EU AI Act guide · updated 3 August 2026

EU AI Act vs GDPR: two regimes, one system

Every privacy team in Europe is being asked the same question this month: we are GDPR compliant — how much of the AI Act is actually new? The honest answer is that the two laws ask different questions about the same system. GDPR asks whether you may process the personal data. The AI Act asks whether the system may be placed on the market and used at all, and under which controls. Article 2(7) settles the relationship explicitly: the AI Act leaves EU data protection law untouched. They apply cumulatively.

Practical translation: a mature GDPR programme is a real head start, but the head start is in habits — inventory, impact assessment, vendor diligence, training — not in deliverables. The product-safety half of the AI Act (classification, technical documentation, conformity assessment, registration, post-market monitoring) has no GDPR equivalent to inherit from.

The two regimes side by side

What it regulates

GDPR: The processing of personal data — lawfulness, fairness, purpose, security.

AI Act: The system as a product — whether it may be placed on the market and used, and under what controls.

What triggers it

GDPR: Any processing of personal data in scope of Article 2/3.

AI Act: An AI system placed on the EU market, put into service, or whose output is used in the EU.

Who the actors are

GDPR: Controller, joint controller, processor.

AI Act: Provider, deployer, importer, distributor, authorised representative.

Core artefacts

GDPR: Records of processing (Art. 30), DPIA (Art. 35), privacy notices, DPAs.

AI Act: Annex IV technical documentation, EU declaration of conformity, CE marking, EU database registration, FRIA.

Who enforces

GDPR: Data protection authorities.

AI Act: National market surveillance authorities and the AI Office — and, for Annex III law-enforcement, migration and justice systems, the data protection authority in many Member States (Art. 74(8)).

Maximum penalty

GDPR: €20M or 4% of worldwide annual turnover.

AI Act: €35M or 7% for prohibited practices; €15M or 3% for other obligations.

Five places the two regimes touch

These are the seams where compliance programmes actually fail — not because either law is unclear, but because each team assumes the other one owns it.

Data governance

GDPR wants minimisation and accuracy; Article 10 of the AI Act wants training, validation and test data that are relevant, representative, error-screened and examined for bias. These pull in different directions often enough to matter — and Article 10(5) is the reconciliation: special categories of personal data may be processed where strictly necessary to detect and correct bias in high-risk systems, subject to safeguards.

Impact assessments

DPIA under Article 35 GDPR, FRIA under Article 27 AI Act. Overlapping inputs, different questions: the DPIA asks about risk to data subjects from processing; the FRIA asks about harm to affected persons from the system's use in a specific deployment context. Article 27(4) makes the FRIA a complement to an existing DPIA, not a duplicate of it.

Transparency to the individual

GDPR Articles 13–15 cover information about processing and Article 22 covers solely automated decisions with legal or similarly significant effects. The AI Act adds Article 50 disclosure duties (you are talking to an AI; this content is synthetic), Article 26(11) notice that an Annex III system is being used on you, and Article 86 — a right to an explanation of the role that system played in the decision.

Human involvement

Passing the GDPR Article 22 test for meaningful human involvement does not satisfy Articles 14 and 26(2) of the AI Act, and vice versa. The AI Act asks whether oversight is designed into the system and whether the named person has the competence, authority and support to override or stop it; GDPR asks whether the decision was in substance made by a human.

Logs and retention

Article 12 requires high-risk systems to log automatically, and Article 26(6) requires deployers to keep the logs they control for at least six months. GDPR storage limitation still applies to the personal data inside those logs — so the retention schedule needs a documented justification rather than a default, and the two teams have to write it together.

What your GDPR work already buys you

  • The inventory habit. Your Article 30 records are the fastest route to an AI system register — walk the processing activities and mark which ones involve an AI system.
  • Assessment muscle. Teams that have run DPIAs know how to describe a system, identify affected people and document mitigations — most of a FRIA is that skill applied to a new question.
  • Vendor due diligence. The processor questionnaire becomes the provider questionnaire; the DPA sits next to the Article 13 instructions for use.
  • Training and accountability. Awareness programmes extend naturally to the Article 4 AI literacy duty.

