← Back to all articles
Insights

EU AI Act vs GDPR: A Plain-English Guide to Dual Compliance

Generated image

If your organisation deploys AI that processes personal data - a hiring tool, a credit-scoring model, a customer-service chatbot - you are already living under two regulatory frameworks at once. The EU AI Act (Regulation (EU) 2024/1689) and the GDPR (Regulation (EU) 2016/679) both apply. Neither cancels the other out.

This guide explains the relationship in plain English, maps the six areas where the two frameworks overlap, and ends with a practical action list for running one compliance programme that satisfies both.


The Core Framing: Two Laws, One AI System

Think of it this way: GDPR governs the personal data flowing through an AI system; the AI Act governs the AI system that processes that data.

Recital 10 of Regulation (EU) 2024/1689 states explicitly that the AI Act "does not seek to affect the application of existing Union law governing the processing of personal data," including the GDPR. The AI Act is, at its heart, a product-safety law - it treats AI systems like products that must be made safe through harmonised European rules. The GDPR, by contrast, is a fundamental rights law that gives individuals a wide range of rights in relation to the processing of their personal data.

The consequence is straightforward: an AI system that processes personal data must independently satisfy both frameworks. GDPR governs how personal data is processed; the AI Act governs the risks posed by the AI system itself. They are complementary, not substitutes.

star Important

Both frameworks apply simultaneously. Every AI system that processes personal data still needs its own GDPR lawful basis under Article 6 (and Article 9 for special-category data), data minimisation, purpose limitation, and data subject rights — independently of whatever the AI Act requires. GDPR compliance is a floor, not a ceiling.


Key Differences You Need to Understand

Before diving into the overlaps, it helps to be clear on where the two frameworks genuinely diverge.

1. Scope

The AI Act applies to AI systems regardless of whether personal data is involved. It is a horizontal product-safety regulation: if you place an AI system on the EU market or put it into service in the EU, the Act applies - even if the system processes no personal data at all. GDPR, by contrast, only applies when personal data is processed. The broad definition of "processing" under GDPR (which includes storage, retrieval, and use) means that in practice most AI systems will trigger both frameworks - but the AI Act's scope is wider.

2. Regulatory Model

The AI Act uses a pre-market conformity assessment model - closer to CE marking for machinery than to data protection law. High-risk AI systems must be assessed, documented, and registered before deployment. GDPR uses an ongoing accountability model: you must demonstrate compliance continuously, through records of processing activities, DPIAs, and data subject rights management. Both require documentation, but the timing and purpose differ.

3. Penalties

Under Article 99(3) of the AI Act, non-compliance with the Article 5 prohibited practices is subject to fines of up to EUR 35,000,000 or 7% of total worldwide annual turnover for the preceding financial year, whichever is higher. GDPR's maximum fine under Article 83(5) is EUR 20,000,000 or 4% of global annual turnover, whichever is higher. The AI Act's top tier therefore significantly exceeds GDPR's ceiling.

For high-risk AI system non-compliance (provider obligations, deployer obligations, transparency under Article 50), the AI Act's mid-tier applies: up to EUR 15,000,000 or 3% of worldwide annual turnover under Article 99(4). GPAI model providers face a separate enforcement track under Article 101: fines of up to EUR 15,000,000 or 3% of annual worldwide turnover, imposed directly by the European Commission rather than national authorities.

Penalty Comparison: EU AI Act vs GDPR
Violation CategoryAI Act MaximumGDPR MaximumWho Enforces
Prohibited practices / most serious breaches€35M or 7% of global turnover (Art. 99(3))€20M or 4% of global turnover (Art. 83(5))National market surveillance authorities
High-risk AI non-compliance / transparency failures€15M or 3% of global turnover (Art. 99(4))€10M or 2% of global turnover (Art. 83(4))National market surveillance authorities
GPAI model obligations€15M or 3% of global turnover (Art. 101)N/AEuropean Commission / AI Office
Misleading information to authorities€7.5M or 1% of global turnover (Art. 99(5))Covered under Art. 83(4)National market surveillance authorities

4. Who Enforces

GDPR is enforced by data protection authorities (DPAs) - the ICO in the UK, the CNIL in France, the DPC in Ireland, and so on. The AI Act is enforced by national market surveillance authorities and, for GPAI model providers, by the EU AI Office (a body within the European Commission). These are different regulators. A single AI incident involving personal data could, in principle, attract scrutiny from both a DPA and a market surveillance authority - for distinct violations under each framework.


