EU AI Act Risk Tiers, GDPR Data Minimization, and U.S. State Law Converge on Agentic AI Compliance in 2026

Tuesday, June 30, 2026 

Overview

Shannon Yavorsky of Orrick and associate Caitlin Burke surveyed the EU AI Act, GDPR, Digital Omnibus, and U.S. state frameworks governing agentic AI, robotics, and quantum computing, identifying data minimization conflict and black-box opacity as the defining compliance tensions of 2026 and urging organizations to build scalable programs calibrated to the full legislative landscape.

Instructor(s)
Shannon Yavorsky, Partner, Orrick; co-leader of Orrick’s global Cyber, Privacy & Data Innovation group & the firm’s AI practice
Caitlin Burke, Associate, Orrick; Cyber, Privacy & Data Innovation team 

Keywords

EU AI Act risk classification (prohibited, high-risk, limited risk, minimal risk) • GDPR data minimization and agentic AI conflict • Digital Omnibus legitimate interest AI training data 2025 • California ADMT regulations 2026 — CCPA automated decision-making • U.S. state AI legislation 2026 — comprehensive privacy law framework • agentic AI human-in-the-loop governance obligations • black box transparency GDPR automated decision-making • shadow AI governance program system mapping • quantum computing Q Day mandatory post-quantum cryptography compliance • “what are the EU AI Act high-risk AI system requirements” • “how does the EU AI Act interact with GDPR for agentic AI compliance” • FTC Act Section 5 unfair deceptive acts practices AI enforcement

Key Takeaways

  • Agentic AI Triggers Distinct Obligations. Unlike generative AI, agentic AI’s capacity to “independently plan, execute, and adapt a series of actions” with minimal human intervention generates heightened data-access and human-oversight obligations under both the EU AI Act and state privacy frameworks.
  • EU AI Act Risk Tiers Are the Threshold Question. Any company deploying an AI system touching the EU market must first classify it as prohibited, high-risk, limited-risk, or minimal-risk — a determination that drives the entire compliance architecture, including whether risk assessments, audit requirements, and human oversight apply.
  • GDPR and EU AI Act Operate in Parallel. An HR hiring tool, for example, is simultaneously high-risk under the EU AI Act and subject to full GDPR data-subject rights; companies must analyze both frameworks concurrently, as Yavorsky observed: “lots of companies are having to look at both the GDPR and the EU AI Act.”
  • Data Minimization Is AI’s Structural Adversary. Privacy law’s core principle that companies collect only data needed to provide services directly conflicts with agentic AI’s need for “massive amounts of information,” creating a compliance tension that has no easy resolution under current law.
  • Digital Omnibus Eases AI Training Data Burdens. The November 2025 Digital Omnibus proposal would make legitimate interest the default lawful basis for AI model training under the GDPR, reducing friction for European AI development while preserving stricter consent requirements for sensitive data.
  • Shadow AI Is the Governance Threshold Problem. Yavorsky identified system mapping as “really step one” for any AI governance program, given the widespread use by employees of unauthorized AI tools that result in “plugging company data into the tool” without compliance review.
  • Human-in-the-Loop Design Is Non-Negotiable. Both the EU AI Act and sound governance practice require that agentic AI systems be designed so that “a human can monitor and potentially override the AI’s output”; Yavorsky noted that organizations are actively debating the optimal intervention point in agentic workflows.
  • No SME Exemption Under EU AI Act. Unlike the GDPR, the EU AI Act contains “no clear exceptions for smaller businesses,” meaning compliance obligations apply regardless of company size — a point Yavorsky flagged as frequently overlooked by clients.
  • U.S. State AI Law Has Reached Critical Mass. With approximately 1,500 bills proposed and over 150 enacted at the state level as of June 2026, state AI statutes now constitute a mandatory and materially complex compliance layer for any AI product or service touching the domestic market.
  • Scalable Compliance Programs Are the Strategic Imperative. Yavorsky’s overarching counsel was that organizations must build “a scalable compliance program against the backdrop of the quickly moving legislation,” calibrated to the organization’s “overall risk tolerance, in light of all of the laws that are in place.”

B-CLE Recording | Youtube Recording|Resource(s) | Speaker Bio(s) & Contact Info

Download the interview/transcript and slides here!

