Advertisement

Reviewed by: Mansoor Ali, Technical Editor, PenPonder | Last Updated: September 2026

EU AI Act and GDPR compliance can overlap when a business uses AI to process personal data, but the two laws don’t regulate the same thing. GDPR governs personal data processing. The AI Act regulates AI systems according to their role, use, and risk level. In 2026, that distinction matters more than usual, because the EU’s July 2026 Digital Omnibus changed the timeline for high-risk AI systems while new AI transparency rules started applying on schedule.

This article explains the current state of that compliance picture for businesses. It isn’t legal advice for your specific situation. Regulatory deadlines, especially around the AI Act, have shifted more than once in 2026, so treat this as a starting point for your own research or a conversation with a qualified lawyer, not a substitute for one.

Quick Answer: Do You Need to Follow Both?

Possibly, and they regulate different things. GDPR governs how you handle personal data. The AI Act governs the AI systems themselves, what risk category they fall into and what obligations follow. Many AI use cases touch both, since AI systems often process personal data, but whether each law applies to you depends on your specific situation, not a blanket rule.

What Changed Under the EU AI Act in 2026

If you read anything about the EU AI Act before mid-2026, some of it is now out of date. The EU’s Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal on July 24, 2026 and entered into force on July 27, 2026, six days before the AI Act’s original high-risk compliance deadline. It pushed that deadline back significantly. (Source: Official Journal of the European Union.)

This matters because a lot of content published earlier in 2026, including earlier versions of this article, treated August 2, 2026 as the date high-risk AI rules took full effect. That is no longer accurate. If you’re new to this topic, our broader AI compliance guide covers the wider regulatory landscape businesses need to track beyond just the EU.

EU AI Act Timeline and Current Deadlines

ObligationCurrent application date
Prohibited AI practices and AI literacy dutiesFebruary 2, 2025 (unchanged)
General-purpose AI (GPAI) provider obligationsAugust 2, 2025 (unchanged)
Article 50 transparency obligations (informing people they’re interacting with AI)August 2, 2026 (unchanged)
Article 50(2) marking and detection obligations for certain AI systems already on the marketDelayed to December 2, 2026
New prohibition on AI-generated non-consensual intimate imagery and CSAMDecember 2, 2026
High-risk AI systems, standalone (Annex III: recruitment, credit scoring, biometric identification, education, law enforcement, and similar)Delayed from August 2, 2026 to December 2, 2027
High-risk AI embedded in regulated products (Annex I: medical devices, machinery, vehicles)Delayed from August 2027 to August 2, 2028

Important: the delay is not a reason to do nothing until 2027. Building an inventory of your AI systems, classifying which Annex III category each one falls into, and getting your product and engineering teams into the habit of maintaining that inventory takes real time regardless of the deadline. Starting now gives you months to refine the work. Starting in late 2027 gives you weeks.

Does the EU AI Act Apply to Your Business?

This is more specific than “if an EU citizen uses your product.” The AI Act’s territorial scope covers several distinct categories of businesses, and whether you fall into one depends on facts specific to your situation.

SituationPotential AI Act relevance
You provide an AI system placed on the EU marketLikely yes
Your company is based in the EU and deploys AILikely yes
You’re outside the EU, but your AI system’s output is used in the EUPotentially yes, where the AI Act’s territorial conditions are met
You use an AI tool purely internally, outside the EU, with no EU-facing outputDepends on the specific circumstances
You have a single EU website visitor with no EU-targeted product or outputNot automatically

A useful way to think about it: a SaaS company based outside the EU that provides an AI system whose output is used within the EU may fall within the AI Act’s scope, even without an EU office or an EU-based customer base as such. It depends on the specific processing and output, not on where any single user happens to be located. If you’re unsure whether this applies to you, this is exactly the kind of question worth a real legal consultation rather than a generic rule of thumb.

Who Actually Needs to Care About This?