What it does not buy you

  • Classification. Nothing in a GDPR programme tells you whether a system is Annex III high-risk — and every other obligation depends on that answer.
  • Annex IV technical documentation, the conformity assessment, the EU declaration of conformity, CE marking and Article 49 registration — a product-safety stack with no privacy analogue.
  • Accuracy, robustness and cybersecurity (Art. 15) as a declared, measured property of the system.
  • Post-market monitoring and serious-incident reporting (Arts. 72–73) on a 15-day clock.
  • Role mapping. Controller/processor does not map onto provider/deployer. A processor can be a provider; a controller can be a deployer that becomes a provider under Article 25 by rebranding or substantially modifying a system.

See which of your systems the AI Act treats differently — free, 10 minutes

The free AnnexWise assessment classifies a system in about 10 minutes — risk tier, open obligations and a gap report, with article references throughout. It runs in your browser; answers never leave your device.

Run the free assessment →

Who should own it

The AI Act does not assign an owner, which is why it drifts. The pattern that works: the privacy function coordinates and keeps the register, because it already has the inventory and the assessment cadence; product and engineering own the provider obligations, because Articles 9–15 are design and testing work that no legal team can perform; and the business unit that presses “use” owns the Article 26 deployer duties. Written role assignment per system is itself evidence of the governance both regimes expect.

Start where the two programmes agree: one register of systems, each with a documented risk tier, a named owner and a dated assessment. From there the AI Act work is a defined list rather than an open-ended project — the compliance checklist runs it in order, and the penalty guide explains why the sequencing matters.

Frequently asked questions

We completed a DPIA. Do we still need a FRIA?

They are different instruments and the AI Act says so directly: Article 27(4) provides that where an obligation is already met through the GDPR Article 35 DPIA, the fundamental rights impact assessment complements that DPIA — it does not replace it, and the DPIA does not discharge it. In practice you reuse the system description, the data flows and the risk register, then add what Article 27 asks for that a DPIA never covers: the deployer's processes, the period and frequency of use, the categories of natural persons affected, the specific harms to them, the human oversight arrangements, and the governance and complaint mechanisms.

Does the AI Act create a role like the DPO?

No. There is no mandatory 'AI officer' and no registration of one. What the Act does require is concrete and distributable: sufficient AI literacy for staff dealing with AI systems (Article 4, applicable since 2 February 2025), named and competent people assigned to human oversight of each high-risk system (Article 26(2)), and — for providers established outside the EU — an authorised representative in the Union (Article 22). Most organisations put coordination with the DPO or a compliance lead, and the substance with product and engineering owners.

Our AI system doesn't process personal data. Does the AI Act still apply?

Yes. The two laws have independent triggers. GDPR engages when personal data is processed; the AI Act engages when an AI system is placed on the EU market, put into service, or its output is used in the EU — regardless of whether any personal data is involved. A predictive-maintenance model on machine telemetry is out of GDPR scope and can still be a high-risk safety component under Article 6(1).

Can the same incident be fined under both regimes?

Yes, where it breaches obligations under both. They are separate legal regimes with separate authorities: data protection authorities enforce GDPR (up to €20M / 4%), while market surveillance authorities and the AI Office enforce the AI Act (up to €35M / 7% for prohibited practices, €15M / 3% for other breached obligations). A biased CV-screening model can be a GDPR fairness and Article 22 problem and an AI Act Article 10 and Article 26 problem at once — the ne bis in idem principle protects against being punished twice for the same offence, not against two different offences arising from the same system.

Where does your AI system actually stand?

The free AnnexWise assessment classifies a system in about 10 minutes — risk tier, open obligations and a gap report, with article references throughout. It runs in your browser; answers never leave your device.

Run the free assessment →

Keep reading

AnnexWise is compliance software, not a law firm; this guide is general information about Regulation (EU) 2024/1689, not legal advice for your situation. Verdict logic is documented on the methodology page.