Writing / Field Guide
The Field Guide
A practitioner's glossary for the law–AI–data intersection — 23 terms, explained plainly, with a Global South lens. Not academic definitions. Working ones, written for people drafting submissions, not reading textbooks.
Practitioner's lexicon
Authoritative working definitions for key terms at the intersection of law, AI governance, and data privacy — with every entry noting what it means for practitioners outside Brussels and Washington.
Under the EU AI Act's risk-stratified architecture, a high-risk AI system is one whose deployment in specified critical sectors — including biometric identification, critical infrastructure management, educational and vocational assessment, employment-related decision-making, essential public services, law enforcement, migration and border control, and the administration of justice — carries a materially elevated probability of causing harm to health, safety, or fundamental rights. The classification triggers a mandatory conformity assessment regime requiring documented technical robustness, human oversight obligations, data governance protocols, and registration in the EU's centralized AI database prior to market placement.
For practitioners in the Global South, the critical question is how analogous risk-tiering principles can be transposed into domestic regulatory instruments that lack the institutional infrastructure — notified conformity bodies, enforcement agencies, sector-specific technical standards — that underpin EU implementation; a direct legislative copy without that institutional substrate produces a nominally rigorous regime that is functionally unenforceable.
A general-purpose AI model (GPAI model) is trained on broad data at scale and is capable of competently performing a wide range of distinct tasks, integrable into a plurality of downstream systems — the paradigm case being large language and multimodal foundation models. The EU AI Act's Chapter V introduces a tiered GPAI regime: all providers must maintain technical documentation and comply with copyright obligations regarding training data, while providers of models assessed to present systemic risk (operationalized by a computational threshold of 10²⁵ floating-point operations for training) face heightened obligations including adversarial testing, incident reporting, and cybersecurity measures.
The GPAI regime creates a structural tension with data privacy law that is particularly acute in cross-border contexts: training-data transparency obligations necessarily require disclosure of sourcing practices, which surfaces compliance questions under GDPR-equivalent provisions — a tension most emerging-market jurisdictions are only beginning to legislate.
A Data Protection Impact Assessment (DPIA) is a structured, prospective risk-analysis process mandated under Article 35 GDPR — and incorporated by reference or analogy in a growing number of Global South data protection statutes — whenever a proposed processing operation is likely to result in high risk to data subjects' rights and freedoms. A compliant DPIA must, at minimum, describe the envisaged processing and purposes, assess necessity and proportionality, assess risks to data subjects, and document mitigation measures.
In the AI context, DPIAs have acquired heightened relevance as a pre-deployment governance tool: where a system's logic is opaque by design, the DPIA process forces controllers to articulate the systemic effects of automated processing — effectively operating as a rudimentary AI impact assessment in jurisdictions that lack a purpose-built instrument.
Algorithmic accountability is the normative and legal framework by which persons responsible for designing, deploying, or operating an automated decision-making system can be required to explain, justify, and where necessary remediate decisions affecting others. It synthesizes administrative law (procedural fairness), tort law (product liability and negligence), human rights law (non-discrimination, due process), and consumer protection — with growing consensus favouring an ex ante model imposing obligations at the design stage rather than relying solely on ex post litigation.
The practical challenge in low-resource jurisdictions lies not in the absence of applicable legal doctrine but in the asymmetric information and technical capacity between regulators and regulated entities: an accountability regime is only as strong as the enforcing institution's ability to audit the system against which accountability is claimed.
A regulatory sandbox is a time-limited, supervised experimentation framework permitting designated firms to test novel products or business models in a live-market environment under relaxed or modified regulatory requirements, on the understanding that the regulator will observe outcomes and ultimately determine permanent regulatory treatment. Originally developed in financial services regulation (the UK FCA sandbox is the foundational model), the instrument has migrated to AI governance: the EU AI Act expressly mandates national AI regulatory sandboxes.
For counsel advising technology clients where AI-specific regulation is nascent, the sandbox offers a strategically valuable pathway: legal certainty during the experimental period, proactive engagement with regulators before adverse enforcement positions crystallize, and evidence that can shape the eventual permanent framework.
Data localisation describes a regulatory mandate — absolute or conditional — requiring personal data to be stored or processed on servers physically located within a designated territory, restricting or conditioning transfer abroad. The rationale ranges from national security and law enforcement access, to economic sovereignty, to privacy protection. Pakistan's PDPA and India's DPDP Act both contain localisation provisions, though scope and permissible transfer mechanisms differ materially.
