# Workshop 10: AI and Data Governance - Regulations and Standards

> Governance is where the technical practices of the program meet the law. This workshop maps the regulations and standards that increasingly decide how AI systems built on personal data may be developed, deployed, and held accountable.

## Overview

The earlier workshops treated security, privacy, and fairness as engineering properties. This one treats them as legal and organizational obligations. As AI systems make consequential decisions about people, in hiring, credit, healthcare, and public services, a fast-moving body of regulation and standards has grown up to govern how their data is collected, how the systems are risk-classified, and what accountability their operators owe. Understanding that landscape is now part of building an AI system responsibly, not an afterthought bolted on once the model works.

This session surveys the terrain in two halves. The first is **data governance**: the internal discipline by which an organization manages the quality, security, provenance, stewardship, and lifecycle of the data its models learn from. The second is the **external regulatory landscape**: the EU's GDPR and AI Act, California's CCPA/CPRA, and the United States' soft-law approach built on the Blueprint for an AI Bill of Rights and the NIST AI standards. Between them sits the practical problem every real system faces, designing one architecture that satisfies several overlapping regimes at once, and the data-protection techniques (anonymization, pseudonymization, encryption) that make compliance achievable while preserving usefulness.

This is a panel-and-reference session rather than a coding lab. It is delivered as a panel discussion among practitioners and researchers, and the material below, together with the linked primary sources, is written to be studied closely and used as a reference map when you need to place a system inside its regulatory context. There is no notebook for this workshop.

**Prerequisites:** Complete [Workshop 1](../Workshop01/Introduction_and_Fundamentals_in_AI.md) first. This session builds directly on [Workshop 9](../Workshop09/AI_Development_and_Security.md), which introduced compliance frameworks as part of the development lifecycle, and on [Workshop 6](../Workshop06/AI_and_Privacy_Differential_Privacy_and_Federated_Learning.md), which covered the privacy-enhancing techniques that governance regimes increasingly expect.

## Workshop Video

This session is a recorded panel discussion on AI and data governance. Watch the recording, then work through the reading below.

**Panel Recording:** Coming Soon - the video link will be added here once published.

### Panelists

This panel brings together practitioners and researchers from industry and academia to examine how governance frameworks such as GDPR, CCPA, and the EU AI Act shape the way organizations collect, process, and protect data, and what it takes to build AI systems that are not only compliant but genuinely trustworthy across multiple regulatory regimes.

<div style="margin-bottom: 40px; overflow: auto;">
  <img src="../assets/images/abusnaina.png" alt="Ahmed Abusnaina" align="left" width="250" height="250" style="float: left; width: 250px; height: 250px; object-fit: cover; border-radius: 50%; margin: 10px 30px 10px 0;">
  <h4 style="margin-top: 0;">Ahmed Abusnaina</h4>
  <p><strong>Meta</strong> | Machine Learning Research Scientist</p>
  <p>Ahmed Abusnaina is a Machine Learning Research Scientist at Meta. At Meta, his work revolves around social graphs user understanding, pattern recognition, and robust signal processing. Before joining Meta, he obtained his Ph.D. in Computer Science (Security Research) from the University of Central Florida. His dissertation focused on introducing robust machine learning applications in malware detection, image recognition, and anomaly detection domains.</p>
</div>

<div style="margin-bottom: 40px; overflow: auto;">
  <img src="../assets/images/saad.png" alt="Muhammad Saad" align="left" width="250" height="250" style="float: left; width: 250px; height: 250px; object-fit: cover; border-radius: 50%; margin: 10px 30px 10px 0;">
  <h4 style="margin-top: 0;">Muhammad Saad</h4>
  <!-- affiliation differs from WS1 (PayPal); confirm current employer -->
  <p><strong>X</strong> | Senior Research Scientist</p>
  <p>Muhammad Saad is a Senior Research Scientist. He is interested in advancing the security and privacy of the internet through applied research, with a focus on distributed systems security, web and network security, privacy-enhancing technologies, and social engineering attacks. His experience spans both industry and academia, where he has acquired skills in measurements and modeling, big data analytics, machine learning, and formal analysis.</p>
</div>

