An organisation launches twenty AI initiatives. Legal reviews twenty use cases. Six months later there are two hundred. The organisation hires more reviewers. Twelve months later there are six hundred. The backlog grows anyway. Business units start routing around the process. Governance coverage becomes performative: the review function is still running, but it is covering a fraction of what the organisation is actually doing.

This is not a hypothetical. It is the trajectory organisations deploying AI at volume tend to find themselves on. The inherited governance model was designed for a different volume. When new data processing activities arrived occasionally, reviewing each one individually was practical. AI programmes generate use case requests at a rate that model was never designed to handle.

The Digital Personal Data Protection Act did not create this problem. It made it impossible to ignore. Organisations that were informally managing the backlog can no longer do so informally. The Act requires assessments to be documented, consistent, and defensible. At the volume AI creates, that requirement exposes a scaling failure that was already underway.

The governance surface

The governance surface is the number of independent governance decisions an organisation must make and defend. Not the number of AI initiatives. Not the number of use cases reviewed. The number of decisions that are genuinely independent of each other, where the reasoning cannot be inherited from a prior decision because the question is genuinely new.

Governance cost scales with governance surface, not AI volume. Every independent decision must be analysed, documented, defended, and kept consistent with every other decision. That is where the cost sits. AI volume can grow ten times while governance surface grows barely at all, if the additional volume consists of requests sufficiently similar to existing precedent that they inherit rather than generate independent decisions. In organisations that reuse prior judgment effectively, legal review grows with the rate of genuine novelty, not with the number of AI initiatives.

In the inherited model, every use case is treated as an independent decision. Three hundred AI use cases produce a governance surface of three hundred. Each decision must be documented, each must be consistent with the others without any structural mechanism ensuring that consistency, and each must hold up individually if challenged. In the precedent model, the governance surface is determined by genuine novelty. Three hundred use cases may produce twenty genuinely novel governance decisions. The remaining two hundred and eighty inherit their reasoning from one of those twenty. The governance surface is twenty.

The same volume. A different governance surface.

Inherited model
300 requests. Governance surface of 300.
300use case requests treated as individually novel
300independent legal decisions required
300records to document and defend
300opportunities for inconsistency
Precedent model
300 requests. Governance surface of 20.
20genuinely novel cases requiring independent legal decisions
280cases inheriting reasoning from prior decisions
20records to document and defend
Consistency determined by governing precedent rather than individual reviewer interpretation

Reducing the governance surface does not mean less governance. It means the same governance applied at a level where each decision compounds. One precedent governs every future case the LLM identifies as sufficiently similar to inherit it.

The real problem is not volume. It is retrieval.

When a legal reviewer examines an AI use case request, most of what they do is pattern recognition: is this similar enough to something we have reviewed before that the same analysis applies? For the majority of requests the answer is yes. The combination is familiar. The purpose is consistent with previously approved purposes. The legal basis applies as it did in analogous cases.

The inherited model requires the reviewer to determine manually whether a new request is sufficiently similar to prior decisions for the same reasoning to apply. The prior judgment exists. Prior approvals, DPIAs, legal opinions, and policy decisions contain years of reusable reasoning. Recognising when a new request is similar enough to inherit that reasoning does not scale. It requires a trained reviewer to read the new request, recall or search prior decisions, and make the connection. At low volumes that is manageable. At the volume AI creates, it is the bottleneck.

Pattern-based governance has existed as an idea for decades. Large organisations have always known that prior decisions contain reusable reasoning. What was missing was a reliable way to recognise similarity at scale. A new request described in different language, involving slightly different data assets, for a marginally different stated purpose, would not surface the prior decision in a keyword search. Recognising that two differently described use cases raise the same legal question required a trained reviewer to make the connection manually. It was tried. It was called knowledge management. It mostly failed because matching quality was not good enough to make it operationally reliable. The decisions were stored. The similarity between new requests and existing decisions could not be determined at scale.

"AI finally gives us a way to reuse legal judgment instead of rediscovering it. That is the change this moment makes possible."

What LLMs change about this

LLMs are unusually effective at recognising semantic similarity across descriptions that use different language to describe the same underlying pattern. That capability is precisely what pattern-based governance has always required and never had a reliable mechanism for.

A new use case request submitted in natural language can be assessed against a corpus of prior decisions not through keyword matching but through semantic similarity. The LLM extracts the governing dimensions of the request: the data assets involved, the processing purpose, the outputs the model will produce, the jurisdictions, the transfer mechanisms. It then assesses those dimensions against the governed precedent set, identifying which prior decisions are sufficiently similar that their analysis can be inherited, and which dimensions are genuinely novel and require fresh legal assessment.

The challenge is not creating the library. Large organisations already have one in the form of prior approvals, DPIAs, legal opinions, and policy decisions. The challenge has always been recognising when a new request is sufficiently similar to inherit an existing decision. That is the problem LLMs solve. The library was always there. The retrieval mechanism was not.