The Relationship in Law

The AI Act is "without prejudice" to the GDPR. This means GDPR continues to apply in full to any personal data processing that occurs within an AI system's lifecycle - training, validation, inference, logging. Providers and deployers of AI systems retain all their obligations as data controllers or processors under GDPR, regardless of what the AI Act requires.

Distinct violations under each framework can be penalised separately. If an AI system both processes personal data unlawfully (a GDPR breach) and fails to meet high-risk conformity requirements (an AI Act breach), both sets of penalties are potentially in play. However, Article 99(7)(c) of the AI Act requires authorities to take into account whether other authorities have already applied fines for the same conduct - a proportionality mechanism that limits, though does not eliminate, the risk of compounding penalties for a single underlying act.


Six Areas of Overlap - and How to Harmonise Them

The good news: much of the work you do for one framework directly supports the other. Here are the six main areas where a single, integrated programme pays dividends.

1. Data Governance

GDPR requires data minimisation (Article 5(1)(c)), purpose limitation (Article 5(1)(b)), and accuracy (Article 5(1)(d)). The AI Act's Article 10 imposes detailed data governance requirements on high-risk AI systems - training, validation, and testing datasets must meet quality criteria, be relevant, representative, and free from errors.

Reuse: Your GDPR data inventory and processing records are a natural starting point for the AI Act's Article 10 dataset documentation. The purposes differ - GDPR protects individuals; Article 10 ensures system safety - but the underlying data mapping work is largely the same. Note that Article 10(5) of the AI Act creates a narrow additional permission to process special-category data for bias detection and correction, but GDPR Article 9 conditions must still be satisfied simultaneously.

2. Transparency

GDPR Articles 13-15 require transparency about how personal data is processed. AI Act Articles 11-13 require transparency about how AI systems function - their capabilities, limitations, and intended purpose. Article 50 adds specific transparency obligations for certain AI interactions (chatbots, emotion recognition, deepfakes).

Reuse: For AI systems processing personal data, these requirements can be met through a single layered disclosure - an AI system transparency notice that incorporates GDPR processing information. The audiences and legal bases differ, but a well-designed notice satisfies both.

3. Impact Assessments

This is the area that generates the most confusion, so it deserves careful treatment.

  • GDPR Article 35 requires a Data Protection Impact Assessment (DPIA) before processing likely to result in high risk to individuals - AI-driven profiling, large-scale monitoring, and automated decision-making sit squarely within that category.
  • AI Act Article 27 requires a Fundamental Rights Impact Assessment (FRIA) before deploying certain Annex III high-risk systems.

These are not the same document. The FRIA must complement any DPIA already conducted - it does not replace it. A DPIA focuses on data subjects and personal data risks; a FRIA considers the risks to fundamental rights of all individuals affected by the system, including those whose personal data was never processed. Article 27(4) of the AI Act explicitly allows deployers who have already performed a DPIA to leverage it for the FRIA - a mechanism of documentary economy, not substantive equivalence.

Research published in 2026 found that DPIAs are always required in 23 out of the 25 subclauses of Annex III of the AI Act, which means that for the vast majority of high-risk AI deployments, both assessments will be needed. The practical approach: build a combined DPIA/FRIA template that satisfies both requirements from a single assessment exercise, with clearly labelled sections for each obligation.