Interview/Transcript

This interview/transcript featuring Shannon Yavorsky, Partner, Orrick; co-leader of Orrick’s global Cyber, Privacy & Data Innovation group & the firm’s AI practice, and 
Caitlin Burke, Associate, Orrick; Cyber, Privacy & Data Innovation team, addresses emerging technology matters and privacy cybersecurity regulations. 

Wayne Stacy  00:23

So welcome everyone to the Berkeley Center for Law and Technologies expert series webcast. Today we have a wonderful, and not only wonderful, but entertaining topic around emerging technologies and the privacy cybersecurity regulations, and with us, if you’ve been to other privacy programs with us, our primary instructor today, Shannon Yavorsky from Orrick, Shannon is got a long set of titles, but I think the one that matters the most for this is she’s Orrick’s Global Chair for cyber privacy and data innovation, and now I think they’ve added another comment in there and made you the global chair for AI innovation too. If I, if I understand all of your titles, but the easier way to sum that up is that if it’s data related, Shannon’s in charge, I think that’s globally the way to put that, and with us today, for the first time, I’m excited, Caitlin Burke is joining us, she’s an associate at Orrick in the Privacy Group, working with Shannon, just recently finished her JD PhD at a school that I understand is down the road from us here in the, in the Bay Area, I can’t remember its name,

 

Shannon Yavorsky  01:51

Stanford, Stanford

 

Wayne Stacy  01:54

Oh yeah, that’s the red color, I get it. So, I’m really excited to see the two of you together and go through this presentation, so nobody ever comes to listen to me, so I’m going to get out of your way and listen and enjoy. Thank you.

 

Shannon Yavorsky  02:13

Great, thank you so much. Thank you for the kind introduction, Wayne. And I’m so thrilled to be joined by Caitlin here today, we’re, we are going through a number of different topics. We’re going to talk through emerging technology, and then talk about how the different regulatory regimes read on this emerging technology.

 

Caitlin Burke  02:35

So, Shannon, to start with, the emerging technology matters and different topics, would you mind beginning with agentic AI?

 

Shannon Yavorsky  02:44

Yeah, so one of the terms you’re likely hearing more and more about is agentic AI. So, what does that actually mean? Most of us are familiar with generative AI tools at this stage that respond to prompts, so maybe you’ve used ChatGPT and Claude, or one of the other tools that’s out there. You ask a question, request a summary, or draft a document, and the system generates an output. Agentic AI goes a step further, rather than simply responding to a single prompt, an AI agent can be given a goal, and then independently plan, execute, and adapt a series of actions to achieve that goal. So, in other words, it can make decisions about how to complete a task, use tools, gather information, and take multiple steps with very limited human intervention, so for example, moving on to the next slide, instead of asking an AI to draft an email, you might ask an agent to organize a customer meeting, and the agent could review calendars, identify available times, send invitations, prepare briefing materials, all in a coordinated workflow. And on this slide we have just a few examples of some of the agentic AI we’re starting to see out there.

 

Caitlin Burke  04:14

Shannon, would you also mind talking a bit about 2026 trends in robotics?

 

Shannon Yavorsky  04:20

So much is happening in robotics, Caitlin. It’s super exciting. We’re seeing all kinds of humanoid robots taking the headlines. There are also headlines related to both failures and progress. In May of 2026 there was a clip of a robotics failure that went viral after a robot was seen falling off the stage at an event in China. On the other hand, I also recently saw a video of a robot doing a pretty amazing dance, so there are lots of evolution in that space, and we’re seeing just a ton of data collection in order to inform the development of robotics, and one example of that that I just think is really interesting is the rise of arm farms, which is people who are, they have a camera attach their head and it videos what their hands are doing to capture that data to then train robots to do similar things, so think about doing the dishes — all of that data being collected, so that a robot can one day, hopefully very soon, do the dishes, or do laundry, or the complex human tasks

 

Caitlin Burke  05:41

And rounding out this section on emerging technology matters. How about trends in quantum computing in 2026

 