Business typeMain question to work through
SaaS company using an AI API (ChatGPT, Claude, etc.)What data is sent to the vendor, and what role does each party play under GDPR?
HR or recruitment software companyDoes the AI system fall into a high-risk employment use case under Annex III?
Marketing agency using generative AIDo the generated or manipulated outputs trigger Article 50 transparency rules?
AI model providerDo GPAI obligations apply, and does the model carry systemic risk?
EU-based employer using AI internallyWhich specific AI systems are deployed, and what personal data do they touch?
Non-EU SaaS company with EU usersDoes the system or its output fall within the AI Act’s territorial scope?

The Main AI Compliance Areas to Check

The AI Act isn’t one flat set of rules. It splits into distinct areas, and General-Purpose AI in particular isn’t just another risk tier, it has its own separate obligations.

Prohibited AI practices

Certain AI uses are banned outright: social scoring by public authorities, real-time biometric identification in public spaces outside narrow exceptions, and subliminal manipulation techniques, among others. As of December 2, 2026, AI systems that generate non-consensual intimate imagery or CSAM join this list. These obligations have applied since February 2, 2025.

High-risk AI systems

Systems used in areas like recruitment, credit scoring, education access, and law enforcement carry the heaviest documentation, oversight, and conformity-assessment requirements. As covered above, these obligations are now delayed to December 2027 (standalone) and August 2028 (embedded in products). Being used in a sensitive sector like these does not, by itself, answer the classification question, the specific AI system and use case still need to be checked against the AI Act’s classification rules and the relevant Annex III categories.

What High-Risk AI Compliance Actually Involves

RequirementWhat it means in practice
Risk managementIdentify, assess, and reduce foreseeable risks throughout the system’s lifecycle
Data governanceEnsure the data used meets appropriate quality standards and controls
Technical documentationMaintain documentation showing how the system works and how it meets requirements
LoggingKeep records that support traceability of the system’s operation
Human oversightBuild in appropriate human intervention and the ability to override the system
Accuracy and robustnessMonitor performance and resilience against errors and failures
CybersecurityProtect the system against relevant attacks and manipulation
Quality managementMaintain internal processes that support ongoing compliance
Conformity assessmentComplete the required assessment before the system goes on the market or into use, where applicable
Post-market monitoringContinue monitoring the system’s performance after deployment

Transparency obligations

These require telling people when they’re interacting with AI in relevant circumstances, and marking certain AI-generated or manipulated content. Most of this applies from August 2, 2026, though the specific labelling requirement for content already on the market got a short extension to December 2, 2026.

General-purpose AI (GPAI) obligations

Providers of general-purpose AI models, the underlying models behind tools like large language models, have had their own separate obligations since August 2, 2025, with added requirements for models the Commission classifies as carrying systemic risk. These are enforced directly by the European Commission, not national authorities. Most businesses that simply use ChatGPT, Claude, Gemini, or another third-party AI service are not GPAI model providers themselves, the obligations primarily target the organisations that provide the underlying model. If you substantially modify a model or provide one yourself, the analysis can become more complicated, and that’s worth a specific review.

AI literacy

This obligation was itself amended by the July 2026 Digital Omnibus. The original wording required businesses to “ensure a sufficient level” of AI literacy. The current wording, in force since July 27, 2026, requires providers and deployers to take measures to support the development of AI literacy among relevant staff and other people who operate or use AI systems on their behalf, taking into account their technical knowledge, experience, education, and the context of use. The amended rule explicitly states it does not require guaranteeing any specific level of AI literacy for any individual. (Source: Regulation (EU) 2026/1744, amending Article 4 of the EU AI Act.) In practice this still means real measures, not doing nothing, but training staff on a system’s limitations, risks, intended use, human oversight expectations, and how to handle AI outputs safely is a reasonable way to support that, not a one-size-fits-all course you can point to as a guarantee.