<div style="margin-bottom: 40px; overflow: auto;">
  <img src="../assets/images/mclachlan.png" alt="Jon McLachlan" align="left" width="250" height="250" style="float: left; width: 250px; height: 250px; object-fit: cover; border-radius: 50%; margin: 10px 30px 10px 0;">
  <h4 style="margin-top: 0;">Jon McLachlan</h4>
  <p><strong>YSecurity</strong> | Co-founder & Security Leader</p>
  <p><a href="https://www.linkedin.com/in/jon-mclachlan/" rel="noopener" target="_blank"><u>Jon McLachlan</u></a> co-founded <a href="https://ysecurity.io/" rel="noopener" target="_blank"><u>YSecurity</u></a> and hosts <a href="https://open.spotify.com/show/5lK5ZeozOPsZD4cR0Ii5pM?si=b8b458923f9c43f6" rel="noopener" target="_blank"><u>The Security Podcast of Silicon Valley</u></a>. With a history of roles at Apple, Pure Storage, Robinhood, and startups like UnifyId, he has led diverse security teams across various sectors. His approach prioritizes creativity, professional growth, and the human aspect of security. He holds a Master's in Computer Science from the University of Minnesota, specializing in product security and privacy. Jon is passionate about integrating diversity and inclusion into team building and security practices, especially in AI.</p>
</div>

<div style="margin-bottom: 40px; overflow: auto;">
  <img src="../assets/images/Yasser_Shoukry.png" alt="Yasser Shoukry" align="left" width="250" height="250" style="float: left; width: 250px; height: 250px; object-fit: cover; border-radius: 50%; margin: 10px 30px 10px 0;">
  <h4 style="margin-top: 0;">Yasser Shoukry</h4>
  <p><strong>University of California, Irvine</strong> | Professor</p>
  <p>Yasser Shoukry is a professor at the University of California, Irvine, whose research addresses the security, resilience, and verification of AI-controlled cyber-physical systems, drawing on formal methods and control theory to build secure and verifiable autonomy.</p>
</div>

<div style="margin-bottom: 40px; overflow: auto;">
  <img src="../assets/images/Eric_Chan-Tin.png" alt="Eric Chan-Tin" align="left" width="250" height="250" style="float: left; width: 250px; height: 250px; object-fit: cover; border-radius: 50%; margin: 10px 30px 10px 0;">
  <h4 style="margin-top: 0;">Eric Chan-Tin</h4>
  <p><strong>Loyola University Chicago</strong> | Associate Professor & Center Director</p>
  <p>Eric Chan-Tin is an associate professor in the Department of Computer Science, the Director for the Center of Cybersecurity, and the Director of the Fellowship Office at Loyola University Chicago. He is the PI for the NSA/DHS Center of Academic Excellence in Cyber Defense at Loyola University Chicago. He teaches mostly programming and cybersecurity courses. His research is broadly on network/computer security and privacy/anonymity. His research has been funded by the NSF, DoD, NSA, and various companies. He also organizes the Loyola cybersecurity club and coaches student teams to participate in cybersecurity competitions.</p>
  <p>Previously, he was an associate professor in the CS Department at Oklahoma State University. He received his Ph.D. degree from the University of Minnesota in 2011 under the supervision of Dr. Nick Hopper and his B.A. from Macalester College in 2006. His research areas are in network security, distributed systems, privacy, and anonymity. He has published over 30 peer-reviewed papers, including publications at conferences and journals such as ACM CCS, NDSS, ACM TISSEC, and IEEE TIFS. He has also previously worked as a Helpdesk consultant and software engineer at Guidewire and Retek (now Oracle).</p>
</div>

## Learning Objectives

After completing this workshop, you will be able to:

- Describe the core disciplines of data governance, data quality management, security, metadata management, data stewardship, and lifecycle management, and explain why they underpin trustworthy AI.
- Explain GDPR's core data-protection principles and their specific implications for AI, including the constraints on automated decision-making under Article 22, the debated "right to explanation," and Data Protection Impact Assessments.
- Summarize the consumer rights created by California's CCPA/CPRA (the rights to know, delete, opt out of sale, and non-discrimination) and how they apply to AI systems.
- Classify an AI system under the EU AI Act's risk-based tiers, unacceptable/prohibited, high-risk, limited-risk, and minimal-risk, and list the obligations that attach to high-risk systems.
- Situate the US approach as soft law and standards rather than binding statute, mapping the Blueprint for an AI Bill of Rights, the NIST AI Risk Management Framework, the NIST adversarial-ML taxonomy, and the National AI R&D Strategic Plan.
- Compare anonymization, pseudonymization, and encryption as data-protection techniques and explain the limits of each, including re-identification risk.
- Design an AI system to satisfy several overlapping regulatory regimes at once, connecting governance obligations to the secure-development and privacy techniques developed earlier in the program.

