← Blog

GDPR Isn't Your Biggest AI Problem

Mads Kristiansen

CTO, Liviate

It's become the standard response: "We can't move forward with AI because of GDPR."

It sounds responsible. It signals prudence. And it effectively halts any progress.

But in the vast majority of Danish organizations, it isn't actually true.

GDPR is rarely what's actually blocking AI initiatives. It's simply the most acceptable place to put the blame. Because behind that explanation lie three far more fundamental problems: lack of data ownership, absence of auditability, and, most importantly, a lack of internal trust.

If you don't address those three, you won't get anywhere — no matter how compliant you are.

GDPR is a known quantity, and that's exactly the point

GDPR isn't new. It isn't unpredictable. It's a well-defined set of rules with clear principles: purpose limitation, data minimization, transparency, and the right to access and erasure.

If your organization already handles personal data today — and most do — you're already operating within that framework. AI doesn't fundamentally change that. It just makes the weaknesses more visible.

The problem isn't that the rules are unclear. The problem is that your data foundation isn't built to live up to them in practice.

So when GDPR is used as a roadblock, it's often a proxy for something else: "We don't have our data under control, and we know it."

Problem 1: No one knows who owns the data

Ask around the organization: Who owns customer data? Who's responsible for its quality? Who's allowed to approve its use in new contexts?

You rarely get a clear answer.

In many Danish companies, data is "something IT has," but not something anyone actually owns. That works fine — until someone wants to actively use the data, for example for AI.

AI demands explicit decisions: Can this data be used for this purpose? What's the consequence if the output is wrong? Who's accountable for it?

Without clear ownership, every decision becomes political. And it's far easier to say "GDPR" than to take responsibility. Projects stall — not because they're illegal, but because no one dares approve them.

Problem 2: Lack of auditability

Even if you're allowed to use the data, the next problem arises quickly: can you explain what's happening?

Which data was used? When was it retrieved? Which model generated the output? Can you reproduce the result?

In classic software, this is already a challenge. In AI systems, it becomes critical. Because if an employee or a citizen asks: "How did you arrive at this result?" — "we're not entirely sure" isn't an acceptable answer.

Many organizations only discover at this point that their setup wasn't built for traceability. Data flows between systems without clear logs. Transformations aren't documented. Output can't be explained. And once again: it's easier to say "we're not allowed to, because of GDPR" than to admit "we can't document what we're doing."

Problem 3: Lack of internal trust

The biggest, and most overlooked, problem is trust. Not legal trust. Internal trust.

Management doesn't trust the output. The business units don't trust the data. IT doesn't trust how the business uses it. Compliance doesn't trust any of it.

AI amplifies this because it introduces a new kind of uncertainty: output is probabilistic, errors are harder to predict, and accountability is unclear. In a Danish context, where decisions are often consensus-driven, this quickly becomes a dead stop. If no one feels comfortable, the default decision is to do nothing. GDPR then becomes the shared language everyone can hide behind.

Where GDPR actually is relevant

That doesn't mean GDPR doesn't matter. It does.

But it's important to be precise about where it actually applies: the use of personal data in training or inference, transfer of data to third countries, automated decisions with legal effect, and transparency requirements toward users.

These are concrete, manageable issues. Organizations that succeed with AI in Denmark do neither: they don't ignore GDPR, and they don't use it as an excuse either. They operationalize it.

What those organizations do differently

There's a pattern among the companies and public bodies that actually make progress.

They establish clear data ownership — not in theory, but in practice. Every dataset has an owner, someone responsible for quality, and an approval process for its use. That alone removes 80% of the friction.

They build auditability in from the start, not as a compliance layer bolted on afterward. They ensure logging of data flows, versioning of models and prompts, and the ability to reproduce output. That makes it possible to stand behind the system.

They start with low-risk use cases: internal document search, draft responses, support tools for employees. That builds trust gradually, without betting everything at once.

They make uncertainty explicit instead of hiding it. Output is labeled as a suggestion. There's always a human in the loop. Limitations are communicated clearly. That reduces fear, both internally and externally.

The real blocker

The real blocker is rarely legal. It's organizational: unclear responsibilities, lack of systematic process, low trust.

GDPR is just the most acceptable place to park the problem.

But it's also an opportunity. Because if you commit to solving the underlying challenges — getting data ownership under control, establishing auditability, building internal trust — GDPR suddenly becomes something you can work with instead of against.

Saying "we can't, because of GDPR" feels safe. But in most cases, it isn't accurate.

The harder, and more valuable, realization is: We're not ready yet. Not because the law is stopping us, but because our foundation isn't strong enough.

That's actually good news. Because unlike GDPR, which you can't change, you can change your own organization.

That's where the work begins.

Want to talk about what's actually blocking your AI initiatives?

Mads Kristiansen is happy to have a no-obligation chat.

Book a meeting →