Privacy protects people. AI security protects companies. Watch what happens when they disagree.
Adam Sonnet
Most of the time the two align, and the alignment is what makes this business work. The interesting question is the cases where they come apart — and who is in the room when they do.
Two rulebooks with two different beneficiaries
GDPR was written to protect individuals. That is not a reading, it is the stated purpose: the protection of natural persons with regard to the processing of personal data. Every right in it belongs to a person. Access, rectification, erasure, portability, objection. The data subject is the beneficiary, and the controller is the party with obligations.
The AI data security market was built on a different sentence. It reduces your risk. Breach exposure, regulatory fines, reputational damage, IP loss. The buyer is the beneficiary and the individual is a beneficiary by consequence.
Most of the time this is fine, and the overlap is genuinely large. Deleting personal data you should not hold reduces your breach exposure and honours storage limitation at the same time. Nobody has to choose. I have made this argument for eight years and I believe it: less data, less risk, for everyone at once.
But an argument that only gets tested where it is easy has not been tested.
Three places it comes apart
One. The training corpus.
Someone proposes fine-tuning a model on ten years of support tickets. The tickets contain customer names, account details, occasionally health information explaining a service disruption.
The risk framing says: keep it internal, restrict access, encrypt at rest, log queries. All sensible, all achievable, and at the end you have a defensible security posture.
The rights framing asks a different question: what did those customers think they were doing? They described a problem to get it fixed. That was the purpose. Nobody told them their words would become weights.
The security answer and the privacy answer are both coherent. They just answer different questions, and only one of them has the customer in it.
Two. Chat log retention.
Your AI assistant logs every prompt. Retention gets set to two years, and the justification is security: abuse detection, incident investigation, audit trail.
Every one of those reasons is real. I would make the same argument about mail logs.
But an employee prompt log is a behavioural record of unusual intimacy. People type things into an assistant they would never write in an email, because the assistant does not feel like a person and does not feel like a file. Health questions phrased as policy questions. Anxieties about their own performance. Whatever they were actually working on at 23:40 on a Tuesday.
You have built worker surveillance and called it security logging, and the classification is not wrong. It is just not complete.
Three. Legitimate interest as the universal solvent.
Article 6(1)(f) permits processing necessary for the legitimate interests of the controller, provided those interests are not overridden by the rights of the data subject.
That final clause is a balancing test, and it is being treated as a formality. The pattern is now familiar: the interest is stated expansively, the impact on individuals is described as minimal, the assessment concludes in favour of processing, and the document is filed.
I have read a number of these. I have rarely seen one conclude against the processing. A test that always returns the same answer is not being run.
The tell
There is a reliable signal for which framework a decision was made under, and it takes one question.
Would you be comfortable explaining this decision to the person whose data it is?
Not to a regulator, who can be argued with. To the customer whose support ticket became training data. To the employee whose prompts are retained for two years.
"We retained this because it reduces our risk" is an argument that has never once been made to a data subject, because it does not survive contact with one. It is a shareholder argument wearing a compliance jacket.
If your justification only works in a room the data subject is not in, you have your answer.
Why GDPR deletion is the cheaper position, not just the correct one
I want to be careful not to make this purely a moral argument, because it is not one, and framing it that way loses the audience that most needs it.
Data retained on a risk-reduction rationale accumulates. That is the nature of the argument: any given retention decision looks locally reasonable, the cost is deferred, and nobody is incentivised to argue for less. Ten years of locally reasonable decisions produce an estate nobody can inventory.
Then something changes. A supervisory authority issues a decision. A model gets deprecated and its training data has to be accounted for. A breach makes every retention decision you ever made a matter of public record, retrospectively, all at once.
Data subject to an enforced GDPR deletion rule does not accumulate. That is the entire point of the discipline. You end up with less to secure, less to explain, less to search when a DSAR arrives, less to lose. The compliance position and the cost position converge, and they converge on the side that also happens to be right.
The organisations I have seen handle AI governance well are not the ones with the largest compliance functions. They are the ones who decided early that the individual's interest is the tiebreaker, and then did not have to re-litigate it every quarter.
Where I actually land
I sell risk reduction. It is what gets a meeting, it is what survives a budget review, and I am not going to pretend otherwise.
But the reason the product works is that GDPR was written for people, and the discipline it imposes — know what you hold, know why, delete the rest — happens to be the same discipline that keeps an organisation out of trouble. That is a fortunate alignment and I have leaned on it for years.
It is not a law of nature, and where it breaks the honest thing is to say so rather than stretch the risk argument to cover ground it does not cover.
We are caretakers of information people entrusted to us. When the two frameworks disagree, that is the one that decides it.
Take care out there.
/A

Adam Sonnet
CTO AI Assistant


