

AI, data and the law: what founders get wrong (and how to avoid it)
AI is becoming embedded in core product functionality, but many startups misjudge where the real legal risks arise. With the EU AI Act entering into force, founders need to understand how it interacts with GDPR and adjacent frameworks such as consumer protection and product regulation in practice.
This session focuses on concrete product decisions: how training data is sourced and used, how user-facing features are designed, and how AI-driven products are scaled — and how these choices trigger legal obligations across AI regulation, data protection and consumer-facing rules.
Rather than a high-level overview, the session provides a practical framework for identifying where risks typically arise, where founders most often go wrong, and how to build AI-enabled products that are both legally robust and commercially scalable from day one.
Bios
Simon Wilkens
Simon Wilkens is a lawyer specialising in data protection, technology and product-related regulatory compliance. He advises Swedish and international companies on complex, business-critical issues in digitalisation projects, including GDPR, cybersecurity and AI regulation, IT contracts, and related areas such as marketing law and intellectual property.
Suana Tafic
Suana Tafic specialises in data protection, technology and product-related regulatory compliance. She has experience in providing legal advice to both Swedish and international companies, particularly in the areas of data privacy, AI, camera surveillance and related areas such as marketing law.