AI Transparency Requirements in 2026

Article 50 covers several distinct transparency obligations, not one blanket rule:

Advertisement
  • Informing people when they’re interacting with an AI system, in relevant circumstances
  • Marking certain AI-generated or manipulated content, including deepfakes
  • Disclosure requirements around emotion recognition and biometric categorisation systems
  • Marking certain AI-generated content published for public-interest purposes

Most of these apply from August 2, 2026. AI systems generating synthetic audio, image, video, or text that were placed on the market before August 2, 2026 have until December 2, 2026 to comply with the Article 50(2) marking and detection obligation specifically.

What Role Does Your Business Have Under the AI Act?

The AI Act’s obligations depend heavily on which role you play, and it’s easy to assume you’re not covered simply because you didn’t build the AI system yourself.

  • Provider: develops an AI system or model and places it on the market or puts it into service under its own name, or has one developed with that intent
  • Deployer: uses an AI system under its own authority, this covers most businesses simply using a third-party AI tool
  • Importer: brings an AI system from outside the EU into the EU market
  • Distributor: makes an AI system available on the EU market without being its provider or importer
  • Product manufacturer: places a product on the market with an AI system embedded in it under its own name or trademark
  • Authorised representative: acts on behalf of a non-EU provider for the purposes of the Act

This distinction matters in practice. A company using an AI recruitment tool built by another vendor usually isn’t the provider of that system, it’s the deployer, while the vendor carries the provider obligations. The two roles carry different requirements, so knowing which one applies to you is often the first real question, not an afterthought.

How the EU AI Act and GDPR Work Together

These two frameworks can apply to the same AI use case, but they ask different questions. Treating them as one combined checklist tends to produce compliance gaps, since neither law substitutes for the other.

GDPR asks: What personal data are you processing? What’s your lawful basis? What’s the purpose? What rights do individuals have over that data? Is the processing transparent? Are any international transfers lawful? Does this require a Data Protection Impact Assessment (DPIA)?

The AI Act asks: What type of AI system is this? What role do you play, provider, deployer, or something else? Is the practice prohibited outright? Does the system count as high-risk? Do transparency rules apply? Are GPAI obligations relevant? What documentation, human oversight, or other requirements follow from the answers?

The two frameworks can apply to the same AI use case at the same time, so it’s worth assessing them together as part of one review rather than as two separate, disconnected compliance projects.

Key GDPR Checks When Using AI

These are the GDPR questions that come up most often once AI enters the picture.

Lawful basis

Identify which Article 6 lawful basis supports the processing involved in training, fine-tuning, or running the AI system. Consent, legitimate interests, and contractual necessity are the ones that come up most often, but the right basis depends on the specific processing activity, not the AI system as a whole.

Special category data

Check whether the data involves health, biometric, or other special-category information that triggers Article 9. AI systems that process images, voice, or health-adjacent data are the most common places this gets missed.

Purpose limitation and data minimisation

Review whether you’re sending more personal data to the AI system than the task actually requires. It’s common for integrations to pass an entire record to an AI service when only a few fields are relevant.

Transparency

Confirm that individuals have actually been told, in practice, that AI is involved in processing their data, not just that a general privacy policy technically covers it somewhere.

Controller vs processor

Determine who decides the purposes and means of the processing, you or the AI vendor, for this specific activity. The answer can change depending on the exact feature or integration, so check per use case rather than assuming one role covers every interaction with a vendor.

Does AI need a data processing agreement under GDPR?

Where a vendor acts as your processor, GDPR Article 28 requires an appropriate data processing agreement covering that specific processing activity. Not every AI vendor relationship involves a processor role, so this needs checking individually rather than assumed as a blanket rule.

International transfers

Check whether personal data is being transferred outside the EEA to reach the AI system, and whether a valid GDPR transfer mechanism and safeguards are in place. Many popular AI services process data on servers outside the EEA, so this step gets missed more often than it should.

Does AI need a DPIA under GDPR?

