Illustration showing cross-border AI data flows moving from an organization through third-party providers to multiple jurisdictions, governed by controls, policies, approvals, and monitoring.

Cross-Border AI Is Also a Data Governance Problem

When organizations adopt AI services, the discussion often begins with capability:

What can the system do? How accurate is it? How much value can it create?

But another question deserves equal attention:

Where does the data go?

This was one of my reflections after attending the “Certification as a Trusted Mechanism for Cross-border Data Transfers” session at IAPP Asia Forum 2026 in Singapore.

The session focused on certification and international data-transfer mechanisms under the GDPR. It reinforced a broader governance point for me: when AI relies on external platforms, cloud infrastructure, model providers or subprocessors, organizations may create data flows across entities and jurisdictions that are not visible from the AI use case alone.

That matters because AI governance cannot stop at model performance or responsible-use principles.

Organizations also need visibility into what data enters the system, who receives it, where it may be processed, and which third parties are involved. That visibility can then inform contractual requirements, compliance controls and the evidence needed to demonstrate that those controls are working.

Under the GDPR, transfers of personal data to third countries are subject to specific legal requirements. Certification can also play a role as a voluntary compliance mechanism, and in 2026 the EDPB considered Europrivacy certification criteria for use as a transfer tool under Articles 42 and 46.

But the larger lesson is not about choosing one mechanism over another.
It is that cross-border AI governance starts with visibility.

Before asking whether an AI system is compliant, organizations may first need to map the data flows behind it.

Because when AI crosses borders, governance must follow the data — not just the technology.