<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>notraced</title>
    <link>https://notraced.com</link>
    <description>Practical AI privacy guidance for builders. Every article starts from a situation, not a regulation.</description>
    <language>en</language>
    <managingEditor>Shephard</managingEditor>
    <atom:link href="https://notraced.com/feed.xml" rel="self" type="application/rss+xml" />
    
    <item>
      <title><![CDATA[When you call OpenAI, who actually processes your data? The AI sub-processor cascade]]></title>
      <link>https://notraced.com/articles/ai-sub-processor-cascade</link>
      <description><![CDATA[A trace-walk of one OpenAI API call through every entity in the cascade, with the Article 28, CLOUD Act, Article 48, and DMA layers stacked on top.]]></description>
      <pubDate>Thu, 09 Apr 2026 00:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://notraced.com/articles/ai-sub-processor-cascade</guid>
    </item>
    <item>
      <title><![CDATA[Otter, Fireflies, Zoom AI Companion: when meeting transcription becomes a confidentiality breach]]></title>
      <link>https://notraced.com/articles/meeting-transcription-tools-confidentiality</link>
      <description><![CDATA[Four named confidentiality failure modes for AI meeting notetakers, anchored in the Brewer v Otter and Cruz v Fireflies 2025 cases and the EU consent stack.]]></description>
      <pubDate>Thu, 09 Apr 2026 00:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://notraced.com/articles/meeting-transcription-tools-confidentiality</guid>
    </item>
    <item>
      <title><![CDATA[A customer asks 'what does your AI know about me?' How to answer an Article 15 request when you ship LLM features]]></title>
      <link>https://notraced.com/articles/dsar-ai-systems</link>
      <description><![CDATA[GDPR Article 15 for AI stacks after CEF 2024 and CJEU C-203/22. The copy, the explanation, the sub-processor list, and the one-month clock.]]></description>
      <pubDate>Wed, 08 Apr 2026 00:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://notraced.com/articles/dsar-ai-systems</guid>
    </item>
    <item>
      <title><![CDATA[Right to erasure when your AI used the data: what's actually deletable in 2026]]></title>
      <link>https://notraced.com/articles/right-to-erasure-ai-models</link>
      <description><![CDATA[GDPR Article 17 applied to AI stacks after the EDPB's February 2026 CEF report. Three deletability tiers, what unlearning cannot do yet, and a response template.]]></description>
      <pubDate>Wed, 08 Apr 2026 00:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://notraced.com/articles/right-to-erasure-ai-models</guid>
    </item>
    <item>
      <title><![CDATA[Your AI feature just leaked customer data. The first 72 hours, hour by hour]]></title>
      <link>https://notraced.com/articles/ai-data-leak-first-72-hours</link>
      <description><![CDATA[An operational guide for AI data leaks. GDPR Article 33 timing, containment, evidence preservation, notification templates, three worked incident walkthroughs, and the regulator differences that catch teams off guard.]]></description>
      <pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://notraced.com/articles/ai-data-leak-first-72-hours</guid>
    </item>
    <item>
      <title><![CDATA[Sending data to OpenAI, Anthropic, or Google? The 2026 state of EU-US AI transfers]]></title>
      <link>https://notraced.com/articles/eu-us-ai-transfers-2026</link>
      <description><![CDATA[Section 702 sunsets April 20. The April 2026 state of EU-US AI transfers, what the DPF actually rests on, and the contract review you should do this week.]]></description>
      <pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://notraced.com/articles/eu-us-ai-transfers-2026</guid>
    </item>
    <item>
      <title><![CDATA[Are vector embeddings personal data under GDPR? A technical answer for RAG builders]]></title>
      <link>https://notraced.com/articles/are-vector-embeddings-personal-data</link>
      <description><![CDATA[Vector embeddings of personal data are likely personal data under GDPR. Here is the legal test, the 2025 attack research, the regulator convergence, and how to document your position.]]></description>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://notraced.com/articles/are-vector-embeddings-personal-data</guid>
