AI is no longer experimental, and GDPR enforcement is accelerating. This post covers the governance basics that hold up in audit: lawful basis, DPIAs, monitoring limits, hallucination controls, and a practical checklist for the next 30 days.