The same problem, a different domain
The semantic registry was not valuable because it stored meaning. It was valuable because it made similarity retrievable. Legal governance has the same structure.
The prior legal decision exists. The value of LLMs here is their ability to recognise that a new request, described differently, raises the same legal question as a case already reviewed. Not replacing the lawyer. Finding the precedent the lawyer already created.

"LLMs do not remove the need for legal judgment. They change where legal judgment is applied: from recognising similarity to assessing novelty."

Governance is the management of novelty

Novelty, in the governance sense, means a combination that raises a legal question the organisation has not previously answered in any sufficiently similar form. Genuine novelty is rare. Most AI use cases involve data asset types the organisation already holds consent for, processing purposes within the scope of existing notices, and legal bases already applied to analogous combinations. They are not identical to prior cases, but they are sufficiently similar that the governance question is the same. The organisation has already answered it. The LLM finds that answer.

A precedent is a previously reviewed combination: data asset types, processing purpose, legal basis, applicable transfer restrictions, and the analysis that produced the outcome. The precedent captures the reasoning, not just the decision. A future case inheriting a precedent is not accepting a machine decision. It is inheriting a documented legal analysis made by a qualified person, retrieved because an LLM recognised the semantic similarity between the new request and the prior case.

The governance job is to validate the similarity judgments, review genuinely novel cases, and ensure the precedent set remains current as regulation evolves. The precedent set is not built from scratch. It emerges from decisions the organisation has already made. The LLM's role is to assess whether a new request is sufficiently similar to existing precedent to inherit it, and to identify specifically which dimensions are genuinely novel. Novelty is escalated. Similarity is inherited. The legal judgment does not disappear. It compounds.

Inherited model: every case treated as novel
New use case arrives
v
Legal reviewer assesses from first principles
v
Prior decisions searched by keyword. Semantically similar cases in different language not surfaced.
v
Decision recorded
v
Next similar case starts from scratch. Judgment exists. Not retrievable.
Precedent model: similarity retrieved, novelty escalated
New use case arrives
v
LLM extracts governing dimensions: assets, purpose, outputs, jurisdictions, transfers
v
LLM assesses semantic similarity against governed precedent set
v
Sufficiently similar: inherits prior analysis. Genuinely novel: escalated to legal with specific question identified.
v
Novel case adds to precedent set. Next similar case inherits the answer.

What the Act changes about this

The Act structures its requirements around purposes, not use cases. Processing must be for a specific, clear, and lawful purpose. Data principals must be informed of that purpose. Consent must be specific to the purpose. That structure already implies that purposes are defined at a level above individual processing instances and that new activities are assessed against them. Organisations that have made their prior legal reasoning retrievable have built what the Act requires: a governed framework new activities are checked against, with documented escalation for activities that fall outside it.

The Act's rulemaking is ongoing. Significant data fiduciary designations, consent manager requirements, and cross-border transfer rules are still being developed. A governed precedent set must be reviewed when rules change. An organisation with retrievable prior reasoning can update a governing decision when a rule changes and propagate that update to every case that inherited from it. An organisation relying on individual reviewer judgment must hope that every reviewer absorbs every regulatory development consistently.

What happens if you keep the inherited model

AI programmes become constrained by governance throughput. Not by model capability. Not by data availability. Not by engineering capacity. By the rate at which legal can review use cases.

The trajectory is predictable. AI adoption increases. Review volume increases with it. Legal headcount grows, but consistently trails deployment volume because hiring is slow and training takes time. Backlogs emerge. Business units learn that governance is slow and begin routing around it: scoping requests narrowly to avoid triggering full review, describing use cases in terms that fit pre-approved patterns even when the actual processing differs, proceeding informally with the intention of retrospective approval that never quite arrives.

Governance coverage becomes performative. The review function is still running. The volume it covers is a fraction of what the organisation is actually deploying. The regulatory exposure accumulates in the gap between what was formally reviewed and what was actually running. Under the Act, that gap is no longer invisible. It is a documentation failure that a regulator or data principal can surface. The organisation discovers it has two problems: a backlog it cannot clear and a compliance record it cannot defend.

"The question is no longer whether legal can review every AI initiative. The question is whether legal judgment can be reused faster than AI generates new requests."

In the inherited model, the answer is no. The review rate is fixed by human capacity. The request rate is set by the organisation's AI deployment ambition. Every quarter the gap widens. Every quarter more of the organisation's AI activity falls outside the governance perimeter.

Organisations that continue to treat every request as novel will find governance headcount growing alongside AI deployment. Organisations that make prior judgment reusable will find that one decision can govern hundreds of future requests. The difference is not legal capability. It is whether the organisation can recognise similarity before it starts another review.