way the model will be placed on the market or the number of users it may affect. To complement this system, there should be a possibility for the Commission to take individual decisions designating a general-purpose AI model as a general-purpose AI model with systemic risk if it is found that such model has capabilities or an impact equivalent to those captured by the set threshold. That decision should be taken on the basis of an overall assessment of the criteria for the designation of a general-purpose AI model with systemic risk set out in an annex to this Regulation, such as quality or size of the training data set, number of business and end users, its input and output modalities, its level of autonomy and scalability, or the tools it has access to. Upon a reasoned request of a provider whose model has been designated as a general-purpose AI model with systemic risk, the Commission should take the request into account and may decide to reassess whether the general-purpose AI model can still be considered to present systemic risks.

## Guidance

### Statement on the Digital Services Package and Data Strategy

*Source: EDPB, statement-on-the-digital-services-package-and-data-en, 2021-11-18 — https://overview.legal/posts/125982 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-on-the-digital-services-package-and-data_en*

1 Adopted Statement on the D igital Services Package and Data Strategy Adopted on 18 November 2021 The European Data Protection Board has adopted the following statement: Since November 2020 , the European Commission has presented several legislative proposals as part of its digital and data strategies, most notably the Digital Services Act (DSA), the Digital Markets Act (DMA), the Data Governance Act (DGA) and the Regulation on a European appr oach for A rtificial I ntelligence (AIR). A fifth…

### EDPB-EDPS Joint Opinion 03/2021 on the Proposal for a regulation of the European Parliament and of the Council on European data governance (Data Governance Act)

*Source: EDPB, edpb-edps-joint-opinion-032021-on-the-proposal-for-a-regulation-of-en, 2021-03-11 — https://overview.legal/posts/126050 — original: https://www.edpb.europa.eu/documents/legislative-opinion/edpb-edps-joint-opinion-032021-on-the-proposal-for-a-regulation-of_en*

1 Adopted EDPB - EDPS Joint Opinion 03 /2021 on the Proposal for a regulation of the European Parliament and of the Coun cil on European data governance (Data Governance Act) Version 1.1 2 Adopted Version history Version 1.1 09 June 2021 Minor editorial changes Version 1.0 10 March 2021 Adoption of the Joint Opinion 3 Adopted 5 Adopted The European Data Protection Board and the European Data Protection Supervisor Having regard to Article 42(2) of the Regulation 2018/1725 of 23 October 2018 on…

### Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models

*Source: EDPB, opinion-282024-on-certain-data-protection-aspects-related-to-en, 2024-12-18 — https://overview.legal/posts/125697 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-282024-on-certain-data-protection-aspects-related-to_en*

Adopted 1 Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models Adopted on 17 December 2024 Adopted 2 Executive summary AI technologies create many opportunities and benefits across a wide range of sectors and social activities. By protecting the fundamental right to data protection, GDPR supports these opportunities and promotes other EU fundamental rights, including the right to freedom of thought, expression and information,…

### Report of the work undertaken by the ChatGPT Taskforce

*Source: EDPB, report-of-the-work-undertaken-by-the-chatgpt-taskforce-en, 2024-05-24 — https://overview.legal/posts/125752 — original: https://www.edpb.europa.eu/documents/task-force-report/report-of-the-work-undertaken-by-the-chatgpt-taskforce_en*

Report of the work undertaken by the ChatGPT Taskforce 23 May 2024 Final 2 Final 3 D ISCLAIMER The positions presented in this document result from the coordination of the members of the ChatGPT taskforce with a view to handling investigations regarding the service ChatGPT provided by the US based company OpenAI OpCo, LLC . They reflect the common denominator agreed by the S upervisory A uthorities in their interpretation of the applicable provisions of the GDPR in relation to the matters that…

### EDPB-EDPS Joint Opinion 03/2022 on the Proposal for a Regulation on the European Health Data Space

*Source: EDPB, edpb-edps-joint-opinion-032022-on-the-proposal-for-a-regulation-on-en, 2022-07-12 — https://overview.legal/posts/125922 — original: https://www.edpb.europa.eu/documents/legislative-opinion/edpb-edps-joint-opinion-032022-on-the-proposal-for-a-regulation-on_en*

Adopted 1 EDPB - EDPS Joint Opinion 03 /2022 on the Proposal for a Regulation on the European Health Data Space Adopted on 12 July 2022 Adopted 2 Adopted 3 Executive Summary With this Joint Opinion, the EDPB and the EDPS aim to draw attention to a number of overarching concerns on the Proposal on the European Health Data Space and urge the co - legislature to take decisive action. The EDPB and the EDPS note that the Proposal ai ms at supporting individuals to take control of their own health…

### EDPB Work Programme 2021-2022

*Source: EDPB, edpb-work-programme-2021-2022-en, 2021-03-16 — https://overview.legal/posts/126048 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-work-programme-2021-2022_en*

EDPB Work Programme 2021/2022 The European Data Protection Board The European Data Protection Board (EDPB) is an independent European body established by the General Data Protection Regulation (GDPR). The EDPB has the following main tasks: To issue opinions, guidelines, recommendations and best practices to promote a common understanding of the GDPR and the Law Enforcement Directive (LED); To advise the European Commission on any issue related to the protection of personal data in the Union; To…

## Recent developments

### Is the AI Act caging ChatGPT and other General Purpose Artificial Intelligence systems?

*Source: Gaming Tech Law, 2023-03-29 — https://overview.legal/posts/6223 — original: https://www.gamingtechlaw.com/2023/03/draft-ai-act-general-purpose-artificial-intelligence/#entry-4244*