Localisation mandates create structural tension with global AI training pipelines, which depend on aggregating large, geographically dispersed datasets: a strict regime applicable to personal data effectively prohibits that data from cross-border LLM training without a jurisdiction-specific adequacy finding — a compliance burden most global GPAI providers have not yet operationalized for Global South jurisdictions.
Explainability refers to an AI system's capacity to furnish intelligible, sufficient accounts of how it arrives at outputs, in a form useful to the relevant human audience — affected individuals, auditors, regulators, or courts. It must be distinguished from interpretability (a technical property of a model's internals) and transparency (a disclosure obligation): a system can be transparent about its limitations without being interpretable, and interpretable models may still fail to explain adequately to lay persons.
The legal tension is acute for large language models: transformer architecture renders faithful mechanistic explanation practically impossible with current tools, creating a compliance gap wherever a regulatory framework imposes meaningful explanation obligations — a gap post-hoc methods (LIME, SHAP) address only partially.
Automated individual decision-making (AIDM) is a legal or similarly significant determination reached solely through automated means — without meaningful human involvement — based on personal data. Article 22 GDPR gives data subjects the right not to be subject to such a decision, including profiling, except under defined exceptions (explicit consent, contract necessity, or domestic legal authorisation with safeguards). The qualification "solely" is operative: a reviewer who rubber-stamps AI output without genuine deliberation likely does not break the automated chain.
For counsel advising on AI deployment in credit, employment, or criminal justice contexts, the practical advice is to design human-in-the-loop oversight as a substantive procedural safeguard rather than a formal check-box — documented, consequential, and capable of overriding the recommendation, or it will not survive regulatory scrutiny.
Contextual adequacy is a proposed regulatory doctrine — advanced in the author's forthcoming monograph — under which the legality of an AI system's deployment is assessed against the specific institutional, cultural, and rights environment of the receiving jurisdiction rather than a universal technical compliance standard. It proceeds from the observation that existing international AI governance frameworks are calibrated to the enforcement capacities of their originating jurisdictions, and systematically fail to account for weak regulatory institutions, high informality, resource asymmetry, and the absence of meaningful redress mechanisms elsewhere.
The doctrine does not propose a lower standard of protection; it argues for a different starting question — what constitutes an adequate governance response given actual institutional conditions, rather than the institutions of the EU or US. It reframes AI governance from a matter of technology standards to one of institutional design and capacity-building.
AI liability is the body of doctrine — drawn from tort, contract, product liability, and administrative law — determining who bears legal responsibility for harm caused by an AI system's operation. Mainstream ML systems combine characteristics that frustrate traditional liability attribution: opacity, emergent behaviour, distributed causation across a deployment chain, and non-determinism. The EU's proposed AI Liability Directive attempts to address causation difficulties through a rebuttable presumption of causal linkage where a defendant has breached an AI Act obligation and harm resulted.
In Global South jurisdictions, AI liability questions arise within tort frameworks developed long before algorithmic harm was conceivable. Practitioners must work creatively within existing doctrine — negligence and product liability — while advocating for purpose-built legislative reform addressing causal attribution directly.
Digital sovereignty is a contested political-legal concept describing a state's claimed right to exercise effective control over digital infrastructure, data flows, and technological systems within its territory. It encompasses related but distinct claims: data sovereignty (control over data flows), platform sovereignty (regulatory authority over global platforms operating domestically), technological sovereignty (capacity to develop strategic technologies without critical foreign dependence), and AI sovereignty. It has become a central organising concept for Global South states asserting a regulatory posture reflecting their own priorities rather than Brussels' or Washington's.
The discourse carries an inherent tension: the most plausible interventions to assert sovereignty — localisation, platform access conditions, audit requirements — impose compliance costs that may deter foreign investment, entrenching the dependency sovereignty claims aim to address. Effective strategy requires distinguishing assertions that redistribute power from those that merely impose friction.
Algorithmic bias refers to systematic, unjustifiable disparities in AI outputs that disadvantage individuals or groups on protected or proxy characteristics, reproducing or amplifying existing inequalities. It encompasses historical bias, representation bias, measurement bias, and feedback loops. Whether algorithmic bias qualifies as unlawful discrimination depends on whether anti-discrimination frameworks designed for human decision-makers can be interpreted to capture automated systems — a question unresolved in most Global South legal systems.
The Global South context adds a distributional dimension: systems deployed at scale here are frequently trained predominantly on Western, English-language data, producing both performance disparities and representational harms for out-of-distribution populations — a dimension that has received comparatively little regulatory attention despite its wide practical effect.