    </item>
    <item>
      <title><![CDATA[20 AI app breaches in 12 months: the patterns every developer should know]]></title>
      <link>https://notraced.com/articles/ai-app-breaches-patterns</link>
      <description><![CDATA[Between January 2025 and February 2026, 20 documented AI app breaches exposed hundreds of millions of records. Four configuration mistakes explain nearly all of them.]]></description>
      <pubDate>Sun, 05 Apr 2026 00:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://notraced.com/articles/ai-app-breaches-patterns</guid>
    </item>
    <item>
      <title><![CDATA[AI memory and persistent context: what your chatbot remembers about users]]></title>
      <link>https://notraced.com/articles/ai-memory-persistent-context</link>
      <description><![CDATA[AI memory is profiling, and the deletion story is broken. The two layers, the NYT court order, the CIMemories benchmark, memory poisoning, and what survives a supervisory audit.]]></description>
      <pubDate>Sat, 04 Apr 2026 00:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://notraced.com/articles/ai-memory-persistent-context</guid>
    </item>
    <item>
      <title><![CDATA[Open source AI models: privacy and security considerations]]></title>
      <link>https://notraced.com/articles/open-source-ai-models-privacy-security</link>
      <description><![CDATA[What to check before deploying open-weight models in 2026. The supply chain attacks, SafeTensors migration, Article 53 open-source exemption, and the GDPR blind spot.]]></description>
      <pubDate>Sat, 04 Apr 2026 00:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://notraced.com/articles/open-source-ai-models-privacy-security</guid>
    </item>
    <item>
      <title><![CDATA[Your AI coding assistant sees your entire codebase. Here's what that means]]></title>
      <link>https://notraced.com/articles/ai-coding-assistant-sees-your-codebase</link>
      <description><![CDATA[What Copilot, Cursor, Claude Code, and Windsurf actually do with your code after the March 2026 Claude Code source leak. Secrets, tier gaps, and GDPR angles.]]></description>
      <pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://notraced.com/articles/ai-coding-assistant-sees-your-codebase</guid>
    </item>
    <item>
      <title><![CDATA[Prompt injection in production: how to defend what you've shipped]]></title>
      <link>https://notraced.com/articles/prompt-injection-in-production</link>
      <description><![CDATA[What EchoLeak actually showed, what the lethal trifecta actually is, and how your defense posture should change by architecture tier. Grounded in 2025 Microsoft, Google, and OWASP research.]]></description>
      <pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://notraced.com/articles/prompt-injection-in-production</guid>
    </item>
    <item>
      <title><![CDATA[AI and children's data: extra obligations you might not know about]]></title>
      <link>https://notraced.com/articles/ai-and-childrens-data</link>
      <description><![CDATA[What the DSA, GDPR Article 8, the AI Act, and COPPA 2.0 require when your AI feature is accessible to minors. Walks the four regimes one at a time, with 2025-2026 enforcement and the AI-training-consent rule most builders missed.]]></description>
      <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://notraced.com/articles/ai-and-childrens-data</guid>
    </item>
    <item>
      <title><![CDATA[Securing MCP servers: the attack surface your AI agent just opened]]></title>
      <link>https://notraced.com/articles/securing-mcp-servers</link>
      <description><![CDATA[The MCP specification is strict. Most implementations skip the MUST-level requirements. The 30+ CVEs filed in the first 60 days of 2026 live in that gap. A field guide to the four attack classes that matter, with named CVEs and what to actually do.]]></description>
      <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://notraced.com/articles/securing-mcp-servers</guid>
    </item>
    <item>
      <title><![CDATA[AI-generated content labeling: what Article 50 requires and how to implement it]]></title>
      <link>https://notraced.com/articles/ai-generated-content-labeling</link>
      <description><![CDATA[Article 50 of the AI Act applies on 2 August 2026. C2PA for images and audio, SynthID-Text and the paraphrase gap, the Code of Practice second draft, and a Python starter.]]></description>
