A Law That Never Mentions AI — So How Does It Keep AI in Check?
An explainer on how GDPR, a law that never mentions AI, still governs AI systems through consent, data minimization, automated decision rules, and explanation rights, based on a European Parliament research study.

A few days ago, a friend of mine who runs a cross-border e-commerce business invited me out for tea. The moment the conversation reached the European market, his face fell.
European users, he said, are almost fanatically serious about their personal data. He wanted his system to make recommendations for users — legal stopped him before he could start: get past GDPR (the EU's General Data Protection Regulation) first, then we'll talk.
Then he asked me: GDPR was passed in 2016 — back when ChatGPT wasn't even a glimmer. Can an "old" law really keep today's AI in check?
I told him: funny you should ask. In 2020, the European Parliament's research service brought together a group of scholars to study exactly this question: can a law that never once contains the words "artificial intelligence" actually govern AI?
Their conclusion was counterintuitive: yes, it can. On one condition — the law doesn't need changing, but the homework absolutely has to get done.
Today, I'll walk you through that study's line of thinking, in plain language you can actually use.
1. Why Is AI Suddenly So Hungry?
For many people, AI still lives in science fiction. But what's actually changing the world today is a method that looks almost embarrassingly simple: machine learning.
What is machine learning?
Start with the old-school approach. Want a machine to recognize cats? Hire experts and turn their knowledge into rules, one by one: has whiskers — cat. Pointy ears — cat. Eyes that glow in photos — cat. Write a few thousand rules, and the machine still can't recognize a cat with its head tilted.
That road was called expert systems. In the eighties and nineties, countless brilliant people crashed on it. Common sense is the kind of thing where the more you write down, the more leaks through the cracks. Academia calls it the "knowledge representation bottleneck."
Machine learning flipped the logic entirely.
Can't write the rules? Then don't. I hand you ten thousand labeled photos: this one's a cat, this one isn't. The machine works out on its own what a cat looks like.
This is supervised learning. Humans stop playing teacher and just set the exam. The questions plus the answer key are called the training set. The machine grinds through the training set again and again — solving, checking answers, correcting itself — until a model grows out of it.
Now think about it: in this whole setup, what's the most valuable asset?
Not the algorithms. The data.
Without a training set, even the cleverest algorithm can't cook without ingredients. That's why AI has a hunger for data written into its bones. And today's world happens to serve an endless buffet: roughly 30 billion devices are now online — your phone, your car, your doorbell, your fitness band — every single one quietly keeping score.
And so a flywheel starts spinning: the stronger AI gets, the more data it wants; the more it eats, the stronger it grows.
And your personal data is the richest stretch of that wheel.
2. What Has All That Feeding Produced?
Let's start with the good news — and it really is good.
Algorithms often judge more reliably than people do. Humans come with a bundle of incurable quirks: overconfidence, loss aversion, first impressions that never wash out, bonus points for anyone we happen to like. Algorithms have no moods, never get tired, aren't afraid of offending anyone, and can be audited over and over. In quite a few head-to-head comparisons in hiring, credit, and medical diagnosis, algorithms have outperformed human experts.
Now the bad side.
Point the same capability in a different direction, and it's a different story entirely.
What the model works out from your data isn't just what you like. It's who you are: whether you're healthy, whether you can repay what you owe, which side of an argument you lean toward, which sales pitch will make you waver.
This process has a name of its own: profiling.
What is profiling? You feed the model the data points you leave behind and let it infer things even you never realized about yourself. A like is data. Your browsing is data. Which neighborhood you live in is data. The model pieces the clues together and completes a portrait of you that you never painted yourself.
Once the portrait exists, what's it for? It can predict you — and therefore influence you.
Too abstract? Let me tell you a true story.
Around the 2016 US election, a company called Cambridge Analytica rolled out a little personality-quiz app. You got paid to take it — $2 to $5. There was only one condition: log in with your Facebook account.
About 320,000 people took the quiz.
What they didn't know was that the app followed their accounts and swept up their friends' data too. The consent of 320,000 people became the data of 30 to 50 million.
The company then took those 320,000 people's "quiz answers plus social data" as a training set and trained a model: which liking patterns correspond to which personalities, and which personalities respond to which messaging.
The final step: run the model over the tens of millions who never took the quiz, profile them, pick out the swing voters who'd flip with the slightest push, zero in on a handful of key states, and deliver political ads tailored to each person.
Do you see the structure here?
Things 320,000 people gave up willingly became things inferred about tens of millions who never consented to any of it. Each link in the chain looks harmless on its own: take a quiz, collect a reward. Put them together, and it's a mass-scale operation on the psychology of millions.
That's the most terrifying thing about profiling: it can hurt you in the gentlest possible way.
And here's the kicker: even if every company plays strictly by the rules — even if the algorithms are fair, accurate, and unbiased — it doesn't end there. Being continuously recorded, assessed, and "thoughtfully" fed content is itself a form of pressure. You think you're choosing your information. The information is choosing you.
3. "Anonymous" May Be Nothing But an Illusion
At this point someone will surely say: fine, then I'll just anonymize the data. Problem solved?
Nice try.
Let me give you three cases — all classics the study cites again and again.
First. The US state of Massachusetts once published the medical records of state government employees with names stripped out — anonymized, for research use. A researcher crossed this "anonymous" dataset against the public voter registration roll: birthday, ZIP code, gender. Three fields matched, and there was the governor's own complete medical record.
Second. Netflix ran an algorithm competition and released a set of "anonymized" user movie ratings. Researchers matched them against public reviews on another movie site: knowing just any two reviews a user had written there was enough to pick that same person out of the "anonymous" data.
Third. One study found that if an app knows which four apps are installed on your phone, and gets hold of the full app-installation list to compare against, it can pick you out of a pool of "anonymous" users.
Three fields. Two reviews. Four apps.
Feel a slight chill? You think you've put on an invisibility cloak. You've only taken off your name tag. Your gait, your height, your accent — all still there.
In the AI era, deciding whether a dataset counts as personal data can no longer be done by looking at the data alone — you have to ask what it sits next to. A dataset that means nothing on its own, joined with one more piece, is you.
The study goes one step bolder: new information a model infers from your data — say, sexual orientation or political leaning derived from browsing history — should itself count as new personal data, even sensitive data, and be regulated just the same.
Otherwise, companies need only one move to slip past the law: don't "collect" your sensitive information — guess it.
4. How Does a Law That Never Mentions AI Actually Govern It?
Back to the original question. The word "artificial intelligence" appears nowhere in GDPR — so on what grounds does it govern AI?
The answer: everything AI does ultimately lands on personal data. And personal data is exactly what this law governs.
There are four levers. Let me take them one at a time.

