{"id":19949,"date":"2026-08-18T14:39:10","date_gmt":"2026-08-18T12:39:10","guid":{"rendered":"https:\/\/haimagazine.com\/uncategorized\/first-they-deploy-ai-then-they-ask-if-its-legal\/"},"modified":"2026-08-20T18:22:26","modified_gmt":"2026-08-20T16:22:26","slug":"first-they-deploy-ai-then-they-ask-if-its-legal","status":"publish","type":"post","link":"https:\/\/haimagazine.com\/en\/law-and-ethics\/first-they-deploy-ai-then-they-ask-if-its-legal\/","title":{"rendered":"\ud83d\udd12 First they deploy AI. Then they ask if it&#8217;s legal."},"content":{"rendered":"<p class=\"wp-block-paragraph\">First, employees start using a public chatbot. Then the company buys team access, connects its own documents or adds a customer support tool. Only at one of the later stages do these questions come up: What data goes into the system? Is the company allowed to process it that way?<\/p><p class=\"wp-block-paragraph\">This isn\u2019t just a hypothetical scenario. <a href=\"https:\/\/uodo.gov.pl\/pl\/138\/4533\" target=\"_blank\" rel=\"noopener\"><mark style=\"background-color:#82D65E\" class=\"has-inline-color has-base-color\">The Personal Data Protection Office says outright<\/mark><\/a> that the question of legal compliance usually comes up when an AI tool is already running and the decisions about the provider and the data being used have already been made. That means legal analysis doesn\u2019t precede deployment. It\u2019s trying to catch up.<\/p><h4 class=\"wp-block-heading\">The AI is running, but nobody knows whether it&#8217;s processing data<\/h4><p class=\"wp-block-paragraph\">The scale of the problem is illustrated by <a href=\"https:\/\/uodo.gov.pl\/pl\/file\/7022\" target=\"_blank\" rel=\"noopener\"><mark style=\"background-color:#82D65E\" class=\"has-inline-color has-base-color\">a survey conducted by UODO<\/mark><\/a> among 492 organizations. Only 16.7% of respondents reported using AI in their day-to-day operations. Others were running tests, planning deployments or were interested in the technology but didn&#8217;t know where to start.<\/p><p class=\"wp-block-paragraph\">At the same time, 38.2% of respondents said that their use of AI systems doesn&#8217;t involve processing personal data. Another 20.3% couldn&#8217;t assess it. That adds up to 58.5% of organizations that either didn&#8217;t see a link between using AI and personal data or weren&#8217;t sure such a link exists.<\/p><p class=\"wp-block-paragraph\">The responses about preparedness for implementing the GDPR are even more interesting. Only 4.1% of organizations considered themselves very well prepared. Another 25% chose &#8220;somewhat prepared,&#8221; while 44.9% couldn&#8217;t assess their own readiness. The remaining respondents judged their organizations as somewhat or completely unprepared.<\/p><p class=\"wp-block-paragraph\">UODO summed up these results by saying that 95.9% of organizations are unprepared or unsure of their readiness. That\u2019s a broad interpretation, because it also includes organizations that described themselves as somewhat prepared. Far more telling, though, are two other figures: only 4.1% of respondents were confident they were well prepared, and nearly half couldn\u2019t assess it at all.<\/p><p class=\"wp-block-paragraph\">We should be cautious here. The study wasn\u2019t representative, and its quantitative component was dominated by the public sector. It included 439 public entities, 39 private ones, and 19 social and industry organizations. So you can\u2019t automatically generalize the results to all Polish companies. However, they do show a mechanism that may also appear in business: tools are emerging faster than knowledge of their legal consequences.<\/p><h4 class=\"wp-block-heading\">Personal data isn&#8217;t just your social security number<\/h4><p class=\"wp-block-paragraph\">Part of the problem probably stems from the fact that people still think of personal data mainly as a name, an ID number or an address. But an AI system might receive the contents of an email, a candidate&#8217;s CV, a customer complaint, notes from a meeting, a medical record, a conversation history or an excerpt from an internal report. Even if the user removes the name, the remaining information can still let someone identify the person.<\/p><p class=\"wp-block-paragraph\">Data also shows up in many places at once. It can be in the prompt you type into the model, an attached file, the conversation history, technical logs, the knowledge base connected to the system and the AI-generated response. Just because an organization uses an off-the-shelf tool doesn&#8217;t remove its responsibility for how information is entered and used.<\/p><p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.edpb.europa.eu\/news\/edpb-opinion-on-ai-models-gdpr-principles-support-responsible-ai_en\" target=\"_blank\" rel=\"noopener\"><mark style=\"background-color:#82D65E\" class=\"has-inline-color has-base-color\">The European Data Protection Board<\/mark><\/a> points out that you can&#8217;t assume upfront that an AI model is inherently anonymous and doesn&#8217;t process personal data. In practice, you need to check whether personal data can surface in its operation\u2014for example, whether the model was trained on such data or can reproduce it in its responses. You also assess whether appropriately crafted prompts could extract information about specific individuals from it. Even using an external model doesn&#8217;t automatically mean there&#8217;s no processing of personal data. Each such system should be assessed on a case-by-case basis.