      <pubDate>Wed, 01 Apr 2026 00:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://notraced.com/articles/ai-generated-content-labeling</guid>
    </item>
    <item>
      <title><![CDATA[EU AI Act: what developers who deploy AI features need to do by August 2026]]></title>
      <link>https://notraced.com/articles/eu-ai-act-deployer-obligations-august-2026</link>
      <description><![CDATA[The April 2026 trilogue reshaped the deadline. What binds you regardless, what the Omnibus will probably move, and the deployer obligations most dev teams underestimate.]]></description>
      <pubDate>Tue, 31 Mar 2026 00:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://notraced.com/articles/eu-ai-act-deployer-obligations-august-2026</guid>
    </item>
    <item>
      <title><![CDATA[GDPR and the AI Act: where they overlap and where they don't]]></title>
      <link>https://notraced.com/articles/gdpr-and-ai-act-overlap</link>
      <description><![CDATA[The 2026 state of the GDPR/AI Act interplay. What Joint Opinion 1/2026 and C-203/22 tell you about DPIAs, FRIAs, Article 22, Article 10 bias data, and fines.]]></description>
      <pubDate>Mon, 30 Mar 2026 00:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://notraced.com/articles/gdpr-and-ai-act-overlap</guid>
    </item>
    <item>
      <title><![CDATA[What to do when your AI provider gets breached]]></title>
      <link>https://notraced.com/articles/what-to-do-when-ai-provider-gets-breached</link>
      <description><![CDATA[Downstream incident runbook for the moment your AI vendor's breach email arrives. The 72-hour clock from your awareness, scoping with API logs only, and the three real 2025-2026 cases.]]></description>
      <pubDate>Sun, 29 Mar 2026 00:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://notraced.com/articles/what-to-do-when-ai-provider-gets-breached</guid>
    </item>
    <item>
      <title><![CDATA[Build vs buy: AI tools for your team]]></title>
      <link>https://notraced.com/articles/build-vs-buy-ai-tools</link>
      <description><![CDATA[Build vs buy is not one decision. It is five — one for each layer of the AI stack. The five layers, the question that decides each, and the AI Act trap that catches teams who build the wrong layer.]]></description>
      <pubDate>Sat, 28 Mar 2026 00:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://notraced.com/articles/build-vs-buy-ai-tools</guid>
    </item>
    <item>
      <title><![CDATA[Your AI feature makes recommendations to users. Here are the rules]]></title>
      <link>https://notraced.com/articles/ai-recommendations-to-users</link>
      <description><![CDATA[GDPR, the DSA, and the AI Act apply different rules to different recommender systems. The three stakes tiers, the case law that reshaped them in 2025, and what each tier actually has to do.]]></description>
      <pubDate>Fri, 27 Mar 2026 00:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://notraced.com/articles/ai-recommendations-to-users</guid>
    </item>
    <item>
      <title><![CDATA[AI in HR and recruitment: what your team needs to know]]></title>
      <link>https://notraced.com/articles/ai-in-hr-and-recruitment</link>
      <description><![CDATA[Five HR use cases for AI, each with the rule that applies, the 2024-2025 enforcement that shaped it, and the question to ask the vendor before you sign.]]></description>
      <pubDate>Thu, 26 Mar 2026 00:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://notraced.com/articles/ai-in-hr-and-recruitment</guid>
    </item>
    <item>
      <title><![CDATA[Logging and monitoring AI outputs: what to keep and what not]]></title>
      <link>https://notraced.com/articles/logging-and-monitoring-ai-outputs</link>
      <description><![CDATA[How to log AI features without violating GDPR storage limitation or failing the EU AI Act audit. Three-tier architecture, PII redaction defaults that 2026 observability vendors get wrong, and the Article 12 vs Article 26 split.]]></description>
      <pubDate>Wed, 25 Mar 2026 00:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://notraced.com/articles/logging-and-monitoring-ai-outputs</guid>
    </item>
    <item>
      <title><![CDATA[Third-party AI integrations: what to check before you connect]]></title>
