AI Governance Rooted in Data Protection Principles: A New Guide by LDI

Author: LDI Team

September 24, 2026

One of the hallmarks of the Legal Data Intelligence model is that it’s actionable by design. Whether an LDI practitioner is responding to a data subject access request (DSAR) or protecting the source code of a technology company, the workflow breaks down into the same three phases: Initiate, Investigate, and Implement.

It is these three phases that enable practitioners to take a structured and proactive approach to solving legal data challenges, regardless of the use case or practice area they are working in.

Today, they are of particular importance in AI governance. As AI adoption accelerates across all levels and facets of business, regulatory scrutiny increases, and the rapid pace of AI development makes daily headlines, AI oversight has become a boardroom priority.

The LDI Guide to Data Protection in AI Governance graphic
Guide

The LDI Guide to Data Protection in AI Governance

Get the Guide

In this new reality, in-house legal and privacy teams can no longer rely on static checklists. AI systems carry unique risks. AI models can drift, for instance. They can experience a gradual drop in accuracy and performance over time because the real-world data a model was trained on can become outdated compared with the data it is later fed.

Models can also behave in unpredictable ways. These emergent behaviors appear as models scale up in size and data, despite not being explicitly programmed or present in smaller versions.

The risks are not only technical. Putting a person “in the loop” to review what the AI produces is one thing. Validating that the person is actually exercising judgment is quite another. People are prone to automation bias, the tendency to trust an output simply because a machine produced it.

Likewise, a checkbox confirming a retention policy exists does not mean it is being enforced. Retention schedules have to be audited consistently, so that training files and backups containing personal data are not held indefinitely under the guise of model fine-tuning.

The common thread is that these risks demand continuous oversight, as opposed to one-time checks or traditional patch management. What in-house teams need is a dynamic governance and data protection compliance program that can scale and keep pace with the rapid adoption and integration of AI across business operations.

That is exactly what the LDI Data Protection Compliance group set out to create. "The LDI Guide to Data Protection in AI Governance" situates the LDI model's three phases (Initiate, Investigate, and Implement) within five dimensions of AI governance. Within each dimension, the three phases break governance down into actions a team can actually take and repeat for continuous compliance.

The five dimensions are:

  • Data Governance and Privacy: Ensuring the data feeding AI models is lawfully obtained, accurate, fit for purpose, and retained no longer than necessary, with privacy built in by design.
  • People, Accountability, and Oversight: Establishing clear accountability and real AI literacy so that human oversight is meaningful rather than nominal.
  • Third-Party and Ecosystem Risk: Managing the vendors and data supply chains behind most AI systems through binding contracts and ongoing due diligence.
  • Responsible AI Lifecycle: Governing an AI system from design through deployment, change, and retirement, so compliance is continuous rather than a one-time check.
  • Technology and Security Assurance: Extending security to the unique attack surface of AI, protecting model weights, code, data pipelines, and the infrastructure beneath them.

While the five dimensions provide the substantive principles of AI governance, the LDI phases within each dimension provide practical considerations and actionable steps for continuous AI governance from a data protection point-of-view.

The LDI Guide to Data Protection in AI Governance graphic
Guide

The LDI Guide to Data Protection in AI Governance

Get the Guide

The guide is grounded in global AI laws and technical standards. It also includes an appendix surveying the leading global AI governance regimes, including the EU AI Act, the NIST AI Risk Management Framework, ISO/IEC 42001, and the OECD AI Principles, giving teams a concise reference on the standards and laws they already answer to.

Ultimately, by integrating the three LDI phases (Initiate, Investigate, and Implement) into each of the five AI governance dimensions, this guide enables corporate legal departments, data protection officers, and risk management professionals to ensure that their AI governance lifecycle is in continuous alignment with data protection rules.

The guide was authored by LDI founding member Briordy Meyers, head of legal data intelligence and customer success at Seedless; and LDI Architects Ryan Costello, executive vice president of global advisory and client engagements at HaystackID; and Mike Kearney, counsel at Redgrave LLP.

Get the LDI newsletter

Bask in the SUN with the Legal Data Intelligence newsletter.

Sign Up