Shannon Yavorsky  05:49

So, quantum computing has been the topic of discussion for years, but we’re in the people who are really into quantum computing often talk about Q Day, and we’re now seeing meaningful progress that is moving the technology from primarily theoretical research toward really practical applications. At a high level, Quantum computers differ from traditional computers because they use quantum bits or qubits, which can process certain types of problems in fundamentally different ways, so while we’re still at the early-ish stages of commercial deployment, investment and development efforts continue to accelerate. There are a few key trends worth watching, and just to go back to that something, actually today, a very interesting company, Quantinuum, which was a spin-off from Honeywell, had an IPO, and that I think demonstrates how we’re seeing sort of lots of trend like this trending upwards and steady improvements in hardware performance, for example, and there are technology companies, startups, and governments are investing heavily in increasing the number and quality of qubits, while reducing error rates. So, even though today’s systems are limited, the pace of advancement is really, really significant. And then the second thing I want to mention is that organizations are increasingly exploring the practical use cases, so again going back to the fact that this was sort of theoretical before, a lot of theoretical research these days, industries like pharma, material science, logistics, financial services, and energy are all evaluating how quantum computing could really help solve complex optimization, simulation, and modeling problems that are difficult, early, really time consuming for classical computers.

 

Caitlin Burke  08:05

Thank you so much for that introduction on different emerging technology matters. Shannon, would you mind starting to bring us into the different regulatory regimes, which are both constraining and helping these different matters innovate?

 

Shannon Yavorsky  08:21

Yeah, sure thing. So I think the most important law that everyone is paying close attention to, is the EU AI Act, which is a regulation in Europe that is a risk-based approach to regulating, regulating AI, so I think a lot of people are familiar with the GDPR, the General Data Protection Regulation, that focuses on protecting on personal data, the collection and use of personal data, but the EU AI Act, which interestingly preceded the development and deployment of large scale foundation models, so it was really, before ChatGPT came out, the EU AI Act was being drafted, and at the time, the what was in scope was really predictive analytics and machine learning, and they kind of had to pause when Gen AI was launched, because they needed to review how those definitions worked for the new use cases that were unlocked with Gen with Gen AI, and at a very high level, the EU AI Act sort of organizes AI into a couple of different buckets. There’s prohibited AI, so on a real-time biometric surveillance, emotion recognition in workplace or in schools, anything that manipulates human behavior is flat out prohibited. There’s another bucket of high-risk AI systems, and these are the I think the one that is most relevant for that we’re seeing our clients focus on are things like hiring HR tools, so if you think about anything that might impact an individual hiring, firing, getting credit, for, as another example, those things likely fall into this bucket of high-risk AI systems, which have a number of different obligations associated with them. Their risk assessments are required, human oversight, the high quality data, their data documentation and audit requirements for that bucket of high risk AI systems. Then there’s a bucket, and it’s not written, I don’t think it’s on the next slide, but I think it’s worth mentioning, there’s also limited risk AI systems, and those are things like chat bots, right? Really, they’re just transparency requirements. So, if you’re launching an AI chat bot, you just have to tell people that they’re interacting with AI and not a human, so that’s the more limited risk AI. And then there’s a lower, lower category of minimal risk, so these are things like a spam filter, right? Like it’s not going to hopefully cause any harm, you might not get an email, I don’t know, but not so risky for not so potentially harmful to individuals. So let me just recap that for you. It’s minimal risk spam filters, limited, limited risk, which is like chat bots, high risk, think HR systems, and then prohibited, which is, you know, real-time biometric public surveillance, as a, as another, as another example. Oh, wow, we got through a lot of those. That’s great. And this is, I really like this slide, actually, on the interplay between the EU AI Act and the GDPR. The idea is that the EU AI Act was going to be one rule to rule them all in relation to AI, but in reality it hasn’t turned out to be the case, because alongside the EU AI Act, you have the GDPR, which regulates how companies collect and use personal data, and of course, companies are collecting and using personal data in the context of AI systems, so lots of companies are having to look at both the GDPR and the EU AI Act to understand how their product or service might be regulated if they’re using personal data in the context of an AI system, an HR, an HR hiring system is a great example of that. It falls into the high-risk bucket under the EU AI Act. Also, lots of personal data, so companies are having to look at both of these regulations to understand their interplay and how they’re, how they’re regulated. All right, so, there are really interesting privacy issues associated with, with AI. Some of the AI, and we’ve seen this with other technologies as well. A good example is blockchain, where some of those principles that are the way in which blockchain operates were antithetical to privacy law. As an example, with blockchain, you are, the point of blockchain is, in many cases, is that it is a public blockchain that is immutable, it’s unchangeable, right? You can’t move it. It would disrupt the core functionality of that technology. Whereas GDPR says if there’s personal data, you have to be able to delete it or amend it. So, what happens when there’s this friction between, you know, the public blockchain being immutable, and the GDPR saying personal data has to be able to be deleted or amended or changed. There’s this sort of fundamental dissonance that happens, and so we’re seeing a little bit of that with privacy and AI services. So one of the main ways this shows up is with data minimization. The core principle in privacy legislation, privacy legislation all around the world is this concept of data minimization, where companies are only supposed to collect the data and use data that they need to provide the services. Well,  Q AI services would, and especially Agentic AI, which needs massive amounts of information, including personal data, in order to provide good results. You have to train models on lots and lots of data sets in order to get a good result. So, there’s this friction that happens between privacy legislation and what’s happening with the evolution of AI services, and you can see that really with the in the context of agentic AI, because agentic AI, that is off doing not only coming up with answers but doing things, thrives on context, it wants to read all of your emails and look at your whole schedule in order to schedule a meeting with someone, and by doing that, by getting that context, it just has access to massive amounts of data. Another really core friction that we see is the fact that a lot of AI models are black boxes, we don’t know exactly how they work or exactly how they came up with a particular answer, and this is even predates large language models. I think the really early example of that was it was a game of Go, which is a Korean game, I believe, and oh my god, I hope that’s right. Where it’s very difficult, and there was a particular move, and it was like old, the like old school AI was playing on the other side, and they couldn’t figure out why the computer had made a particular move, and that was the initial sort of example that people go to, of this is a black box, we don’t know why it made this decision, and so that is again antithetical to the core privacy principle of transparency, of having to, of telling people, providing meaningful information about the logic involved in automated decisions, and that becomes really challenging when you’re not 100% sure exactly how AI has made a decision, and you think about how that shows up in hiring decisions, in credit decisions, like whether you do, you want a machine deciding whether you get a mortgage or not, and unpacking, like, why it decided that you were not credit worthy, you could not buy a new, no, you could not buy a new car, as an example, so you can see where this, how this plays out in real life, and can be potentially harmful to individuals. So that’s another thing that we’re really wrestling with I would say.