      <link>https://notraced.com/articles/third-party-ai-integrations</link>
      <description><![CDATA[Third-party AI integration is not one shape. It is four. The four patterns, the data flows they create, and the check that fits each.]]></description>
      <pubDate>Tue, 24 Mar 2026 00:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://notraced.com/articles/third-party-ai-integrations</guid>
    </item>
    <item>
      <title><![CDATA[Fine-tuning vs RAG vs prompt engineering: privacy implications]]></title>
      <link>https://notraced.com/articles/fine-tuning-vs-rag-vs-prompt-engineering-privacy</link>
      <description><![CDATA[The privacy tradeoffs between fine-tuning, RAG, and prompt engineering for AI customization. Erasure feasibility, EDPB Opinion 28/2024, and the production hybrid pattern.]]></description>
      <pubDate>Mon, 23 Mar 2026 00:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://notraced.com/articles/fine-tuning-vs-rag-vs-prompt-engineering-privacy</guid>
    </item>
    <item>
      <title><![CDATA[Your AI agent has access to production data. Is that ok?]]></title>
      <link>https://notraced.com/articles/your-ai-agent-has-access-to-production-data</link>
      <description><![CDATA[Five concentric rings of agent blast radius (read, write, OAuth reach, external input, memory) anchored on the AEPD's 18 February 2026 agentic AI guidance and EchoLeak (CVE-2025-32711).]]></description>
      <pubDate>Sun, 22 Mar 2026 00:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://notraced.com/articles/your-ai-agent-has-access-to-production-data</guid>
    </item>
    <item>
      <title><![CDATA[EU vs US data processing for AI: how to decide]]></title>
      <link>https://notraced.com/articles/eu-vs-us-data-processing-ai</link>
      <description><![CDATA[EU vs US is a per-workload decision, not a per-company flag. The four sorting questions, the political backdrop that keeps shifting the answer, and the portfolio shape most teams actually end up with.]]></description>
      <pubDate>Sat, 21 Mar 2026 00:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://notraced.com/articles/eu-vs-us-data-processing-ai</guid>
    </item>
    <item>
      <title><![CDATA[Data residency and AI: does it matter where your data is processed?]]></title>
      <link>https://notraced.com/articles/data-residency-and-ai</link>
      <description><![CDATA[EU AI data residency in 2026: the seven layers where data lives, the CLOUD Act mechanic, the OpenAI in-region GPU launch, and when sovereignty beats residency.]]></description>
      <pubDate>Fri, 20 Mar 2026 00:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://notraced.com/articles/data-residency-and-ai</guid>
    </item>
    <item>
      <title><![CDATA[Building RAG with customer data. Here are the 5 things that matter]]></title>
      <link>https://notraced.com/articles/building-rag-with-customer-data</link>
      <description><![CDATA[A practical guide to building RAG systems with customer data while handling GDPR obligations. Lineage tables, retrieval authorization, embedding inversion, and erasure planning.]]></description>
      <pubDate>Thu, 19 Mar 2026 00:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://notraced.com/articles/building-rag-with-customer-data</guid>
    </item>
    <item>
      <title><![CDATA[AI vendor evaluation: a due diligence checklist for small teams]]></title>
      <link>https://notraced.com/articles/ai-vendor-evaluation-due-diligence-checklist</link>
      <description><![CDATA[Generic AI vendor checklists fail because they treat every provider as one category. The right questions depend on which of four vendor archetypes you are evaluating.]]></description>
      <pubDate>Tue, 17 Mar 2026 00:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://notraced.com/articles/ai-vendor-evaluation-due-diligence-checklist</guid>
    </item>
    <item>
      <title><![CDATA[How to audit your codebase for AI data leakage]]></title>
      <link>https://notraced.com/articles/how-to-audit-your-codebase-for-ai-data-leakage</link>
      <description><![CDATA[A practical, surface-by-surface audit recipe for finding personal data flowing to AI services. Covers prompt templates, observability defaults, embedding pipelines, and the limits of audit-by-grep in agent mode.]]></description>
