I Was in Brussels When GDPR Was Born. Here's What the EU AI Act Is Really Repeating.
In the summer of 2015, I stood inside the Berlaymont Building in Brussels, the seat of the European Commission, as a law student studying comparative international law. Two days after my program ended, the Council of the EU finalized the document that gave it the mandate to enter Trilogue and negotiate what became the General Data Protection Regulation.
What I did know, from six weeks of briefings across Paris, Strasbourg, Brussels, and London, was that something tectonic was shifting beneath the surface of European law, and that the United States had very little idea it was coming.
Read the full essay
The Room Where It Happened. The Comparative Law Program I participated in was not a tourist circuit: it was a structured immersion into the institutions shaping international law in real time. In Strasbourg, we sat inside the Grand Chamber courtroom of the European Court of Human Rights, and afterward Judge Nona Tsotsoria of Georgia took our group into a private chamber for a direct discussion. In Brussels, at the Justus Lipsius Building, home of the European Council, we were close to negotiations that had been deadlocked for three years, and briefed by attorneys at Steptoe & Johnson who walked us through the legislative landscape with the clarity you only get from practitioners watching a bill take shape in real time. Having spent time on Capitol Hill as a legislative assistant drafting legislation that became law, I recognized the texture of that room immediately. This wasn't theoretical. This was the machinery.
What I took away from those weeks was not a summary of GDPR's key articles. It was an understanding of the underlying tensions: who has jurisdiction over foreign companies, what constitutes a legitimate reason to process personal data, how high fines should be set before they actually change corporate behavior. And underneath all of it, a transatlantic fault line: the Safe Harbor Agreement, visibly under strain, was struck down by the Court of Justice of the EU that October in the Schrems I ruling.
The EU AI Act Is the Same Fight, Wearing Different Clothes. Now, working across GRC, AI governance, and regulatory compliance, I find myself reading the EU AI Act with an odd sense of familiarity. The territorial scope fight under Article 2, whether EU law should bind foreign companies whose AI systems affect EU residents, is the same argument as GDPR's Article 3. The EU's answer with GDPR was yes, and the enforcement record since then has demonstrated they meant it. The exemptions carved out for general-purpose AI models carry an uncomfortable resemblance to the "legitimate interest" loophole that consumed so much of the GDPR Trilogue. And the transatlantic tension that produced Safe Harbor's collapse in 2015, Privacy Shield's collapse in 2020, and the ongoing fragility of the EU-U.S. Data Privacy Framework is now playing out in AI governance divergence. The EU is building a risk-tiered regulatory architecture. The United States is not.
What Practitioners Need to Carry Forward. The organizations that navigated GDPR most effectively were not the ones that waited for the regulation to take final shape before beginning their work. They were the ones that understood the intent behind the rules: the values, the fears, the political compromises, and built governance programs durable enough to absorb the details as they evolved. The EU AI Act is in a similar position now. The text is finalized, but the standards, implementing acts, and enforcement precedents are still being written. The practitioners who will be most effective are those who understand why these rules exist, not just what they require.
Some rooms you sit in shape how you view everything that comes after. That summer spent in Europe was one of mine. If you're working on EU AI Act readiness, GDPR compliance, or cross-jurisdictional governance, I'd welcome the conversation.