 

Caitlin Burke  17:56

And so maybe as we conclude this section, what are some top five things for us to think about when using automated decisions?

 

Shannon Yavorsky  18:05

So I think the AI literacy obligations, which show up in the EU AI Act, is making sure that everyone who’s involved in using AI tools, which, let’s face it, it’s now like everyone at a company should be using AI in some, it’s kind of like when you know the dawn of the internet, it, you can’t be an analog employee anymore. Everybody has to be using AI, but they need to understand how the systems work and the risks that are posed by the system, so that education becomes really, really important. Next is system mapping and classification. This is a sticky problem. Companies don’t always know or get their arms around all of the different systems that are actually in use at an organization. There’s a lot of what we refer to as shadow AI, and that is your people in regular employees who are like, Oh, look at this amazing tool that’s going to help me do my job. They’ve made it as frictionless as possible to click through the terms of service, and all of a sudden they’re plugging company data into the tool, so getting your arms around the systems that are in use at an organization is, is really step one. It’s like the cornerstone for building an AI governance program. Next, I think is vendor looking at the vendor agreements. We’re starting to see companies develop and deploy AI addenda at a large scale, kind of like how we saw the evolution and deployment of data processing agreements. It’s almost like every agreement now has an AI section or a separate AI addendum, and maybe that addendum says, hey, you service provider will not use any AI, but more often than not it will say, if you’re using AI, you need to tell us or place some guardrails on the uses of AI in the context of the provision of the services. Next, and this is a recurring theme in AI governance, is human in the loop, so if you’re using tools that are making decisions, you have to have, or using agentic AI is another great example, you have to design it so that a human can monitor and potentially override the AI’s output, and that’s really important. We’re having a lot of conversations now about the point at which that human in the loop needs to be needs to enter the scenario, so at what stage do you put the human in the loop to review what agent has done, for example, or review a decision that AI has made. Another point to make, finally, on this slide is that there are no exemptions for smaller, like with the GDPR. There are no clear exceptions for smaller businesses, so you still need to comply with many of the features of the EU AI Act. So a good thing to really be thinking about that.