An adequacy decision is a formal determination — most consequentially, by the European Commission under Article 45 GDPR — that a third country offers a level of data protection essentially equivalent to the EEA, permitting unrestricted personal data transfers without supplementary safeguards. Absent adequacy, organisations rely on alternative mechanisms — Standard Contractual Clauses, Binding Corporate Rules — each with limitations, particularly in the AI context where data flows are diffuse and continuous.
As of 2026, none of the major Global South AI-relevant jurisdictions — Pakistan, Nigeria, Kenya, Indonesia, Bangladesh — holds a GDPR adequacy determination. This creates a persistent structural barrier to participation in European digital markets. Strengthening supervisory authority independence and enforcement capacity is the most direct lever available toward adequacy candidacy.
Coined by legal scholar Anu Bradford, the Brussels Effect describes the EU's capacity to unilaterally regulate global markets by setting standards so demanding that multinational firms find it cheaper to apply them worldwide than to maintain separate compliance regimes per jurisdiction. GDPR is the canonical case: companies with no EU establishment adopted GDPR-grade data practices globally rather than fragment their systems. The EU AI Act is widely expected to reproduce the pattern for AI governance.
For Global South practitioners, the Brussels Effect is a double-edged tool: it can raise domestic compliance standards for free — riding on obligations firms have already built for the EU market — but it also means domestic regulators can end up enforcing rules they had no hand in drafting, calibrated to European institutional capacity and priorities rather than local ones.
Regulatory capture occurs when an agency created to act in the public interest instead comes to advance the interests of the industry it regulates — through information asymmetry (the regulator depends on the regulated for technical expertise), revolving-door staffing, or sustained lobbying pressure that a resource-poor agency cannot match. The concept originates in public-choice economics but is now a standard diagnostic tool in administrative law.
The risk is structurally elevated in nascent AI regulators: a new authority with few in-house technical staff, facing well-resourced global AI firms as its primary source of both compliance data and technical briefing, is capture-prone almost by design. Guarding against it usually means building independent technical capacity before, not after, the first major enforcement dispute.
Proportionality, rooted in German administrative law (Verhältnismäßigkeit) and now a foundational principle across EU and human-rights law, requires that any interference with a right be suitable to its stated aim, necessary (no less-intrusive alternative achieves the same result), and balanced against the burden imposed. It structures GDPR's data-minimisation principle, runs through the EU AI Act's risk-tiering logic, and is the standard courts apply under the ECHR when weighing state interference against individual rights.
Proportionality analysis is where most AI governance arguments are actually won or lost: a measure that is facially legitimate can still fail if a narrower alternative was available. Drafting compliance justifications, or challenging a regulator's order, without walking through the three-part test is the single most common gap in submissions from jurisdictions where the doctrine is less embedded in legal training.
A lawful basis is one of six grounds under Article 6 GDPR that must exist before any personal data processing is lawful: consent, contractual necessity, legal obligation, vital interests, performance of a public task, or legitimate interests. No amount of good-faith intent substitutes for identifying which basis applies — and it must be identified before processing starts, not retrofitted afterward. Most GDPR-modelled statutes across South Asia and the Gulf reproduce a version of this six-basis structure.
In practice, "consent" is reached for by default far more often than it should be — it is also the weakest basis operationally, since it must be freely given, specific, and revocable at any time, which is awkward for anything resembling an ongoing AI training pipeline. Contractual necessity or legitimate interests are frequently the more defensible basis for AI-adjacent processing, provided the accompanying balancing test is actually documented.
India's Digital Personal Data Protection Act 2023 deliberately departs from GDPR's "data controller" terminology, naming the equivalent role a Data Fiduciary — the person who, alone or with others, determines the purpose and means of processing digital personal data. The word choice is not decorative: "fiduciary" imports a connotation of duty of care toward the individual, closer to trust law than to GDPR's more procedural "controller" framing, and India's Parliament has been explicit that this framing was intentional.
For practitioners comparing India's regime to GDPR or Pakistan's PDPA, resist mapping "Data Fiduciary" onto "Data Controller" as a pure synonym — the enhanced duty language can matter in how Indian courts interpret a fiduciary's obligations in a dispute, particularly around purpose limitation and the "Significant Data Fiduciary" category, which carries extra obligations (DPO appointment, independent data audits) once notified by the central government.