Assess whether the processing meets the Article 35 threshold for requiring a Data Protection Impact Assessment. AI-driven processing that involves systematic monitoring, special-category data, or large-scale profiling is more likely to trigger this requirement than routine, low-stakes uses.

Automated decision-making

Determine whether the AI system makes or meaningfully supports decisions about individuals in a way that engages Article 22, particularly for anything with legal or similarly significant effects, like credit, employment, or eligibility decisions.

Retention and security

Confirm how long AI-related personal data is kept and what security measures protect it, including any data the AI vendor itself retains for its own purposes, such as model improvement, which is worth checking in the vendor’s terms separately.

When Does GDPR Apply, and When Does the AI Act Apply?

SituationGDPREU AI Act
AI system processes personal dataPotentially, run the standard analysisDepends on the system and use case
AI system doesn’t process personal dataPotentially not, for that specific processingPotentially, depending on the system
High-risk recruitment AI processing applicant dataLikely relevantPotentially high-risk, subject to classification
AI-generated public-interest textDepends on whether personal data is processedArticle 50 transparency rules may apply
Third-party AI tool used internallyDepends on the data processing involvedDepends on your role, the system, and its use

EU AI Act vs GDPR Comparison

GDPREU AI Act
Main focusPersonal data processingAI systems and related risks
Applies toControllers, processors, and related actorsProviders, deployers, and other operators within scope
ApproachRights and accountability-basedRisk-based
Personal dataCentral to the regulationRelevant where an AI system processes it, not the core focus
AI-specific rulesLimitedCore purpose of the regulation
Impact assessmentsDPIA where GDPR Article 35 requires oneRisk classification, conformity assessment, and other requirements depending on the system and role
TransparencyYes, toward data subjectsYes, for specified AI uses
EnforcementNational data protection authoritiesNational market surveillance authorities, with the Commission handling GPAI directly
Maximum headline fine€20M or 4% of global turnoverUp to €35M or 7% for prohibited practices

Do You Need to Comply With Both? A Few Examples

  • An AI chatbot that doesn’t process personal data: the AI Act may still be relevant depending on the system and its use. GDPR may not apply to that particular processing if no personal data is genuinely involved.
  • An AI recruitment tool processing applicant data: GDPR is almost certainly relevant. AI Act high-risk rules may also apply, depending on the specific use case and classification, subject to the delayed timeline above.
  • An AI tool analyzing customer personal data: requires a GDPR assessment. Whether the AI Act applies depends on the system, your role, and the specific use case.
  • AI-generated marketing content: AI Act transparency rules may apply in specific circumstances, such as deepfakes or certain AI-generated text on matters of public interest, but the Act does not require every piece of AI-generated marketing content to carry the same public-facing label. GDPR relevance depends on whether personal data is processed as part of generating or targeting that content.

Your EU AI Act and GDPR Compliance Checklist

  1. Inventory your AI systems. List what AI tools and models your business builds, deploys, or relies on, including third-party tools.
  2. Classify each system. Determine which AI Act rules may apply to each system, including prohibited-practice rules, high-risk classification, transparency obligations, GPAI requirements where relevant, and other applicable requirements.
  3. Map personal data separately. For each AI use case, identify whether personal data is involved and run the standard GDPR analysis: lawful basis, purpose, retention, and individual rights.
  4. Review your AI vendor relationships. Don’t assume every AI vendor is automatically your GDPR processor. Determine each vendor’s role for each specific processing activity.
  5. Check for required agreements. Where a vendor processes personal data on your behalf as a processor, GDPR Article 28 requires an appropriate data processing agreement. Review the vendor’s terms, subprocessors, data locations, and transfer mechanisms.
  6. Assess international data transfers. Check whether AI vendors or other service providers transfer personal data outside the EEA, and whether an appropriate GDPR transfer mechanism and safeguards are in place.
  7. Update privacy notices where needed. Review your privacy notices to ensure they accurately explain relevant AI-related processing, purposes, legal bases, recipients, retention, and individual rights, rather than adding a generic “we use AI” paragraph.
  8. Build AI literacy into your team. Take measures to support the development of relevant staff’s understanding of a system’s limitations, risks, intended use, and oversight expectations for their role, consistent with the amended Article 4.
  9. Assess automated decision-making. Where AI is used to make or meaningfully support decisions about individuals, determine whether GDPR’s rules on automated decision-making, including Article 22, are relevant.
  10. Document your decisions as you go. Note why each system was classified a certain way, why GDPR does or doesn’t apply, each vendor’s determined role, which transparency requirements apply, and what training or assessments you’ve completed. This turns the checklist into a record you can actually point to later, not just a one-time exercise.
  11. Check your transparency obligations specifically. Confirm whether any system needs to disclose AI interaction to users, mark generated or manipulated content, or flag emotion recognition or biometric categorisation use, see the transparency section below for specifics.

