Not the same as privacy governance
Privacy governance asks whose personal data it is and what rights apply. AI governance asks whether the system that uses that data is lawful, documented, and under control. A GDPR-clean process can still produce biased or unexplained outputs; a classified model can still train on data with no valid basis. High-risk AI that processes personal data typically needs both a DPIA (GDPR Art. 35) and, for some deployers, a FRIA (AI Act Art. 27).