## Theoretical Background

### Data Governance Fundamentals

Data governance is the discipline of managing an organization's data so that it remains available, usable, accurate, and secure throughout its life, and is used responsibly and in line with the regulations and internal policies that apply to it. For AI it is foundational rather than administrative: a model is a function of the data it learns from, so the quality and integrity of that data set an upper bound on the fairness, reliability, and trustworthiness of everything built on top of it. Governance is the machinery that makes data trustworthy before it ever reaches a model.

Five capabilities make up the core of the discipline:

| Capability | What it manages | Why it matters for AI |
|---|---|---|
| **Data quality management** | Accuracy, completeness, and consistency of data, through error detection and correction against defined quality standards | Inaccurate or biased training data produces biased, unreliable models; quality is the precondition for a fair one |
| **Data security** | Protection of data from unauthorized access, via encryption, authentication, and secure storage and transmission | Training data is often sensitive; a breach exposes individuals and creates legal liability |
| **Metadata management** | Documentation of data sources, lineage, and transformations, recorded in data dictionaries | Provenance and lineage make a model reproducible and auditable, and let you answer where a decision's data came from |
| **Data stewardship** | Designation of data owners and their roles, responsibilities, and governance policies | Clear accountability ensures someone is answerable for the quality and protection of each data asset |
| **Lifecycle management** | Handling of data through collection, processing, analysis, retention, and disposal | Enforces retention limits and safe disposal, satisfying storage-limitation and minimization duties in law |

The payoff of doing this well is cumulative: accurate data yields fairer models, documented lineage yields auditability, enforced retention limits yield compliance, and clear stewardship yields accountability. Governance is therefore the connective tissue between the engineering practices of Workshop 9 and the legal obligations that the rest of this workshop describes.

### GDPR: The European Baseline

The EU General Data Protection Regulation (GDPR) governs the processing of the personal data of people in the EU, and it reaches any organization anywhere that processes such data, which is why it has become a de facto global baseline. It is built on seven principles that any lawful processing must satisfy.

| GDPR principle | What it requires |
|---|---|
| **Lawfulness, fairness, transparency** | Processing must have a valid legal basis, be free of deception, and be clearly communicated to the data subject |
| **Purpose limitation** | Data may be used only for the specific purposes stated at collection; a new purpose needs a new basis or consent |
| **Data minimization** | Collect only the data necessary for the stated purpose, and no more |
| **Accuracy** | Keep personal data accurate and up to date, and provide means to correct it |
| **Storage limitation** | Retain data only as long as the purpose requires, then delete it |
| **Integrity and confidentiality** | Secure data against unauthorized access, loss, or damage, through encryption and access controls |
| **Accountability** | Be able to demonstrate compliance, document processing, and report qualifying breaches to authorities within 72 hours |

For AI, three implications stand out. First, **automated decision-making**: Article 22 gives individuals the right not to be subject to a decision producing legal or similarly significant effects that is based *solely* on automated processing, with limited exceptions, and where such processing is permitted it must carry safeguards including human review and the ability to contest the outcome. Second, the debated **"right to explanation"**: GDPR requires that individuals receive meaningful information about the logic involved in automated decisions, and although the precise scope of a right to an explanation of any specific decision is contested among scholars and regulators, the direction is unmistakably toward decisions that can be explained. Third, **Data Protection Impact Assessments (DPIAs)**: for high-risk processing, which large-scale profiling and many AI applications qualify as, GDPR requires a documented assessment of the risks to individuals and the measures taken to mitigate them, before the processing begins.

### CCPA and CPRA: The California Model

The California Consumer Privacy Act (CCPA), as strengthened by the California Privacy Rights Act (CPRA), takes a different, rights-based route to a similar end. Rather than imposing a comprehensive processing regime up front, it grants California consumers a set of enforceable rights over their personal information.

| Consumer right | What it grants |
|---|---|
| **Right to know** | To learn what personal information a business collects, and how it is used and shared, and to obtain a copy |
| **Right to delete** | To request deletion of personal information a business has collected, subject to exceptions for legitimate business needs |
| **Right to opt out** | To direct a business not to sell or share personal information (CPRA extends this to sharing for cross-context behavioral advertising) |
| **Right to non-discrimination** | To exercise these rights without being penalized through higher prices or worse service |

CPRA additionally introduced rights to correct inaccurate information and to limit the use of sensitive personal information, and it established a dedicated enforcement agency. For AI, the salient consequences are that training data derived from consumers is subject to access and deletion requests, and that automated profiling which significantly affects consumers falls within the regime's expanding scope, requiring transparency about the use of such systems.