Where they differ in purpose: Non-compliance with a DPIA can result in significant GDPR fines; the AI Act does not specify separate sanctions for failing to conduct a FRIA (though failure to comply with Article 27 as a deployer obligation falls within the Article 99(4) tier). A DPIA that identifies high residual risks requires prior consultation with the supervisory authority; a FRIA does not have the power to prevent deployment.

4. Human Oversight

GDPR Article 22 gives individuals the right not to be subject to solely automated decisions that produce legal or similarly significant effects - and requires human review on request. The AI Act's Article 14 requires that high-risk AI systems be designed to allow effective human oversight, including the ability to override, interrupt, or disregard system outputs.

Reuse: Your Article 22 GDPR human-review mechanisms are a direct building block for Article 14 AI Act oversight. Document them together. Note the scope difference: Article 22 GDPR is triggered by the nature of the decision; Article 14 AI Act applies to all high-risk systems regardless of whether the decision is automated.

5. Risk Management

GDPR requires ongoing risk assessment through continuous DPIA review and the accountability principle (Article 5(2)). The AI Act's Article 9 requires a continuous risk management system for high-risk AI - covering known and reasonably foreseeable risks throughout the system's lifecycle, with post-market monitoring under Article 72.

Reuse: Build a single continuous risk review process that covers both frameworks. Your GDPR risk register and DPIA review cycle provide the governance infrastructure; extend it to capture AI-specific risks (accuracy degradation, distributional shift, adversarial inputs) required by Article 9.

6. Documentation and Record-Keeping

GDPR requires records of processing activities (Article 30) and documentation sufficient to demonstrate compliance (the accountability principle). The AI Act requires extensive technical documentation under Article 11 and Annex IV - system architecture, training data, performance metrics, risk management files - plus automatic logging under Article 12.

Reuse: Policy libraries, audit trails, and governance procedures built for GDPR provide a credible scaffold for AI Act documentation. However, the AI Act requires considerably more elaborate documentation of development and design choices than GDPR's DPIAs and processing records. Maintain distinct registers - your Record of Processing Activities alongside your AI system inventory; your DPIAs alongside your Article 9 risk management files and Article 11 technical documentation packages - but build them on shared governance infrastructure.

lightbulb Tip

Article 47 of the AI Act requires providers of high-risk AI systems to include a statement of GDPR compliance in their declaration of conformity where the system processes personal data. This is a formal legal link between the two frameworks — and a practical reason to complete your GDPR analysis before finalising your conformity assessment.


Why GDPR Compliance Is a Foundation, Not a Finish Line

Organisations with mature GDPR programmes have a genuine head start: data inventories, DPIAs, accountability frameworks, and privacy-by-design cultures all translate directly into AI Act readiness. But GDPR compliance alone is not sufficient. You must add AI-specific elements that GDPR simply does not require:

  • System classification - determining whether your AI system falls within Annex III high-risk categories (biometrics, employment, credit, education, law enforcement, critical infrastructure, and others)
  • Technical documentation under Article 11 and Annex IV
  • Conformity assessment - self-assessment or third-party, depending on the system type - and CE marking
  • AI-specific transparency under Article 50 (chatbot disclosure, synthetic content labelling, emotion recognition notices)
  • Registration in the EU database of high-risk AI systems before deployment

It is estimated that a large majority of Annex III high-risk AI systems process personal data - making dual compliance the norm rather than the exception for organisations deploying AI in regulated domains. This is an estimate based on the nature of the Annex III use cases (hiring, credit, biometrics, law enforcement), not a precise figure from the regulation itself.


Timeline: Where Things Stand

The GDPR has applied since 25 May 2018. The AI Act entered into force on 1 August 2024 and applies in phases:

  • 2 February 2025 - Article 5 prohibited practices and Article 4 AI literacy obligations became enforceable.
  • 2 August 2025 - GPAI model obligations (Articles 51-56), governance framework, and the penalties chapter (Article 99) became applicable.
  • 2 August 2026 - Most Article 50 transparency obligations apply. The AI Office's enforcement powers over GPAI model providers activate.