The DPDPA 2023's counterpart term to GDPR's "data subject" is Data Principal — the individual to whom the personal data relates. Where a minor or a person with a disability is concerned, the Act extends the definition to include a parent, lawful guardian, or the person acting as a lawful guardian on their behalf for purposes of exercising rights under the Act — a structural provision GDPR handles through separate, more scattered clauses on children's data.
Pairing "Data Fiduciary" and "Data Principal" as India's own vocabulary — rather than translating them into GDPR's "controller" and "subject" by habit — matters when drafting cross-referenced compliance memos: citing the wrong term signals unfamiliarity with the statute to an Indian regulator or opposing counsel in a way that a generic "data subject" reference does not.
Under Article 43 EU AI Act, providers of high-risk AI systems must complete a conformity assessment before market placement — a formal evaluation that the system meets the Act's requirements on risk management, data governance, technical documentation, human oversight, and accuracy, robustness, and cybersecurity. Depending on the risk category, this is either an internal control procedure conducted by the provider, or a third-party assessment by a notified body — an organisation formally designated and audited by an EU member state to perform these evaluations.
No jurisdiction outside the EU currently operates an equivalent notified-body infrastructure for AI. A Global South regulator drafting a conformity regime without first establishing (or contracting for) an accredited assessment capacity risks legislating an obligation that providers cannot practically discharge — the same institutional-substrate problem that recurs across this glossary.
Legitimate interest is the sixth lawful basis under GDPR — processing is permitted where necessary for the legitimate interests of the controller or a third party, unless overridden by the interests or fundamental rights of the data subject. It is the only basis that requires a documented, three-part balancing test on the controller's own initiative: identify a genuine interest, show the processing is necessary to achieve it, and weigh that necessity against the individual's rights.
It is often the more defensible basis for internal AI system training and improvement than consent, precisely because it doesn't require the data subject's active, revocable agreement to an ongoing process — but only if the balancing test is actually written down before processing starts. An unwritten legitimate-interest assessment is functionally indistinguishable, on audit, from no legal basis at all.
Article 17 GDPR's right to erasure — popularly the "right to be forgotten" — entitles a data subject to request deletion of their personal data where it is no longer necessary for the purpose collected, consent is withdrawn, processing was unlawful, or the data subject objects and no overriding legitimate ground exists. It is subject to significant exceptions: freedom of expression, legal compliance obligations, public interest archiving, and the establishment or defence of legal claims all can defeat an erasure request.
In the AI context, erasure raises a genuinely unresolved technical question: deleting a record from a database is straightforward, but "unlearning" a data point that has already shaped a trained model's weights is, with current methods, extremely difficult and sometimes practically impossible without full retraining. Regulators and providers are still working out what a good-faith erasure obligation looks like once data has entered a model rather than sitting in a queryable store.
Red-teaming, borrowed from cybersecurity practice, is structured adversarial testing in which evaluators deliberately attempt to elicit harmful, unsafe, or policy-violating outputs from an AI system before or after deployment, in order to identify and mitigate weaknesses that ordinary testing would miss. Under Article 55 EU AI Act, providers of GPAI models with systemic risk are required to conduct adversarial testing as part of their risk-mitigation obligations, alongside incident reporting and cybersecurity measures.
Red-teaming is one of the few AI-safety practices that transfers reasonably well to low-resource regulatory environments without requiring heavy institutional infrastructure — it can be contracted out, run by a small internal team, or even crowdsourced — which makes it a comparatively practical starting obligation for a Global South regulator building an AI oversight regime from close to zero.
Currently writing · Forthcoming monograph
Regulating Intelligence at the Periphery
The "Contextual Adequacy" entry above (term 09) is drawn from this in-progress book — a foundational legal theory for AI governance that starts from the conditions of the Global South rather than Brussels or Washington.
Practitioner toolkits
Operational guides written for in-house counsel, compliance teams, and policy advisors. Free to reference — attribution appreciated.
PDF Guide · 1 Page
The AI Governance Readiness Checklist for Legal Counsel
A one-page blueprint enabling in-house legal teams to self-assess their organisation's AI governance posture — asset inventory, vendor risk, data provenance, human-in-the-loop controls, and continuous monitoring.
PDF Briefing · 2 Pages
Cross-Border Data Flows & AI Training: A Primer for Emerging Markets
An executive briefing on the legal friction between localised data privacy regimes and borderless LLM training pipelines, closing with three tactical compliance frameworks for jurisdictions where AI-specific legislation is still embryonic.