Harmonizing Data Protection with Cutting-EdgeTechnologies: A Cross-Examination of AI andCybersecurity Regulations

Authors

  • Ravish Singh Research Scholar, Department of Law, Sharda School of Law, Sharda University, Greater Noida, Uttar Pradesh, India
  • Tarun Kaushik Assistant Professor, Department of Law, Sharda School of Law, Sharda University, Greater Noida, Uttar Pradesh, India

Keywords:

Data Protection, AI Technologies, Cross-Examination, Cybersecurity Regulations, Personal Data

Abstract

The blistering development of the latest technologies, including artificial intelligence (AI), has fundamentally changed the manner in which personal data is gathered, processed, analyzed, and used, bringing forth tensions never seen before with traditional data protection regimes. There must be a fine balance between promoting innovation, providing strong cybersecurity, and preserving basic privacy rights to harmonize data protection with these frontier technologies. The main areas of crossexamination of AI and cybersecurity regulations are presented and compared with other major jurisdictions such as the European Union (EU) and its General Data Protection Regulation (GDPR) and the United States and its sectoral and state strategies and India under the Digital Personal Data Protection Act, 2023 (DPDP Act). These frameworks are examples of divergent philosophies that include rights-based and prescriptive in the EU, innovation driven and disjointed in the US, and consent-based with developmental goals in India. The inherent nature of AI as a massive data processing model trainer, opaque algorithmic decision-maker, inferred automated decisions, and increased cybersecurity risks in the form of data poisoning attacks, model inversion attacks, or
adversarial inputs that infer weaknesses in privacy is the fundamental dilemma of privacy principles, such as consent, transparency, data minimization, purpose limitation, and accountability, that are to be reconciled with the nature of AI.

References

1. Batlle A, van Waeyenberge A. Reflections on the data protection compliance of AI systems under the EU AI Act. Cogent Soc Sci. 2024; Advance online publication. doi: 10.1080/23311886. 2025.2560654.

2. European Data Protection Board. AI privacy risks & mitigations – Large language models (LLMs). 2025 [cited 2025 Apr]. Available from: https://www.edpb.europa.eu/system/files/2025-04/ai-privacy-risks-and-mitigations-in-llms.pdf.

3. Maham E, Küspert S. General-purpose AI risks and governance [report]. Stiftung Neue Verantwortung; 2023.

4. Mantelero A. AI and fundamental rights: A comparative perspective. In: Veale M, Zuiderveen Borgesius F, editors. The Cambridge handbook of artificial intelligence and the law. Cambridge: Cambridge University Press; 2022. p. 83–105.

5. Casarosa F. Dual-use risks in general-purpose AI: Cybersecurity implications under the EU AI Act. Internet Policy Rev. 2024;13(3). doi: 10.14763/2024.3.1790.

6. European Parliament. Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Off J Eur Union. 2024.

7. Krook J, Winter P, Downer J, Blockx J. A systematic literature review of artificial intelligence (AI) transparency laws in the European Union (EU) and United Kingdom (UK): A socio-legal approach to AI transparency governance. SSRN Electron J. 2024. doi: 10.2139/ssrn.4976215.

8. Laksito J, Pratiwi B. Harmonizing data privacy frameworks in artificial intelligence: Comparative insights from Asia and Europe. PERKARA J Ilmu Huk Polit. 2025;2(4):579–588.

9. Calzada I. Trustworthy AI for whom? GenAI detection techniques of trust through decentralized Web3 ecosystems. Big Data Cogn Comput. 2025;9(3):62. doi: 10.3390/bdcc9030062.

10. Gesley J. Netherlands: face-recognition company Clearview AI fined for violating EU’s General Data Protection Regulation. Glob Leg Monit (Library of Congress). 2024. Available from: https://www.loc.gov/item/global-legal-monitor/2024-10-16/netherlands-face-recognition-company-clearview-ai-fined-for-violating-eus-general-data-protection-regulation.

11. Leenes R. The General Data Protection Regulation: Challenges for patients’ rights in AI-driven healthcare. Common Mark Law Rev. 2018.

12. Brown RD, Harmon A, Yaacoub S. Enhancing the EU AI Act with CSR: the role of corporate social responsibility in AI regulation. TalTech J Eur Stud. 2025.

13. Center for Security and Emerging Technology (CSET), Georgetown University. Harmonizing AI guidance: Analysis of frameworks on AI safety, cybersecurity, privacy, and risk management. 2024. Available from: https://cset.georgetown.edu/wp-content/uploads/CSET-Harmonizing-AI-Guidance.pdf.

14. Olarinde O. Assessing frameworks for eliciting privacy & security requirements from laws and regulations. ResearchGate Publication; 2022.

15. Feng S, et al. Bias in large language models: Implications for privacy and cybersecurity. 2023.

16. Veale M, Zuiderveen Borgesius F. AI and the right to explanation under GDPR: Harmonization challenges. Int Data Priv Law. 2021;11(2):112–130.

17. Europol. Cybersecurity threats from general-purpose AI systems [report]. Europol; 2023.

18. National Institute of Standards and Technology (NIST). AI risk management framework. 2023–2025.

19. DLA Piper. Data protection laws in the United Kingdom (post-Brexit comparative with EU AI Act). 2025. Available from: https://www.dlapiperdataprotection.com/?c=GB.

20. IBM. What is AI governance? 2025. Available from: https://www.ibm.com/think/topics/ai-governance.

21. Al-Karaki JN. Data privacy and security standards in AI-powered scientific research. In: Ensuring secure and ethical STM research in the AI era. IGI Global; 2025.

22. Munroe J. Strengthening healthcare cybersecurity through multi-cloud and AI. 2025.

23. European Union. Directive (EU) 2022 on measures for a high common level of cybersecurity across the Union (NIS 2 Directive). 2022.

24. U.S. Department of Justice. Preventing access to U.S. sensitive personal data and government-related data by countries of concern. Fed Regist. 2025;90(5). Available from: https://www.federalregister.gov/documents/2025/01/08/2024-31486/preventing-access-to-us-sensitive-personal-data-and-government-related-data-by-countries-of-concern.

Published

2026-02-24

How to Cite

Harmonizing Data Protection with Cutting-EdgeTechnologies: A Cross-Examination of AI andCybersecurity Regulations. (2026). Journal of Human Rights Law and Practice, 9(1), 24-28. https://lawjournals.celnet.in/index.php/jhrlp/article/view/1994