### The EU AI Act: A Risk-Based Regime

Where GDPR governs *data*, the EU AI Act (Regulation (EU) 2024/1689) governs *AI systems* directly. It is the first comprehensive horizontal law for AI, and its central design is a risk-based pyramid: obligations scale with the risk a system poses to health, safety, and fundamental rights.

| Risk tier | Examples | Obligations |
|---|---|---|
| **Unacceptable / prohibited** | Government social scoring, manipulative or exploitative systems, most real-time remote biometric identification in public spaces, untargeted facial-image scraping | Banned outright |
| **High-risk** | AI used in hiring and worker management, creditworthiness and essential services, education, critical infrastructure, law enforcement, and as safety components of regulated products | Full compliance program (see below) before market entry, and throughout operation |
| **Limited-risk** | Chatbots, emotion-recognition systems (except in the workplace and education, where they are prohibited), and generative AI producing synthetic or "deepfake" content | Transparency duties: users must be told they are interacting with, or seeing output from, an AI system |
| **Minimal-risk** | AI-enabled video games, spam filters, and the large majority of AI applications | No mandatory obligations; voluntary codes of conduct encouraged |

For **high-risk** systems the Act specifies a substantial set of obligations, mirrored in the IAPP compliance matrix's mapping of the relevant articles to providers and deployers:

| Obligation | Basis |
|---|---|
| **Risk management system** established, documented, and maintained across the lifecycle | Article 9 |
| **Data and data governance**: appropriate quality criteria for training, validation, and test datasets | Article 10 |
| **Technical documentation** drawn up before the system is placed on the market | Article 11 |
| **Record-keeping / logging** to ensure traceability of the system's functioning | Article 12 |
| **Transparency** and provision of information to deployers so they can interpret and use the system correctly | Article 13 |
| **Human oversight** designed in, so a person can understand, intervene in, and override the system | Article 14 |
| **Accuracy, robustness, and cybersecurity** appropriate to the intended purpose | Article 15 |

The Act also imposes tiered obligations on providers of general-purpose AI models, with heavier duties where a model presents systemic risk. Its provisions phase in over time following entry into force in 2024, with prohibitions applying first and high-risk obligations later.

### The US Landscape: Soft Law and Standards

The United States has, as of this writing, no single comprehensive federal AI statute comparable to the EU AI Act. Its approach is instead a patchwork of sector-specific laws, state legislation, and, most importantly for this workshop, *soft law*: non-binding frameworks, principles, and technical standards that shape practice through adoption, procurement, and expectation rather than direct legal command. Four instruments define it.

- **Blueprint for an AI Bill of Rights** (White House Office of Science and Technology Policy, 2022). A non-binding framework of five principles for the design and use of automated systems: (1) **safe and effective systems**; (2) **algorithmic discrimination protections**; (3) **data privacy**; (4) **notice and explanation**; and (5) **human alternatives, consideration, and fallback**. It articulates what people should be able to expect, without itself creating enforceable rights.
- **NIST AI Risk Management Framework (AI 100-1)**. A voluntary framework structured around four functions, **Govern, Map, Measure, and Manage**, for identifying and mitigating AI risks such as bias, robustness failure, and misuse. It is the AI-specific counterpart to the widely used NIST Cybersecurity Framework introduced in Workshop 9.
- **NIST AI 100-2, Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations**. The authoritative reference behind the attack taxonomy used throughout this program, cataloging evasion, poisoning, privacy, and abuse attacks and their mitigations, and giving governance a shared vocabulary for AI-specific technical risk.
- **National AI R&D Strategic Plan (2023 Update)** and related federal roadmaps. Government strategy documents that set research priorities and direct agencies, including on trustworthy and responsible AI, shaping the standards ecosystem from which much US soft law flows. NIST's draft guidance on managing the misuse risk of dual-use foundation models (AI 800-1) is part of this same standards effort.

The practical takeaway is that US obligations are best read as *expectations that harden into requirements* through federal procurement, agency rulemaking, and state law, rather than as a single binding text. An organization operating in both the EU and the US must therefore satisfy binding European statute and align with American standards at the same time.