<\/p><p class=\"wp-block-paragraph\">That means choosing an off-the-shelf solution from a large vendor doesn\u2019t settle the matter. The organization still needs to know what data it\u2019s handing over, for what purpose, on what legal basis, where it\u2019s stored and who can access it.<\/p><h4 class=\"wp-block-heading\">The most important decisions are made at the point of purchase<\/h4><p class=\"wp-block-paragraph\">Once the tool is up and running, some key decisions are already settled. The provider, hosting approach, licensing model and scope of integration have been chosen. Sometimes they\u2019ve also signed off on policies for retaining conversation history, using data to improve the service and transferring it outside the European Economic Area.<\/p><p class=\"wp-block-paragraph\">Bringing in a lawyer or a data protection officer later on doesn\u2019t always make it easy to reverse those decisions. Changing course may require renegotiating a contract, migrating data, reconfiguring the tool or dropping a feature around which the workflow has already been built.<\/p><p class=\"wp-block-paragraph\">The French data protection authority, CNIL \u2014 which has probably taken the most concrete approach to this issue \u2014 <a href=\"https:\/\/www.cnil.fr\/en\/cnils-qa-use-generative-ai-systems\" target=\"_blank\" rel=\"noopener\"><mark style=\"background-color:#82D65E\" class=\"has-inline-color has-base-color\">recommends analyzing risk and defining management rules before implementing generative AI. An organization should define its role and the provider\u2019s role, check the terms for data transfers and determine who\u2019s responsible for each operation. For cloud-based services, the scope of responsibility and access to data should be set out in the contract, not in the user\u2019s assumptions.<\/mark><\/a><\/p><p class=\"wp-block-paragraph\">In higher-risk applications, it may be necessary to conduct a data protection impact assessment, or DPIA. It\u2019s not just about creating a document in case of an audit. This analysis should show what risks arise, who they might affect and whether they can be mitigated before the system goes live.<\/p><h4 class=\"wp-block-heading\">The risk that remains in the shadows<\/h4><p class=\"wp-block-paragraph\">Even a well-planned deployment still leaves one problem unsolved. An organization can control the system it purchased, but it doesn&#8217;t always know which tools its employees use.<\/p><p class=\"wp-block-paragraph\">The UODO report uses the term &#8220;shadow AI&#8221;\u2014the uncontrolled use of artificial intelligence outside official procedures. An employee might paste a document into a public chatbot to get a summary done faster. They might upload client data to generate a response, or use an external tool to analyze candidates, even though the company hasn&#8217;t formally approved it.<\/p><p class=\"wp-block-paragraph\">In such a situation, the organization might not even realize that data is now being processed in a new way. It doesn&#8217;t know the provider, hasn&#8217;t reviewed its terms, hasn&#8217;t established the legal basis and doesn&#8217;t know whether the information is being stored. The formal security policy covers one environment, while the actual work happens in a completely different one.<\/p><p class=\"wp-block-paragraph\">Banning the use of AI usually doesn&#8217;t solve this problem. It can only push it deeper into the gray area. We need approved tools, clear data policies and training that shows not only what not to do but also why a given use case creates risk.<\/p><h4 class=\"wp-block-heading\">When analysis arrives too late<\/h4><p class=\"wp-block-paragraph\">One example of a reversed rollout is Snap\u2019s My AI chatbot. The service launched for paying Snapchat users in February 2023 and, less than two months later, for all users on the platform.<\/p><p class=\"wp-block-paragraph\">The UK data protection authority (ICO) <a href=\"https:\/\/ico.org.uk\/about-the-ico\/media-centre\/news-and-blogs\/2024\/05\/ico-warns-organisations-must-not-ignore-data-protection-risks-as-it-concludes-snap-my-ai-chatbot-investigation\/\" target=\"_blank\" rel=\"noopener\"><mark style=\"background-color:#82D65E\" class=\"has-inline-color has-base-color\">opened an investigation after the service launched<\/mark><\/a>, because it was concerned about how privacy risks were being assessed, especially for children. The regulator issued a preliminary notice regarding a potential breach of regulations, and Snap then conducted an in-depth analysis and implemented additional risk-mitigation measures.<\/p><p class=\"wp-block-paragraph\">Ultimately, the ICO found the revised impact assessment compliant with UK GDPR requirements. It also didn\u2019t find a breach of the obligation to consult the regulator before launching the service. That doesn\u2019t change the most important part of this story, though: the more thorough assessment and additional safeguards only appeared after the product hit the market and proceedings had begun.