Salesforce AI Without Training Data Governance
maximum fine for using prohibited AI practices: or 7% of global annual turnover
The EU AI Act (in force August 2024, phased enforcement 2025-2027) imposes strict requirements on high-risk AI systems. Including those trained on personal data. For Salesforce organizations using AI features like Agentforce, Einstein, or custom Apex ML models, training data governance is now a compliance obligation, not just a best practice.
of training datasets for high-risk AI systems must be governed. Including data quality, relevance, and personal data minimization
EU AI Act Article 10 requires that training, validation, and testing datasets for high-risk AI systems undergo data governance practices: relevant, representative, free of errors, and handled in compliance with GDPR. For Salesforce teams, this means the customer data used to train or fine-tune AI models must be masked or anonymized before use.
full EU AI Act enforcement deadline for general-purpose AI systems and high-risk AI categories
The EU AI Act has a phased enforcement timeline: prohibited AI practices (Feb 2025), codes of practice (Aug 2025), high-risk AI obligations (Aug 2026), and general-purpose AI obligations (Aug 2027). Organizations using Salesforce AI for customer scoring, service routing, or predictive analytics should classify their systems now and begin training data governance.
High-Risk AI Systems Must Govern Training Data
The EU AI Act has applied in phases since 1 August 2024: prohibited practices banned from 2 February 2025, general-purpose AI obligations from 2 August 2025, and — after the Digital Omnibus on AI (Regulation (EU) 2026/1744) deferred them — high-risk obligations from 2 December 2027 for Annex III systems and 2 August 2028 for AI embedded in regulated products. Three articles create specific obligations in Salesforce AI deployments:
Article 10
Training Data Quality & Governance
Training, validation, and testing datasets for high-risk AI systems must be governed for relevance, representativeness, and personal data minimization. Customer records used to train Agentforce or Einstein models must be masked or anonymized before use. Replacing real PII with realistic synthetic data.
Data Retention ManagerArticle 11
Technical Documentation of Training Data
High-risk AI providers must maintain technical documentation including training data sources, governance practices, and data quality measures. Regulators require timestamped records of: which records were included, which fields were masked, masking rules applied, and when the job ran.
Masking Audit LogsArticle 99
Enforcement & Penalties
Article 99 establishes penalties for prohibited AI practices and violations of high-risk AI obligations: up to €35M or 7% of global annual turnover. Regulators assess fines based on revenue, severity of violation, and cooperation during investigation.
Masking Audit LogsArticle 99
EU AI Act fine tiers
Article 99 sets three ceilings, each the higher of a fixed amount or a share of total worldwide annual turnover for the preceding financial year.
| Infringement | Article | Maximum fine |
|---|---|---|
| Prohibited AI practices — social scoring, manipulative systems, untargeted facial-recognition scraping, and the other Article 5 bans | Art. 99(3): Art. 5 | €35 million or 7% of turnover |
| Obligations of providers, deployers, importers, distributors and notified bodies, including high-risk system duties and transparency | Art. 99(4): Arts. 16, 22–26, 31, 33, 34, 50 | €15 million or 3% of turnover |
| Supplying incorrect, incomplete or misleading information to notified bodies or national authorities | Art. 99(5) | €7.5 million or 1% of turnover |
Source: Regulation (EU) 2024/1689 (AI Act), Article 99. Figures last checked . For SMEs and start-ups each fine is the lower of the fixed amount and the percentage (Art. 99(6)).
Training Data Masking, Retention, & Audit Compliance
Article 10: Training Data Quality
DataMaskerMask PII Before AI Training Data Extraction
DataMasker masks Salesforce records before they are used as AI training data. Names, email addresses, phone numbers, and other personal identifiers are replaced with realistic synthetic data that preserves the statistical patterns AI models need. Without containing real PII. The masked dataset is GDPR-compliant and meets EU AI Act Article 10 data quality requirements.
Article 10: Data Minimization
Data Retention ManagerEnforce Training Data Retention Limits
EU AI Act and GDPR together require that training data is not retained longer than necessary. Data Retention Manager implements retention schedules for AI training datasets stored in Salesforce. When a model is deprecated or retrained, the associated training data is automatically purged according to your configured retention policy.
Article 11: Technical Documentation
Masking Audit LogsDocument Training Data Provenance for Audits
EU AI Act requires high-risk AI providers to maintain technical documentation including training data sources and governance practices. DataMasker's masking logs provide a complete audit trail: which records were included, which fields were masked, when the masking job ran, and which rules were applied. This documentation satisfies both EU AI Act technical documentation requirements and GDPR data processing records.
Key Takeaways
EU AI Act Article 10 data quality requirements addressed through data minimization before AI training
Agentforce and Einstein models should not reason over PII your org was never supposed to retain
Sandbox masking prevents AI models in development from training on live production personal data
Data Retention Manager removes obsolete records that would otherwise be in AI model training scope
High-risk AI system documentation supported by automated data inventory from Personal Data Discovery
Act applies from August 2026, organizations deploying Salesforce AI need data governance in place now
Frequently Asked Questions
It depends on how you use Agentforce. The EU AI Act focuses on AI systems. Combinations of AI models, software, and business processes. If your Agentforce deployment makes automated decisions about individuals that have significant effects (credit scoring, insurance pricing, employment screening, service prioritization), it likely qualifies as a high-risk AI system under Annex III. General-purpose use for content generation or summarization faces lighter obligations.
Article 10 requires that training, validation, and testing datasets for high-risk AI systems meet data governance standards: relevance to intended purpose, representativeness of the deployment context, and minimization of personal data. For Salesforce teams, this means customer records used to train or fine-tune AI models should be masked before use. Replacing real PII with realistic synthetic data that preserves the patterns the model needs.
Partially. GDPR requires a lawful basis for processing personal data, including for AI training. Using customer records to train AI models without explicit consent or another lawful basis is a GDPR risk. Separate from the EU AI Act. The EU AI Act adds additional obligations around technical documentation, data quality, and bias management for high-risk AI systems. CC addresses both simultaneously: DataMasker masks training data for GDPR compliance; the masking audit log satisfies EU AI Act documentation requirements.
High-risk AI system obligations (including training data governance requirements) apply from August 2026. General-purpose AI model obligations apply from August 2027. Organizations should begin classification and compliance work now. Data governance infrastructure typically takes 3-6 months to implement properly.
Yes. DataMasker's masking logs provide timestamped documentation of: which Salesforce objects and fields were included in training data exports, which masking rules were applied, and when the masking job ran. This output can be incorporated directly into the EU AI Act Article 11 technical documentation package for high-risk AI systems.
EU AI Act Article 10 requires that training data for high-risk AI systems be relevant, representative, and free from errors or bias, and specifically prohibits training on personal data beyond what is necessary for the intended purpose. When Agentforce or Einstein models reason over your Salesforce org, they access your full data landscape. Stale records, excess PII, and unmasked sandbox data all expand your AI Act exposure. Cloud Compliance addresses this at the data layer: Data Retention Manager deletes obsolete records before they reach AI training pipelines, and Sandbox DataMasker ensures AI models in development environments train on masked data, not live personal data.
Related Compliance Solutions
DataMasker: Sandbox PII Protection
Automatic data masking for AI training datasets and sandbox environments.
Data Retention Manager: Automated Deletion
Enforce retention limits for AI training datasets.
GDPR Compliance for Salesforce
GDPR requirements that overlap with EU AI Act obligations.