### Data Protection Techniques and Their Limits

Governance regimes repeatedly demand that personal data be protected, and three techniques do most of the work. Each buys protection at a cost, and each has a limit that matters.

| Technique | What it does | Strength | Limit |
|---|---|---|---|
| **Anonymization** | Irreversibly removes identifying information (through suppression, aggregation, generalization, or synthetic data) so individuals can no longer be identified | Truly anonymized data falls outside GDPR entirely | Re-identification is often possible by linking with external datasets; genuine, durable anonymization is hard to achieve and easy to overestimate |
| **Pseudonymization** | Replaces identifiers with tokens or salted hashes, keeping the re-identification key separate | Reduces exposure while preserving the data's analytical usefulness and linkability | Remains personal data under GDPR because re-identification is possible with the key; protection depends on protecting that key |
| **Encryption** | Encodes data so only holders of the key can read it, at rest and in transit (symmetric, asymmetric, or end-to-end) | Strong confidentiality in storage and transport; a baseline expectation of nearly every regime | Protects data only while encrypted; it must be decrypted to train or infer, and the security reduces to key management |

The critical, often-missed point is about anonymization. Because machine-learning datasets are high-dimensional and can be cross-referenced with other data, a record stripped of obvious identifiers can frequently be re-identified. Treating pseudonymized data as if it were anonymous is a common and consequential governance error; under GDPR, pseudonymized data is still personal data and still regulated. These techniques therefore reduce risk, they do not eliminate it, and they are complemented by the stronger, principled privacy tools from Workshop 6.

### Designing for Cross-Jurisdiction Compliance

Few real systems face only one regime. A single AI product may serve EU residents (GDPR and the AI Act), Californians (CCPA/CPRA), and users in states or sectors with their own rules, simultaneously. Building a separate system per jurisdiction does not scale, so the practical discipline is to design one architecture to the *highest common denominator* and then accommodate local specifics.

That means adopting the strictest applicable defaults, purpose limitation, data minimization, retention limits, and demonstrable accountability, as the baseline, since a system that satisfies GDPR will already meet much of what other regimes ask. It means treating the EU AI Act's high-risk obligations (risk management, data governance, documentation, human oversight, robustness) as an engineering checklist wired into the development lifecycle rather than a compliance exercise appended at the end. And it means implementing governance as living documentation, DPIAs, model and data lineage, decision logs, so that the same evidence answers a European regulator, a Californian access request, and a NIST-aligned audit.

This is where the program's threads converge. The **secure-development practices of Workshop 9**, input validation, provenance tracking, dependency and supply-chain control, are the mechanism by which many of these governance duties are actually met. And the **privacy-enhancing techniques of Workshop 6**, differential privacy and federated learning, are not only defenses but *governance tools*: differential privacy offers a principled, quantifiable notion of data protection that goes beyond ad hoc anonymization, and federated learning can reduce the movement and central collection of personal data in the first place, directly serving data minimization. Governance sets the obligations; the earlier workshops supply the means.

## Hands-on Lab

This workshop has no coding notebook. A recorded talk covers the governance material instead.

<div class="video-embed">
  <iframe src="https://www.youtube.com/embed/2Do8I3l5kn0?start=2600" title="Workshop 10: Data Governance, talk" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" allowfullscreen></iframe>
</div>

## Key Takeaways

- Data governance, spanning quality, security, metadata and lineage, stewardship, and lifecycle management, is the foundation of trustworthy AI, because a model can be no more reliable or fair than the data it is governed on.
- GDPR sets a global baseline through seven principles, constrains solely-automated decisions under Article 22, points toward explainable decisions, and requires DPIAs for high-risk processing.
- CCPA/CPRA grants California consumers rights to know, delete, opt out of sale or sharing, and not be discriminated against, and reaches AI through consumer data and profiling.
- The EU AI Act regulates AI systems directly on a risk-based pyramid, prohibited, high-risk, limited-risk, minimal-risk, and loads the bulk of its obligations (risk management, data governance, documentation, human oversight, robustness) onto high-risk systems.
- The US relies on soft law and standards, the Blueprint for an AI Bill of Rights, the NIST AI RMF, the NIST adversarial-ML taxonomy, and federal strategy, rather than one binding statute.
- Anonymization, pseudonymization, and encryption reduce but do not eliminate risk; re-identification is a real limit, and pseudonymized data remains regulated personal data.
- Real systems must satisfy several regimes at once; design to the strictest common baseline and meet governance duties with the secure-development and privacy techniques from Workshops 9 and 6.

## Additional Resources

### Slide Deck

- **AI and Data Governance (panel slides, PDF):** [`AI and Data Governance.pdf`](https://github.com/SecureAI-luc/SecureAI-Lab/blob/main/Workshop10/slides/AI and Data Governance.pdf) - the deck accompanying this panel session.