AI Act and GDPR Fines and Enforcement

The AI Act does not have one flat maximum fine. Its main penalty levels include up to €35 million or 7% of worldwide annual turnover for prohibited practices under Article 5, up to €15 million or 3% for many other violations, and up to €7.5 million or 1% for certain incorrect or misleading information supplied to authorities. GPAI providers are subject to a separate Commission enforcement framework, also with fines of up to €15 million or 3%. The €35 million/7% maximum applies to prohibited practices; it is not the maximum penalty for every AI Act violation.

Violation typeMaximum fine
Prohibited AI practices (Article 5)€35M or 7% of global turnover, whichever is higher
Other AI Act obligations, including high-risk and transparency breaches€15M or 3% of global turnover
Supplying incorrect, incomplete, or misleading information to authorities€7.5M or 1% of global turnover
GPAI provider obligations, enforced by the CommissionUp to €15M or 3%

For SMEs, including startups, Article 99 limits each fine to the lower of the fixed amount or the applicable percentage. For larger companies, the applicable maximum is generally determined using the higher of the fixed amount or the percentage-based amount. The July 2026 amendment introduced a similar lower-of rule for small mid-cap companies, applying to the middle and information-request penalty tiers rather than the top Article 5 tier. That’s a meaningful protection, though the fines can still be significant relative to a small company’s revenue.

GDPR’s maximum fine remains €20M or 4% of global annual turnover, a separate and lower ceiling than the AI Act’s top tier.

A word of caution on real-world fine examples: some widely cited cybersecurity and privacy fines, such as the Dutch authority’s fine against Clearview AI and the Italian authority’s fine against OpenAI, were GDPR enforcement actions, not EU AI Act cases. The two enforcement regimes are separate, and citing a GDPR fine as an “AI Act fine” is a common but incorrect conflation. If you’re researching enforcement precedent for your own risk assessment, verify which law each case was actually decided under, and check current status, some cases have seen later legal developments.

Common Compliance Mistakes

  • Assuming one EU user triggers the AI Act. Territorial scope depends on specific facts about your role and the AI system’s output, not a single user’s location.
  • Treating GDPR and AI Act enforcement as interchangeable. They’re separate legal frameworks with separate enforcement bodies.
  • Assuming every AI vendor is automatically a GDPR processor. This depends on what the vendor actually does with the data and why.
  • “Follow the strictest rule and comply everywhere.” Different jurisdictions have different definitions, exemptions, and requirements. A common baseline can reduce duplicated work, but it doesn’t replace jurisdiction-specific analysis.
  • Treating the 2027/2028 delay as “nothing to do yet.” The underlying inventory and classification work still needs to start now.

For Businesses Outside the EU

Being outside the EU doesn’t automatically exempt you. What matters is whether you fall into one of the AI Act’s territorial scope categories, and GDPR has its own, separate scope that doesn’t always line up with the AI Act’s. A few questions worth working through if your business operates outside the EU:

  • Are you placing an AI system or model on the EU market?
  • Are you acting as a provider or deployer covered by the Act’s specific role definitions?
  • Is your AI system’s output used within the EU, even if you have no EU office or EU customers as such?
  • Are you supplying an AI component to another organisation that operates in the EU?
  • Do you operate through an EU-based entity, distributor, or authorised representative?
  • Does GDPR separately apply because your processing falls within GDPR’s own territorial scope, regardless of whether the AI Act applies?