> The growth of generative artificial intelligence systems has led EU lawmakers to focus on General Purpose AI in drafting the AI Act, which will set the framework governing artificial intelligence in the European Union. As previously reported, the EU Parliament has already broadened the definition of artificial intelligence for the purposes of the AI Act…

### Artificial intelligence: the action plan of the CNIL

*Source: CNIL, 2023-05-16 — https://overview.legal/posts/6206 — original: https://www.cnil.fr/en/artificial-intelligence-action-plan-cnil#entry-5218*

The main thing is:

The CNIL has been undertaking work for several years to anticipate and respond to the issues raised by AI.
In 2023, it will extend its action on augmented cameras and wishes to expand its work to generative AIs, large language models and derived applications (especially chatbots).
Its action plan is structured around four strands:

to understand the functioning of AI systems and their impact on people;
enabling and guiding the development of privacy-friendly AI;
federate and

### Data Protection Officer or Chief Privacy Officer?The rise of the Data Protection Officer

*Source: White Label Consultancy, 2022-01-04 — https://overview.legal/posts/6311 — original: https://whitelabelconsultancy.com/2022/01/chief-privacy-officer-or-data-protection-officer/#entry-16*

> Do we need an Chief Privacy Officer, a Data Protection Officer, or do we need both?In the following article, I will examine the benefits of both roles, but I will also look at some of the challenges related to each of the roles and why these have impelled both Data Protection Officers and organisations to question what the ideal setup is for them.

## Literature

### Health AI Governance, Medical Devices Health Data

*Source: Open Science Framework, 2026-07-17 — https://overview.legal/posts/132112 — original: https://doi.org/10.17605/osf.io/kpxn7*

This AGRIR-Lab component develops an interdisciplinary research programme on the governance, regulation, clinical safety, cybersecurity and ethical deployment of artificial intelligence in healthcare. It examines the EU Artificial Intelligence Act, the Medical Devices Regulation and In Vitro Diagnostic Medical Devices Regulation, the European Health Data Space, GDPR, NIS2, Medical Device Software, clinical and performance evaluation, health-data governance, anonymisation, predictive analytics, h

### From the EU AI Act to Audit Practice: A Governance-to-Controls Framework for Quality Management and Evidence

*Source: Accounting and Auditing, 2026-07-15 — https://overview.legal/posts/132365 — original: https://doi.org/10.3390/accountaudit2030012*

Artificial intelligence (AI) tools—including audit data analytics, robotic process automation, machine-learning models, and generative AI—are changing how audit teams identify risks, select procedures, and evaluate evidence. At the same time, Regulation (EU) 2024/1689 (the EU AI Act) establishes a risk-based governance architecture built around risk management, data governance, technical documentation, logging, transparency, human oversight, robustness, cybersecurity, and post-market monitoring.

### REGULATION OF APPLIED ARTIFICIAL INTELLIGENCE IN BIOMEDICAL ENGINEERING AS A HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM IN THE EU AI ACT

*Source: AFMN Biomedicine, 2026-07-13 — https://overview.legal/posts/132435 — original: https://doi.org/10.65641/afmnai-2026-075*

lt;p style= quot;text-align: justify; quot; gt; lt;span class= quot;a_GcMg font-feature-liga-off font-feature-clig-off font-feature-calt-off text-decoration-none text-strikethrough-none quot; gt;Artificial intelligence (AI) represents a global phenomenon changing all spheres of human life. Biomedical engineering is no exception, as many AI systems are applied to biomedical engineering inventions. The European Union has enacted the new EU AI Act, one of the world amp;rsquo;s first laws on AI. The

### The ethics of regulation: Social contract insights on the 2024 European Union Artificial Intelligence Act

*Source: Ethics & bioethics, 2026-07-06 — https://overview.legal/posts/83515 — original: https://doi.org/10.2478/ebce-2026-0014*

Abstract The paper provides a critical analysis of the EU AI Act (Regulation 2024/1689) within the broader context of contemporary AI developments. Starting from an historical overview on the development of advanced AI systems, it moves the focus onto the intrinsic meaning of Artificial Intelligence to highlight how, despite such fascinating wording, there cannot be a shift of responsibility onto the systems themselves—as was proposed, for example, by the European Parliament resolution of 16 Feb

### General-Purpose AI under the EU AI Act: A Conceptual Allocation of Duties across the Value Chain

*Source: SCRIPTed A Journal of Law Technology & Society, 2026-06-30 — https://overview.legal/posts/132370 — original: https://doi.org/10.2218/scrip.12300*

This article examines how the final version of the EU Artificial Intelligence Act (“AI Act”, adopted 2024) allocates obligations across the AI value chain, with a focus on general-purpose AI (“GPAI”) or foundation models. It proposes a taxonomy of key actors – foundation model providers, fine-tuners, integrators, and deployers – and analyses the interfaces between them, including documentation tools (model cards, system cards) and logging requirements. Building on principles of control, foreseea

## Related topics

- **Artificial Intelligence** — https://overview.legal/topics/ai
  AI systems and their implications for data protection
- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **AI Value Chain Actors and Roles** — https://overview.legal/topics/ai-value-chain-actors
  The content focuses on responsibilities distributed across different actors in the AI value chain. A dedicated topic for understanding the various actors, their
- **Accountability** — https://overview.legal/topics/accountability
  Principle of demonstrating GDPR compliance
- **Training Data Requirements** — https://overview.legal/topics/training-data-requirements
  The AI Act specifically addresses requirements for training, validation, and test data used in high-risk AI systems. This warrants a dedicated topic covering da
- **Transparency** — https://overview.legal/topics/transparantie
  Openness about data processing activities

---
Generated by overview.legal · https://overview.legal/topics/data-governance-ai · 2026-08-22