<\/p><p class=\"wp-block-paragraph\">It&#8217;s not a direct precedent for Polish organizations, but it shows that a post-deployment analysis can lead to the need to overhaul the system&#8217;s operating rules, even when users are already using it.<\/p><h4 class=\"wp-block-heading\">What to check before deciding<\/h4><p class=\"wp-block-paragraph\">In August, UODO published <a href=\"https:\/\/uodo.gov.pl\/pl\/138\/4533\" target=\"_blank\" rel=\"noopener\">four sets of questions that organizations should ask before implementing AI<\/a>. Separate versions were prepared for small and medium-sized enterprises, the public sector and other entities. There\u2019s also an expanded version that includes, among other things, risk classification based on the AI Act and an assessment of the impact on fundamental rights.<\/p><p class=\"wp-block-paragraph\">The questions cover, among other things, the purpose of the deployment, the categories of data used and their sources, retention policies, the vendor agreement, transfers of information outside the EEA, output review and the degree of human involvement in decision-making. Organizations should also determine whether an employee reviews the AI-generated output before it&#8217;s used in relation to a candidate, a client or any other person.<\/p><p class=\"wp-block-paragraph\">The checklist alone doesn&#8217;t determine compliance. UODO makes it clear that it doesn&#8217;t replace a risk assessment, a DPIA or an assessment of the impact on fundamental rights. Its primary role is to trigger the right process at the right time.<\/p><p class=\"wp-block-paragraph\">Timing is crucial here. Questions about purpose, data, the vendor and accountability should be asked before the system is purchased and deployed, because the answers may determine whether the tool should be implemented at all.<\/p><h4 class=\"wp-block-heading\">Add a conformity assessment to the process<\/h4><p class=\"wp-block-paragraph\">Implementing AI is often framed as a technology decision: you have to choose a model, buy licenses, connect the data and train employees. In reality, it&#8217;s also about designing a new process for processing information.<\/p><p class=\"wp-block-paragraph\">That\u2019s why accountability can\u2019t begin in the legal department only once the contract is signed. The analysis should include people responsible for technology, security, data, procurement, the specific business process and personal data protection. Each of them sees a different facet of the risk.<\/p><p class=\"wp-block-paragraph\">So the most important question isn\u2019t whether the company has an AI use policy. What matters more is whether it can pause deployment until it\u2019s clear what data will be processed, on what basis and with what consequences.<\/p>","protected":false},"excerpt":{"rendered":"<p>Many organizations can&#8217;t tell whether their use of AI involves processing personal data, or whether they&#8217;re prepared for it. The problem starts when questions about legal compliance come up only after a tool has been selected and deployed.<\/p>\n","protected":false},"author":354,"featured_media":19930,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"rank_math_lock_modified_date":false,"footnotes":""},"categories":[832,805],"tags":[],"popular":[],"difficulty-level":[38],"ppma_author":[776],"class_list":["post-19949","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-editors-picks","category-law-and-ethics","difficulty-level-medium"],"acf":[],"authors":[{"term_id":776,"user_id":354,"is_guest":0,"slug":"redakcja","display_name":"Redakcja","avatar_url":{"url":"https:\/\/haimagazine.com\/wp-content\/uploads\/2025\/07\/Zrzut-ekranu-2025-07-10-o-16.00.36.png","url2x":"https:\/\/haimagazine.com\/wp-content\/uploads\/2025\/07\/Zrzut-ekranu-2025-07-10-o-16.00.36.png"},"first_name":"","last_name":"","user_url":"","job_title":"","description":""}],"_links":{"self":[{"href":"https:\/\/haimagazine.com\/en\/wp-json\/wp\/v2\/posts\/19949","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/haimagazine.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/haimagazine.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/haimagazine.com\/en\/wp-json\/wp\/v2\/users\/354"}],"replies":[{"embeddable":true,"href":"https:\/\/haimagazine.com\/en\/wp-json\/wp\/v2\/comments?post=19949"}],"version-history":[{"count":1,"href":"https:\/\/haimagazine.com\/en\/wp-json\/wp\/v2\/posts\/19949\/revisions"}],"predecessor-version":[{"id":19950,"href":"https:\/\/haimagazine.com\/en\/wp-json\/wp\/v2\/posts\/19949\/revisions\/19950"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/haimagazine.com\/en\/wp-json\/wp\/v2\/media\/19930"}],"wp:attachment":[{"href":"https:\/\/haimagazine.com\/en\/wp-json\/wp\/v2\/media?parent=19949"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/haimagazine.com\/en\/wp-json\/wp\/v2\/categories?post=19949"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/haimagazine.com\/en\/wp-json\/wp\/v2\/tags?post=19949"},{"taxonomy":"popular","embeddable":true,"href":"https:\/\/haimagazine.com\/en\/wp-json\/wp\/v2\/popular?post=19949"},{"taxonomy":"difficulty-level","embeddable":true,"href":"https:\/\/haimagazine.com\/en\/wp-json\/wp\/v2\/difficulty-level?post=19949"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/haimagazine.com\/en\/wp-json\/wp\/v2\/ppma_author?post=19949"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}