That last point matters: the AI Act and GDPR use different scope tests. An AI Act analysis may depend on where an AI system is placed on the market, where a provider or deployer is established, or where the system’s output is used. GDPR scope depends on its own territorial rules, including establishment and certain activities involving people in the EU. One law applying does not automatically mean the other applies, so don’t assume that clearing one review means you’ve cleared both.

Free Official Compliance Resources

Frequently Asked Questions

Does the high-risk AI deadline delay mean I can wait until 2027?

Not practically. The compliance deadline moved, but the work of inventorying your AI systems and classifying which ones are high-risk still takes significant time. Businesses that start now have time to refine their approach. Businesses that wait until late 2027 will be working under real time pressure.

Does the EU AI Act apply to companies outside the EU?

It can. Being outside the EU doesn’t automatically exempt or cover a business, the specific Article 2 scope conditions determine whether the Act applies: whether you place an AI system on the EU market, deploy AI as an EU-based entity, or produce AI output that’s used in the EU.

Does GDPR apply if an AI company has EU users?

Not simply because the users are EU residents. GDPR territorial scope depends on the circumstances described in Article 3, including factors such as establishment in the EU and certain processing activities related to offering goods or services to, or monitoring the behaviour of, people in the EU. The specific facts should be assessed rather than relying on nationality or residence alone.

If I comply with GDPR, does that cover the AI Act too?

No. They regulate different things. GDPR compliance addresses your personal data handling. It doesn’t address AI-specific requirements like risk classification, transparency labelling, or conformity assessments under the AI Act. Both need their own assessment.

Do I need a Data Processing Agreement with every AI vendor?

Only where that vendor processes personal data on your behalf as a processor under GDPR Article 28. Not every AI vendor relationship involves that role, so check each one individually rather than assuming a blanket requirement.

Do AI systems always need to be labelled as AI-generated?

No. Article 50 contains several different transparency obligations that apply in specific circumstances, not one universal label. These include requirements concerning direct interaction with AI, certain AI-generated or manipulated content, deepfakes, emotion recognition, biometric categorisation, and certain public-interest content. The Act does not impose one blanket “AI-generated” label on every piece of AI-generated content.

What’s the actual maximum AI Act fine?

€35 million or 7% of global annual turnover, whichever is higher, but only for prohibited AI practices under Article 5. Most other violations, including high-risk and transparency breaches, sit at the lower €15 million or 3% tier.

Final Takeaway

The regulatory picture around the EU AI Act changed meaningfully in mid-2026. The core obligations haven’t disappeared, they’ve been rescheduled, and some, like prohibited practices and GPAI provider duties, never moved at all. The practical approach is to start building your AI inventory and classification work now. Treat GDPR and the AI Act as related but separate assessments, and get specific legal advice for anything involving cross-border operations, vendor contracts, or high-stakes AI use cases such as recruitment or credit decisions.

For the broader compliance picture, see our AI compliance guide and the complete compliance guide.

Sourced from the Official Journal of the European Union, the European Commission’s Digital Strategy pages, and the European Data Protection Board. This article reflects the regulatory position as of September 2026 and does not constitute legal advice. PenPonder does not have commercial relationships with any vendor, law firm, or compliance tool mentioned in this article.

Share.

Mansoor Ali is the Technical Editor at PenPonder and the founder of MajestySEO. With over 14 years of hands-on experience in technical SEO, WordPress architecture, and site security, he specializes in building and recovering digital assets. He founded his agency in 2012 and writes strictly from personal experience, breaking down complex technical guidelines into steps that actually work in the real world.

Advertisement
Leave A Reply