First, consent.
Many people assume data protection runs on "notice plus consent": the company posts a privacy policy, you click agree, and everyone's square.
The study shows this model no mercy. Data processing today is too complex for anyone to understand, privacy policies are too long for anyone to finish reading, and plenty of services simply won't work unless you click agree. Does that deserve to be called freely given consent?
GDPR's answer is to allow a more flexible reading: when your data is put to another use, consent doesn't necessarily have to run all over again — as long as the new purpose is "compatible" with the original one. For statistical and scientific research purposes, the law presumes compatibility outright.
It's like handing your building manager a key so he can fix the plumbing. If he also fixes the hallway light while he's in there, fine. If he opens your safe — absolutely not.
Second, minimization.
On its face it means: collect less data, just enough to get the job done. That collides head-on with AI, whose entire appetite is for massive data.
The study offers a clever translation: minimization shouldn't fixate only on the quantity of data, but on its identifiability — how easily it can be traced back to a person.
What does that mean? The data can be plentiful, but it should be masked (pseudonymized) so it can't easily be linked back to any specific person. You can't stop anyone from storing data, but you can make the data unable to "recognize" anyone. And the moment someone re-links de-identified data back to you, that act itself counts as "collecting your personal data all over again" — full rules apply, from scratch.
Third, automated decision-making.
This one has real teeth. GDPR says it in black and white: decisions made solely by machines that produce legal consequences for you or similarly significant effects are, in principle, prohibited.
Note the phrase "in principle." It's followed by three broad exceptions: necessary for a contract, authorized by law, or based on your explicit consent. So automated decisions like hiring filters and loan approvals keep running exactly as before.
But if they run, you're owed safeguards: the right to have a human step in, the right to express your view, the right to contest the decision.
In plain terms: a machine can block you, but you have the right to call a human over.
Fourth, the right to an explanation.
This one is the most interesting, because it's the most ambiguous spot in the entire law.
GDPR's recitals — the preamble — say that people subjected to machine decisions have the right to "obtain an explanation of the decision." But flip to the operative articles, and that sentence is gone. What's left is the trio: human intervention, expressing your view, contesting the outcome.
Present in the preamble, absent from the operative text. What is that? It's like a verbal promise made across the negotiating table that never made it into the written terms.
Which is why academics have been arguing to this day: do companies actually have a legal obligation to explain "why was my loan rejected"? Some say that line is a friendly reminder, not a duty; others read the words "at least" and argue a higher requirement may be hiding behind them.
The study's position is refreshingly practical: the explanation can be rough, even broad-brush, but it has to exist — and it has to be enough for you to contest the decision. Otherwise, what exactly are you contesting? You don't even know why you were rejected.
And here's what the practice actually looks like. The study cites Airbnb's privacy policy: on profiling, the whole explanation, translated, comes to a single sentence — we analyze your characteristics and preferences to show you things you might be interested in.
That's it. You read it. You learned nothing.
5. The Real Challenge Isn't the Law. It's the Homework.
By now you might be thinking: not bad — the principles are all there, and they all seem workable.
The researchers' conclusion says as much: GDPR and AI don't conflict, and the law doesn't need drastic surgery.
But hold the optimism.
This law has one defining trait: many of its provisions are vague and open-ended. "Compatible." "Reasonable." "Appropriate." "Meaningful." Words like that, everywhere. In ordinary settings, a little vagueness is fine — everyone operates on common sense.
But in AI settings, the technology is new, the impact is large, and the consequences are uncertain. Vague rules plus eye-watering fines equals what, exactly?