### EU AI Act

- **Official text of the EU AI Act, Regulation (EU) 2024/1689 (PDF):** [`OJ_L_202401689_EN_TXT-1.pdf`](https://github.com/SecureAI-luc/SecureAI-Lab/blob/main/Workshop10/docs/OJ_L_202401689_EN_TXT-1.pdf) - the corrected text as published in the Official Journal of the European Union.
- **EU AI Act Compliance Matrix (IAPP, PDF):** [`eu_ai_act_compliance_matrix.pdf`](https://github.com/SecureAI-luc/SecureAI-Lab/blob/main/Workshop10/docs/eu_ai_act_compliance_matrix.pdf) - maps the Act's articles to operators (providers, deployers, importers, distributors) across high-risk systems, AI systems, and general-purpose AI models.
- **EU AI Act (article-by-article explainer):** [artificialintelligenceact.eu](https://artificialintelligenceact.eu/) - a searchable, article-by-article reference to the Act.

### US Frameworks and Standards

- **Blueprint for an AI Bill of Rights (White House OSTP, PDF):** [`Blueprint-for-an-AI-Bill-of-Rights.pdf`](https://github.com/SecureAI-luc/SecureAI-Lab/blob/main/Workshop10/docs/Blueprint-for-an-AI-Bill-of-Rights.pdf) - the five-principle framework for automated systems.
- **NIST AI 100-2e2023, Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations (PDF):** [`NIST.AI.100-2e2023.pdf`](https://github.com/SecureAI-luc/SecureAI-Lab/blob/main/Workshop03/docs/NIST.AI.100-2e2023.pdf) - the authoritative attack taxonomy used across the program.
- **NIST AI 800-1 (Initial Public Draft), Managing Misuse Risk for Dual-Use Foundation Models (PDF):** [`NIST.AI.800-1.ipd.pdf`](https://github.com/SecureAI-luc/SecureAI-Lab/blob/main/Workshop10/docs/NIST.AI.800-1.ipd.pdf) - draft guidance on the misuse risks of foundation models.
- **National AI R&D Strategic Plan, 2023 Update (PDF):** [`National-Artificial-Intelligence-Research-and-Development-Strategic-Plan-2023-Update.pdf`](https://github.com/SecureAI-luc/SecureAI-Lab/blob/main/Workshop10/docs/National-Artificial-Intelligence-Research-and-Development-Strategic-Plan-2023-Update.pdf) - federal research priorities, including trustworthy and responsible AI.
- **Global AI Governance Law and Policy: United States (IAPP, PDF):** [`global_ai_governance_law_policy_series_us.pdf`](https://github.com/SecureAI-luc/SecureAI-Lab/blob/main/Workshop10/docs/global_ai_governance_law_policy_series_us.pdf) - an overview of the US AI governance landscape.
- **AI Roadmap (CIO, PDF):** [`24_0315_ocio_roadmap_artificialintelligence-ciov3-signed-508.pdf`](https://github.com/SecureAI-luc/SecureAI-Lab/blob/main/Workshop10/docs/24_0315_ocio_roadmap_artificialintelligence-ciov3-signed-508.pdf) - an agency roadmap for adopting and governing AI.

### Authoritative External References

- **GDPR full text and guidance:** [gdpr.eu](https://gdpr.eu/) and the official [EUR-Lex text of Regulation (EU) 2016/679](https://eur-lex.europa.eu/eli/reg/2016/679/oj).
- **GDPR Article 22 (automated individual decision-making):** [gdpr-info.eu/art-22-gdpr](https://gdpr-info.eu/art-22-gdpr/).
- **California CCPA (Office of the Attorney General):** [oag.ca.gov/privacy/ccpa](https://oag.ca.gov/privacy/ccpa).
- **NIST AI Risk Management Framework:** [nist.gov/itl/ai-risk-management-framework](https://www.nist.gov/itl/ai-risk-management-framework).
- **Blueprint for an AI Bill of Rights (White House OSTP):** [whitehouse.gov/ostp/ai-bill-of-rights](https://www.whitehouse.gov/ostp/ai-bill-of-rights/).
- **[Program Resource Library](../resources.md)** - shared papers, tools, and datasets for the full workshop series.

## Next Steps

Continue to [Workshop 11: Secure Deployment and Operation of AI Systems](../Workshop11/Secure_Deployment_and_Operation_of_AI_Systems.md), which turns from the governance obligations surveyed here to the operational security of running AI systems in production, the deployment stage previewed at the end of Workshop 9.