      <pubDate>Sun, 15 Mar 2026 00:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://notraced.com/articles/how-to-audit-your-codebase-for-ai-data-leakage</guid>
    </item>
    <item>
      <title><![CDATA[What happens when an AI provider changes their terms]]></title>
      <link>https://notraced.com/articles/what-happens-when-ai-provider-changes-terms</link>
      <description><![CDATA[Three real 2025-2026 vendor term changes (Anthropic's August 2025 consumer pivot, OpenAI's Mixpanel sub-processor removal, and Microsoft's January 2026 Anthropic addition) and the four-step playbook for when the notification email arrives.]]></description>
      <pubDate>Fri, 13 Mar 2026 00:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://notraced.com/articles/what-happens-when-ai-provider-changes-terms</guid>
    </item>
    <item>
      <title><![CDATA[Building with AI APIs: the 5 privacy questions to answer first]]></title>
      <link>https://notraced.com/articles/building-with-ai-apis-privacy-questions</link>
      <description><![CDATA[A code-review walk through the seven things a senior reviewer should ask before an AI API integration ships, with the EU regulatory anchors that make each one load-bearing in 2026.]]></description>
      <pubDate>Wed, 11 Mar 2026 00:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://notraced.com/articles/building-with-ai-apis-privacy-questions</guid>
    </item>
    <item>
      <title><![CDATA[Do you need a DPIA for your AI feature? A practical check]]></title>
      <link>https://notraced.com/articles/do-you-need-a-dpia-for-your-ai-feature</link>
      <description><![CDATA[The trigger question is settled. The harder question is which assessment, and when. EDPB Opinion 28/2024, CNIL July 2025, and the Article 27(4) FRIA carry-over.]]></description>
      <pubDate>Mon, 09 Mar 2026 00:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://notraced.com/articles/do-you-need-a-dpia-for-your-ai-feature</guid>
    </item>
    <item>
      <title><![CDATA[How to write an AI acceptable use policy for your team]]></title>
      <link>https://notraced.com/articles/how-to-write-an-ai-acceptable-use-policy</link>
      <description><![CDATA[A guide-tier walkthrough of writing an AI acceptable use policy that survives contact with reality. Includes the full template, the four sections that matter, the rollout playbook, and the EU AI Act Article 4 connection most teams miss.]]></description>
      <pubDate>Sat, 07 Mar 2026 00:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://notraced.com/articles/how-to-write-an-ai-acceptable-use-policy</guid>
    </item>
    <item>
      <title><![CDATA[Anthropic vs OpenAI vs Google: privacy policy comparison]]></title>
      <link>https://notraced.com/articles/anthropic-vs-openai-vs-google-privacy-comparison</link>
      <description><![CDATA[What changed for the three providers in 2025-2026: Anthropic's August 2025 consumer shift, the October 2025 Google TPU sub-processor expansion, the Court of Rome OpenAI annulment, and the Latombe DPF appeal pending at the CJEU.]]></description>
      <pubDate>Thu, 05 Mar 2026 00:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://notraced.com/articles/anthropic-vs-openai-vs-google-privacy-comparison</guid>
    </item>
    <item>
      <title><![CDATA[OpenAI's data processing agreement: what it actually says]]></title>
      <link>https://notraced.com/articles/openai-data-processing-agreement</link>
      <description><![CDATA[A clause-by-clause read of OpenAI's DPA in April 2026: what changed in the last 12 months, what still trips deployers, and the operational decisions that follow each clause.]]></description>
      <pubDate>Tue, 03 Mar 2026 00:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://notraced.com/articles/openai-data-processing-agreement</guid>
    </item>
    <item>
      <title><![CDATA[Self-hosted LLM vs cloud API: the privacy tradeoff]]></title>
      <link>https://notraced.com/articles/self-hosted-llm-vs-cloud-api-privacy-tradeoff</link>
      <description><![CDATA[A 2026 decision framework for dev teams choosing between self-hosting an open-weight LLM and calling a cloud API. Refreshed with Llama 4, the Latombe DPF challenge, and Azure / Bedrock EU data zones.]]></description>