 

Caitlin Burke  21:26

And I think we’ve touched on this a bit already, but how would you think about the digital omnibus as intersecting with the EU AI Act and GDPR?

 

Shannon Yavorsky  21:35

So the Digital Omnibus, which was proposed and officially released in November of last year was designed to help align the emerging digital strategy legislation in Europe, and I’ve talked about the EU AI Act and the GDPR, but there’s also the Data Act, the Digital Markets Act, the Digital Services Act. So, there is, in the last couple of years, there’s been just a lot of new legislation, and in Europe, and the Digital Omnibus Proposal, instead of creating net new law, it acts as a master amendment to these existing laws to help them avoid some of the overlap between the laws and just make it easier for companies to comply with the law, so I think we talked a little bit, this is this is a really great slide talking about some of the core features, this lawful basis. These are the lawful bases of processing under the GDPR that folks are lots of folks are familiar with it at this point. So, consent is one example of a lawful basis of processing that requires lots of different processing activities require user individual consent, whereas the digital omnibus interpretation, it’s reserved for sensitive data or private spaces. I think there are some interesting points with respect to AI training data. Legitimate interest, this is another really interesting development under the GDPR. There’s this really pretty complex three-part process for establishing that there’s like a balancing exercise for whether you can rely on legitimate interest or not, you have to look at whether it’s in the legitimate interest of the company, and that’s not outweighed by the rights and freedoms of the data subject, so the legitimate interest would be sort of the default for training under the digital under the digital omnibus, so I just wanted to hit on a couple of things there, but I think we can move on to the next slide

 

Caitlin Burke  24:16

And I think you’ve touched on some of these issues already, but rounding out this section, thinking about the EU AI Act, the GDPR, the Digital Omnibus. How do you see these different regimes as intersecting with emerging technology matters?

 

Shannon Yavorsky  24:32

Yeah, great, really great question. So any company that’s deploying, let’s call it agentic services at the organization will need to look at whether it falls within one of those buckets of the of risk under the EU AI Act. Is it for some reason prohibited? Is it high risk? Is it a high-risk service? And then under the GDPR, they’ll need to think about, okay, is the data that I’m using in the context of this service, am I permitted to do that? And then they’ll have to look at the Digital Omnibus, the impact of the Digital Omnibus proposal, and see whether is it, are there any changes there that might make their compliance a little bit easier, and that I mean, I think those three, looking at those across those three laws, is going to become really standard for all of the technologies we’ve just talked about. So, for agentic and then for robotics and also in the context of quantum computing, so looking at where it falls on the scale under the EU AI Act, understanding whether there’s personal data being used in the context of that technology, and then what the compliance obligations are from there, and then looking at the layering on of the Digital Omnibus to see whether any of that impacts the compliance obligations.

 

Caitlin Burke  26:10

So, thank you for the talking about these global regimes moving back to the US. Shannon, would you mind giving us an overview of US data privacy laws, and then we’ll talk about how those laws intersect as well with these emerging technology matters.

 