It equals handing drivers a traffic rulebook full of "use your discretion" while installing high-definition cameras on every corner.
Big companies aren't afraid — they have legal teams lined up to work through it. It's the small companies that are afraid. The study puts it sharply: heavy fines plus uncertainty, and the most likely outcome is that small teams simply stop touching AI altogether. The cost of compliance becomes the wall that keeps out the very people most eager to innovate.
So the study's real position, distilled to one line: leave the law alone; do the homework.
Regulators need to step in and turn each vague spot into something concrete, using guidelines, codes of conduct, and certification schemes to show businesses the way — especially smaller ones. Which AI applications are absolutely off-limits, and which get a conditional green light, should be settled by open, society-wide debate. And because individuals fighting alone are too weak, the channels for collective redress need opening too — around the time the study was written, the EU's Court of Justice had just made clear that a person going to court can claim only their own loss; they can't bundle everyone else's claims into one suit.
There's one more line in the study I'm itching to highlight for you: the reuse of data for statistical purposes is presumed compatible.
What does that mean? As long as the output of the data processing is aggregate results that never land on any specific individual, the law opens a green channel — add safeguards like pseudonymization, and you're through.
It's essentially a ladder lowered down to businesses: harvest the dividends of big data without stepping on the personal-data red line.
6. A Better Question Than "How Accurate Is It?"
Finally, a few closing thoughts of my own, beyond the study.
One detail in this study stopped me for a long time.
Teams have already built models that can infer sexual orientation — and so-called "criminal tendency" — from a person's face. How should we treat them? The study's answer: we shouldn't only ask "is it accurate?" We should ask "should it be built at all?"
Those two questions are worlds apart.
"How accurate?" is a technical question; engineers can answer it. "Should it exist?" is a question of values, and only society as a whole can answer it.
Take predictions from health data. Used in medicine, they save lives early. Used in insurance, they raise premiums for some people. Used in hiring, they keep the less healthy from ever getting the job.
Same data, same model — place it in a different context, and you get entirely different moral outcomes.
Technology decides what can be done. Deciding what may be done should be up to us.
AI's appetite for data can't be stopped, and doesn't need to be. The real watershed is this: will the intelligence raised on our data turn around to serve people — or to scheme against them?
So this is what I told my friend afterward: don't treat GDPR as a wall; treat it as homework. The companies that do that homework well will, as it turns out, go further in the European market.
An old law that never contains the word "AI" proves at least one thing: when technology runs ahead, the law can keep up. It's just that every generation has to answer the same question all over again: which things must never be computed.
Here's wishing you never have to prove to a machine that you are you.
Continue reading
Related articles

Cross-Border Business: Time to Upgrade Your AI Toolbox
A learn article explaining how AI tools help cross-border e-commerce sellers clear five hurdles: language, regulation, logistics, payments, and fraud. It outlines a five-compartment toolbox, a five-step adoption path, and metrics such as conversion rate and CLV, while cautioning against over-reliance on AI.

AI Is Taking Over the Dirty Work of Social Media Marketing, One Task at a Time
This learn article outlines four social media marketing tasks AI can handle — audience analytics, content drafting and design, ad targeting and creative testing, and spam moderation — and cautions that taste, judgment, and data security remain human responsibilities.

AI Is Already This Good — Why Is Your Social Media Marketing Still Pure Manpower?
An overview of 18 AI tools for social media marketing, organized into six categories covering audience research, content creation, scheduling, comment and DM handling, ad management, and visual production, plus notes on personalization, prediction, and emerging trends.