      <pubDate>Sun, 01 Mar 2026 00:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://notraced.com/articles/self-hosted-llm-vs-cloud-api-privacy-tradeoff</guid>
    </item>
    <item>
      <title><![CDATA[Your dev team uses Copilot with client code. What to know]]></title>
      <link>https://notraced.com/articles/your-dev-team-uses-copilot-with-client-code</link>
      <description><![CDATA[Using GitHub Copilot on client repositories is a contract problem before it is a privacy problem. The 2026 sub-processor reality, what Copilot Business actually fixes, and the engagement-level conversation to have first.]]></description>
      <pubDate>Fri, 27 Feb 2026 00:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://notraced.com/articles/your-dev-team-uses-copilot-with-client-code</guid>
    </item>
    <item>
      <title><![CDATA[Shadow AI: your team is using tools you don't know about]]></title>
      <link>https://notraced.com/articles/shadow-ai-your-team-is-using-tools-you-dont-know-about</link>
      <description><![CDATA[Three tiers of shadow AI in 2026: the browser tab, the in-SaaS toggle, the OAuth-scoped agent. IBM puts the breach delta at $670K, Article 4 enforcement starts 2 August 2026, and a register beats a ban.]]></description>
      <pubDate>Wed, 25 Feb 2026 00:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://notraced.com/articles/shadow-ai-your-team-is-using-tools-you-dont-know-about</guid>
    </item>
    <item>
      <title><![CDATA[Your employee pasted client data into ChatGPT. Now what]]></title>
      <link>https://notraced.com/articles/your-employee-pasted-client-data-into-chatgpt</link>
      <description><![CDATA[A time-anchored runbook for handling the most common AI incident in 2026: a team member pasted personal data into a consumer-tier ChatGPT account. First hour through the policy that stops the next one.]]></description>
      <pubDate>Mon, 23 Feb 2026 00:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://notraced.com/articles/your-employee-pasted-client-data-into-chatgpt</guid>
    </item>
    <item>
      <title><![CDATA[Your company uses AI tools with customer data. Here's what to check]]></title>
      <link>https://notraced.com/articles/your-company-uses-ai-tools-with-customer-data</link>
      <description><![CDATA[Six questions a regulator, a DPO, or an enterprise customer will ask you about AI and customer data. Grounded in 2025-2026 enforcement, CNIL guidance, and the Court of Rome OpenAI annulment.]]></description>
      <pubDate>Sat, 21 Feb 2026 00:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://notraced.com/articles/your-company-uses-ai-tools-with-customer-data</guid>
    </item>
    <item>
      <title><![CDATA[AI Act: a plain-English overview for dev teams]]></title>
      <link>https://notraced.com/articles/ai-act-plain-english-overview</link>
      <description><![CDATA[The EU AI Act's structure, risk tiers, timeline, and penalties in one place — a reference for developers and small teams. Updated April 2026 with the Digital Omnibus trilogue state.]]></description>
      <pubDate>Thu, 19 Feb 2026 00:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://notraced.com/articles/ai-act-plain-english-overview</guid>
    </item>
    <item>
      <title><![CDATA[GDPR and AI: the 5 articles that actually matter]]></title>
      <link>https://notraced.com/articles/gdpr-and-ai-the-5-articles-that-matter</link>
      <description><![CDATA[The five GDPR articles that actually decide whether your AI feature ships in 2026: legal basis, transparency after Dun & Bradstreet, Article 22, privacy by design, and DPIA.]]></description>
      <pubDate>Tue, 17 Feb 2026 00:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://notraced.com/articles/gdpr-and-ai-the-5-articles-that-matter</guid>
    </item>
    <item>
      <title><![CDATA[Key terms: DPA, DPIA, legal basis, data processor — what they mean in practice]]></title>
      <link>https://notraced.com/articles/key-terms-ai-privacy</link>
      <description><![CDATA[A curated reference for developers: the GDPR and AI Act terms you will trip over when you ship an AI feature, one tight line each, grouped by role, legal concept, document, and AI Act specifics.]]></description>
      <pubDate>Sun, 15 Feb 2026 00:00:00 GMT</pubDate>
      <guid isPermaLink="true">https://notraced.com/articles/key-terms-ai-privacy</guid>
    </item>
  </channel>
</rss>