Shannon Yavorsky  26:25

Yeah, sure thing. So I’m going to talk about the privacy legislation, and a little bit about AI. So, privacy legislation in the US, there are federal sectoral privacy laws, so think about the COPPA [Children’s Online Privacy Protection Act] for children’s data, the FERPA [Family Educational Rights and Privacy Act] for education data, the HIPAA [Health Insurance Portability and Accountability Act] for protected health information. So, there’s this federal sectoral landscape, but there are also now about, depends on the week, I think 21 different comprehensive state privacy laws, and those state privacy laws look a whole lot like the GDPR. They’re comprehensive, they have disclosure obligations, they have data subject access request requirements, they have obligations in relation to data processing agreements, so in privacy legislation you have this world of federal laws, and then you have this world of state privacy laws. Now I want to talk — let’s put that to one side for the moment, and then let’s talk about AI law in the US, which is a pretty complex landscape, and when I talk about this, I like to help people understand that there are five key things to think about. So, number one, there are federal laws, like the FTC [Federal Trade Commission] Act, and employment legislation, still applies to AI, right? So, even though there’s no federal AI act, there’s no single AI law for the US. Existing federal legislation applies to AI, and the federal agencies have made clear that they will regulate AI as it falls within their jurisdictional authority. So that brings us to bucket number two, which is guidance documents issued by the FTC, the EEOC [Equal Employment Opportunity Commission], the CFPB [Consumer Financial Protection Bureau], as it then was to explain how they will regulate AI as it falls within their jurisdictional authority, so existing federal laws, federal guidance that layers on how that the agency is going to interpret their federal laws. The third bucket that applies to AI is all of those different state privacy laws that I talked about, the 21 different state privacy laws, talk about notices and automated decision making technology, so all of those privacy laws. The fourth area that applies to AI is state AI legislation, and in the last year, and we’re in June of 2026 right now, but in the last year there have been about 1500 bills proposed at the state level in relation to AI, so the state AI statute world is incredibly complex. Over 150 laws have passed now at the state at the state level, and we have publicly available on the Orrick website and AI law tracker that shows just the laws that have gone into effect, so that’s the fourth area that you have to look at when you’re looking at AI technologies and services, or the state AI laws, and then the fifth area is litigation and investigation. And the litigation investigations and settlements help us understand what regulators and litigants are focused on from an issues perspective, and so far it’s been pretty clear that the agencies are focused on things that can harm people, so some of the early cases have been about around there was one that was in relation to an automated tool for loans, as one example, the FTC has been focused on unfair and deceptive acts and practices, so all of that, settlements, litigations, investigations rounds out the fifth area of law that applies to AI in the US, so that’s a high level overview, and I think it’s helpful to organize under those core rubrics.

 

Caitlin Burke  30:58

And would you mind, Shannon, shifting a little bit into some more state-specific efforts, such as California’s ADMT rights?

 

Shannon Yavorsky  31:07

Sure, so California has the California Consumer Privacy Act [CCPA] and the  CPRA [California Privacy Rights Act], and is enforced by both the California AG and Cal privacy, which is the California Privacy Protection Agency [CPPA], and in I want to say January of this year, the final automated decision making technology regulations were published, and that helps us understand additional obligations that are placed on companies if they are using automated decision making technology.

 

Caitlin Burke  31:54

Moving quickly kind of towards the, we’ve gotten such a great overview of these different regimes moving back into the question of emerging technology matters. You’ve touched on this already, but would you mind talking a little bit about how you see these different regimes in the US intersecting with agentic AI, quantum computing, and even robotics?

 

Shannon Yavorsky  32:17

Sure thing. So I think like we, the exercise that we did for Europe, where you have to look at the AI Act and privacy legislation, the GDPR, it’s really similar, so you have to look at the comprehensive state privacy laws, the 21 different state privacy laws for each of these buckets, for agentic quantum and robotics. You’re going to need to look at the privacy laws. You’re going to need to look at the regulations we just talked about. You’re going to need to look at whether any of the federal law reads on it, and then whether any of the state AI statutes apply to this kind of technology, so it’s really similar calculus of the different buckets of laws that you need to look across in order to understand whether your technology, your product, or service complies with the whole legislative landscape.

 

Caitlin Burke  33:19

And thank you so much, Shannon, for such a comprehensive overview of both global regimes and US law as it pertains to emerging technology matters. And what are some maybe key takeaways from this section for the CLE?

 

Shannon Yavorsky  33:37

Yeah, great, really great question. I think that any company that is either deploying or using or developing emerging AI technology really needs to understand the full legislative landscape to help them really orient around what to focus on from a compliance standpoint, and to build a scalable compliance program against the backdrop of the quickly moving legislation. It’s really important to stay on top of the new laws to understand what regulators are focused on, and then calibrate that to the organization’s overall risk tolerance, in light of all of the laws that are in place. How does the company want to develop a resilient and durable compliance program?

 

Caitlin Burke  34:36

Thank you so much, Shannon, for such a fascinating overview of emerging technology in 2026.

 

Shannon Yavorsky  34:42

Thanks so much, Caitlin.

 

Caitlin Burke  34:44

Thank you.

This transcript was created with an automated transcription service and reviewed by a human