Seems like something that should exist as a specialist knowledge team within an existing compliance team i.e. guided by legal concerns primarily.
You might be surprised how often the tail wags the dog in these situations. Lawyers shrug and defer to the policy doomers because they ultimately don’t understand the tech.
Conversely, there's no real downside to being too conservative, especially if engineers and leadership are entirely deferential to you because they don't understand your field (or are too afraid to speak up.)
Although this is also somewhat true for security, privacy, and safety organizations, their remit tends to include "enabling business." A safety team that defaults to "you shouldn't be doing this" is not going to have much sway. A legal department might.