Colorado repealed its AI Act — the ADMT law that replaced it starts January 1, 2027See what changed →
The chrome lion scanning data packets for personal information
🔐 Privacy

AI didn't create your privacy obligations. It stretched them.

You already answer to HIPAA, GDPR, or CCPA. What changed is that a tool nobody reviewed can now send the data somewhere nobody approved, and make a decision you have to be able to explain. Same duties, new surface.

Where it bites

Three moments privacy law meets an AI tool

“Someone pasted a client record into a chatbot.”

Whether that's a breach depends on which tool, what agreement is in place, and what the vendor does with it — three facts your inventory should already hold.

“A customer asked us to delete everything.”

You have 30 or 45 days depending on the law, and the answer has to include whatever went into the AI tools too.

“Explain how the system decided that.”

GDPR Article 22 and the CCPA ADMT rules both ask. The impact assessment you already completed is the explanation.

Privacy rules, mapped

The privacy laws you already answer to

Each of these gets its own crosswalk showing where your program addresses it — and, just as usefully, where it doesn’t yet.

CCPA / CPRA
California residents

Notice before collection, deletion on request, an opt-out of automated decision-making, and knowing which vendors received what. The ADMT rules share Colorado's January 1, 2027 date.

Pro plan and above
GDPR
People in Europe

A lawful basis, a stated purpose, and the ability to explain an automated decision to the person it was made about. Article 22 is the one AI keeps walking into.

Agency plan
HIPAA
Health information

If patient data could reach an AI tool, the business associate agreement and the safeguards have to be in place first — before the tool is switched on, not after.

Agency plan
What you get

Four things, and none of them is a PDF of the statute

A crosswalk per law

Each requirement sits next to the clause in your own program that answers it, and the ones nothing answers are listed as gaps rather than quietly omitted.

A privacy policy you can publish

Generated from your own answers and grounded in the same cited control library as everything else. Pro plan and above.

The deletion clocks, tracked

A request arrives, the clock starts. 30 days for GDPR, 45 for CCPA, counted for you, with the overdue ones surfaced before they are overdue.

A breach response plan

Written in advance, with the notification deadline on it, because the afternoon of a breach is the worst possible time to be drafting one.

Privacy frameworks are included in the plans noted above — CCPA on Pro and above, GDPR and HIPAA on Agency. A defensible starting point that you review and approve, not legal advice.

About the founder
Jim TunnessenFounder & CEO, GOVERNBOX.ai
Former 2× Federal CIO / CAIO / CTO / CPO

Two decades directing large-scale technology portfolios, enterprise risk management and applied machine learning — which is why the control library is authored and versioned the way it is, rather than assembled from templates.

Gradient Descent LLC is an independent company. GOVERNBOX.ai is not affiliated with, endorsed by, or produced on behalf of any government agency.

Find out what's leaving your building

The free scorecard asks what data your team puts into AI tools, and shows you the gaps.

Take the free scorecard →