On the high-risk Annex III obligations: the Digital Omnibus on AI - a provisional agreement reached on 7 May 2026 between the European Parliament and the Council - deferred the Annex III high-risk deadline from 2 August 2026 to 2 December 2027. The Council gave its final green light on 29 June 2026, following Parliament's formal endorsement on 16 June 2026. The amendments are expected to be published in the Official Journal and enter into force shortly thereafter. Until formal publication, the original 2 August 2026 deadline remains the legal baseline - and the Omnibus does not change the fine ceilings, the Article 5 prohibitions, or the GPAI obligations.

The practical message: the extra time on Annex III is a deferral, not a reprieve. The classification work, system inventory, and documentation architecture need to be built now.


One Programme, Two Frameworks: Your Action List

The most efficient approach is a shared governance layer that serves both regimes simultaneously - not two parallel workstreams.

1
Build your AI system inventory

List every AI system your organisation provides or deploys — standalone, embedded, internally built, procured. For each system, record: does it process personal data? Does it fall within an Annex III category? This inventory is the foundation for both your GDPR Record of Processing Activities and your AI Act risk classification.

2
Classify risk under both frameworks

For GDPR: identify the lawful basis, assess whether a DPIA is required under Article 35, and document data subject rights obligations. For the AI Act: determine the risk tier (prohibited, high-risk, limited, minimal) and, for high-risk systems, identify the relevant Annex III category. Do this in a single triage workflow.

3
Run an integrated DPIA/FRIA

Build a combined assessment template with clearly labelled sections for each obligation. Conduct the DPIA first (GDPR Article 35), then extend it to address the broader fundamental rights dimensions required by AI Act Article 27. Document which sections satisfy which obligation. Neither authority requires separate physical documents — but both require their specific content to be demonstrably present.

4
Align transparency notices

Draft a layered transparency notice that covers GDPR Articles 13–15 processing information and AI Act Articles 11–13 system information in a single document. Add Article 50 disclosures (chatbot identification, synthetic content labelling) where applicable. Review notices before the 2 August 2026 Article 50 deadline.

5
Build a unified risk management cycle

Extend your GDPR risk register and DPIA review cycle to capture AI Act Article 9 risks — accuracy degradation, distributional shift, adversarial inputs, post-market monitoring findings. One risk committee, one review cadence, two regulatory frameworks.

6
Prepare your technical documentation and conformity assessment

For high-risk AI systems, draft the Article 11 / Annex IV technical documentation structure now. Use your GDPR accountability documentation as a scaffold, but add the AI-specific elements: system architecture, training data governance, performance metrics, and the risk management file. Engage a notified body early if third-party conformity assessment is required.

7
Assign clear ownership at the intersection

Decide who is responsible when a high-risk AI system processes special-category data — the point where GDPR's most stringent provisions meet the AI Act's highest-obligation tier. This intersection carries the greatest regulatory exposure and requires integrated governance. Typically this means the DPO and the AI compliance lead working from a shared programme, not separate silos.

8
Monitor both enforcement landscapes

Track guidance from your national DPA (for GDPR) and your national market surveillance authority (for the AI Act), as well as the EU AI Office for GPAI obligations. The EDPB published a harmonised DPIA template in April 2026; the AI Office is expected to publish a FRIA template. Both will shape best practice for integrated assessments.


The Interactive Dual-Compliance Mapper

Use the tool below to map your AI system against both frameworks and identify which obligations apply - and where the work overlaps.


A Note on What This Guide Is Not

This is a plain-English orientation to the relationship between the EU AI Act and the GDPR. It is not legal advice, and it does not substitute for qualified legal or regulatory counsel. Both regulations are complex, the AI Act's supporting standards are still being finalised, and the Digital Omnibus amendments are subject to formal publication. Always verify your obligations against the official text of Regulation (EU) 2024/1689 and Regulation (EU) 2016/679, and the latest guidance from the EU AI Office and your national data protection authority.

For the official AI Act text and supporting documents, see artificialintelligenceact.eu and the AI Act Service Desk.